What's new

[Beta] Asuswrt-Merlin 384.11 Beta is now available

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

My guess is that OVPN Server and or Client cannot start without a WAN connection and or NTP update.

That would make sense, since both of these require an accurate clock for SSL/TLS.

Also, the IPv6 listening address ( - 0::1@53 )is not added when IPv6 is enabled.

It shouldn't be required, that interface is only used for dnsmasq to communicate with it. As long dmsmasq tries to use 127.0.1.1:853, stubby will receive the query, and then forward it to the appropriate IPv6 server as needed.
 

Attachments

  • Picture 1.jpg
    Picture 1.jpg
    35.4 KB · Views: 503
  • Picture 3.jpg
    Picture 3.jpg
    63.8 KB · Views: 504
That site shows I am not using TLS, and I am configured to use Cloudflare DNS-TLS in the router
I'm getting the following:
upload_2019-4-27_13-32-48.png
 
I have removed the beta 1 build for both the RT-AC87U and RT-AC3100 for now. The info I have gathered so far was that Asus introduced a change to the squash compression, which does not seem to work so well. Their own RT-AC68U 45708 release suffered from the same issue.
 
I am getting the following error while trying to connect to the router with ssh:
Code:
Apr 27 14:27:34 dropbear[2125]: Early exit: Bad buf_getptr
The ssh server on the router is configured for Lan Only, either password or keys. I have performed a full reset after upgrading. Any clues to what's happening here appreciated...

@RMerlin - has this been reported previously or do I have a config problem? Unable to access router via ssh.
 
Last edited:
I have removed the beta 1 build for both the RT-AC87U and RT-AC3100 for now. The info I have gathered so far was that Asus introduced a change to the squash compression, which does not seem to work so well. Their own RT-AC68U 45708 release suffered from the same issue.
score 1 for merlin 0 for asus devs
 
This is my router setup.
I would disable DNSSEC through Stubby because it is being removed in the next release anyway.
DNSSEC will still work by proxy from dnsmasq and will be less DNS traffic.
DNS_TLS.png DNS_TLS2.png
The Cloudflare tests might work afterwards.
 
That would make sense, since both of these require an accurate clock for SSL/TLS.



It shouldn't be required, that interface is only used for dnsmasq to communicate with it. As long dmsmasq tries to use 127.0.1.1:853, stubby will receive the query, and then forward it to the appropriate IPv6 server as needed.

Thx.
I am too eager to test ipv6 and didnt notice that it works with just the ipv4 listening.
Previously my firefox PC browser disable ipv6. So it didnt work. I began working on my ipad and it work with adding in ipv6 listening address. I thought it is required. haha..
 
yes it is better to use dnssec via dnsmasq as it relies more on hard coding for validation and handles caching better. --- I like the default caching is set to 1500 nice...

- on top of this alot of the dnssec features built into stubby are still under development-- makes me feel like it is not 100%
 
I would disable DNSSEC through Stubby because it is being removed in the next release anyway.
DNSSEC will still work by proxy from dnsmasq and will be less DNS traffic.
View attachment 17249 View attachment 17250
The Cloudflare tests might work afterwards.
i believe it has already been removed in beta 1 because i am able to use just dnsmasq with gui.
 
Sorry if I sound like a newbie on this but where do I get the TCP Dump pkg
I have not used this myself yet, but:
  • Tcpdump is an Entware package (opkg install tcpdump)
  • If I recall correctly, it can save minimal information to a text file
  • If you save a binary trace, then you will need to get the file to your PC and load it into Wireshark
 

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top