IPSec Issues

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware
Goto page Previous  1, 2
Author Message
nolimitz
DD-WRT Guru


Joined: 26 Nov 2010
Posts: 597

PostPosted: Mon May 06, 2019 20:17    Post subject: Reply with quote
egc wrote:
The R7000P was misidentified in a couple of builds, it was identified as an R6400 and thus Wifi was not working.

Problem existed between build 36816 and 37713, if you have used builds in that range do "nvram erase" to clean/clear


Wifi disappears on build 35550M and 37985M, only if IPSec is enabled and router is rebooted. to get wifi back i disable IPSec and reboot again (login to router using a lan cable), its correctly identified as R7000P.
Sponsor
<Kong>
DD-WRT Guru


Joined: 15 Dec 2010
Posts: 4339
Location: Germany

PostPosted: Tue May 07, 2019 21:29    Post subject: Reply with quote
Can you guys check something I just debugged the wan access issue under my openwrt strongswan setup and saw, that safari tells me it cannot establish a secure connection to the server, then I tried a non https site and it worked. Try some http only site and let me know if that works.

Update: I had to close safari completely after that it worked. Thus it works with 12.2. But have to check on the dd-wrt install.

_________________
KONG PB's: http://www.desipro.de/ddwrt/
KONG Info: http://tips.desipro.de/
spaceghost
DD-WRT User


Joined: 08 Jun 2010
Posts: 109
Location: New Zealand

PostPosted: Tue May 07, 2019 22:22    Post subject: Reply with quote
<Kong> wrote:
Can you guys check something I just debugged the wan access issue under my openwrt strongswan setup and saw, that safari tells me it cannot establish a secure connection to the server, then I tried a non https site and it worked. Try some http only site and let me know if that works.


Hi Kong - I can't really replicate the issue and test for you.

If I connect from iOS 12.1.1 over cellular data to my RT-AC3200 running r37985m via IPSEC, I can initiate the session and I have no problems with https or http sites.

If I upgrade to any recent builds from the last several months, I cannot even establish an IPSec session at all. And that's where I get these errors in my logs:

Apr 21 16:15:03 DD-WRT daemon.info : 06[KNL] unable to add SAD entry with SPI c6f7a0bb (FAILED)
Apr 21 16:15:03 DD-WRT daemon.info : 06[KNL] received netlink error: No such file or directory (2)
Apr 21 16:15:03 DD-WRT daemon.info : 06[KNL] unable to add SAD entry with SPI 0525fab7 (FAILED)

So perhaps two different problems are at play here?

_________________
RT-AX86U MerlinWRT & RT-AC68U DD-WRT
nolimitz
DD-WRT Guru


Joined: 26 Nov 2010
Posts: 597

PostPosted: Wed May 08, 2019 8:22    Post subject: Reply with quote
<Kong> wrote:
Can you guys check something I just debugged the wan access issue under my openwrt strongswan setup and saw, that safari tells me it cannot establish a secure connection to the server, then I tried a non https site and it worked. Try some http only site and let me know if that works.

Update: I had to close safari completely after that it worked. Thus it works with 12.2. But have to check on the dd-wrt install.


i just connected from my iphone on iOS 12.2 to IPSec server on R7000 (build 35550M) and http works fine both lan and wan.

the issue remains as latest builds will not establish a connection, and R7000P wifi will not work if IPSec is enabled and a reboot is done (tested on builds 35550M and 37985M). hoping you can look into both,

thanks
superdupe
DD-WRT Novice


Joined: 23 Jul 2018
Posts: 6

PostPosted: Sat May 11, 2019 3:45    Post subject: Reply with quote
I see Kong posted in the Atheros section, his new beta firmware r39715M had IPSEC fixed. I tried this version for my (5) r7000's and (1) r6400 and IPSEC appears to still be broken... (Yes I used the correct firmware for my devices) Wondering if he fixed it only in the Atheros firmware?

I am sticking with r38580 for now as it is working for both IOS and Windows devices.
nolimitz
DD-WRT Guru


Joined: 26 Nov 2010
Posts: 597

PostPosted: Sat May 11, 2019 6:36    Post subject: Reply with quote
superdupe wrote:
I see Kong posted in the Atheros section, his new beta firmware r39715M had IPSEC fixed. I tried this version for my (5) r7000's and (1) r6400 and IPSEC appears to still be broken... (Yes I used the correct firmware for my devices) Wondering if he fixed it only in the Atheros firmware?

I am sticking with r38580 for now as it is working for both IOS and Windows devices.


I also tested 39715M on my R7000P and can’t create a vpn link, i updated from 35550M without reset.
jerrytouille
DD-WRT Guru


Joined: 11 Dec 2015
Posts: 1304

PostPosted: Sat May 11, 2019 6:38    Post subject: Reply with quote
superdupe wrote:
I see Kong posted in the Atheros section, his new beta firmware r39715M had IPSEC fixed. I tried this version for my (5) r7000's and (1) r6400 and IPSEC appears to still be broken... (Yes I used the correct firmware for my devices) Wondering if he fixed it only in the Atheros firmware?

I am sticking with r38580 for now as it is working for both IOS and Windows devices.

nolimitz wrote:
I also tested 39715M on my R7000P and can’t create a vpn link, i updated from 35550M without reset.


backup settings nvram erase reconfig from scratch see if it works if not restore settings
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum