- 
				Content Count11524
- 
				Joined...
- 
				Last visited...
- 
				Days Won2034
Everything posted by Staff
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  Using Eddie (or other Airvpn software) in terminal environmentStaff replied to emtlo's topic in General & Suggestions @emtlo Hello! Yes, it is possible. You can run the AirVPN Suite, please see here: https://airvpn.org/suite/readme/ Kind regards
- 
	Hello! We're glad to inform you that we have just released: "Road To OpenVPN 2.6" migration plan - https://airvpn.org/road_to_openvpn26/ A new version of Config Generator with options related to OpenVPN 2.6 A new Eddie Desktop beta release (2.23.0) related to the road above, feature-locked to reach stable release https://airvpn.org/forums/topic/56428-eddie-desktop-223-beta-released/ A new server (Marsic), the first running OpenVPN 2.6 powered by DCO (server-side) and ready for client-side DCO. Kind regards & datalove AirVPN Staff
- 
	Hello! We're very glad to inform you that a new Eddie Air client version has been released: 2.23 beta. It is ready for public beta testing. How to test our experimental release: Go to download page of your OS Click the button Switch to EXPERIMENTAL Download and install There are important changes in this release, mainly: Network Lock will be activated by default. Switch back to old behavior by unchecking Preferences > Network Lock > Ensure in session OpenVPN is linked against OpenSSL 3, that deprecates old SHA1 signed certificates (already upgraded under-the-hood) for Linux systems, every and each systemd-resolved working mode is fully supported: DNS push and settings are properly managed PLEASE CONSIDER THIS AS A BETA VERSION. Don't use it for sensitive connections, it's only for those who want to collaborate on the project as beta-testers. Kind regards & dataloveAirVPN Staff
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  Ubuntu + Network Loss + Eddie Crash = StuckStaff replied to Chained's topic in Eddie - AirVPN Client Hello! We seriously doubt that the problem is caused by Network Lock because Network Lock is a set of non-permanent firewall rules which are lost when you reboot the system. Anyway, the answer to your question is: sudo nft flush ruleset (provided that Ubuntu 22.04 is based on nftables). Please check your DNS settings as well, as those are indeed permanently set by Eddie and maybe the previous DNS settings were not restored if Eddie did not exit cleanly. If the problem persists, do not hesitate to open a ticket. By the way, we rule out that the failure to load X and/or a Desktop Environment is related to Eddie. Some other problem is apparently ongoing. Kind regards
- 
	How? Or is this specific to Eddie (which I do not use)? I find nothing on the website about this. EDIT: posted unknowingly together with @benfitita - we confirm that the described procedure is fine. Hi, you need to renew the key when you end the current session or you start a new one (but in this latter case you need the consider the caveat below). You can automate the procedure via API, but also remember to update the key or the whole profile for the next session. You can automate this procedure too. With a caveat: key renewal order through the API is not executed in real-time, it may take several seconds (you can check the status via API, or you can simply renew the key at the end of the session and take care to allow enough time for the next key/profile download and session). Kind regards
- 
	@galbeedee Thank you for your review! We would like to point out some features of our service that you probably missed according to your review, so that you will be able to use them. You can use per-session WireGuard key, to overcome the questionable design of WireGuard under this respect (WireGuard does not offer dynamic address management at all). It's not very important that your private key is held by you when WireGuard demands that, server side, each public key is linked in files to the VPN IP address and to the public IP address of the client. Therefore, thanks to our design, you are able to use a one session key if necessary. You can renew your key either through the web site or through the API in order to patch this problem. On our side, we actively remove WireGuard entries to public IP addresses when a session is over. We do not understand the link you claim between the key and your browser, feel free to clarify if you wish so. File names of the generated profiles are very descriptive and they reflect community requirements. Community majority currently prefers descriptive file names and wants that the system is not tweaked to accommodate terrible WireGuard design under this respect (WireGuard wants to name the virtual interface with the file name regardless of the system limits). This is an understandable point of view and we will respect it. We will change according to community suggestions. Far