Diamond67
Senior Member
Give it a try, and see if that works for ya.
Thanks. I'll try that and other tips too (if necessary) sometimes later. Maybe after next compulsory/forced reboots of Win10 client computers. I'm a bit busy with other stuff atm.
Give it a try, and see if that works for ya.
Updated to 384.12 on RT-AC66U
QoS is off and apps analysis is off.
Should QoS - WAN/LAN Bandwidth Monitor still show Upload Bandwidth and Download Bandwidth even if Apps analysis is off?
Jul 3 05:20:22 RT-AC87R Diversion: rotated dnsmasq log files, from /opt/share/diversion/file/rotate-logs.div
Jul 3 05:35:58 RT-AC87R kernel: [tdts_shell_ioctl_stat:256] Recv ioctl req with op 2
Jul 3 06:06:00 RT-AC87R kernel: [tdts_shell_ioctl_stat:256] Recv ioctl req with op 2
Jul 3 06:28:30 RT-AC87R kernel: 92 503 0 0 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4894] 0 4894 503 0 0 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4896] 0 4896 503 0 1 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4910] 0 4910 503 0 1 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4912] 0 4912 503 0 0 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4913] 0 4913 353 0 0 0 0 grep
Jul 3 06:28:30 RT-AC87R kernel: [ 4914] 0 4914 503 0 0 0 0 sh
Jul 3 06:28:30 RT-AC87R kernel: [ 4915] 0 4915 354 0 0 0 0 awk
Jul 3 06:28:30 RT-AC87R kernel: [ 4916] 0 4916 353 0 1 0 0 grep
Jul 3 06:28:30 RT-AC87R kernel: [ 4917] 0 4917 354 0 0 0 0 awk
Jul 3 06:28:35 RT-AC87R kernel: [ 4918] 0 4918 503 0 0 0 0 sh
Jul 3 06:28:35 RT-AC87R kernel: [ 4919] 0 4919 353 0 1 0 0 grep
Jul 3 06:28:35 RT-AC87R kernel: [ 4920] 0 4920 354 0 1 0 0 awk
Jul 3 06:28:35 RT-AC87R kernel: [ 4921] 0 4921 503 0 0 0 0 sh
Jul 3 06:28:35 RT-AC87R kernel: [ 4924] 0 4924 503 0 0 0 0 sh
Jul 3 06:28:35 RT-AC87R kernel: [ 4928] 0 4928 503 0 1 0 0 sh
Jul 3 06:28:35 RT-AC87R kernel: [ 4929] 0 4929 503 0 0 0 0 sh
Jul 3 06:28:35 RT-AC87R kernel: [ 4930] 0 4930 353 0 0 0 0 grep
Jul 3 06:28:35 RT-AC87R kernel: [ 4932] 0 4932 355 0 1 0 0 nslookup
Jul 3 06:28:35 RT-AC87R kernel: [ 4933] 0 4933 353 0 1 0 0 grep
Jul 3 06:28:45 RT-AC87R kernel: [ 4935] 0 4935 354 0 1 0 0 awk
Jul 3 06:28:45 RT-AC87R kernel: [ 4938] 0 4938 357 0 1 0 0 sed
Jul 3 06:28:45 RT-AC87R kernel: [ 4939] 0 4939 354 0 1 0 0 awk
Jul 3 06:28:45 RT-AC87R kernel: [ 4940] 0 4940 503 0 0 0 0 sh
Jul 3 06:28:45 RT-AC87R kernel: [ 4947] 0 4947 503 0 1 0 0 sh
Jul 3 06:28:45 RT-AC87R kernel: [ 4949] 0 4949 503 0 1 0 0 sh
Jul 3 06:28:45 RT-AC87R kernel: [ 4950] 0 4950 354 0 1 0 0 awk
<I've truncated this, a hundred lines all more of the same>
Jul 3 06:58:16 RT-AC87R kernel: [ 5241] 0 5241 503 0 1 0 0 sh
Jul 3 06:58:16 RT-AC87R kernel: [ 5242] 0 5242 503 0 0 0 0 sh
Jul 3 06:58:16 RT-AC87R kernel: Out of memory: Kill process 199 (nt_monitor) score 1 or sacrifice child
Jul 3 06:58:16 RT-AC87R kernel: Killed process 207 (nt_monitor) total-vm:5060kB, anon-rss:0kB, file-rss:0kB
Jul 3 06:58:34 RT-AC87R kernel: tdts_core_ioctl_udb_op_prog_ctrl() fail!
