Jump to content
Not connected, Your IP: 3.237.94.109

Technical Specs

We provide ONLY OpenVPN protocol/servers.
  • OpenVPN >=2.4, negotiation with following ciphers (ncp-ciphers directive server-side):
    AES-256-GCM AES-256-CBC AES-256-CFB AES-256-OFB AES-256-CFB1 AES-256-CFB8 AES-128-GCM AES-128-CBC AES-128-CFB AES-128-OFB AES-128-CFB1 AES-128-CFB8 CAMELLIA-256-CBC SEED-CBC
    OpenVPN <2.4, AES-256-CBC as data channel cipher.
  • Negotiation with following TLS ciphers (IANA names, tls-cipher directive server-side):
    TLS-DHE-RSA-WITH-AES-256-GCM-SHA384 TLS-DHE-RSA-WITH-AES-256-CBC-SHA256 TLS-DHE-RSA-WITH-AES-256-CBC-SHA TLS-DHE-RSA-WITH-CAMELLIA-256-CBC-SHA
    Unlike the OpenVPN default, we don't accept any AES-128 or any TLS-ECDHE.
  • Perfect Forward Secrecy through Diffie-Hellman key exchange DHE. After the initial key negotiation, re-keying is performed every 60 minutes (this value can be lowered unilaterally by the client)
  • 4096 bit RSA keys size
  • 4096 bit Diffie-Hellman keys size (unique for each server, VPN or webserver)

Recommended daemons (client >=2.4) (not yet supported in all servers)

  • Encrypt and authenticate all control channel packets (tls-crypt directive) with 2048 bit.
  • SHA512 message digest (if the negotiated cipher is not AEAD, e.g. GCM).

Compatibility daemons (client <2.4)

  • TLS additional authorization layer key (tls-auth directive): 2048 bit
  • HMAC-SHA1 for authentication

Available port/protocols

Multiple entry ports (53, 80, 443, 1194, 2018, 28439, 38915, 41185), native OpenVPN tcp/udp or with additional tunnel layers (SSL, SSH).

Assigned IP

Servers support both IPv4 and IPv6 tunnel (exit-ip), and are reachable over IPv4 and IPv6 (entry-ip). Currently (2018/01) not all servers support IPv6 tunnel yet.
DNS server address is the same as gateway, in both IPv4 and IPv6 layer.

IPv4 Local Address chosen: 10.{daemon}.*.*, Subnet-Mask: 255.255.255.0
IPv6 Unique Local Address (ULA) chosen: fde6:7a:7d20:{daemon}::/48.

Restrictions

  • Outbound port 25 blocked to prevent spam.

VPN DNS Server

OpenNIC
Namecoin
  • Every VPN server has its DNS server, directly finds out information about the root servers, top level domains and authoritative name servers.
  • Our DNS servers are neutral, do not ever inject or alter the requests (other services resolve to search results, try to fix typo etc).
  • Where ICANN or root servers themselves interfer with censorship, we may apply specific censorship fix to our DNS server. See "AirVPN does not recognize ICANN authority anymore" topic for more informations.
  • Using our DNS allows our customers to use our anti-geolocation discrimination features. For example, visit a website that allows only United States connections from a Netherlands VPN server.
  • It's recommended to use our DNS server to avoid censorship and use our anti-geolocation features.
  • VPN DNS addresses (private addresses, only reachable from inside the VPN): 10.4.0.1 / fde6:7a:7d20:4::1 - reachable from any virtual subnet
    However, we recommend that your machine accepts the DNS push from our servers. If that's not possible, then we suggest to set the DNS IP address matching the VPN gateway IP address, as this is the safest method to prevent certain attacks based on hijacking.
  • For any kind of issue about censorship or geolocation restriction you encounter using our services, please feel free to write us in our forums or write a support ticket.

Protocols and entry-IP addresses of each VPN server

Every AirVPN server has 4 entry-IPv4 addresses and 4 entry-IPv6 addresses that support different ports and protocols. Look at the faq "How can I get VPN servers entry-IP addresses?" for more information about FQDN resolution.

