-
Content Count
11887 -
Joined
... -
Last visited
... -
Days Won
2178
Everything posted by Staff
-
Countries and servers not showing in Eddie 2.21.8
Staff replied to Howlingwolf's topic in Eddie - AirVPN Client
Hello! Please upgrade, your Eddie version is too many years old. See also: https://airvpn.org/forums/topic/81119-limited-server-access/ @yeshi On PCLinuxOS please try the tarball. Kind regards -
Solved! Kind regards
-
Eddie 2.26.2 Desktop Edition released Hello! We're very glad to inform you that a new stable release of Eddie is now available for Linux (various ARM based architectures included, making it compatible with several Raspberry Pi systems), macOS, Windows. Special thanks to all the beta testers, whose invaluable contributions and suggestions in the last months have helped developers fix several bugs and improve the overall stability of the software. Eddie is a free and open source (GPLv3) OpenVPN GUI and CLI by AirVPN with many additional features such as: traffic leaks prevention via packet filtering rules DNS handling optional connections over Tor or a generic proxy customizable events traffic splitting on a destination IP address or host name basis complete and swift integration with AirVPN infrastructure with OpenVPN and WireGuard white and black lists of VPN servers ability to support IPv4, IPv6 and IPv6 over IPv4 support to Linux systems based on systemd and SysV-style init This version includes bug fixes and security improvements as well as OpenVPN, WireGuard and libraries updates. A new Eddie UI is in the works. We know we’ve been promising that for a long time, but development is well along. Stay tuned. Operating and architectural notes Eddie GUI and CLI run with normal user privileges, while a "backend" binary, which communicates to the user interface with authentication, gains root/administrator privileges, with important security safeguards in place featured in this new version: strict parsing is enforced before passing a profile to OpenVPN in order to block insecure OpenVPN directives fix for CVE-2025-14979 backend hardened authentication of client commands hardened security for sensitive operations client memory usage protection through limitation of client helper replies general cleanup Furthermore: external system binaries which need superuser privileges (examples: openvpn, iptables, hummingbird) will not be launched if they do not belong to a superuser. Eddie events are not run with superuser privileges: instead of trusting blindly user's responsibility and care when dealing with events, the user is required to explicitly operate to run something with high privileges, if strictly necessary Please consult the changelog for a more detailed and exhaustive list. Backend binary is written in C++ on all systems (Windows included), making the whole application faster. Settings, certificates and keys of your account stored on your mass storage can optionally be encrypted on all systems either with a Master Password or in a system key-chain if available. Download Eddie 2.26.2 Eddie 2.26.2 can be downloaded here: https://airvpn.org/linux - Linux version (several architectures and various distribution specific packages for easier installation) https://airvpn.org/macos - Mac version https://airvpn.org/windows - Windows version Eddie is free and open source software released under GPLv3. Source code is available on GitHub: https://github.com/AirVPN/Eddie Complete changelog can be found here. Kind regards & datalove AirVPN Staff
-
Hello! We're sorry, Eddie 2.24.6 requires macOS Mojave or higher versions. If your Mac is Intel based you can run Hummingbird 2.1.0 (Hummingbird is optimized for Apple Silicon Mx too, but with this CPU Hummingbird requires Mojave or higher versions). Alternatively, you can consider OpenVPN Connect, or Tunnelblick 3.8.8g, but this Tunnelblick version contains serious vulnerabilities: https://www.tunnelblick.net/downloadsDeprecated.html Kind regards
-
Hello! On macOS Tahoe you can run Eddie 2.26 (now available on all download pages as a stable release) or Hummingbird 2.1.0 (on top of any other non-AirVPN software of course, such as WireGuard, Tunnelblick etc.). On macOS Catalina you can run Eddie 2.24.6, Hummingbird 2.1.0, Tunnelblick etc. We will verify with developers compatibility between Eddie 2.26 and Catalina and will let you know. Obviously not. At present, any system capable of running WireGuard, AmneziaWG 0.2.15, or OpenVPN 2.4 and later can connect to our service as usual. The most significant change following the deployment of DCO across our infrastructure is the discontinuation of support for OpenVPN 2.3 and earlier versions. Considering that OpenVPN 2.3 was released in 2013 and OpenVPN 2.4 in 2017, AirVPN’s continued support for such long-standing version demonstrates its strong commitment to backward compatibility - provided that maintaining compatibility does not compromise security or hinder the proper evolution of the service. Kind regards
-