Jul 3 06:58:34 RT-AC87R syslog: hotplug2 terminated unexpectedly, restarting.
May 5 01:05:02 syslogd started: BusyBox v1.25.1
I at first thought it was windows 10 on my end since Microsoft put out a update that turned samba off but i remembered i had turned it back on for my freenas shares.I was wondering why infuse on apple tv wouldnt connect to the NAS any longer, thought it was a NAS update that caused the issue, so thanks for sharing.
I have both ProtonVPN and PIA running on 384.12. See if there is more detail in the log and adjust settings accordingly.ProtonVPN client no longer works on 384.12 and hangs indefinitely while attempting to connect. "Error check configuration"
Changing new Inbound Firewall settings to Allow/Block have no effect.
What do you have under Advanced settings for the VPN connection?? Specifically "Block routed clients if tunnel goes down?"With the new release 384.12 what is the expected behaviour when connected over VPN and this tunnel goes down?
In my specific setup I have no values entered under WAN DNS. What I think should happen is that when my VPN connection goes down all my connected devices should loose access to internet.
However, I am noticing that when that happens all connected clients get ISP dns and connections are open. Is that a desired behaviour?
I have the policy set to ALL.What do you have under Advanced settings for the VPN connection?? Specifically "Block routed clients if tunnel goes down?"
View attachment 18518
Also VPN DNS is set to exclusive.I have the policy set to ALL.
That option is not available if you select All.Option below all that. The one regarding what to do when the vpn tunnel goes down.
Sent from my iPhone using Tapatalk
Since that option doesn't come up with All then I wouldn't think that option would default to blocking them. May need to ping @RMerlin to get his thoughts....That option is not available if you select All.
You need to create the file /jffs/scripts/stubby.postconf
You can do this with WinSCP. Navigate to /jffs/scripts. Right click in the right window and select New/File or Shift + F4. Name the file stubby.postconf and enter the following (just copy and paste):
Save the file. Right click on the file and check the boxes next to the three X's to make the Octal:755 then click OK. Restart Stubby by turning DoT off then on or in a terminal session withCode:#!/bin/sh CONFIG=$1 source /usr/sbin/helper.sh pc_replace "idle_timeout: 9000" "idle_timeout: 2000" $CONFIG pc_replace "tls_connection_retries: 2" "tls_connection_retries: 5" $CONFIG pc_replace "timeout: 3000" "timeout: 2000" $CONFIG pc_replace "round_robin_upstreams: 1" "round_robin_upstreams: 0" $CONFIG
service restart_stubby
These settings seem to help at least on my ISP. I have found Cloudflare to be the most reliable for me with CleanBrowsing next then Quad9. I manage a couple of routers on another ISP and Quad9 seems to work better than Cloudflare. I feel it is how the DNS resolver anycast addresses are routed. The closest Quad9 data center to me is 100 miles away as the crow flies but I get routed to another Quad9 data center 1,000 miles away and have been routed to the Quad9 data center clear across the country on the west coast! Using Cloudflare I'm routed to the data center 100 miles away. Also feel that DNSSEC is handled better by Cloudflare.
Any. I have a couple of AC68U's on a cable provider that I recently switched from Cloudflare to Quad9. My home router has been on several other providers but Cloudflare seems to be the best.Thanks for the information.... question...can you do the instructions posted only when using cloudflare or any DNS server i.e. Quad9??
For those who prefer to route all LAN traffic to the VPN, enabling the “Policy Rules” or “Policy Rules (Strict)” setting enables the option to “Block routed clients if tunnel goes down” to be displayed. Enabling this option will allow you to block LAN traffic from traversing to the WAN interface if the VPN tunnel goes down.That option is not available if you select All.
LAN_IPs 192.168.1.0/24 0.0.0.0 VPN
Router 192.168.1.1 0.0.0.0 WAN
Unplugging all USB devices, and give it a reboot and try again, aslo which model?I have been using this Rounter and Merlin for almost 2 years. Love you guys for keeping this device up and running. Am facing a problem for upgrading 384.6 to latest 384.12 but never reflected the update.
Tried the traditional way of uploading the .trx file under upload latest firmware upload.
can someone help me on this issue ?

Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!