Recent content by eibgrad

  • ATTENTION! As of November 1, 2020, you are not able to reply to threads 6 months after the thread is opened if there are more than 500 posts in the thread.
    Threads will not be locked, so posts may still be edited by their authors.
    Just start a new thread on the topic to post if you get an error message when trying to reply to a thread.
  1. eibgrad

    VPN Throttling

    The problem is not just a matter of transferring data, but how that data is managed in the non-VPN vs. VPN modes. And it's not just the CPU itself, but the overall system architecture used on the router compared to say a full-blown desktop (x86)...
  2. eibgrad

    DDNS setting "forced update interval"

    Correct.
  3. eibgrad

    ASUS RT-AC86U - ExpressVPN disconnecting

    DNSMasq is a lightweight, combo DHCP+DNS server designed for embedded systems. Its small footprint and miserly use of system resources makes it a popular choice for providing these services to the router. By default, the router configures the network clients w/ DNSMasq as their DNS server. It...
  4. eibgrad

    How to configure a Mesh + dedicated VPN Router in one subnet or?

    You could effectively disable the firewall on the WAN of the VPN router ... WAN_IF="$(nvram get wan0_ifname)" iptables -I INPUT -i $WAN_IF -j ACCEPT iptables -I FORWARD -i $WAN_IF -j ACCEPT ... then establish a static route on the primary router that points to the VPN router's WAN ip as the...
  5. eibgrad

    How to configure a Mesh + dedicated VPN Router in one subnet or?

    IIRC, the OpenVPN client is only bound to the WAN w/ Merlin. Not 100% positive, but I seem to recall that being the case.
  6. eibgrad

    ASUS RT-AC86U - ExpressVPN disconnecting

    Basically, yes. As I said initially, trying to determine exactly what's causing your problems is not easy, esp. when all I have are your descriptions. These changes are my attempt to remove issues that *might* be affecting the reliability of your VPN connection. OpenVPN has the ability to be...
  7. eibgrad

    Connect 2 locations over vpn

    As I said before, in a site-to-site config, you do NOT push the server's DNS server to the client. That creates a circular reference! The client is trying to resolve its own names by referencing back to the server's DNS server. And according to your images, you appear to be doing just that...
  8. eibgrad

    Connect 2 locations over vpn

    Btw, did you push the DNS server on the server side to the client? In a normal site-to-site config, this is NOT what you would do. And if client to server is working, this may be the reason.
  9. eibgrad

    ASUS RT-AC86U - ExpressVPN disconnecting

    I don't see any obvious mistakes. However, I did notice that on my ExpressVPN setup using dd-wrt, I had specified the Fragment field (something not present w/ Merlin) to 1300. And thus why it's not in my custom config field. So try adding back that directive. fragment 1300
  10. eibgrad

    Connect 2 locations over vpn

    One other thing. The server also has to know to use the DNS server on the client side when those devices are referenced. You typically do this by adding a server directive to DNSMasq on the server side that directs queries to the client's DNS server based on the domain name used by the client...
  11. eibgrad

    Connect 2 locations over vpn

    In order for the server to access the DNS server of the client, the *client* must have its tunnel's network interface name added (tun21 tun22, etc., or tun*) to DNSMasq on its side. I just checked, and by default, the OpenVPN client definitely doesn't do this by default.
  12. eibgrad

    ASUS RT-AC86U - ExpressVPN disconnecting

    Post the OpenVPN log. I want to see specifically what's happening.
  13. eibgrad

    Connect 2 locations over vpn

    I'm assuming the OpenVPN server is NOT adding its own network interface name to DNSMasq, but to be honest, I've never checked if that's the actually case. If it is, then name resolution should work client to server. But it's seem unlikely the OpenVPN client would similarly and automatically...
  14. eibgrad

    Connect 2 locations over vpn

    Name resolution will only work if the tunnel's network interface name (e.g., tun21) is added to DNSMasq. IOW, DNSMasq by default is NOT listening to that network interface, only the default network (br0). interface=tun* The '*' is a wildcard, which makes things a bit simpler. But you could...
  15. eibgrad

    ASUS RT-AC86U - ExpressVPN disconnecting

    Nothing in the above should have prevented a connection unless those remote directives are just wrong (protocol, port, etc.). The router directives are ineffective w/o changes to DNSMasq. You need to create a custom config file in order to make them effective...
Top