Leaderboard
Popular Content
Showing content with the highest reputation since 09/04/26 in all areas
-
4 points
New 10 Gbit/s server available (SE)
Tim Cooks pasta and 3 others reacted to Staff for a post in a topic
Hello! We're very glad to inform you that a new 10 Gbit/s full duplex server located in Stockholm, Sweden, is available: Formosa. The AirVPN client will show automatically the new server; if you use any other OpenVPN or WireGuard client you can generate all the files to access it through our configuration/certificates/key generator (menu "Client Area"->"Config generator"). The server accepts connections on ports 53, 80, 443, 1194, 2018 UDP and TCP for OpenVPN and ports 1637, 47107 and 51820 UDP for WireGuard. Formosa supports OpenVPN over SSL and OpenVPN over SSH, TLS 1.3, OpenVPN tls-crypt and WireGuard. Full IPv6 support is included as well. As usual no traffic limits, no logs, no discrimination on protocols and hardened security against various attacks with separate entry and exit-IP addresses. You can check the status as usual in our real time servers monitor , by clicking the server name. Direct link: https://airvpn.org/servers/Formosa Do not hesitate to contact us for any information or issue. Kind regards & datalove AirVPN Staff -
1 point
I was under a rock, new to airvpn
mktux reacted to Tech Jedi Alex for a post in a topic
It's the furthest thing from Arch tech-wise. Arch tracks upstream and is very often up-to-date (only Fedora is a bit ahead), while AirVPN has been on this IP.Board version for almost a decade soon. I'd say, install it from the AUR and check it out yourself – just like Arch compels you to do -
1 point
I was under a rock, new to airvpn
go558a83nk reacted to mktux for a post in a topic
Hello everyone! I recently learned about the airvpn. What i like is the tools are all opensource, aligns with my ethos. I even used ipleak back in the day to check my ip info as well. Later i found out that it was made by air's team as well. What truly surprised me is the availability of a forum. It's quite rare and i like it. The website reminds me of archlinux, simple and functional not following every UI/UX trends. I don't have a active plan right now as i joined-in today. Missed the deal by a day, oh well. I am using linux, and earlier with another vpn service i used to get the openvpn files and set it up inside the kde plasma network-manager then setup a firewall rule as kill switch. Is eddie gui a better way to connect to airvpn on archlinux, instead of the above method? -
1 pointHello! Thank you for the detailed suggestion. The main reason for this design is privacy. Sharing public exit IP addresses among many customers is one of AirVPN's foundational privacy features, and we deliberately preserve that property for IPv6 as well. Assigning a unique public IPv6 address to each customer or tunnel would make that tunnel's traffic distinguishable by its source address. Websites and other observers able to see multiple connections could use that address to correlate activity belonging to the same tunnel, even without knowing the customer's real identity. With a shared exit address, the address alone does not provide that distinction between customers. Changing the address on each OpenVPN reconnect, or rotating it periodically through Eddie, would reduce the time window for this correlation. However, throughout each address lifetime it would still identify one tunnel rather than be shared by many customers. Rotation therefore does not preserve the same privacy property. We understand the appeal of globally routable tunnel addresses and the compatibility concerns you raise. However, the availability of IPv6 addresses does not resolve this privacy tradeoff: assigning an exclusive public address to each customer would remove a fundamental characteristic of our service. If you have a specific application or reproducible IPv6 issue with the current setup, please share the details so we can examine that separately. Kind regards
-
1 point
New 10 Gbit/s server available (SE)
Staff reacted to Tim Cooks pasta for a post in a topic
Very nice!!! I've had some speed issues with the other Nordic servers, but Formosa speeds are great!!! -
1 point
Eddie shows no servers
19990909jp reacted to alrosm@sbcglobal.net for a post in a topic
do not see anything for windows 7 i wish to keep my old computer everything is expensive right now and i would like to use my computer with win7 until it dies thanks in advance -
1 pointHello! The sustained change you describe deserves investigation, especially since the same setup previously reached 180–200 Mbps. The plateau alone does not establish an imposed bandwidth cap, and we cannot yet link it to a particular server-side change around September 2. Since you have already tried different servers, Gluetun versions and MTUs, we suggest two controlled comparisons before changing more settings: On the NAS, run the direct and VPN tests one after the other, using the same Speedtest application/version and a manually selected Speedtest server ID. Pause other downloads/uploads and record both download and upload speeds. Please confirm whether your two trackers already use the same test server, and verify that the VPN test shows an AirVPN exit IP. If another computer is available, preferably connected by Ethernet to the same router, test AirVPN with a native WireGuard client outside Docker. Use the same AirVPN server, endpoint port and Speedtest destination as the NAS test. Stop the Gluetun tunnel for this comparison, or use a separate AirVPN device key so the two clients do not share a key while connected. If the second computer reaches approximately 200 Mbps while the NAS remains near 100, that would narrow the investigation toward the NAS/container path. If both show the reduction, we should investigate the shared network path and VPN endpoint further. During the NAS test, please also check CPU usage per core and any CPU limit configured for the container. An overall reading of 60% does not rule out one core reaching its limit, although it does not by itself explain why performance changed. Please share the exact AirVPN server names and endpoint ports tested, the Speedtest server ID, download/upload results, and test times with your time zone. Those details will let us correlate your measurements with the relevant servers. Take care not to post your WireGuard private key or full configuration file. Kind regards
-
1 pointFantastic news! Good to have more servers in the Nordics. Hopefully Baltics would also receive an update soon.