Hello! In a couple of cases, DDoS / flood attack was ongoing but was mitigated and caused no packet loss or other critical issue that could be detected by the monitoring system. However, they caused some problem: bandwidth impact and inability to communicate with the backend servers, which in turn did not have data to fill all the stats. However, the monitoring system did not put the server on "limited access" or "closed access" and did not log the issue mainly because IPv4 and IPv6 addresses were all reachable with no packet loss and not other failures were detected. Another case is simply congestion on any upstream. Although we have a guaranteed bandwidth inside the datacenter and on interconnection with the main IP transit, some routes can be occasionally congested, even when this problem is not caused by the datacenter network and/or by the transit provider. However, this is a rare case, whereas flood attacks are more common throughout the whole infrastructure. The last case is occasional. When the server needs an urgent kernel upgrade, it will be rebooted, and therefore will go completely down for a couple of minutes. However, this event is always recorded on the stats as it causes 100% packet loss on all addresses. Kind regards
-
@bilis @riotamus @Harold99_0 @sebalpatine @zeedatrup @Veep Peep Hello! A plausible explanation is that you're running an obsolete Eddie Desktop edition version. Eddie filters out servers whose connection mode is not compatible with your system setup. For example, as DCO support is completed throughout the whole infrastructure, an old Eddie version not supporting WireGuard and running an OpenVPN version 2.3.x will be unable to find a suitable server. Please upgrade your Eddie Desktop edition and report back at your convenience. If you are not running Eddie Desktop edition, please specify the software you're running. Kind regards
-
ANSWERED Servers are becoming so unreliable
Staff replied to moving shadow's topic in Troubleshooting and Problems
Hello! First of all please respect the netiquette or you will be moderated. You provided inaccurate information about Castula. Here below a screenshot (from the public real time servers monitor) with the recent history of the problems it had. As you can see, such problems were not critical. Packet loss occurred for a very limited time, a matter of minutes, and sporadically: no events in June, only one event in July, not impacting events on August. Note how solid and reliable Castula is. Also note that the packet loss is recorded as a weighted average of ping from VPN server to various testing servers in different locations, and from those testing servers to the VPN server. Thus, the outcome is reliable but a small probability that the problem affects the testing servers, or any hop in-between, and not the VPN server, remains. The same can be said for each VPN client node: if a client loses packets to or from a VPN server, the problem is not necessarily only on the VPN server side. Uptime is more than 99.5% with Tzulo servers. Flood attacks may happen and can alter the normal uptime, but after 1 year the uptime remains good and the servers are solid. You use AirVPN for self hosted servers, although this is not the purpose of the service. For self hosted servers you may need a dedicated server or your own VPS, especially if you want more than 99.5% uptime and all inbound ports available. Using AirVPN for hosting purposes is possible but questionable. Even if AirVPN offers remote inbound port forwarding, AirVPN is not a hosting provider and you can't expect for the current price the same performance you have with a dedicated or virtual server with business lines that you operate exclusively. Also note that downtime due to server maintenance (especially for kernel upgrades) is another factor that you can't manage by yourself and that makes AirVPN not suitable for hosting purposes if you pretend the uptime of a hosting provider. We can upgrade and reboot the servers when necessary especially for security reasons and best practice. With all the above said, we are constantly striving to improve our service; however, limitations may arise when it is used for purposes for which it was not designed. Kind regards -
Hello! We're very glad to inform you that a new 10 Gbit/s full duplex server located in Los Angeles, California, is available: Flegetonte. The AirVPN client will show automatically the new server; if you use any other OpenVPN or WireGuard client you can generate all the files to access it through our configuration/certificates/key generator (menu "Client Area"->"Config generator"). The server accepts connections on ports 53, 80, 443, 1194, 2018 UDP and TCP for OpenVPN and ports 1637, 47107 and 51820 UDP for WireGuard. Flegetonte supports OpenVPN over SSL and OpenVPN over SSH, TLS 1.3, OpenVPN tls-crypt and WireGuard. Full IPv6 support is included as well. As usual no traffic limits, no logs, no discrimination on protocols and hardened security against various attacks with separate entry and exit-IP addresses. You can check the status as usual in our real time servers monitor , by clicking the server name. Direct link: https://airvpn.org/servers/Flegetonte Do not hesitate to contact us for any information or issue. Kind regards & datalove AirVPN Staff
-
Hello! Thank you! Can you please describe all the steps you perform to reproduce the problem? Can you also add the app's log generated after you have reproduced the problem? In the "Log" view please tap the paper plane icon and send the link that the app will give you back. Kind regards
-
Hello! Which Eddie version are you running? Can you also generate a system report and send us a link to it? https://airvpn.org/forums/topic/50663-youve-been-asked-for-a-support-filesystem-report-–-heres-what-to-do/ Kind regards
-
Hello! Because it's not the latest version, which is 1.0.16, and which requires macOS 12 or higher version. https://apps.apple.com/us/app/wireguard/id1451685025?mt=12 Kind regards
-
Discontinuing subscription. Feedback
Staff replied to Janice Redfern's topic in General & Suggestions
Hello! This is an interesting smearing message that occasionally comes out, trying to exploit the forum we keep open for the community, for some hidden purpose or, we guess, just for hate. You can easily verify that every defect mentioned by the OP is either false or distorted. A community moderator provided some corrections that disprove the OP's claim, here we would like to add just three remarks on subjects we care about: interoperability with other VPN services, infrastructure stability and how good our remote port forwarding system is. We also want to quickly make you aware that the OP never opened a ticket for professional support, so he/she was probably not interested in a solution of his/her problems, but maybe only in building a case based on false or fabricated premises. 1. Eddie Android edition, AirVPN Suite and Eddie Desktop edition allow connections to any VPN supporting either OpenVPN or WireGuard through the most standardized method that can exist, the supported profile for each VPN application (much better than any API, especially when it does not exist on most VPN services). 2. Over the past 16 years AirVPN infrastructure constantly evolved toward more stability and speed, it's all in the records. In AirVPN we have had and we have users connected CONTINUOUSLY for SEVERAL MONTHS. Enough for connection stability? 😉 We could have even longer periods, if it wasn't for the necessity to reboot a server periodically for kernel upgrades. 3. Implementing remote inbound port forwarding over a VPN by having the VPN server use UPnP/NAT-PMP/PCP to dynamically open ports on behalf of clients is generally considered a poor architectural choice because: UPnP was designed for trusted, local networks No authentication in classic UPnP IGD exists Race conditions in a large infrastructure like AirVPN's one becomes an architectural problem UPnP would make "hot change" and other interesting features appreciated by AirVPN customers impossible Privilege escalation. UPnP used outside a local network facilitates various exploits including privilege escalation. The VPN server already controls firewall rules, NAT, routing and connection tracking. Using UPnP as an intermediary adds another protocol layer rather than configuring those systems directly. This depends on your design philosophy, but at the moment management does not see favorably functionality duplication. At the end of the day, such a poor choice would pose a bunch of problems for essentially nothing, as selecting a random port with the additional features is a matter of seconds. Kind regards -
@fishbasketballaries Hello! The error means that Android is refusing to install the APK because an app with the same package name (org.airvpn.eddie) is already installed, but it was signed with a different certificate.This is perfectly possible as the new APK has been signed with our official Google developers signing keys to make life easier for the imminent, new restrictions against side load, while the previous ones were not signed with them. Please uninstall the previous package adb uninstall org.airvpn.eddie and then install the new APK. Kind regards
-
Hello! We're very glad to announce the Eddie Android edition 4.1.0 is available Eddie Android edition is a fully integrated with AirVPN, free and open source client allowing comfortable connections to AirVPN servers and generic VPN servers offering compatible protocols: OpenVPN, WireGuard, and AmneziaWG 2.0 powered up protocol. Source code available on GitLab: https://gitlab.com/AirVPN/EddieAndroid Eddie Android edition is Android TV friendly and also offers GPS spoofing, traffic splitting on an application basis, 10 languages, extended compatibility from Android 5.1.1 to Android 16, and much more. What's new Eddie Android edition 4.1.0 introduces a new custom AirVPN library that combines wg-go and amneziawg-go into a single runtime. This architectural change addresses a fundamental constraint of the Go runtime. Go was designed with the