Jump to content

OverviewMissionSpecsFAQTerms Of ServicePrivacyAbout Us

Technical Specs
We provide ONLY protocol/servers.
  • OpenVPN >=2.4, negotiation with following ciphers (ncp-ciphers directive server-side):
    OpenVPN <2.4, AES-256-CBC as data channel cipher.
  • Negotiation with following TLS ciphers (IANA names, tls-cipher directive server-side):
    Unlike the OpenVPN default, we don't accept any AES-128 or any TLS-ECDHE.
  • Perfect Forward Secrecy through Diffie-Hellman key exchange DHE. After the initial key negotiation, re-keying is performed every 60 minutes (this value can be lowered unilaterally by the client)
  • 4096 bit RSA keys size
  • 4096 bit Diffie-Hellman keys size (unique for each server, VPN or webserver)

Recommended daemons (client >=2.4) (not yet supported in all servers)

  • Encrypt and authenticate all control channel packets (tls-crypt directive) with 2048 bit.
  • SHA512 message digest (if the negotiated cipher is not AEAD, e.g. GCM).

Compatibility daemons (client <2.4)

  • TLS additional authorization layer key (tls-auth directive): 2048 bit
  • HMAC-SHA1 for authentication

Available port/protocols

Multiple entry ports (53, 80, 443, 1194, 2018, 28439, 38915, 41185), native OpenVPN tcp/udp or with additional tunnel layers (SSL, SSH).

Assigned IP

Servers support both IPv4 and IPv6 tunnel (exit-ip), and are reachable over IPv4 and IPv6 (entry-ip). Currently (2018/01) not all servers support IPv6 tunnel yet.
DNS server address is the same as gateway, in both IPv4 and IPv6 layer.

IPv4 Local Address chosen: 10.{daemon}.*.*, Subnet-Mask:
IPv6 Unique Local Address (ULA) chosen: fde6:7a:7d20:{daemon}::/48.


  • Outbound port 25 blocked to prevent spam.

VPN DNS Server

  • Every VPN server has its DNS server, directly finds out information about the root servers, top level domains and authoritative name servers.
  • Our DNS servers are neutral, do not ever inject or alter the requests (other services resolve to search results, try to fix typo etc).
  • Where ICANN or root servers themselves interfer with censorship, we may apply specific censorship fix to our DNS server. See "AirVPN does not recognize ICANN authority anymore" topic for more informations.
  • Using our DNS allows our customers to use our anti-geolocation discrimination features. For example, visit a website that allows only United States connections from a Netherlands VPN server.
  • It's recommended to use our DNS server to avoid censorship and use our anti-geolocation features.
  • VPN DNS addresses (private addresses, only reachable from inside the VPN): / fde6:7a:7d20:4::1 - reachable from any virtual subnet
    However, we recommend that your machine accepts the DNS push from our servers. If that's not possible, then we suggest to set the DNS IP address matching the VPN gateway IP address, as this is the safest method to prevent certain attacks based on hijacking.
  • For any kind of issue about censorship or geolocation restriction you encounter using our services, please feel free to write us in our forums or write a support ticket.

Web Server - airvpn.org

  • Web site supporting HTTP2, Perfect Forward Secrecy, Secure Renegotiation, TLS up to 1.2, DHE, ECDHE and HSTS.
  • No external tracking applications or cookies from third parties.
  • See Qualys SSL Labs for a peer review of our web site.
Servers online. Online Sessions: 14483 - BW: 46115 Mbit/sYour IP: Access.