-
1 point
Castula needs help!
Lance Kaufman reacted to Flx for a post in a topic
For now...things back to normal. I'll give it about 6 days to stabilize. Unless others have other "dillemas". -
1 pointNorway's servers are over 60% most of the day. Can you ship a couple of Sweden's unused servers to Oslo? There's like 5 not being used.
-
1 point
Eddie Desktop Edition 2.27 beta released
lotuslove165 reacted to OWild for a post in a topic
eddie 2.27.2 works fine for me (debian 13 trixie / KDE / Wayland) -
1 point
Eddie 2.26.2 not MacOS28 compatible - Why?
ethanlee93 reacted to GoetzPhilippinen for a post in a topic
Why does it tell me I must install Rosetta now - why after years its still not ARM compatible? -
1 point
Cannot reuse the host VPN connection on a virtual machine with network lock enabled.
cheeze reacted to jx35552zza for a post in a topic
Quick add: I'm now using VMs where networking works with Network Lock enabled. I use VMware Workstation, I do not remember what I was using when I wrote my previous comment in 2023. That said, I've only tested NAT mode, I haven't tried Bridged or other setups since I haven't used them recently. One thing to note is that VMware's NAT hands out 127.0.0.1:53 as the DNS server via DHCP for my setup. So I always change it manually on the guest machines that I set up. That said, I’m not entirely sure how solid Network Lock actually is. The Eddie client tends to be pretty unstable for me in a lot of areas. Still, it does display the lock icon when the VPN is active. -
1 point
kvm/qemu guest nat blocked by network lock
lotuslove165 reacted to cheeze for a post in a topic
This has been an issue for years. A kvm/qemu guest using NAT (default) to connect to the internet via the host does not work because Eddie network lock prevents it. Can or will AirVpn whitelist libvirt's virtual interfaces by default in Network Lock. Thank you -
1 pointIt works! 😀 Thank you so much for your work! This fix for a persistent bug related to privilege escalation allows me to upgrade directly from version 2.25.1 to version 2.27.2. I can therefore confirm to anyone who is a bit too quick to criticize the eddie-ui user interface that version 2.27.2 poses no obstacle to its use on current operating systems, and that—among many other options—it allows you to choose between 3 WireGuard protocols and more than 50 for OpenVPN! When free software works perfectly, is secure, and offers the end user so much freedom of choice in a graphical interface, we should 👏 thank and encourage the developers rather than criticizing the project for no good reason without contributing improvements in the form of pull requests or forks. 🌻 I hope that other users who encountered similar privilege escalation issues will take as much pleasure as I did in thanking the development team.
-
1 point
Non-Deterministic BSOD 0x3B in wireguard.sys on Disconnect
knighthawk reacted to blockchain420 for a post in a topic
Hello AirVPN Support and Development Team, I am writing to report a stability issue regarding a non-deterministic Blue Screen of Death (BSOD) with error code **0x3B (SYSTEM_SERVICE_EXCEPTION)** triggered when disconnecting from a WireGuard tunnel via the Eddie client. Because this crash happens intermittently during the teardown sequence, it strongly indicates a **Race Condition** or **Use-After-Free (UAF)** vulnerability inside the `wireguard.sys` driver wrapper, where memory buffers are accessed after being invalidated by the NDIS subsystem. **System Environment** * **OS:** Windows 10 IoT Enterprise LTSC 2021 (64-bit) * **Build Number:** 19044.7725 * **Eddie Version:** Any version utilizing WireGuard 1.0.0.0 * **WireGuard Driver Version:** WireGuard 1.0.0.0 **Bug Check Details & Stack Trace Summary** * **Bug Check Code:** 0x3B (`SYSTEM_SERVICE_EXCEPTION`) * **Exception Code:** 0xC0000005 (`EXCEPTION_ACCESS_VIOLATION`) * **Faulting Address:** `0xfffff8004f01111e` (Inside `ndis.sys`) * **Trigger Event:** Disconnecting from the WireGuard tunnel using Eddie. * **Key Stack Frames:** Crash manifests inside `ndis!ndisDeviceControlHandler` triggered by concurrent execution paths originating from `wireguard.sys+0x13b02` and `wireguard.sys+0x13844` during an IOCTL-driven shutdown. **Technical Analysis (Race Condition Hypothesis)** The crash signature and call stack point to a synchronization gap during the driver's teardown phase: 1. **Teardown Initiation:** Eddie issues an IOCTL call to halt the adapter. 2. **Memory Invalidation:** NDIS begins freeing `NDIS_MINIPORT_BLOCK` structures and associated packet buffers. 3. **Concurrent Access:** A pending network interrupt or timer event inside `wireguard.sys` simultaneously attempts to process packets using stale pointers. 4. **Violation:** The driver dereferences the invalidated memory, throwing an access violation within `ndis.sys`. **Reproduction Steps** 1. Launch Eddie and connect to any WireGuard endpoint. 2. Maintain the connection for an arbitrary duration. 3. Click **Disconnect**. 4. **Result:** The client intermittently crashes with BSOD 0x3B instead of executing a clean disconnect. The failure is purely stochastic and independent of network traffic load. **Troubleshooting Performed** * Fast Startup: Disabled. * Clean Install: Performed complete purges of Eddie and residual `wireguard.sys` drivers, followed by clean reinstalls. The issue persists. * Traffic Load: Tested under both idle and high-throughput states; failures occur uniformly, confirming a state-dependent synchronization bug rather than a load-dependent fault. **Impact & Request** This issue undermines system stability on Windows 10 IoT LTSC environments. Since the official WireGuard for Windows client utilizes `Wintun.sys` (which manages adapter concurrency and teardown safely in user-space/TUN architecture), the legacy `wireguard.sys` wrapper appears to lack robust reference counting or synchronization primitives (such as proper spinlock implementation) during NDIS miniport halts. Could you please clarify: * Are you aware of this specific race condition in `wireguard.sys`, and is there an updated build or fix available? * Are there plans to transition Eddie toward native `Wintun.sys` utilization to bypass these kernel-level concurrency constraints? Thank you for your time and assistance in analyzing this behavior. A full kernel memory dump (`MEMORY.DMP`) is attached to this message. 091326-9562-01.dmp -
1 pointHello! We're very glad to announce a special promotion on our long term Premium plans for the end of Summer or Winter, according to the hemisphere you live in. You can get prices as low as 2.06 €/month with a three years plan, which is a 70% discount when compared to monthly plan price of 7 €. If you're already our customer and you wish to stay aboard for a longer period, any additional subscription will be added on top of already existing subscriptions and you will not lose any day. Please check plans special prices on https://airvpn.org and https://airvpn.org/buy Promotion expires on 2026-09-28 09:00 AM UTC. Kind regards & datalove AirVPN Staff
-
1 point
Feature Request: More Ad & Tracker Filter Lists
golom reacted to Tech Jedi Alex for a post in a topic
Your list of filter lists is a copy from uBlock Origin's predefined filter lists, and all of them and most of their variants are integrated into OISD Full, so please use that if you need all the lists you mentioned. Same with OISD NSFW for NSFW content, those two lists are really, really good. You hit the nail on the head. That's why the most popular implementations and suggestions are not those smaller lists, but the projects summarizing/deduplicating them: OISD, Hagezi, Energized (not sure if stlll alive, that one) and others. OISD and Hagezi have been the cornerstone lists in my local network for years now with one false positive a year, maybe. Every profile choice needs a separate (curated) list for that filtering purpose. Currently, AirVPN offers a curated ads/tracking, two security, a dating, a gambling and a porn list. Users can then choose to combine them with any other lists to have their own individual, custom filter – for all devices or just one, if they so choose. An arbitrary definition of profiles takes that freedom away: Some see ads, tracking and privacy as the baseline, some only the most intrusive ads or most known ad domains. If you differ between ads and tracking, chances are you will be tracked without ads being shown. Users should just combine the offered lists to have their own custom definition of strict. -
1 point
Network lock disables kvm networks
lotuslove165 reacted to 89039sa for a post in a topic
I'm using virt-manager and all my created networks stop working when i enable the network lock. Is there some script I could run to renable the networks with the network lock enabled? -
1 point
Network lock disables kvm networks
lotuslove165 reacted to cheeze for a post in a topic
Yes, I understand from researching this that some other VPN's suffer the same issues. It seems when a VPN rewrites the firewall it overwrites the rules libvirt needs to make the NAT connection or maintain the same if the NAT was established before the vpn was was put into service with a network lock enabled. -
1 point
GUI not opening after upgrading to 2.26.2-1 on the AUR
ByteBuccaneer reacted to PhasecoreX for a post in a topic
I got the same error about mscorlib.dll, however I am using Arch with paru instead of yay. By default I have paru build in a chroot, however when I told it not to use a chroot (paru --nochroot eddie-ui) it now runs correctly. Yay doesn't have chroot support so it also worked without any configuration. I am not sure what the difference is between chroot and non-chroot building, but it would be nice to be able to use chroot when building. Regardless of how I build it, the file /usr/lib/mscorlib.dll doesn't exist, so maybe the chroot build thinks it exists for some reason. -
1 point
ANSWERED Firefox(-based browser) startup is stalled when connected to AirVPN with network lock enabled
lotuslove165 reacted to cheeze for a post in a topic
I'll wake this topic up again regarding libvirt. I have the problem with kvm qemu virtual machines not being able to connect due to the Eddie lock not letting the guest machine connect via NAT. It is suspected the issue lies in the way Eddie uses nft and libvert use ip-tables. I tried setting Eddie to Iptables-legacy then closed Eddie and opened it again, but the problem persisted. Should I have rebooted or logged out of the host machine after making the change to iptables-legacy? -
1 point
What's your Share Ratio? (or Total Upload)
Lance Kaufman reacted to DeepAnger for a post in a topic
I probably started before you were born but know that I have 4 times faster upload since I subscribed here. -
1 point
