What's new

[Release] Asuswrt-Merlin 384.12 is now available

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

To be fair, his isn’t dcd but cfg_server. :D
 
I've upgraded my AC86U from 384.10_2 to 384.12. It seems that everything works OK, but my dnsmasq.con.add doesn't apply the configuration that I've added.
The file is called /jffs/configs/dnsmasq.conf.add ?

Jffs scripts is enabled in the GUI?
 
To people having the Asus website coming up when clicking on the Check button, make sure you download a firmware built by me. If you (or someone else) compiles their own firmware image, it will NOT use my update server, and will default to Asus's download site. This is by design, to avoid having people hacking their own version and hitting my update server with bogus update checks. Proper update check must be enabled at compile time.
 
make sure you download a firmware built by me
:)
upload_2019-6-25_16-6-26.png
 
V
 
Last edited:

Then I don't know what's wrong with your setup. I just tested it on my own RT-AC86U, and no issue here. You could check your browser console for any Javascript error that might indicate a problem with that page.

Check on your Tools -> Sysinfo page, the Features section should list the "update" flag (they are in alphabetical order).
 
The problem disappeared before I start checking what is happening. VPN is working properly now with Inbond Firewall Block. Temporary VPN server overload perhaps between my reboots, who knows.

Same problem again, twice today.

VPN server I'm using is at 40% load and very fast with the Desktop client. If Inbound Firewall Block is selected in OpenVPN settings, the VPN speed at some point drops to about 10% of the normal speed. Doesn't happen immediately, but after some time. Inbound Firewall Allow + Router Reboot restores the VPN speed to the maximum for the selected server.

Any ideas why it is happening?
 
Something has changed between the prior two versions of Merlin and 384.12 regarding VPN servers.

Before installing 384.12 I performed a "nuclear reset" on my AC86.

While previously I had no problem getting a VPN server and two VPN clients running I haven't been able to get the VPN server to run.

Tested the ASUS DDNS and it resolves correctly to my WAN IP.

Varied some other WAN settings and nothing seemed to make a difference

The log has repeated entries as follows and the wheel just keeps spinning.

Jun 25 15:53:00 rc_service: service 7532:notify_rc restart_letsencrypt
Jun 25 15:53:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...
Jun 25 15:53:15 rc_service: skip the event: restart_letsencrypt.

Jun 25 15:54:00 rc_service: service 7589:notify_rc restart_letsencrypt
Jun 25 15:54:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...

Jun 25 15:54:15 rc_service: skip the event: restart_letsencrypt.
.
.
I tried numerous settings on the server, but haven't tried using a self generated set of keys yet. On other thing I did notice is that when you click the default button after making changes so you can start over it doesn't really set it back to starting values but only deletes the user name and password.

After trying numerous settings on the server side I managed first to get it so that the VPN clients could not be stopped and then finally I got it so neither of the clients would run or could be started. VPN clients running on ports 1197 & 1198 so no conflict with server ports.

Had to do a factory reset and start over and get the VPN clients going again.
 
Jun 25 15:53:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...
Jun 25 15:53:15 rc_service: skip the event: restart_letsencrypt.

Something is apparently causing your vpnserver to get stuck starting. What's in your System Log during the server start?
 
To people having the Asus website coming up when clicking on the Check button, make sure you download a firmware built by me. If you (or someone else) compiles their own firmware image, it will NOT use my update server, and will default to Asus's download site. This is by design, to avoid having people hacking their own version and hitting my update server with bogus update checks. Proper update check must be enabled at compile time.

I'm using your firmware and the link opens to Asus as well.

Hovering over the check button shows the address as Asus.
 
I'm using your firmware and the link opens to Asus as well.

Hovering over the check button shows the address as Asus.

What does the following command returns?

Code:
nvram get firmware_server
 
Are you running 384.12? That URL is normally automatically upgraded the first time you boot 384.12.

That wouldn't be an issue tho, both URLs are still valid.

No, I'm still running 384.11 - so this issue is not specific to 384.12.
 
Think I found it. The Check button reverts to the Asus link if you disable the Firmware update check. If you re-enable it (and reload the page to refresh it), it should properly point to my servers.
 
Something is apparently causing your vpnserver to get stuck starting. What's in your System Log during the server start?

Here is the entire log from when I tried a restart of the server. Other entries mixed in are the result of Skynet blocking certain IPs. MAC address have been partially erased for security.


Jun 25 16:26:15 rc_service: skip the event: restart_letsencrypt.
Jun 25 16:26:17 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=:26:82:b8:20:00:01:5c:71:b8:46:08:00 SRC=178.19.107.42 DST=71.203.10.63 LEN=40 TOS=0x00 PREC=0x20 TTL=234 ID=48551 PROTO=TCP SPT=40902 DPT=8545 SEQ=2539165433 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Jun 25 16:26:18 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=:26:82:b8:20:00:01:5c:71:b8:46:08:00 SRC=185.176.26.18 DST=71.203.10.63 LEN=40 TOS=0x00 PREC=0x20 TTL=238 ID=47107 PROTO=TCP SPT=46045 DPT=3210 SEQ=3173236406 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
Jun 25 16:27:00 rc_service: service 14806:notify_rc restart_letsencrypt
Jun 25 16:27:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...
Jun 25 16:27:15 rc_service: skip the event: restart_letsencrypt.
Jun 25 16:28:00 rc_service: service 14866:notify_rc restart_letsencrypt
Jun 25 16:28:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...
Jun 25 16:28:15 rc_service: skip the event: restart_letsencrypt.
Jun 25 16:29:00 rc_service: service 14925:notify_rc restart_letsencrypt
Jun 25 16:29:00 rc_service: waitting "restart_chpass;restart_vpnserver1" via httpd ...
Jun 25 16:29:15 rc_service: skip the event: restart_letsencrypt.
Jun 25 16:29:15 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=:26:82:b8:20:00:01:5c:71:b8:46:08:00 SRC=194.61.24.187 DST=71.203.10.63 LEN=40 TOS=0x00 PREC=0x20 TTL=233 ID=25374 PROTO=TCP SPT=44334 DPT=33899 SEQ=1148710218 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000
 
Think I found it. The Check button reverts to the Asus link if you disable the Firmware update check. If you re-enable it (and reload the page to refresh it), it should properly point to my servers.
Now it says Contacting the update server ...
The router's current firmware is the latest version.
No redirect to asus site now , https://fwupdate.asuswrt-merlin.net/
 
Last edited:

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top