from being "best practice", in our opinion, and in the current opinion of the community, that would be the practice to lower a service standard to meet the terrible design of somebody else, something reminding the old, awful but widespread, practice to develop flawed web sites to circumvent Internet Explorer bugs and accommodate its non-W3C compliant dialect. That said, we can of course add some options to make life more comfortable for anyone who should be wearied by the exhausting effort of renaming a set of files. The QR code anyway is already available for Android and iOS (in the Configuration Generator), so you don't need renaming in mobility, just shoot the code from inside wg. This is a key which is necessary when you want an additional encryption layer, and this is a great WireGuard feature. Useful for example in a post-quantum world, when a decent cryptographic algorithm is found (as the wg core has ciphers hard coded by design). Read the WireGuard documentation for more details. Currently pre-shared keys are implemented because a significant part of the community insisted that we got prepared to beat powerful quantum computers, not because we strongly believe that a post-quantum world is imminent. Relevant considerations on the topic can be found here: https://airvpn.org/forums/topic/45608-quantum-computing-and-encryption/?do=findComment&comment=218988 It is anyway considered best practice by various experts to get prepared. Since you mention Mullvad as your opinion of service operating in accordance with best practices, then be informed that pre-shared keys have been recently implemented by them too. We offered this option 13 years ago, well before WireGuard or many other VPN companies even existed. Then they were inspired by our CG. You can pick zip, 7zip, tarball, and compressed tarballs (tar.gz, tar.xz, tar.bz2). You can operate either through the API or web site, as you prefer, to generate and download the package(s) containing the profiles. Note that today the button which would let you select all the servers at once is disabled because of work in progress, but it will be re-enabled very soon. It's a good performance in our infrastructure, but you can improve it (check the top user speed table in the server status page and open a ticket to fine tune WireGuard). About the infrastructure, in 2009 the industry standard was between 20 and 100 Mbit/s, and we are very careful to offer an excellent balance between price and service quality. Since you mention iVPN as an example to follow, please compare AirVPN prices with theirs. Lupus in fabula, the following message by one of our fans reminds us of the consequences of an unwise investment policy. https://airvpn.org/forums/topic/56425-two-new-1-gbits-servers-available-us/?do=findComment&comment=223857 Remember that AirVPN is the only one offering a rigorous no overselling commitment shown by a transparent and verifiable server monitor, that's why most users enjoy higher throughput than with any competitor, and after all we are pleased to see that you are an unsatisfied customer but with 600 Mbit/s throughput and with some requirements for features that are already available. Criticisms help us improve our service, except when required features are already available, as in that case we can't implement them twice. Kind regards
- 
	Hello! We're very glad to inform you that two new 1 Gbit/s full duplex servers located in Miami, Florida, are available: Gudja and Kang, The AirVPN client will show automatically the new servers; if you use any other OpenVPN or WireGuard client you can generate all the files to access them through our configuration/certificates/key generator (menu "Client Area"->"Config generator"). The servers accept connections on ports 53, 80, 443, 1194, 2018 UDP and TCP for OpenVPN and ports 1637 and 47107 UDP for WireGuard. Gudja and Kang support OpenVPN over SSL and OpenVPN over SSH, TLS 1.3, OpenVPN tls-crypt and WireGuard. Full IPv6 support is included as well. As usual no traffic limits, no logs, no discrimination on protocols and hardened security against various attacks with separate entry and exit-IP addresses. You can check the status as usual in our real time servers monitor: https://airvpn.org/servers/Gudja/ https://airvpn.org/servers/Kang/ Do not hesitate to contact us for any information or issue. Kind regards and datalove AirVPN Team
- 
	Hello! Please open a ticket if you need more than 5 connection slots from the same account. The sales department will inform you about options and prices. Kind regards
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  ASUS VPN Fusion and port forwardingStaff replied to Peterom's topic in Troubleshooting and Problems @Peterom Hello! If it's the router the device connecting to the VPN server you need to forward the port to the final destination (your NAS address), from the tun interface. It's important that you don't use the router port panel, which will forward from the physical network interface. You can follow the instructions here because Asus Merlin WRT has iptables (and lets you access it of course): https://airvpn.org/forums/topic/9270-how-to-forward-ports-in-dd-wrt-tomato-with-iptables/ Kind regards
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  Laptop will not connect to internet UNLESS Eddie is runningStaff replied to Rich Z's topic in Troubleshooting and Problems @Rich Z Hello! Maybe Eddie was not shut down cleanly and it did not restore system's DNS settings. When this happens, the problem can be resolved by re-running Eddie and shutting it down properly. If the problem persists, please check manually your system's DNS settings and verify that public DNS are set. Quad9 (9.9.9.9) and DNS.Watch (84.200.69.80) are committed to privacy and neutrality. OpenNIC is an excellent choice as well. If necessary, consult your system's manual or any guide showing how to set or change DNS in WIndows 10, e.g. https://www.windowscentral.com/how-change-your-pcs-dns-settings-windows-10 If the problem still persists after all of the above, please open a ticket to receive dedicated support. Kind regards
- 
	@benfitita Hello! Obviously we don't comment a lot on the lists content, but just in case we remind you that you can de-select it, or you can add the exception for the CDN you mention, thanks to our flexible system. GoodbyeAds lists have been the most requested by our community in the last months, so we made them available. Kind regards
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  qBittorent doesn’t work despite ports being open.Staff replied to ghost_of_rargb's topic in Troubleshooting and Problems @ghost_of_rargb Hello! qBittorrent offers an option to bind to a specific network interface in "Preferences" > "Advanced" > "Network interface" combo box. Please make sure that, while your system is connected to the VPN, that box is set to the VPN network interface (tun in Linux, utun in Mac, etc.). Kind regards
- 
	Hello! Please note that starting Saturday, June 24, all new accounts will have the ability to forward remotely a maximum of 5 inbound ports. The decision is intended to extend the time period after which we will run out of ports. The change is not retroactive: all current customers and all accounts created before Saturday, June 24 will have the usual, total ports availability. In addition, we will continue to investigate viable alternatives in anticipation of port exhaustion. Kind regards & datalove AirVPN Staff
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  Possible ways to circumvent censorship caused by port forwarding.Staff replied to space5's topic in General & Suggestions @space5 Hello! Various good ideas, but it's probably overkill. In our case, the overwhelming majority of reasons causing the addition of an IP address into black lists is not related in any way to remote port forwarding. Kind regards
- 
	@colorman Hello! The error you get with the mainline version is correct. Unfortunately your distribution is based on a glibc released on February 2020. No worries though, as you can see you can run the legacy version. On the AirVPN Suite user's manual you can find how to use the option which probably you need to modify: Enter it in the Bluetit's run control file which you can edit with any text editor and root privileges, then restart Bluetit. Example to turn it on: allowuservpnprofiles on Kind regards
- 
	@Matoomba Hello! They couldn't. Your ISP or third party entities can monitor your torrent activity (and other specific activities) while your system is not connected to the VPN or leaking traffic outside the VPN tunnel. "Network Lock" feature, available in all of our free and open source software, prevents any possible leak outside the VPN tunnel, including leaks caused by p2p program mis-configuration and leaks caused by unexpected VPN disconnection, thanks to firewall rules, as you might know from all of our guides, welcome e-mail, answers to FAQ, discussions in the forum etc. To explain what happened, Network Lock must have been disabled, or you did not run our software. Network Lock is effective even in case our software shuts down unexpectedly (for example in the unlikely event when OpenVPN or WireGuard crash). If you don't run our software you can prevent leaks by yourself. Check our guides in the "How-To" forum and consider to bind your torrent software to the VPN virtual network interface. https://airvpn.org/forums/forum/15-how-to/ Besides, please re-check your torrent software settings against the following article, as it looks like you haven't done so according to your message. https://airvpn.org/faq/p2p/ Kind regards
- 