AirDash (Dashboard unofficial for iOS and iPadOS)
Y7h-2dfrgrtAA-3 reacted to zlimteck for a post in a topic
Hello, A lot has happened since my last update (v1.0.4), so here's a recap of everything added. Notes: I now have a paid Apple Developer account, which unlocked native VPN connect/disconnect (see below). Because of that, the project now ships as two builds: AirDash (full): includes native VPN, requires a paid developer account to build yourself AirDash Lite: same app minus native VPN (profile generation/export still works), sideloadable with a free Apple ID, this is the one on GitHub Releases I've also started preparing an actual App Store submission, currently on hold waiting for the Xcode 27 Release Candidate (I'm on macOS 27 beta) plus a French cryptology declaration (ANSSI) that's still being processed. I'll post here once/if it goes live. What's new since v1.0.4: Native WireGuard VPN: connect and disconnect straight from the app via NetworkExtension, no external VPN app needed. Live tunnel status on the Dashboard, one-tap connect from any server's detail page (full build only) Server history & trends: load/connected-users charts per server (1h/24h/7d/30d), a reliability breakdown (healthy vs warning/error), a peak-hours chart highlighting the quietest window, and a Trends screen ranking servers by average load, all powered by a companion history service I run separately, not the AirVPN API Server comparison upgrades: bandwidth and an overlaid historical load chart across compared servers Multiple accounts: add, switch and remove AirVPN accounts, each with its own favorites/sort preferences Device management: add, rename, renew WireGuard keys and remove devices from Settings DNS blocklists: browse available lists (read-only, links out to airvpn.org to manage them) Recent profiles page: dedicated screen with search, sort, filter by protocol, quick reimport, QR code and delete Spotlight search: favorite servers and recent profiles searchable from the system search 4 more Siri Shortcuts: Best Server, Generate Profile, Recent Profiles, Show Profile QR Code Widget redesign: load bars instead of plain text, session duration, favorite indicator, plus a new Small-only "AirDash Account" widget (VPN status, connected server, subscription info) Protocol logos and trademark credits for AirVPN, WireGuard and OpenVPN in Settings Various fixes and polish (favorite badge in server list, best-server scoring rebalanced so a heavily loaded low-ping server no longer wins unfairly, tap a session to jump to its server, etc.) Links: GitHub repo: https://github.com/zlimteck/AirDash Releases: https://github.com/zlimteck/AirDash/releases (currently v1.0.9) As always, feedback and suggestions are welcome. Thanks for reading! GrimZ. -
1 pointStill waiting on return of Lithuanian servers, or even high bandwidth (20gbps) ones in any Baltic country.
-
1 point
GUI not opening after upgrading to 2.26.2-1 on the AUR
ByteBuccaneer reacted to Tech Jedi Alex for a post in a topic
Last time this came up:In short, try building that package in a clean chroot. Usually, it indicates that some package was built against an older version of Mono. CachyOS keeps coming up as the culprit from time to time as it provides a repo with prebuilt AUR packages, some of which are not meant to be distributed like that, but Manjaro is not without its problems, either. -
1 point
Norway needs more servers
Andrew109 reacted to caffeine0030 for a post in a topic
The norwegian servers were great before they were "discovered"! I used to be able to play games on them. But now they are very often maxed and you have to skip around to find one that is at 90% capacity and not 100%. Cant use them to play anymore :/ Also very low chance to get any decent speeds anymore I see m247 has 10Gbit servers available in Norway.... Just saying -
1 pointHello! We're very glad to inform you that a new 10 Gbit/s full duplex server located in Los Angeles, California, is available: Flegetonte. The AirVPN client will show automatically the new server; if you use any other OpenVPN or WireGuard client you can generate all the files to access it through our configuration/certificates/key generator (menu "Client Area"->"Config generator"). The server accepts connections on ports 53, 80, 443, 1194, 2018 UDP and TCP for OpenVPN and ports 1637, 47107 and 51820 UDP for WireGuard. Flegetonte supports OpenVPN over SSL and OpenVPN over SSH, TLS 1.3, OpenVPN tls-crypt and WireGuard. Full IPv6 support is included as well. As usual no traffic limits, no logs, no discrimination on protocols and hardened security against various attacks with separate entry and exit-IP addresses. You can check the status as usual in our real time servers monitor , by clicking the server name. Direct link: https://airvpn.org/servers/Flegetonte Do not hesitate to contact us for any information or issue. Kind regards & datalove AirVPN Staff
-
1 point
New 10 Gbit/s server available (US)
EndUser reacted to go558a83nk for a post in a topic
Just curious why add another server in LA, also with Tzulo like the others, when there's already plenty of bandwidth in that SW region and it provides no redundancy by using a different provider from the others? The Dallas servers are what desperately need an upgrade. 🤠 -
1 point
Slow download speed
zmicier reacted to robertoohoho for a post in a topic
