OpenWrt Forum Archive

Topic: Netgear R8000 and OpenVPN

The content of this topic has been archived between 8 Apr 2018 and 18 Apr 2018. There are no obvious gaps in this topic, but there may still be some posts missing at the end.

ulmwind wrote:

OK, so I don't understand, on RPi and wr841nd it works, so the issue is specific ONLY for Netgear?

Yes sad
I cannot configure only this!
it's strange that it can only connect for a few seconds!
I repeat, if you can, I can show you through teamviewer! Thanks

(Last edited by Squalo on 26 Oct 2017, 18:10)

Broadcom is not recommended. I doesn't have open drivers, so as far as I know, proprietary ones are used. Result of using you have observed. So it is firmware question to developers of OpenWRT, LEDE.
Use MediaTek, Ralink.

(Last edited by ulmwind on 27 Oct 2017, 08:59)

ulmwind wrote:

Broadcom is not recommended. I doesn't have open drivers, so as far as I know, proprietary ones are used. Result of using you have observed. So it is firmware question to developers of OpenWRT, LEDE.
Use MediaTek, Ralink.

Today i configured dd-wrt ... i got the same result as LEDE
But the is more detailed:

Clientlog:
20171027 16:12:24 W WARNING: file '/tmp/openvpncl/ta.key' is group or others accessible
20171027 16:12:24 W WARNING: file '/tmp/openvpncl/credentials' is group or others accessible
20171027 16:12:24 I OpenVPN 2.4.2 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Jun 11 2017
20171027 16:12:24 I library versions: OpenSSL 1.0.2k 26 Jan 2017 LZO 2.09
20171027 16:12:24 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:16
20171027 16:12:24 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20171027 16:12:24 Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
20171027 16:12:24 Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
20171027 16:12:24 I TCP/UDP: Preserving recently used remote address: [AF_INET]185.94.193.179:1194
20171027 16:12:24 Socket Buffers: R=[180224->180224] S=[180224->180224]
20171027 16:12:24 I UDPv4 link local: (not bound)
20171027 16:12:24 I UDPv4 link remote: [AF_INET]185.94.193.179:1194
20171027 16:12:24 TLS: Initial packet from [AF_INET]185.94.193.179:1194 sid=4f998d3c 0273c2dc
20171027 16:12:24 W WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
20171027 16:12:24 VERIFY OK: depth=1 C=PA ST=PA L=Panama O=NordVPN OU=NordVPN CN=it9.nordvpn.com name=NordVPN emailAddress=cert@nordvpn.com
20171027 16:12:24 VERIFY KU OK
20171027 16:12:24 Validating certificate extended key usage
20171027 16:12:24 NOTE: --mute triggered...
20171027 16:12:24 4 variation(s) on previous 3 message(s) suppressed by --mute
20171027 16:12:24 I [it9.nordvpn.com] Peer Connection Initiated with [AF_INET]185.94.193.179:1194
20171027 16:12:25 SENT CONTROL [it9.nordvpn.com]: 'PUSH_REQUEST' (status=1)
20171027 16:12:25 PUSH: Received control message: 'PUSH_REPLY redirect-gateway def1 sndbuf 524288 rcvbuf 524288 dhcp-option DNS 78.46.223.24 dhcp-option DNS 162.242.211.137 route-gateway 10.8.8.1 topology subnet ping 60 ping-restart 180 ifconfig 10.8.8.22 255.255.255.0 peer-id 17 cipher AES-256-GCM'
20171027 16:12:25 OPTIONS IMPORT: timers and/or timeouts modified
20171027 16:12:25 NOTE: --mute triggered...
20171027 16:12:25 1 variation(s) on previous 3 message(s) suppressed by --mute
20171027 16:12:25 Socket Buffers: R=[180224->360448] S=[180224->360448]
20171027 16:12:25 OPTIONS IMPORT: --ifconfig/up options modified
20171027 16:12:25 OPTIONS IMPORT: route options modified
20171027 16:12:25 OPTIONS IMPORT: route-related options modified
20171027 16:12:25 NOTE: --mute triggered...
20171027 16:12:25 4 variation(s) on previous 3 message(s) suppressed by --mute
20171027 16:12:25 Data Channel Encrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
20171027 16:12:25 Data Channel Decrypt: Cipher 'AES-256-GCM' initialized with 256 bit key
20171027 16:12:25 I TUN/TAP device tun1 opened
20171027 16:12:25 TUN/TAP TX queue length set to 100
20171027 16:12:25 D do_ifconfig tt->did_ifconfig_ipv6_setup=0
20171027 16:12:25 I /sbin/ifconfig tun1 10.8.8.22 netmask 255.255.255.0 mtu 1500 broadcast 10.8.8.255
20171027 16:12:25 /sbin/route add -net 185.94.193.179 netmask 255.255.255.255 gw 192.168.178.1
20171027 16:12:25 W ERROR: Linux route add command failed: external program exited with error status: 1
20171027 16:12:25 /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.8.8.1
20171027 16:12:25 /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.8.8.1
20171027 16:12:28 I Initialization Sequence Completed
20171027 16:12:28 N write UDPv4: Message too large (code=90)
20171027 16:12:28 N write UDPv4: Message too large (code=90)
20171027 16:12:28 N write UDPv4: Message too large (code=90)
20171027 16:12:32 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20171027 16:12:32 D MANAGEMENT: CMD 'state'
20171027 16:12:32 MANAGEMENT: Client disconnected
20171027 16:12:32 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20171027 16:12:32 D MANAGEMENT: CMD 'state'
20171027 16:12:32 MANAGEMENT: Client disconnected
20171027 16:12:32 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20171027 16:12:32 D MANAGEMENT: CMD 'state'
20171027 16:12:32 MANAGEMENT: Client disconnected
20171027 16:12:32 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20171027 16:12:32 D MANAGEMENT: CMD 'status 2'
20171027 16:12:32 MANAGEMENT: Client disconnected
20171027 16:12:32 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20171027 16:12:32 D MANAGEMENT: CMD 'log 500'
19700101 01:00:00
 

OK, and where is disconnect in log?

ulmwind wrote:

OK, and where is disconnect in log?

I don't know....

I don't know how and i don't know why but now it work correctly O_o (with LEDE)

The discussion might have continued from here.