  1. 43 minutes ago, viry said:
    SO about the whole opnsense vs pfsense, the behaviour he described is about the ceo of pfsense registering the domain opnsense.com to discredit opnsense. 
    The main reason why I choose opnsense over pfsense is that it is more modern, it has a better webgui and the backend uses a MVC framework, it supports more hardware due to not needing aes-ni extensions and uses hardened bsd.
    Not to mention the two factor auth is a big plus but of course this comes with a cost no pfblockerng

    pfsense doesn't require AES-NI.  that requirement was removed.

  2. 46 minutes ago, hvihavai said:

    Thanks for the new server near me.

    Problem is that I'm getting terrible route and ping to the server from Finland. I'm going to contact my ISP, but just wanted to inform you. I'm seeing route finland->amsterdam->hamburg->stockholm->tallinn. :( 

    |                                      WinMTR statistics                                   |
    |                       Host              -   %  | Sent | Recv | Best | Avrg | Wrst | Last |
    |                  -    0 |   15 |   15 |    0 |    0 |    6 |    6 |
    |    XXX.XXX.XXX.XXX.elisa-laajakaista.fi -    0 |   15 |   15 |   16 |   16 |   17 |   16 |
    |                 -    0 |   15 |   15 |   18 |   21 |   27 |   18 |
    |                 -    0 |   15 |   15 |   17 |   19 |   33 |   19 |
    |                -    0 |   15 |   15 |   38 |   38 |   44 |   44 |
    |hu0-4-0-5.ccr21.ams04.atlas.cogentco.com -    0 |   15 |   15 |   38 |   38 |   44 |   44 |
    |   be3458.ccr42.ams03.atlas.cogentco.com -    0 |   15 |   15 |   38 |   38 |   44 |   44 |
    |   be2816.ccr42.ham01.atlas.cogentco.com -    0 |   15 |   15 |   47 |   47 |   49 |   47 |
    |   be2282.ccr22.sto03.atlas.cogentco.com -    0 |   15 |   15 |   69 |   70 |   75 |   75 |
    |   be3741.rcr51.tll01.atlas.cogentco.com -    0 |   15 |   15 |   70 |   71 |   77 |   77 |
    |be2160.nr11.b069785-0.tll01.atlas.cogentco.com -    0 |   15 |   15 |   71 |   71 |   76 |   76 |
    |              estnoc.demarc.cogentco.com -    0 |   15 |   15 |   74 |   75 |   80 |   80 |
    |                -    0 |   15 |   15 |   71 |   71 |   76 |   76 |
       WinMTR v0.92 GPL V2 by Appnor MSP - Fully Managed Hosting & Cloud Provider

    I hate it when that happens.

    EstNOC, AS206804, can be reached by many networks so it's unfortunate your ISP uses Cogent.

  3. 17 minutes ago, Air4141841 said:

    I'll hardwire to the ONT tomorrow and see what is going on.

    appreciate the helpful post 

    I enabled everything ip6.  wan wise.  and within the openvpn tunnel.    wan and tunnel ip6 both show down as of now 

    You probably can't connect directly to the ONT and get any network activity without doing some work  The ISP router probably does vlan tagging and has some sort of username/password authentication.

    If you know what the settings are you may be able to replicate them on your pfsense box.  But if you don't know the best you can do is either put the ISP router into bridge mode or do some other trick where you use a dumb switch and clone the MAC address of the ISP router to your pfense box.  You let the ISP router get your connection up and running and then unplug it from the dumb switch and plug in your pfsense box with cloned MAC.

  4. 3 minutes ago, Flx said:
    Might be just that.
    airvpn.org and airvpn.info show that page if you "fluff" around the forum for too long.
    Mostly happens when you connect UDP.

    It's been better for me since I made a thread complaining about this problem.  I think staff have done some fixing.  But that's interesting that you note that it happens only when connected by UDP tunnel.

    That implies that something is failing with packet fragmentation because we have MTU wrong.

  5. It's quite normal that a company like  Credit Karma wants to block VPN IPs.  They're trying to protect identity so it would behoove you to show them your real location so that if somebody were to try to hack your account from another location they'd more quickly realize it's not you.

    And really, it makes no sense to hide your IP from them when they know everything else about you necessarily. 

  6. 38 minutes ago, vpn_access said:

    Nah, it's not Virgin, they're hopeless.

    I've now got Wintun working, although through OpenVPN directly rather than Eddie as it seems it's not supported. Is that still the case? So at the moment my primary issue is the lack of network lock/kill switch.

    That's correct.  I don't think it's possible to work with Eddie just yet because the network lock doesn't know how to work with the wintun driver.

  7. 7 hours ago, Survival said:
    Did you mean TLS Key Usage Mode: TLS Encryption and Authentication mode in VPN Client of pfsense?
    Will it hide a traffic from DPI of ISP similar way as stunnel via SSL does?
    And does AirVPN permit such a connection to their servers?


    Some people find it works in places where only SSL would work previously.
    Yes.  You must connect to entry IP 3 or 4, use SHA512 for auth digest, and of course use the TLS encryption and auth setting for the TLS key

  8. 11 hours ago, glibthefirst said:
    On 2/9/2020 at 4:23 AM, giganerd said:

    While we can say, yes that's all needed to be done, I'm beginning to question this. Why would you want a lesser encryption level? What are you trying to run OpenVPN on? Router?

    I'm running a game server on a PC through AirVPN. It seems to be creating a little bit of lag, and id rather not have it turned off and expose my public IP.

    Increased lag is going to happen when you're going through a VPN.  It adds "distance" between you and your game server and friends.  Decreasing the encryption will only make things easier on your processor but that's not where the lag is I think.

  9. At least once a day I get the "our tubes are clogged" message.  No other website I visit is as unreliable as this one.  When it is down I can't get to my client area to configure my VPN.  So, it is important that the website is working.

    What's more, no other web site I frequent is as slow to respond as this one as I browse through the forum.  I can literally check on other forums in the time I'm waiting for this site to respond.

    All this is while using AirVPN VPN servers.

    Thanks for your attention.

  10. 1 hour ago, foDkc4UySz said:

    When might we see 10gbit servers? (Ofc granted, in the countries that can reasonably offer it.) With home connections now in the gbits themselves, individual gbit servers are often congested. Eddie isn't the best at loadbalancing. 10gbit has been a market offering for atleast 5 years now: USA, NL. Is the price not right? Are the providers not right? Why not approach existing providers for this?

    Eventually no doubt but really it's hard to get faster than a 1gbit server can support with a single stream of openvpn.

  11. 10 minutes ago, turtle300 said:


    Tried almost every US-Server and a lot of others. Can't even sign into netflix. 
    Is there any update? 

    US-Server Lich is loading the website, but no more. No sign in possible. Most of the other servers get blocked so you can't even load the netflix website.

    It's not a big deal for me I'm just asking myself if there is maybe new servers that are fixing this problems? Because 

     doesn't work anymore. I tried it.

    thanks and regards 

    you misread.  Staff said those servers could NOT reach netflix.