assumption that only one runtime instance exists per process and does not support multiple independent runtimes within the same process. The previous 4.0 version had been linked against two separate Go-based libraries since support for Amnezia WireGuard was introduced. Despite the precautions implemented, on a small subset of devices, this configuration still resulted in rare crashes. Analysis showed that such crashes originated from Go runtime components, most notably the garbage collector. By consolidating both libraries into a single Go runtime, Eddie Android Edition 4.1.0 gets rid of these crashes across all supported devices. Furthermore, Eddie Android edition 4.1.0 adheres more strictly to AmneziaWG protocol version 2 real implementations. Specifically: The <c> tag for I parameters has been removed. Although documented for about a year, it was never implemented in the AmneziaWG protocol and any implementation intent was dropped during February 2026. Because, regrettably, it remained in the Amnezia documentation, Eddie 4.0.x still generated this parameter in certain profiles, resulting in the well-known interoperability issues with other clients. Eddie 4.1.0 eliminates this inconsistency. See: https://github.com/amnezia-vpn/amneziawg-go/issues/120 Added support for the <rc> and <rd> tags for I parameters. Jc, Jmin, Jmax parameters must now be ≥ 1. Previous Eddie / Amnezia releases accepted values ≥ 0, making it possible to explicitly configure zero junk packets, thereby allowing users to explicitly configure a logically degenerate state in which the junk-packet mechanism remained enabled while simultaneously instructing it to emit precisely zero junk packets. This is no longer supported; to disable junk packet generation please omit the J parameters. WireGuard compatibility now requires the canonical header mapping (Hₙ = n), as packet header identifiers are interpreted in a strict semantic order. Earlier AmneziaWG implementations, including that used by Eddie 4.0.x, internally canonicalized header mappings, allowing any non-repeating permutation of {1, 2, 3, 4} to preserve WireGuard compatibility. Eddie now enforces the canonical mapping whenever interoperability with standard WireGuard peers is required, including connections to AirVPN servers using the default Amnezia configuration. Eddie Android Edition 4.1.0 also includes updated libraries and dependencies. Please refer to the changelog available here for additional details. Download link, checksum and changelog Quick reference and download page: https://airvpn.org/android/eddie Eddie Android edition 4.1.0 APK direct download short URL: https://airvpn.org/tv Eddie Android edition 4.1.0 is also available on the Google Play Store https://play.google.com/store/apps/details?id=org.airvpn.eddie Changelog is available here: https://gitlab.com/AirVPN/EddieAndroid/-/blob/master/ChangeLog.txt?ref_type=heads SHA-256 checksum if you prefer to download from our web site and side load the app: $ sha256sum EddieAndroid-4.1.0-VC40.apk d154767a4b4f65c8248f5a3529875bc022a9032baae696beb81529d478d6c190 EddieAndroid-4.1.0-VC40.apk Kind regards & datalove AirVPN Staff
-
Eddie Android edition 4.1.0 preview available
Staff replied to Staff's topic in News and Announcement
Hello! Yes. Eddie needs some time to determine your country via ipleak.net, depending on the speed of access to and response from ipleak.net, and of course on the service availability. When you order a connection while Eddie still does not know your country, Eddie will proceed simply by ignoring this information to prevent any ipleak.net outages or sluggishness from causing excessive slowdowns or freezes. You can resolve this situation by setting your country (or the country you want the app thinks you are in) in the app's Settings: henceforth, shall Eddie abstain from making any further endeavor to establish communication with ipleak.net. Kind regards -
Hello! Yes, you used it on 2026-07-16 for your order 2be14cc8015b7b8149e71078d07f80c4dd142b1f. You can see it on your "Order" dashboard included on your AirVPN account "Client Area". Now, the order is still "On hold" by Stripe for some problem related to the credit card (you might like to check), so you have not really used the credit so far, as it is inside the order for the activation of a plan whose partial payment has not been approved. Please open a ticket, we'll have the Sales department manage this issue. Kind regards
-
Hello! We're very glad to inform you that two new 10 Gbit/s full duplex servers located in Amsterdam, the Netherlands, are available: Dedalus and Felix. The AirVPN client will show automatically the new servers; if you use any other OpenVPN or WireGuard client you can generate all the files to access them through our configuration/certificates/key generator (menu "Client Area"->"Config generator"). The servers accept connections on ports 53, 80, 443, 1194, 2018 UDP and TCP for OpenVPN and ports 1637, 47107 and 51820 UDP for WireGuard. They support OpenVPN over SSL and OpenVPN over SSH, TLS 1.3, OpenVPN tls-crypt and WireGuard. Full IPv6 support is included as well. As usual no traffic limits, no logs, no discrimination on protocols and hardened security against various attacks with separate entry and exit-IP addresses. You can check the status as usual in our real time servers monitor : https://airvpn.org/servers/Dedalus https://airvpn.org/servers/Felix Do not hesitate to contact us for any information or issue. Kind regards & datalove AirVPN Staff