I try switching servers but I usually get the same slow speed. Right now (it's 21:00 local time), it's particularly slow. I was connected to Matar, the best available server according to Eddie, and the download speed from a kDrive was under 200KB/s. I switched to "Crater", same result. I switched to Albali Uppsala Sweden, this time the download speed stalled under 50KB/s! Also, this happens on both of my systems. A few months ago, the speed were good, sometimes very fast. I can't understand what happened. -
1 point
AirDash (Dashboard unofficial for iOS and iPadOS)
Y7h-2dfrgrtAA-3 reacted to zlimteck for a post in a topic
Hello, I'm developing an app called AirDash, it's an AirVPN dashboard that uses the API. It requires at least iOS 26 and iPadOS 26, built-in Swift 6. Notes: I don't have a paid apple developer account, so my only way to offer you a try is either to build the project via Xcode or to use the .ipa of the latest release available (currently v.1.0.4) via your preferred sideloading method. See details in the project readme. Features: Network: Full server list with load, users, health, ping latency, sort (load / name / ping), continent filter, search and favorites Server comparison: Long-press any server to add it to a comparison (up to 3); tap the toolbar button to view them side by side Dashboard: Account info (current IP, VPN status, expiration, credits, sessions, member since); swipe left on a session to disconnect Server detail: WireGuard or OpenVPN profile generation, direct import into the system VPN app, share and QR code (WireGuard) in a ··· menu; recent profiles per server with one-tap reimport Profile history: Recently used server profiles shown in Dashboard and in each server detail; supports one-tap reimport by protocol Biometric lock: Face ID / Touch ID protection, toggleable in Settings App icon: 8 variants: Auto, Classic, Light, Purple, Green, Red, Minimal, Minimal Dark Settings: API key rotation, light/dark/system theme, app icon picker, changelog, credits Notifications: Subscription expiration alerts 7 days and 1 day in advance (delivered by the OS even when the app is closed) Siri Shortcuts: VPN Status, My IP Address, Open Server (navigates directly to a specific server) Widget: Current IP, VPN status and active sessions on the home screen; configurable with a favorite server picker showing load, users and latency (Small, Medium and Large sizes) Quick Actions: Long-press the app icon to jump directly to Dashboard or Network Links: Repositorie Github: https://github.com/zlimteck/AirDash Releases Github: https://github.com/zlimteck/AirDash/releases If any members try it, don't hesitate to give me feedback, and suggestions for improvement. thank you in advance. GrimZ. -
1 point
Discontinuing subscription. Feedback
knighthawk reacted to Staff for a post in a topic
Hello! This is an interesting smearing message that occasionally comes out, trying to exploit the forum we keep open for the community, for some hidden purpose or, we guess, just for hate. You can easily verify that every defect mentioned by the OP is either false or distorted. A community moderator provided some corrections that disprove the OP's claim, here we would like to add just three remarks on subjects we care about: interoperability with other VPN services, infrastructure stability and how good our remote port forwarding system is. We also want to quickly make you aware that the OP never opened a ticket for professional support, so he/she was probably not interested in a solution of his/her problems, but maybe only in building a case based on false or fabricated premises. 1. Eddie Android edition, AirVPN Suite and Eddie Desktop edition allow connections to any VPN supporting either OpenVPN or WireGuard through the most standardized method that can exist, the supported profile for each VPN application (much better than any API, especially when it does not exist on most VPN services). 2. Over the past 16 years AirVPN infrastructure constantly evolved toward more stability and speed, it's all in the records. In AirVPN we have had and we have users connected CONTINUOUSLY for SEVERAL MONTHS. Enough for connection stability? 😉 We could have even longer periods, if it wasn't for the necessity to reboot a server periodically for kernel upgrades. 3. Implementing remote inbound port forwarding over a VPN by having the VPN server use UPnP/NAT-PMP/PCP to dynamically open ports on behalf of clients is generally considered a poor architectural choice because: UPnP was designed for trusted, local networks No authentication in classic UPnP IGD exists Race conditions in a large infrastructure like AirVPN's one becomes an architectural problem UPnP would make "hot change" and other interesting features appreciated by AirVPN customers impossible Privilege escalation. UPnP used outside a local network facilitates various exploits including privilege escalation. The VPN server already controls firewall rules, NAT, routing and connection tracking. Using UPnP as an intermediary adds another protocol layer rather than configuring those systems directly. This depends on your design philosophy, but at the moment management does not see favorably functionality duplication. At the end of the day, such a poor choice would pose a bunch of problems for essentially nothing, as selecting a random port with the additional features is a matter of seconds. Kind regards -
1 point
Apple Silicon version?
