keweonDNS - now with improved Certificate (iOS, Mac & Android)

bond32

Senior Member
Jun 26, 2010
1,175
245
0
Franklin

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
Thanks, I had this primed and ready, but was curious if a root-access alternative provided additional functionality. More functionality than just the VPN icon disappearing...
If you have troubles with this App contact the Developer. Daniel is happy about every feedback and he is really quick with updates.

I don't know if other Apps are also working. I'm using this App since 3 yrs
 
  • Like
Reactions: bond32

adewisman

Senior Member
Feb 2, 2013
558
646
0
Bandung
If you have troubles with this App contact the Developer. Daniel is happy about every feedback and he is really quick with updates.

I don't know if other Apps are also working. I'm using this App since 3 yrs
the app just crashed on latest Miui rom this one working tho : https://play.google.com/store/apps/details?id=com.dnschanger.dnsdegistirici.rootsuz . I have already sent an email of the logs to the devs.

one more thing if I use iptables to redirect dns request using init.d scripts like this :

Code:
 iptables -t nat -A OUTPUT -p udp --dport 53 -j DNAT --to-destination 137.74.155.255:53 && \ iptables -t nat -A OUTPUT -p tcp --dport 53 -j DNAT --to-destination 137.74.155.255:53
why can't I connected to google playstore? , other connection working good tho, and how to debug if something goes wrong with the dns request?,

and your dns is very solid I tried testing it with dnsleak.com its literally hide my connection, great job.
 
  • Like
Reactions: MrT69

Ksathral

Member
Dec 15, 2016
7
4
13
why can't I connected to google playstore? , other connection working good tho, and how to debug if something goes wrong with the dns request?,
Are you not able to connect at all to the playstore or does it not start downloads?

I was having issues with downloads not starting in playstore and also spotify. After setting the dns app to "always on" in the Android connection settings the issue was resolved and downloads are working again.
 
Last edited:
  • Like
Reactions: MrT69

adewisman

Senior Member
Feb 2, 2013
558
646
0
Bandung
Are you not able to connect at all to the playstore or does it not download?

I was having issues with downloads not starting in playstore and also spotify. After setting the dns app to "always on" in the Android settings the issue was resolved and downloads are working again.
It didnt get connected, just a white page.
 

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
It's interesting why a view of you can't get connect to PlayStore. The palystore is definitely not blocked.
Unfortunately I have only Samsung, HTC and Apple devices here around for testing.
For playing around with Android I'm also using Andyroid (Andy Android VM) to check if something went wrong.

There is something blocked what needs to be unblocked and on the other hand what the hell they have hide inside this Apps??? At the moment I have no quick solutions for you because on every device on my side everything is working.

When you know a way to use MUI within an Emulator or if you know someone who has experience within URL logging please let me know. If you have any other idea to find it let me know.

Sorry folks. That's currently not a good news for me.

EDIT:
Found a solution and I guess until tomorrow the problem should be fixed. ?
 
Last edited:

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
Germany is already in Progress.
The problem is that the German BSI make an weekly Inventory on all German IP Adresse to investigate if it's an Open Resolver. On the one hand a good thing because Open Resolver could break down the entire Internet and on the other hand this will cause a lot of troubles for me because I need harder security to prevent this.

It's already done but I need to do more and deeper tests. I guess Germany (and France) will be online on next Thursday or Friday.

At the moment I recommend UK and NL for use in Europe until Germany and France is Online.
 
Last edited:

adewisman

Senior Member
Feb 2, 2013
558
646
0
Bandung
Germany is already in Progress.
The problem is that the German BSI make an weekly Inventory on all German IP Adresse to investigate if it's an Open Resolver. On the one hand a good thing because Open Resolver could break down the entire Internet and on the other hand this will cause a lot of troubles for me because I need harder security to prevent this.

It's already done but I need to do more and deeper tests. I guess Germany (and France) will be online on next Thursday or Friday.

At the moment I recommend UK and NL for use in Europe until Germany and France is Online.
thank you for contacting me, I seem can not send a message to your wa but I sent some details on your telegram account, and I couldn't pm you on xda too, thank you.

Edit : confirm playstore working with Netherlands server.

