What's new

Trend Micro - Odd behavior after update to 378.54_2

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

mirage22

Regular Contributor
Hi,

I have configured OpenDns on my router. On the WAN, LAN and VPN.

After upgrading to the latest merlin FW 378.54_2 i made one more change on the router - the VPN Policy
- Created a rule for WAN access from 192.168.1.1 (destination empty)
- Created a rule for VPN from 192.168.1.0/24 (destination empty)

Earlier, I used to see Trendmicro on the OpenDNS dashboard at the top position for the number of times it was accessed. It used to be between 2000-3000 accesses a day. I figured this is because trendmicro was enabled on the router to scan all internet activity.

After the update and making the above change on the router, when I check the log for the last few days, trendmicro's access has fallen to 10-12 a day!!

Does it mean
A) Trendmicro is not working in the latest update? (it is enabled).
B) did the above policy routing somehow enable the router to bypass opendns? if so, how? Is there a DNS leak? ipleak.net doesn't report any leak. I have also configured OpenDNS on my router for all possible options - WAN, LAN and VPN.
C) Or something else

EDIT:
I remembered a website that was blocked by Trend earlier. I retried it a while ago and it opened. So I guess Trend is not running, which it shows as running on the AI Protection page. Any suggestions?
 
Last edited:
ironically I just played around with opendns yesterday. I think I messed up a setting, and put opendns server in the wan section as well as one client set to use opendns in the aiprotection area. I had 200 hits to trend-micro in 1 day until I changed the wan back to something else. I know how to block trendmicro now by pure luck if I wanted too. lol Its also amazing because I am double NAT'd, and opendns (home package) knows my IP address better then my ddns at no-ip.
 
Ok, this problem is driving me crazy as I can't figure out if trend is not working or am i having a DNS leak from the router.

Plain question.

with the following VPN policy
- Created a rule for WAN access from 192.168.1.1 (destination empty)
- Created a rule for VPN from 192.168.1.0/24 (destination empty)

Does any connection initiated by the router, including to trendmicro's servers, go outside the VPN? 192.168.1.1 being the IP address of the router.
 
Similar threads
Thread starter Title Forum Replies Date
markpmac Odd Issue: Device Not Showing, but Working Asuswrt-Merlin 6
A Odd messages in logs Asuswrt-Merlin 1

Similar threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top