PWolverine reacted to refract-hurled for a post in a topic
I bumped into this because of Mac warning for end of support for Rosetta stuff. For anyone that also find this thread, I found the AirVPN Eddie Github code base mention they are working on a "UI 3.x" effort already underway (unreleased on public GitHub): a full native rewrite in C++, Objective-C/Cocoa on macOS see here: https://github.com/AirVPN/Eddie/blob/master/src/readme.coding.md#projects-ui-3x-under-development-not-released-yet-on-public-github So hopefully that development is going well and we will have a native silicon GUI in for Eddie sometime soon. -
1 pointhello. can you give some screenshots for this two moments? Hello! 1. Go to "Settings" > "Advanced" > "Custom AmneziaWG directives", turn on "Enable CPS" switch, disable "Random Presets" and select a web site from the list appearing after you tap on "Preset". Make sure you tap "OK" at the end to confirm (if you just tap "Back" button, the settings will not be stored). 2. Go back to the main view, select "AIRVPN SERVER", long tap the country or the specific server you want to generate and export a configuration file for, and select "Export AmneziaWG profile" or "Open AmneziaWG profie with..." according to your needs. Kind regards
-
1 point
ANSWERED Extremely low torrent speeds sinds last week despite correct port forwarding and WireGuard
knighthawk reacted to Peter Laanstra for a post in a topic
You actually have set a speed limit of 10 kb/s, might have been by accident of clicking that little speedometer icon OMG that's right @ag999. LMAO! Just tested it and was the same. Now I know. I did not know this was a feature to click on that speedometer. 🙈 Hope it helps others... Anyway, I did some CLI speedtests in my gluetun conainer (I have a 1Gbit connection). I think it is what it is... / # speedtest Retrieving speedtest.net configuration... Testing from Global Layer (213.152.161.181)... Retrieving speedtest.net server list... Selecting best server based on ping... Hosted by Qonnected B.V. (Amsterdam) [16.73 km]: 11.237 ms Testing download speed................................................................................ Download: 60.14 Mbit/s Testing upload speed...................................................................................................... Upload: 44.11 Mbit/s / # speedtest Retrieving speedtest.net configuration... Testing from Global Layer (213.152.161.181)... Retrieving speedtest.net server list... Selecting best server based on ping... Hosted by Qonnected B.V. (Amsterdam) [16.73 km]: 12.603 ms Testing download speed................................................................................ Download: 28.36 Mbit/s Testing upload speed...................................................................................................... Upload: 25.01 Mbit/s -
1 point
ANSWERED Extremely low torrent speeds sinds last week despite correct port forwarding and WireGuard
knighthawk reacted to AG999 for a post in a topic
You actually have set a speed limit of 10 kb/s, might have been by accident of clicking that little speedometer icon -
1 pointMay I request the addition of 10Gbps Tokyo and Singapore servers? Thank you.
-
1 pointMan im tempted to buy more time but I think im covered
-
1 pointHey there, Taiwan is a provincial administrative region of China, an inalienable part of China’s territory. But when I checked my IP on ipleak.net, I saw Taiwan was shown with those outdated flags, which is totally wrong. These flags don’t reflect the fact that Taiwan belongs to China. Using them misrepresents Taiwan’s status and goes against the One - China principle. It’s really important to fix this mistake. Please correct the display and stop using such wrong flags. Let’s make sure the info about Taiwan is right, in line with the One - China principle. Thanks for handling this!
-
1 point
-
1 point
Ipv6 question
Divinity3372 reacted to AeroVIP for a post in a topic
Staying connected now already means they are already associated for months with the same IP address. They are no more exposed over time in that scenario than they are already today. Telling users apart on the exit side of a VPN is a trivial task for almost any use case. You can visit https://www.amiunique.org/ with a fresh install of Tor browser and still get fingerprinted down to the individual level. The real benefit of a commercial VPN is the disconnect between input and exit, not the dubious "herd safety" that one thinks might be there. Yes, I mentioned already this is more difficult to accomplish in Wireguard. It rises from the trivial "few hours to get a proof of concept" it is now with OpenVPN to the more substantial "a couple days work" with Wireguard. It would be easier to do in Wireguard with an OnConnect style hook patched in. The good news is such a patch would not be needed client-side. Client-side nothing changes. As I think about it, it's also probably doable with some clever use of libnetfilter_queue and nft queues. Indeed. But what a great selling point for IPv6. And for this service. I see very little anonymity/privacy difference (positive or negative) in implementing this idea. Already today every IP on a v6 /64 is essentially lumped together as a collective whole anyway, since /64's are handed out like candy to everyone. A lot of places log, filter, and block based only on the /64 prefix and just ignore the bottom 64-bits entirely. So giving out unique addresses from that won't really make anyone more or less anonymous and it probably won't circumvent any blocking of this VPN that's in place now or in the future. But what it does buy is the ability to listen on anything without port forwarding. Listening on anything gives you access to everything. So this is a great selling feature for people who implement a VPN at the home-router or VPS level. The idea that NAT-PMP and UPnP will Just Work™ after implementing this would, I think, be very attractive. Something to think about at least. -
1 point
Ipv6 question
Divinity3372 reacted to AeroVIP for a post in a topic
A dynamic 1:1 exit address assigned on a per-connection basis from each server's /64 pool would be a great solution to this. In fact, it's probably doable now with some clever scripting and an nft map where the permanent fdxx:: for each customer is mapped on a per connection basis with an address from the server's /64 routable pool. In wireguard this might be a little ugly today, being that wireguard has no real "connection" state, so you'd want to hook based on going from "no recent handshake" to "recent handshake". So as I think about it it's probably not feasible with scripting alone. But I don't think it would be all that difficult to hardcode a hook that gets called whenever a connection goes from having a late (or non-existant) last handshake to a recent handshake. Handshakes occur every 120-ish seconds, so you could code it for 150 seconds. I'm not suggesting this in the immediate-term, but it's not something that needs to be a "someday...wouldn't it be nice" event either. In OpenVPN it would be a lot easier being that it does have a client-connect script hook, and is probably something that could have a proof-of-concept with a couple hours work. Or just use DHCP to do the same thing. You wouldn't even have to keep track of IP addresses. Each one can be disposable one-time use. You could start at the server /64's ::1 and count up to FFFF:FFFF:FFFF:FFFF for each connection and not run out until, oh, Andromeda collides with the Milky Way. -
1 point
Norway needs more servers
Andrew109 reacted to caffeine0030 for a post in a topic
Yes more norwegian servers would be nice. I was going to make the same suggestion. Also one more server in estonia would be great. Good speeds from Alruba when its not at capacity -
1 point
ANSWERED Opinions on Disabling IPv6
Divinity3372 reacted to Tech Jedi Alex for a post in a topic
Do you think you should disable 5 GHz WiFi? Do you think you should disable LTE on your phone? Do you think you should disable all USB-C ports? That's the kind of question it is. The answer to all of them is another question: Why would you ever think about preferring older tech if you've got the option to use newer? And no, I don't want to hear arguments like "I disable 5G because of radiation" – the only thing irradiated is that thought, irradiated by some web page, probably served on a v4 IP address over an ADSL line (which, interestingly, emits more radiation and consumes more power than a Fiber line and associated infrastructure). v4 is ossified and does not meet today's needs. It's a pain to maintain for people, organizations and everyone and everything in between. The only reason people still use and maintain it is purely out of conveniece. But that's humanity for you, I guess.. Now, let's analyze this, taking the aforementioned convenience into consideration specifically.. Disabling v6 won't do a thing to your connectivity. There are tiny, tiny freckles in the face of the whole internet talking v6 only, but if you disable v4, half of that face will be gone. If you leave both enabled, v6 will be preferred, but through Happy Eyeballs v4 will be tried and preferred itself if v6 was too slow. Doesn't really up the connectivity, it's just a temporary measure while we all transition to v6, but ooh, the convenience.. and also because there are ISPs in the world still assigning v4 only to their customers. Honestly, v6 is almost 30 years old itself and some parts of the world still treat it as the New Hot Shit™. Talking configuration, OpenVPN's config options differ from those for v4 (--route != --route-ipv6, for example), so for some use cases you will find v4 easier to configure than v6. For Wireguard, I suppose it doesn't really matter since it was written in a time where v6 was actually in use (while OpenVPN was written when Tyrannosaurus Rex was still the apex predator, I believe. Small dino hacking away at a miniature keyboard at the foot of some volcano or the other; times were as wild as this imagined picture). v4's got the leg up here because four numbers up to 255 delimited by a dot are both easier to write and easier to memorize than eight freaking groups of four hexadecimals in each, so you are dependent on DNS more or less.. (as if you're not dependent on DNS with v4, though; care to test yourself? Just name all v4 addresses of, I don't know, YouTube. Oh, do I spot you nslookuping youtube.com? You've fallen into my trap.) So, should you disable v6? No, you should not. You are effectively prolonging the life of v4 by this; a protocol which is finished, both in the literal (as in, finished being developed) and metaphorical (as in, End Of Life) way. If you are insistent on not using v6, pay attention to your config and simply route it via VPN as you would route v4. The OpenVPN v6 options might not have absolute parity with v4, but OpenVPN does route v6 just fine. Route them both. And if you've got v6, connect via v6 (barring the case of v6 availability but the Providers' Piss-Poor Performance® of it; then you are excused if you formally complain to your ISP. It's not even a joke: Complain about shabby v6 treatment of your service providers, to those service providers). Thank you for reading my sermon. May the Elders of the Internet protect you. Or the Admins of the AirVPN, whichever is closer to your heart. -
1 point
ANSWERED Firefox(-based browser) startup is stalled when connected to AirVPN with network lock enabled
lotuslove165 reacted to hcReJhTCzLS5c5U for a post in a topic
It would seem that this actually fixed both issues (for the DNS leak, I can only say so for just one of the tested WiFi networks on which the leak existed). Thanks. -
1 point
ANSWERED AirVPN does not recognize ICANN authority anymore
cipherecho reacted to Staff for a post in a topic
