StunTLS carries an SSH tunnel inside an encrypted TLS connection, so to a network filter it looks like ordinary secure traffic. It connects straight to the server's IP address and doesn't use DNS, which makes it a good fallback on networks that filter or control DNS. This guide covers the SlipNet app on Android, the settings for adding it by hand, and other apps that may work.
How it works
- Your device opens a TLS connection to the SlipNet server, usually on port
8443. - Inside that, it runs a WebSocket connection, and inside that, an SSH tunnel signed in with your SlipNet username and password.
- No domain name or DNS lookup is involved. You connect to the server's IP address.
- The server uses its own TLS certificate rather than one from a public certificate authority. Apps other than SlipNet may need certificate checking turned off (see Troubleshooting). Your connection is still encrypted by SSH inside the TLS layer.
When to use it
Try StunTLS when the DNS tunnels (VayDNS, NoizDNS, DNSTT and Slipstream) won't connect because DNS is tightly filtered, or as a quick fallback on office and hotel networks. It's usually faster than the DNS tunnels. If direct connections to our server addresses are blocked on your network, it won't connect, and a DNS tunnel is the better choice.
What you need
- An active PremierVPN VPN plan
- SlipNet activated on at least one server in the portal
- The free SlipNet app on Android, or one of the other apps below
Android: the SlipNet app
This is the easiest way, and the one we test.
- Sign in to the portal and go to Anti-Censorship › SlipNet.
- Click Activate on a server if you haven't already.
- Open the StunTLS group under Connection links and click Copy.
- Open SlipNet on your phone, tap +, then Import from URI. Paste the link and tap Import.
- The profile appears as an SSH tunnel using WebSocket over TLS. Select it and connect.
If SlipNet says the link can't be imported, click Refresh links on the SlipNet page, copy the StunTLS link again and import the new one.
Manual settings
To add StunTLS to another app, or to SlipNet by hand, use these settings. You'll find the server address and port in the Manual settings box under the StunTLS links on the SlipNet page, and your username and password at the top of the server's section.
| Setting | Value |
|---|---|
| Connection type | SSH |
| Server | The server address from the SlipNet page (an IP address) |
| Port | The port from the SlipNet page, usually 8443 |
| Username | Your SlipNet username |
| Password | Your SlipNet password |
| TLS / SSL | On |
| WebSocket | On, path / |
| Certificate check | Off (sometimes called Allow insecure) |
| SNI | Leave blank, or enter the server address |
The server also accepts plain SSH inside TLS without WebSocket, and an HTTP CONNECT request inside TLS. If an app offers SSH over SSL/TLS but no WebSocket option, it should still work.
Other apps that may work
These third-party apps can make SSH connections over TLS. We haven't tested them all with StunTLS and can't support them directly, and their menus change between versions, so use the manual settings above and look for the matching options.
- Android: HTTP Custom or HTTP Injector. Create an SSH connection, enter the server, port, username and password, and turn on SSL/TLS. If there's a WebSocket or payload option, either use a WebSocket upgrade to path
/or leave it off. - iPhone and iPad: Npv Tunnel (formerly NapsternetV). Add an SSH configuration with the server, port, username and password, and turn on TLS. Only one VPN app can be active on iOS at a time, so turn off any other VPN first.
- Windows, macOS and Linux: OpenSSH. This gives you a SOCKS proxy for the apps you point at it, such as a web browser. It isn't a system-wide VPN. See the steps below.
On iPhone and iPad, the PremierVPN app and our PremierNexus app (StormDNS) are often simpler options on restricted networks. See What is SlipNet?
Computers: SSH with a SOCKS proxy
Replace SERVER, PORT and USERNAME with your details from the SlipNet page. Enter your SlipNet password when asked. The first time, SSH asks you to confirm the server's key: type yes.
macOS and Linux
Open Terminal and run:
ssh -N -D 1080 -o ProxyCommand="openssl s_client -quiet -connect SERVER:PORT" USERNAME@SERVER
Leave the window open while you're connected. Press Ctrl+C to disconnect.
Windows
Windows 10 and 11 include the SSH client. To wrap it in TLS, install stunnel, then:
- Open stunnel's configuration file (Edit Configuration from its tray icon) and add:
[stuntls] client = yes accept = 127.0.0.1:2222 connect = SERVER:PORT - Save it and choose Reload Configuration.
- Open Command Prompt or PowerShell and run:
ssh -N -D 1080 -p 2222 [email protected]
Leave the window open while you're connected.
Use the proxy in your browser
In Firefox, go to Settings › Network Settings › Settings, choose Manual proxy configuration, enter 127.0.0.1 and port 1080 as the SOCKS Host, select SOCKS v5, and tick Proxy DNS when using SOCKS v5. Other apps that support a SOCKS5 proxy can use the same address and port.
Troubleshooting
- The link won't import into SlipNet. Click Refresh links on the SlipNet page and import the new StunTLS link.
- Certificate or TLS errors in another app. Turn off certificate checking (Allow insecure). The server's certificate isn't from a public authority, so strict checking rejects it.
- Connects, then nothing loads. Check the username and password are exactly as shown in the portal, using the copy buttons. In other apps, make sure DNS goes through the tunnel.
- It won't connect at all. Your network may block direct connections to our server addresses. Try a DNS tunnel such as VayDNS or NoizDNS instead. See Which Protocol Should I Use?
- SSH warns that the server's key has changed. Don't connect. Open a ticket and we'll check it.
Still stuck? Open a support ticket from the portal and tell us which app and server you're using.