-
Eddie Android edition 4.1.0 preview available
Staff replied to Staff's topic in News and Announcement
Hello! We're very glad to inform your that Eddie Android edition 4.1.0 beta 3 is now available, featuring an additional update with libeddiewg that moved to amneziawg-go v0.2.19 and a relevant bug fix. The bug affected proper cleanup and compilation of Amnezia In parameters causing connection failures and other problems. If you found any issue related to AmneziaWG, please test beta 3 before reporting. If you decide to test this new beta version and you had any previous Eddie installed version, please delete all app data and cache from Android settings, uninstall the older Eddie app, and finally side load the new beta 3 apk. Please find all the details on the first message of this thread. Kind regards -
It looks like the web site operators blocked access from the whole European Union. It makes sense: a service that lets users upload a face and searches for matching people online is likely processing biometric data. In the EU, that can trigger strict GDPR requirements, including lawful basis, transparency, security measures, and data subject rights, that perhaps the service can not offer at the moment. Moreover, the service might need to retrieve profile photos of many other persons from social networks or other websites without explicit permission in order to compare them with your photo, something that can lead to a quagmire of potential civil and criminal violations in the EU. After the relevant fines imposed by European Union data protection authorities against Clearview and the subsequent, additional criminal charges https://ppc.land/criminal-charges-filed-against-clearview-ai-after-regulatory-fines-fail/ blocking access from EU can be a prudential move, but let's remember that the Commission pretends that the GDPR applies to non EU companies to protect citizens of any country when they are in the EU. (EDIT: this last sentence was edited to fix a factual mistake). Kind regards
-
Hello! For the readers and OP: @mith_y2k had a dramatic performance boost by setting WireGuard MTU to 1280 bytes (from previous 1420 bytes) and by cherry picking servers around his/her location instead of picking a generic continent and let the domain name extract the "best" server. Support team is now considering whether suggesting to add MSS clamping too, in case PMTUD is broken somewhere, but the throughput is now consistent with the "Top 100 Users Speed" so the MTU was for sure the main problem. About server selection, always consider that if you use an entire continent domain name, you are in a sub optimal situation to find the server that can provide you with the best performance. The domain name resolution takes into account important variables to resolve into the entry IP address of an healthy server, but knows absolutely nothing about your location, routing and round trip time from your node to the VPN server. Therefore, when you select an entire continent, you shrink the likelihood of finding a server that's indeed the best for throughput to/from your node. Kind regards
-
@darkocean69 Hello! Good question. In 2010 we wanted an encrypted stream without HTTPS and/or certificates that looked as much as possible as plain HTTP for good reasons. We also wanted to avoid importing public keys and make the procedure immediately usable on the software. The method was good enough to survive for 16 years. Now we can also implement potentially bootstrap server access via HTTPS or more esotic ways but there's really no need at the moment, we'll see. Kind regards
-
Hello! Please open a ticket, each case could be unique and there are no specific problems on the infrastructure. Kind regards
-
Eddie Android edition 4.1.0 preview available
Staff replied to Staff's topic in News and Announcement
Hello! Thank you very much for your tests and report. We can reproduce similar problems and we are investigating. In the meantime, please try this: from Android application settings, delete Eddie data (both data and cache) uninstall Eddie re-install Eddie and report back The above procedure can mitigate one of the problems we detected thanks to your report, but we have found other problems (when using Eddie in Amnezia mode) and a thorough investigation is going on. We will keep you posted. Kind regards -
ANSWERED EDDIE CLIENT BLOCKING LOGIN
Staff replied to minimia's topic in Troubleshooting and Problems
For the readers, the customer solved the problem by entering the correct access credentials. Kind regards