Code:
iptables -t nat -A OUTPUT -p udp --dport 53 -j DNAT --to-destination 45.77.138.206 && \ iptables -t nat -A OUTPUT -p tcp --dport 53 -j DNAT --to-destination 45.77.138.206
Im using a magisk module to run the iptables command on reboot, if anyone interested to test it too kindly grab it here : https://drive.google.com/file/d/0B-pSptpnbKwlREktUVY0Unc3YlU/view?usp=drivesdk
 
Last edited:
  • Like
Reactions: hafiz.hasan

hafiz.hasan

Senior Member
Feb 4, 2013
205
54
0
thank you for contacting me, I seem can not send a message to your wa but I sent some details on your telegram account, and I couldn't pm you on xda too, thank you.

Edit : confirm playstore working with Netherlands server.

Code:
iptables -t nat -A OUTPUT -p udp --dport 53 -j DNAT --to-destination 45.77.138.206 && \ iptables -t nat -A OUTPUT -p tcp --dport 53 -j DNAT --to-destination 45.77.138.206
Im using a magisk module to run the iptables command on reboot, if anyone interested to test it too kindly grab it here : https://drive.google.com/file/d/0B-pSptpnbKwlREktUVY0Unc3YlU/view?usp=drivesdk
how do i check if it works or it has changed?
 

adewisman

Senior Member
Feb 2, 2013
558
646
0
Bandung

Attachments

  • Like
Reactions: MrT69

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
Hi folks!

Please don't compare my DNS Servers with any current standard Servers. For security reasons I locked them down within a damn hard way and if the servers will see any non Standart use every request will be dropped.

Why?
DNS itself is a very sensible Technologie and with a wrong and false configured server you can break down the entire Internet. (Amplifier, DDoS, Mitigation)
At the fist start here at XDA it was a need to change 3 times the Provider because right after the release idiot's running attacks against the server.
Frustrating thing.

The current system a very low budget system but it's working. It's working for local PCs, Mobile Devices and Tablets and for Soho/WiFi Router for to run keweon with one step on every device at home.

Please understand that all other additional things are not possible. This is only related to the reason that I'm running everything on low budget VPS.
As former employee from Level3 they made me an offer to store the entire Infrastructure within the Data Center. Only for the security and even for an Ex employee the would charge 4000 Euro per Month (!) only for this. No kidding - just only for Security. No Rack, Hardware or anything else.

Please understand that I need a heavy security on the servers because I want to keep them longer Online for all of us.

Thanks a lot and any recommendations, tips and help are always welcome.
 
Last edited:
  • Like
Reactions: adewisman

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
Data Center outage Monday at 2 PM GMT +1


The HTTP/HTTPS Termination Server would be offline for round about 2 to 3 hours tomorrow morning. Currently the system is not redundant because this will cause to many costs.

All further updates, informations and technical Details and Staus of Server and Data center be available for the future on this website:

http://status.keweon.center

Impact:
Adblock and Security is still given. The website and the ads Termimation will not look very pretty.

Personal Note:
Need to think about an AMAZON Load Balancer. Has anyone experience about the price of this?
 
  • Like
Reactions: adewisman

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
Ads Termination improvements (HTTP & HTTPS):

- installed Loadbalancer from scratch
- enhanced backend infrastructure
- extended backend infrastructure to 50 Servers
- adjust https response time
- Version upgrade of "Zero SSL Session Broker"
- Reduced memory usage
- Reduced initialization response
- enhanced "Zero SSL Session Responder"
- extended SSL Ciphers
- improved the Domain response
- dropped packet inspection
- enhanced firewall security
- reduced response time

The Server should now run more stable. It's still a VPS environment but I hope to keep the system now more stable with all the changes.

The websites should now look much more pretty and the load of the websites should also processed faster by using the keweon Root Certificate.

Thanks to all tester.
 
Last edited:
  • Like
Reactions: adewisman

MrT69

Senior Member
May 9, 2006
1,731
4,387
153
51
Königsbrunn
www.keweon.de
System Upgrade:

To run keweonDNS on a virtual environment is not the best solution. I know this and please see this as an Proof of Concept.
I see that the VPS sometimes will not do what they should do. Therefore I will do a RAM upgrade and hope that this system will get more stable and faster. I also hope that the performance will increase.

During the coming weekend it is a need to reboot each Server two times. Until they are back again it will take round about 90 seconds for each reboot.

This will not have an impact if you stay i.e. on Facebook or on any other site.
If you are open a website at this moment you will get an timeout. Please wait a moment, take a smoke or order an cup of coffee and everything is fine again within less than 5 Minutes.

I hope the system will become stronger with this.

Thanks in advance