[SOLVED]Huawei Mediapad T5 VPN not working DDWRT

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Tue Apr 13, 2021 0:15    Post subject: [SOLVED]Huawei Mediapad T5 VPN not working DDWRT Reply with quote
I have a Huawei Mediapad T5 which is connected to the VPN wireless on Netgear R7000 running DDWRT. I have checked all other devices which include PS5, iPhone, Laptop and desktop running Linux, Android TV box all show the VPN address but not the Huawei Media pad T5 shows my real ip for my isp and not the VPN. I have tried to restart the Huawei Media pad T5, deleted wireless network both 2.4 & 5 ghz with the same results. Webrtc is is disabled on the Firefox browser.
If I connect through open vpn or my vpn client, it works but if I disconnect it, real up shown even though the ddwrt is on vpn. All other devices do not have this issue and anything connected to the ddwrt shows the vpn ip.
Can anyone help?

_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
Sponsor
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9157

PostPosted: Tue Apr 13, 2021 4:06    Post subject: Reply with quote
dd-wrt is on *what* VPN? OpenVPN? PPTP? WireGuard?

What are using to verify the public IP? Some website? Like http://ipchicken.com?

If using OpenVPN, are you using PBR (policy based routing) on the dd-wrt OpenVPN client?

_________________
ddwrt-ovpn-split-basic.sh (UPDATED!) * ddwrt-ovpn-split-advanced.sh (UPDATED!) * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-remote-access.sh * ddwrt-ovpn-client-backup.sh * ddwrt-mount-usb-drives.sh * ddwrt-blacklist-domains.sh * ddwrt-wol-port-forward.sh * ddwrt-dns-monitor.sh (NEW!)
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Tue Apr 13, 2021 5:34    Post subject: Reply with quote
Thread transferred to the appropriate Advanced networking forum.

See guidelines in my signature how to get the best support

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Tue Apr 13, 2021 8:59    Post subject: Reply with quote
Apologies, when I connect the tablet using open VPN for android which is installed on the tablet, the VPN works but when I disconnect that and connect to the WiFi on the DDWRT router which has VPN running, my ip is shown. All other devices the VPN works fine when connected to the WiFi on the DDWRT router.
In other words, the only way to have VPN on the tablet is by using open VPN Android which is installed on the tablet. I hope this now makes sense.
Apologies if I broke rules with this post by posting in the wrong category.

_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Tue Apr 13, 2021 9:00    Post subject: Reply with quote
I am using www.dnsleak.com and www.whoer.net and www.ipleaks.net
_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Tue Apr 13, 2021 9:20    Post subject: Reply with quote
You did not break any rules so no need to apologize Smile

The important questions from @ eibgrad still needs answering.

Are you using Policy Based Routing?
Because that is how some of your clients can use the WAN and others the VPN.

If not then all attached client must use the VPN and if a client does not then check if it uses your wifi or perhaps someone elses, also check if the VPN on the client is indeed totally switched of otherwise it could connect to something else than your router is connecting to.

To test add a killswitch to your router to stop traffic going out of the WAN.

Test this from the CLI (telnet/Putty):
Code:
iptables -I FORWARD -o $(get_wanface) -j REJECT


You can make it permanent by adding it to Administration/Commands and Save Firewall

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Tue Apr 13, 2021 11:48    Post subject: Reply with quote
I am not using policy based routing but to be certain, how can I check this?
I have checked and it is using my wifi. I even deleted all wifi and added them again and had ro enter the login details for the wifi.VPN is switched on and working:
VPN Client Stats
TUN/TAP read bytes 86996283
TUN/TAP write bytes 2147483647
TCP/UDP read bytes 2147483647
TCP/UDP write bytes 102521824
Auth read bytes 2147483647
pre-compress bytes 0
post-compress bytes 0
pre-decompress bytes 0
post-decompress bytes 0

How do I add this command iptables -I FORWARD -o $(get_wanface) -j REJECT
Firewall is off.

_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Tue Apr 13, 2021 12:09    Post subject: Reply with quote
I hope your firewall is not really disabled.

