What's new

How to access ATT modem through VPN to RT-N66 running Merlin 380.68_4

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

New2Networking

New Around Here
I am trying to admin an RT-N66 remotely for elderly relatives several states away (I have a total 4, 3 are within driving distance).

They recently sold their home and down sized to an apartment. Prior to the move, I had VPN on Merlin working per instructions found at https://www.snbforums.com/threads/h...with-asus-routers-380-68-updated-08-24.33638/

The house had Spectrum/TW and the apartment has AT&T. They took the RT-N66 router to the apartment and the ATT tech set up the BWG210-700 in bridge/IP Passthrough mode. I can successfully access the RT-N66 via VPN. All attempts to remotely access the BWG210 modem fail.

3 questions:

1. The router and modem are on different subnets, how do I access the ATT modem when I VPN to the router? I want to be able to manage the ATT modem remotely via RT-N66 VPN access. I tried doing the procedure found in this link on an RT-N66 that is 20 minutes away and it failed . . .
https://github.com/RMerl/asuswrt-merlin/wiki/Access-modem-Web-UI-on-WAN-port-(no-script)

2. I think attempting a remote firmware upgrade over the internet is too risky, am I being overly cautious? The RT-N66 is running Merlin 380.68_4. and I am not sure when I will visit them to perform the upgrade to Merlin's final 380.70_0. They are church people, so I doubt they are going to XXX tubes or hubs, which should limit their malware risk.

3. How do I determine their router's risk to the recent "VPN Filter" malware on 380.68_4 and 380.70_0?
USB ports arNothing on the RT-N66 is open to the internet except VPN which uses https, a strong password and a port? I know ATT has a history of backdoors in their hardware/software but that is beyond my control.
 
1. Assuming you're using OpenVPN, make sure "Direct clients to redirect Internet traffic" is set to Yes.

2. It's quite possible that a firmware upgrade will require the router to be powered off and on again to complete the process.

3. Of more concern is the numerous confirmed accounts in these forums of Asus routers being hacked that were running firmware levels below 380.70. Even 380.70 is known to have theoretical weaknesses. Although in all cases it's believed that you are protected provided you don't enable remote access to the router (except for OpenVPN).
 
1. Assuming you're using OpenVPN, make sure "Direct clients to redirect Internet traffic" is set to Yes.

2. It's quite possible that a firmware upgrade will require the router to be powered off and on again to complete the process.

3. Of more concern is the numerous confirmed accounts in these forums of Asus routers being hacked that were running firmware levels below 380.70. Even 380.70 is known to have theoretical weaknesses. Although in all cases it's believed that you are protected provided you don't enable remote access to the router (except for OpenVPN).

Changing "Direct clients to redirect Internet traffic" to yes allowed me to access and make changes to the AT&T device. Sincerest thank you!!!

I have learned they will be traveling to my city for a high school graduation. I will try to talk them into bring the RT-N66 with them. My plan "B" is to upgrade a local RT-N66, ship it to them and have them return their RT-N66 to me.

Thanks for your quick and accurate response!
 

Similar threads

Latest threads

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top