Pango Platform
HomeConsole
  • What is Pango Developer Platform
  • Getting started
    • Sign up on the Management Console
    • Create a new project
    • Switch projects
    • Change console settings
    • Edit your profile
    • Try out the demo app
    • Keep exploring
    • Deprecation and Sunset
  • Console details
    • Dashboard
      • General
      • Location loading
    • Users
      • User page
    • Active sessions
    • Network
      • Countries
      • Locations
      • Pools
        • Optimal location
        • Location rules
    • Settings
      • General
        • Project config description (JSON format)
          • Server selector (JSON format)
          • Request selector (JSON format)
      • Authentication methods
        • Auth Plugin requirements
      • VPN
        • General
        • VPN Bypass list
        • Client Networks
      • Member
    • Export Data
    • Log
  • SDK
    • Unified VPN SDK for Android
      • Setup
        • Application Setup
        • Proguard Rules, Notification, and Analytics Configurations
        • Backend URL Configuration
      • Usage
        • Initialization
        • VPN Interface
        • Backend interface
      • Features
        • Hydra Protocol
          • Location profile (Hydra only)
        • Custom sdk dependencies
        • Deferred VPN Service Initialization
        • Authentication
        • Client Network List (CNL)
        • OpenVPN transport
        • Wireguard Transport
        • Reconnection strategy
        • Single Protocol SDK
        • Killswitch
        • Domain route via VPN
        • Process route via VPN
        • Process Bypass
        • Domain Bypass
        • Traffic rules
        • VPN Node DNS Configuration
        • Multihop
          • Optimal Location
      • Exceptions
      • Version migration
      • Changelog
    • Unified VPN SDK for Apple
      • Setup
        • Application Setup
        • Network Extension Setup
          • Network Extension Setup for tvOS
        • Backend URL Configuration
      • Usage
        • Single Protocol SDK
        • Unified SDK
        • Logging
        • Decoding Encoded VPN SDK Logs
      • Features
        • Deferred VPN Service Initialization
        • Authentication
        • Wireguard Transport
        • Reconnection strategy
        • Killswitch
        • Domain Bypass
        • Multihop
          • Optimal Location
        • Client Network List (CNL)
        • Domain route via VPN
      • Changelog
      • API Reference
    • IPSEC VPN SDK for Apple
    • Unified VPN SDK for Windows
      • Setup
        • Backend URL Configuration
        • Service command line arguments
        • ARM Platform Support
      • Usage
        • CoreAPI
        • Events
        • Generating a Unique Device Identifier
        • Error processing
        • Pipe Messaging
      • Features
        • Traffic protection
          • Killswitch
          • Prevent IP Leaks
          • Block Local Networks
        • Other
          • Firewall
            • DNS Monitor
            • Process Bypass
            • Domain Bypass
            • Process route via VPN
            • Domain route via VPN
          • Throttling
          • Optimal Location
          • Common issues
        • Hydra Protocol
          • CustomDNS, UserDNS, MultiHop, VpnProfiles
        • OpenVPN Protocol
        • Wireguard Protocol
        • IPSec Protocol
      • Collecting Debug Logs
      • Changelog
    • Unified VPN SDK for Routers
      • SDK. Shared library.
      • Configuration Interface (CI)
        • Unix Domain Sockets CI
        • REST API CI
    • Unified VPN SDK Feature Comparison By Platform
    • Unified VPN SDK
      • Features
        • Personal Bridge
    • Tunnel Vision and Tunnel Crack Prevention
  • REST API
    • Partner API
  • Sample applications
    • Unified VPN SDK demo for Windows
    • Hydra VPN SDK demo for iOS
    • IPSEC VPN SDK demo for iOS
    • Unified VPN SDK demo for Android
    • Hydra VPN SDK demo for OpenWRT
    • OpenVPN configuration file
  • Resources
    • Use cases
      • Public VPN
      • Business VPN
        • Creating a Business VPN Project
        • Wi-Fi Security for Business
      • Application anti-blocking
    • How-to
      • Create a Firebase project for User Authentication
      • AWS CloudFront Distribution of the Platform URL
      • How can I get Shared Secret key from iTunes Connect for In-App Purchase
  • FAQ
    • General
      • VPN Platform Flow
      • What data is collected by the Platform?
      • What analytic data is collected by your SDK?
      • How the Platform restricts access to our data?
      • Why DNS Leak tests often indicate positive result?
      • Do we need to perform endpoint health checks?
      • How is the VPN exit node found?
      • How are streams re-marked if VPN is enabled/disabled on an active flow?
      • Is there a maximum number of supported devices?
      • Are both IPv4 and IPv6 supported?
      • What is the MTU of the tunnel?
      • Are any redundancy measures in terms of reliability provided?
      • Is there any load balancing?
      • Do you block broadcast and multicast to/from the VPN?
    • List of Open Source libs
Powered by GitBook
On this page
  • Creating a Fireshield Configuration
  • Fireshield Configuration
  • Fireshield Modes

Was this helpful?