The instructions are actually in my post

Test from command line interface (telnet/Putty or what ever you like)

And if it works or if you have no idea what I am talking about place in Administration/Commands and Save as firewall

To be sure this is a normal setup where the router is in gateway mode and the WAN port is connected to the ISP modem?

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Tue Apr 13, 2021 22:34    Post subject: Reply with quote
The DDWRT is in router mode and the WAN port is connected to the ISP modem.
I know how to do the commands. Should I still excute? I have wired connection for my TV and PS5 on Lan1 and Lan 2.All the rest on wireless.
Firewall is on.
VPN is on.

_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Wed Apr 14, 2021 6:55    Post subject: Reply with quote
A kill switch is always a good thing Smile


When you say the router is in router mode I hope you are not referring to the setting of "Operating Mode" on the Advanced Routing Page that should be left in "Gateway"

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
eeff11
DD-WRT User


Joined: 23 Jan 2013
Posts: 116

PostPosted: Wed Apr 14, 2021 8:41    Post subject: Reply with quote
egc wrote:
A kill switch is always a good thing Smile


When you say the router is in router mode I hope you are not referring to the setting of "Operating Mode" on the Advanced Routing Page that should be left in "Gateway"


What are the differences between 'gateway' & 'router',since all op's wire or wireless devices worked.

I guess it's related to Huawei's ROM.
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Fri Apr 16, 2021 20:25    Post subject: Reply with quote
I tried the command and saved firewall and lost connection because the main router has a cable which is connected to the WAN port of the DDWRT router. The VPN is now not working on all devices connected through wifi apart from a linux laptop. Before the iPhone was not showing my real IP when connected to the DDWRT router wifi, now it is doing the same thing as the huawei pad.
_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Wed Apr 28, 2021 11:45    Post subject: Reply with quote
No one seems keen to help not sure why
_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Wed Apr 28, 2021 11:58    Post subject: Reply with quote
Because you are not providing enough information.

As you have been tinkering a lot with the router consider resetting to defaults and only do the minimal setup (manually of course do not restore from a backup file)

Provide details about your network setup. if you followed a wiki what wiki did you follow.

If you are setting up a VPN client what instructions did you follow? For OpenVPN see:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=327398

Post a picture of your OpenVPN settings page (whole page including everything in the additional config.

Post a picture of the OpenVPN Status page whole page

Of course you follow the forum guidelines while posting pictures (i.e. not more than 768 pixels width:
To get the best out of DDWRT and the forum read the forum guidelines with helpful pointers:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
manchesterblack
DD-WRT User


Joined: 04 Mar 2021
Posts: 65
Location: Manchester

PostPosted: Mon Jun 07, 2021 0:03    Post subject: SOLVED Reply with quote
This issue has been resolved, I am not sure how but this is what I did.
1. Flashed DDWRT DD-WRT v3.0-r46788 std (05/28/21)

from scratch.
2. Set up the router using save, next setting, save and then when I have finished that is when I hit Apply and reboot the router.

_________________
Netgear R7000
DD-WRT DD-WRT v3.0-r50595 std (10/23/22)
Manchester
Enable dnsmasq- Yes
Encrypt DNS- NO
DNSCrypt Resolver- No Using Smart DNS
Cache DNSSEC Data- Yes
Validate DNS Replies (DNSSEC)- NO
Check Unsigned DNS Replies- NO
No DNS Rebind- Enable
Query DNS in Strict Order- Enable
Add Requestor MAC to DNS Query- Disable
RFC4039 Rapid Commit Support- Enable
Maximum Cached Entries- 1500

Smart DNS - YES

server-https https://9.9.9.9/dns-query
server-tls 9.9.9.9:853 -host-name: dns.quad9.net
server-tls 5.2.75.75:853 -host-name: dot.nl.ahadns.net
server-https https://1.1.1.1/dns-query

Additional VPN Configuration-
pull-filter ignore "dhcp-option DNS6 "
pull-filter ignore "dhcp-option DNS "

Dnsmasq Additional Options

server=/pool.ntp.org/9.9.9.9
server=/pool.ntp.org/1.0.0.1
server=/adquard-dns.com/9.9.9.9


BrainSlayer wrote:
we just do it since we do not like any restrictions enforced by stupid cocaine snorting managers
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum