iOS App Randomly Reconnects to United States Servers instead of Country I Click On

On the assumption that anything the Brave browser blocks would be one less query counted towards that limit, using NextDNS’ free version could be quite good… I wonder if it will be possible to keep the device protection and keep Quad9.

Quad9’s servers, on the server side, only have malicious link blocking and not ad blocking, as opposed to AdGuard’s DNS server.

The AdGuard app’s default mode, where it used that local VPN that loops back into the device, I assume it let AdGuard process the requests locally, because even when I have the DNS server setting in the app set to Quad9, it still blocks the ads. Given that, my previous iOS networking setup was that the traffic would first loop through AdGuard’s local VPN tunnel back into the iPad to be filtered by the app, and then sent off through ProtonVPN’s IKEv2 tunnel via split-tunneling support, while using Quad9 for DNS queries.

Switching the AdGuard app to Native mode fully overrides the device’s DNS setting by adding a managed DNS configuration (inside the “VPN, DNS, and Device Management” settings menu, not in a given Wi-Fi connection’s DNS configurations), and so I can only either use Quad9 and only have malicious link blocking, or use AdGuard DNS and get full adblocking.

I wish Apple allowed for more freedom and didn’t restrict split-tunneling so much. :disappointed_face:

That is why Quad9 or AdGuard DNS doesn’t make much sense with configuration profiles, as you have no control whatsoever. Then one can use Netshield directly as well. If one needs / wants control, then NextDNS nice as it is very customizable.

I’m looking forward to your guide coming out, then!

Can’t use netshield 'cause I use the free plan, but anything else would be really good.

Thanks so much for being patient with me, and for being the guy who understands. It’s a breath of fresh air!

Looks like I’m not using Brave Browser yet, I just discovered a vulnerability in the iOS app where you can bypass the browser lock BY PRESSIGN GODDAMN FUCKING CANCEL ON THE TOUCH ID PIPOPPUP :NotLikeThis:

https://youtu.be/zilN6otAoCc

I’m gonna be sticking with the IKEv2 solution for some time

Edit: Okay it’s not as bad as I thought but it’s still an epic fail of a security flaw. https://youtu.be/up8634utByc