	Hello! Traffic leaks prevention exists ever since Eddie Windows edition was created. The feature is "Network Lock". Click "Activate Network Lock" button from Eddie's main window before you start a connection. Network Lock will prevent any possible traffic leak outside the VPN tunnel. You may also configure Eddie to start with Network Lock enabled by checking "Activate Network Lock at startup" in "Preferences" > "Protocols" window. Kind regards
- 
	@alfavpn Hello! This might be relevant or not according to how SoulSeek considers NAT-PMP, which you keep enabled, priority when a specific listening port is also entered. NAT-PMP https://en.wikipedia.org/wiki/NAT_Port_Mapping_Protocol might bypass the port you have entered and it could also push the software to bind to the physical network interface. So, even if the program listens both to the NAT-PMP picked port and the manually specified port, the program might end up listening to the physical network interface ports, in place of the virtual network interface ports (assuming that the machine running SoulSeek is also the machine connecting to the VPN). Try to disable NAT-PMP and check whether it makes any difference. Although it's not BitTorrent or eMule, the following guide is useful for some SoulSeek settings too and for a relevant note about the router: https://airvpn.org/faq/p2p/ Kind regards
- 
	@Maggie144 Hello! Hummingbird's Network Lock is disabled when Eddie runs Hummingbird, because it would conflict with Eddie's Network Lock. Eddie keeps the control both of Network Lock and DNS management when it runs Hummingbird. Since Hummingbird enables its own Network Lock by default, Eddie must tell it explicitly not to do so with the proper option. You can see that Eddie's Network Lock is enabled: ! 2023.06.12 20:34:57 - Activation of Network Lock - macOS - PF while HB's Network Lock is disabled: W 2023.06.12 20:35:13 - Hummingbird > WARNING: Network filter and lock are disabled. Mode setting is ignored Kind regards
- 
	@Maggie144 Hello! Yes, the mentioned directive can not be accepted by OpenVPN3-AirVPN (except when pushed by the server). To solve the last problem you reported: from Eddie's main window select "Preferences" > "OpenVPN Directives" in the "Custom directives" box add the following line: -ping-exit 32 Please note the "-" sign in front of the line, telling Eddie to delete this directive from its list click "Save" and start a new connection Kind regards
- 
	@OpenSourcerer Hello! I mean hummingbird. Sure, we meant Hummingbird too. In other words, btcommon.h is needed to verify whether Bluetit is running or not and it is in the "includes", as Hummingbird is part of the Suite. We understand that a separate repository for Hummingbird alone causes this confusion, so we'll give green light to delete it (to be honest, the developer already asked for its deletion repeatedly, time to comply we guess ). Kind regards
- 
	@OpenSourcerer Great! It looks good... Hummingbird is part of the AirVPN Suite. btcommon.h is needed to verify whether Bluetit is running or not and it is in the "includes" as far as we can see. Kind regards
- 
	.thumb.png.8be84fd39f94c1640ac8c5456fbf3449.png)  ANSWERED Local ports for forwarded ports are ignored.Staff replied to space5's topic in Troubleshooting and Problems Hello! Confirmed. For the readers: the problem is that the system supports hot change (on the fly change) for port deletion, protocol change and port addition. However, the system does not support hot local port change, we're sorry. Quick solution: you will need to disconnect and re-connect when you need to change local port, as long as this feature is unimplemented. Luckily, local port change is, probably, quite a rare occurrence. Kind regards
- 
	@Maggie144 Hello! Hummingbird can not connect over SSH or stunnel at the moment due to an OpenVPN3 bug which has been brought in to OpenVPN3-AirVPN as well. We will be soon working to resolve this bug too. In the meantime, if you need OpenVPN over SSH, please use OpenVPN 2.x series. Thank you, you disclosed the bug. The error OpenSSLContext: SSL_CTX_use_certificate failed: error:0A00018E:SSL routines::ca md too weak is still under investigation. We have not found any SHA1-signed certificate for your account, which would explain the error message by OpenSSL. Also, the fact that Hummingbird alone does not throw the error makes the matter quite puzzling. If, from Eddie's main window, you uncheck "Remember me", log your account out, and log your account in again, does this error persist? Kind regards
- 
	@OpenSourcerer Hello! Your build fails because the file wireguard.h is not found. Note how it is delimited by double quotes, and not angular brackets, meaning that it is a local inclusion file. You can find it here: https://git.zx2c4.com/wireguard-tools/tree/contrib/embeddable-wg-library Kind regards
 Not connected, Your IP: 216.73.216.222
 Not connected, Your IP: 216.73.216.222
 Online: 35508 users - 396430 Mbit/s total BW
 Online: 35508 users - 396430 Mbit/s total BW 
			 
					
						