Type Entry IP Protocol & port Specs Description Min. OpenVPN version
OpenVPN3udp 443tls-crypt, tls1.2Recommended for best performance2.4
OpenVPN3tcp 443tls-crypt, tls1.2If you have issue with UDP2.4
OpenVPN3udp 80tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3udp 53tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3udp 1194tls-crypt, tls1.2Official OpenVPN port2.4
OpenVPN3udp 2018tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3udp 41185tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges2.4
OpenVPN4udp 443tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4udp 80tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4udp 53tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4udp 1194tls-crypt, tls1.2Official OpenVPN port, if your ISP blocks the standard Entry IP2.4
OpenVPN4udp 2018tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4udp 41185tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP2.4
OpenVPN3tcp 80tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3tcp 53tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3tcp 1194tls-crypt, tls1.2Official OpenVPN port2.4
OpenVPN3tcp 2018tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3tcp 41185tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges2.4
OpenVPN4tcp 1194tls-crypt, tls1.2Official OpenVPN port, if your ISP blocks the standard Entry IP2.4
OpenVPN4tcp 2018tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4tcp 41185tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP2.4
OpenVPN3ssh 22tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN4ssh 80tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN4ssh 53tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3ssh 38915tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges2.4
OpenVPN4ssh 22tls-crypt, tls1.2If your ISP blocks the standard Entry IP2.4
OpenVPN4ssh 38915tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP2.4
OpenVPN4ssl 443tls-crypt, tls1.2If your ISP applies caps or blocks2.4
OpenVPN3ssl 28439tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges2.4
OpenVPN4ssl 28439tls-crypt, tls1.2If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP2.4
OpenVPN1udp 443Recommended for best performance
OpenVPN1tcp 443If you have issue with UDP
OpenVPN1udp 80If your ISP applies caps or blocks
OpenVPN1udp 53If your ISP applies caps or blocks
OpenVPN1udp 1194Official OpenVPN port
OpenVPN1udp 2018If your ISP applies caps or blocks
OpenVPN1udp 41185If your ISP applies caps or blocks on lower port ranges
OpenVPN2udp 443If your ISP blocks the standard Entry IP
OpenVPN2udp 80If your ISP blocks the standard Entry IP
OpenVPN2udp 53If your ISP blocks the standard Entry IP
OpenVPN2udp 1194Official OpenVPN port, if your ISP blocks the standard Entry IP
OpenVPN2udp 2018If your ISP blocks the standard Entry IP
OpenVPN2udp 41185If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP
OpenVPN1tcp 80If your ISP applies caps or blocks
OpenVPN1tcp 53If your ISP applies caps or blocks
OpenVPN1tcp 1194Official OpenVPN port
OpenVPN1tcp 2018If your ISP applies caps or blocks
OpenVPN1tcp 41185If your ISP applies caps or blocks on lower port ranges
OpenVPN2tcp 1194Official OpenVPN port, if your ISP blocks the standard Entry IP
OpenVPN2tcp 2018If your ISP blocks the standard Entry IP
OpenVPN2tcp 41185If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP
OpenVPN1ssh 22If your ISP applies caps or blocks
OpenVPN2ssh 80If your ISP applies caps or blocks
OpenVPN2ssh 53If your ISP applies caps or blocks
OpenVPN1ssh 38915If your ISP applies caps or blocks on lower port ranges
OpenVPN2ssh 22If your ISP blocks the standard Entry IP
OpenVPN2ssh 38915If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP
OpenVPN2ssl 443If your ISP applies caps or blocks
OpenVPN1ssl 28439If your ISP applies caps or blocks on lower port ranges
OpenVPN2ssl 28439If your ISP applies caps or blocks on lower port ranges and blocks the standard Entry IP

Web Servers

Web site supporting HTTP2, Perfect Forward Secrecy, Secure Renegotiation, TLS 1.2 or 1.3, DHE, ECDHE and HSTS. No external tracking applications or cookies from third parties.
  • airvpn.org web server configuration provides a balance between compatibility and security strength, with no dangerous compromise (A+ rating in Qualys SSL Labs).
  • airvpn.dev web server configuration provides a hardened security configuration to get a rating aiming to 100% (Qualys SSL Labs, CryptCheck) which sacrifices compatibility with older systems and browsers (example: Android 6 will not connect).
  • airvpn3epnw2fnsbx5x2ppzjs6vxtdarldas7wjyqvhscj7x43fxylqd.onion is the onion Tor version. Served in HTTP and HTTPS. HTTP version is recommended, as HTTPS is superfluous with onion hidden services. HTTPS version needs acknowledgment and exception for certificate domain name mismatch, no solution is possible right now.
  • airvpn.eth official frontend via ENS resolution, that resolves into our .onion address.

All website have a PWA (Progressive Web App), use "Add to Home Screen" to instantiate it.
Mail SPF, DKIM, ADSP and DMARC on all domains managed by us.
DNSSEC on our domains (except ipleak.net, airservers.org and airdns.org)

Vulnerability Disclosure Policy and Bug Bounty Program

×
×
  • Create New...