AIRVPN DOES NOT RECOGNIZE ANYMORE VERISIGN, AFILIAS AND ICANN AUTHORITY. OUR COMMITMENT AGAINST UNITED STATES OF AMERICA UNFAIR AND ILLEGAL DOMAIN NAMES SEIZURES. The United States of America authorities have been performing domain names seizures since the end of 2010. The seizures have been performed against perfectly legal web-sites and/or against web-sites outside US jurisdiction. Administrators of some of those web-sites had been previously acquitted of any charge by courts in the European Union. The domain name seizures affect the world wide web in its entirety since they are performed bypassing the original registrar and forcing VeriSign and Afilias (american companies which administer TLDs like .org, .net, .info and .com) to transfer the domain name to USA authorities property. No proper judicial overview is guaranteed during the seizure. Given all of the above, we repute that these acts: - are a violation of EU citizens fundamental rights, as enshrined in the European Convention on Human Rights; - are an attack against the Internet infrastructure and the cyberspace; - are a strong hint which shows that decision capacities of USA Department of Justice and ICE are severely impaired; and therefore from now on AirVPN does not recognize VeriSign, Afilias and/or ICANN authority over domain names. AirVPN refuses to resolve "seized" domain names to the IP address designated by USA authorities, allowing normal access to the original servers' websites / legitimate Ip addresses. In order to fulfil the objective, we have put in place an experimental service which is already working fine. If you find anomalies, please let us know, the system will surely improve in time. Kind regards AirVPN admins -
1 pointBeen using Eddie with no problems but for some reason when trying to run it, it will appear as a background process but won't display the main Eddie window. Can't think of anything major that's been installed in the mean time. Tried uninstalling and re-installing and running as admin all with no success. Have disabled virus and firewalls and stopped other processes but it still won't display the main Eddie window. Win10 is up to date and besides a couple of games (now uninstalled) nothing else has been installed. Something has obviously changed but I wondered if there was any way of finding out what the conflict is to cause the main window to not display. Or if there were any known issues with other programs that could stop Eddie displaying. Thanks. Update: Fixed this. Restored back to an earlier Windows creation point a few days old. Thinking it through I can see where the problem was - I'd installed an update to an app which played with the Windows UI and played with the toolbars - so Eddie was there I just couldn't see the icon and display the main window because it was hidden. Simple stuff and a bit daft of me to not spot this.
-
1 point
How to optimize/setup AirVPN and uTorrent for torrenting?
john_pork reacted to Shiver Me Whiskers for a post in a topic
Hello ! 1) Functional port forwarding is necessary for torrents to work properly. Many users don't have it set up correctly, meaning if you also don't have it set up correctly you won't be able to connect to them... leaving only the overloaded connectable ones. 1a) To do so, first FIND a free port here in the Forwarding section: https://airvpn.org/ports/ 1b) Then use that port in your client - in qBitTorrent - Tools -> Options -> Connection - Set PORT, and make sure you uncheck Use UPnP !!!! (not used for VPN!) and uncheck Use different ports... you want to keep the same port all the time! 2) Speed depends on what are you torrenting - In general any "public" stuff is going to be slow or very slow. Some specialized private trackers however have users with high-speed connections, dedicated seedboxes (servers) and such, and they are interested in ever-increasing that precious ratio so they are not going to throttle their speed. If you get only 100kbps on some random TPB torrent, don't complain about VPN, it's not going to help 3) Make sure Encryption is enabled in your client, even if VPN itself encrypts. If you don't have encryption enabled, it might be that your peers are being throttled, even if you're not ! Remember, this is a 'group dance', it's not just about your speed and your internet. 4) Simply pick another server ! You might have chosen one which is closer to you, but perhaps your PEERS are somewhere else. Generally choosing a server in West Europe ( Netherlands, Germany, UK ) will result in the best speeds for torrents. 5) Have a fast computer ! I've seen so many times that people complain about torrent speeds on a slow laptop with an extremely fragmented harddisk. You're giving that poor computer so much work it can't handle. Use tools like Ccleaner to cleanup garbage files and Defraggler to keep it defragmented (skip this part for SSD's, but cleaning up files is still good !) My torrent machine is a modern Quad-Core Intel overclocked @ 4Ghz with a Raid0 array of 2 HDD's as the "dump" (where things download). It can easily take 1gbps of speed (not available at my current location due to ISP limitations, but I had 1gbps internet before). Never had any problems with it not able to maintain a speed, even for huge tens-of-gigabytes torrents. Hope these help Yarr matey ! -
1 point
Hello AirVPN, Goodbye NordVPN :D
spinmaster reacted to Jaramaiha for a post in a topic
First time using a VPN. After much internal reflection, ended up going with AirVPN Found a discount code to boot XD made it all the more worthwhile IMO and sub for a year. -
1 point
ANSWERED AirVPN does not recognize ICANN authority anymore
cipherecho reacted to GMPSQ for a post in a topic
The United States is an enemy of the Internet. More and more our technology and communications are captured illegaly and stored for many years and then used against us in court. The government seems to sincerely believe that it owns the Internet and regulary hacks into foreign servers to retrieve data, seizes domain names, etc. and any citizen who can be considered a hacker under broad laws will be thrown in prison. My warning as a US citizen is to watch out, encrypt, keep everything secure, keep data offshore, and avoid any US-influenced entities such as ICANN. Thank you AirVPN for the great continued service. I've been using multiple VPN connections almost constantly for the past year everywhere and as far as I can see that will continue