  1. SDK
  2. Unified VPN SDK for Apple
  3. Features
  4. Hydra Protocol

Fireshield (Hydra transport)

In addition to VPN services, the Hydra SDK provides a content categorization service called Fireshield. When the SDK is configured with Fireshield enabled, the URLs of websites visited by the user are checked against a blacklist. If a website's URL is on the blacklist, traffic to and from it is blocked; otherwise, traffic is allowed through. The Hydra SDK provides an API to configure Fireshield and monitor its operation.

  • Fireshield service is available only for Hydra protocol.

  • Fireshield is not supported on tvOS platforms.

Creating a Fireshield Configuration

A categorization configuration is based on a specification of categories and rules for each category. To create categories, use one of the factory methods of the FireshieldCategory type:

Method
Description

FireshieldCategory.block(category: CategoryType) -> FireshieldCategory

Creates a category with the "block" action (traffic is blocked).

FireshieldCategory.proxy(category: CategoryType) -> FireshieldCategory

Creates a category with the "proxy" action (encrypted traffic goes through the tunnel as payload, for TCP only).

FireshieldCategory.bypass(category: CategoryType) -> FireshieldCategory

Creates a category with the "bypass" action (traffic goes directly to its destination, bypassing the VPN tunnel).

FireshieldCategory.alert(category: CategoryType) -> FireshieldCategory

Creates a category with the "block" action (traffic is blocked) and redirection to a specified alert page (HTTP only).

To add category rules that specify which domains belong to each category, use the following instance methods of the FireshieldConfig type:

Method Signature
Description

addRule(withFileName fileName: String, categoryType: FireshieldCategory.CategoryType, in bundle: Foundation.Bundle = .main)

Adds category rules from a file in the application bundle.

addRule(withDomains domains: [String], categoryType: FireshieldCategory.CategoryType)

Adds category rules from a list of domains.

In addition to file-based category configuration, you can use online categorization services. Possible values are defined as constants in the FireshieldConfig header file.

Fireshield Configuration

Fireshield can be either disabled or enabled with a particular mode. Set the mode using the fireshieldMode property of a FireshieldConfig instance. You can pass the respective config when initializing the HydraSDK (e.g., during application launch):

self.configuration = HydraConfiguration(
    // ...
    fireshieldConfig: makeFireshieldConfig(),
    // ...
)

// Fireshield config example
private func makeFireshieldConfig() -> FireshieldConfig {
    guard isFireshieldEnabled else {
        // Return `.disabled` if you don't need Fireshield
        return FireshieldConfig(
            mode: .disabled,
            groupData: VPNGroupData(
                groupID: "YOUR_GROUP_ID",
                usesSystemExtension: false
            )
        )
    }

    let config = FireshieldConfig(
        mode: .vpn,
        groupData: VPNGroupData(
            groupID: "YOUR_GROUP_ID",
            usesSystemExtension: false
        )
    )
    
    // Indicates that Fireshield started in DNS-mode only (default: false)
    config.isDNSModeEnabled = isDNSModeEnabled

    // Black and white lists
    do {
        // Blacklist rule
        try config.addRule(
            withDomains: ["untrusted-domain.com"],
            categoryType: .unsafe
        )

        // Whitelist rule 
        try config.addRule(
            withFileName: "whitelist.txt",
            categoryType: .safe  
        )

        print("Fireshield rules added")
    } catch {
        print("Fireshield rules error: \(error)") 
    }
    
    config.addService(.bitdefender)

    // Add behavior for safe category
    let safeCategory: FireshieldCategory = isBypassSafeTrafficEnabled ?
        .bypass(category: .safe) : .proxy(category: .safe)
    config.addCategory(safeCategory)
    
    // Block resources from unsafe category 
    config.addCategory(.block(category: .unsafe))

    // Custom categories
    if isSocialNetworkBlockingEnabled {
        config.addCategory(.block(category: .custom("safe:socialnetworks")))
    }

    return config
}

Always add a safe category to FireshieldConfig to allow safe traffic.

Fireshield Modes

Fireshield can operate in various modes for added flexibility. For example, you can blend VPN and Fireshield functionality or hide the VPN icon in the iOS status bar. The modes are represented by the FireshieldMode type:

Mode
Description

Disabled

Fireshield is disabled.

Enabled

Fireshield is enabled. The VPN icon is displayed in the status bar, but traffic does not go through the VPN.

VPN

This is the default value. Blends Fireshield and VPN functionality. All traffic goes through the VPN, while Fireshield blocks access to blacklisted websites. The VPN icon is displayed in the status bar.

Fireshield config settings may be overwritten by remote config.

Last updated 3 months ago

Was this helpful?