New Build - 09/20/2021 - r47474

Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware
Goto page Previous  1, 2, 3, 4  Next
Author Message
MLandi
DD-WRT Guru


Joined: 04 Dec 2007
Posts: 1018

PostPosted: Mon Sep 20, 2021 17:40    Post subject: Reply with quote
Alozaros wrote:
is this line in advanced DNSmasq is about doing the same NCSI filtering...i checked mine on my Win 7 it turned up as 0 Razz so i must have changed in the past...but thank you egc

filterwin2k


It is not, should I use it?

_________________
Netgear R9000
DD-WRT v3.0-r55779 std (04/12/24)
Linux 4.9.337 #721 SMP Mon Apr 8 08:07:27 +07 2024 armv7l
Gateway, AP, DNSMasq, Clock 2000MHz
VAP on wlan1 for internet devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
CloudFlare, no SFE, SmartDNS, no QoS
2.4GHz: Vanilla, Airtime Fairness, NG-Mixed, ACK Timing 3150, WPA2 w/AES & WPA3
5GHz: Vanilla, Airtime Fairness, AC/N Mixed, ACK Timing 3150, WPA2 w/AES & WPA3
2 Netgear AX1800 WiFi Mesh Extenders
Xfinity 1.2Gbps/35Mbps
Sponsor
ccbrianf
DD-WRT User


Joined: 10 Jun 2015
Posts: 59

PostPosted: Mon Sep 20, 2021 22:13    Post subject: Gateway leaking LAN traffic Reply with quote
Router/Version: Linksys EA8500
File/Kernel: DD-WRT v3.0-r47474 std (09/20/21)
Mode/Status: Gateway, Wireguard server (inactive)
Issues/Errors: LAN traffic leaking out gateway interface

This router is setup in Gateway mode attached with IP PassThrough all firewall and packet filters disabled (that can be) on an ATT Fiber BGW210-700. The log on that upstream device is reporting source IP addresses on my private LAN (and dropping those packets as invalid sources). There is no other device plugged into the ATT box and Wifi on it is disabled. I'm not sure how long this has been the case.
MLandi
DD-WRT Guru


Joined: 04 Dec 2007
Posts: 1018

PostPosted: Mon Sep 20, 2021 23:17    Post subject: Reply with quote
MLandi wrote:
Alozaros wrote:
is this line in advanced DNSmasq is about doing the same NCSI filtering...i checked mine on my Win 7 it turned up as 0 Razz so i must have changed in the past...but thank you egc

filterwin2k


It is not, should I use it?


I added filterwin2k and the issue persists. It is not often, but it does show in the syslog. I guess DNSMasq is doing what I want by blocking it.

_________________
Netgear R9000
DD-WRT v3.0-r55779 std (04/12/24)
Linux 4.9.337 #721 SMP Mon Apr 8 08:07:27 +07 2024 armv7l
Gateway, AP, DNSMasq, Clock 2000MHz
VAP on wlan1 for internet devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
CloudFlare, no SFE, SmartDNS, no QoS
2.4GHz: Vanilla, Airtime Fairness, NG-Mixed, ACK Timing 3150, WPA2 w/AES & WPA3
5GHz: Vanilla, Airtime Fairness, AC/N Mixed, ACK Timing 3150, WPA2 w/AES & WPA3
2 Netgear AX1800 WiFi Mesh Extenders
Xfinity 1.2Gbps/35Mbps
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14208
Location: Texas, USA

PostPosted: Mon Sep 20, 2021 23:53    Post subject: Reply with quote
RE: "filterwin2k"

https://thekelleys.org.uk/dnsmasq/docs/dnsmasq-man.html

You should also disable netbios in dnsmasq.

https://wiki.dd-wrt.com/wiki/index.php/DNSMasq_as_DHCP_server

And disable network discovery in Windows; unless, of course, you use Samba and don't know the workarounds.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14208
Location: Texas, USA

PostPosted: Tue Sep 21, 2021 0:02    Post subject: Reply with quote
Alozaros wrote:
egc wrote:
AsX wrote:
Try adding a new forward on NAT/QoS->Port Forwarding page. Funny thing happens, at least with my Firefox.


We welcome your full report Smile


i do have some funny stuff on change any value save & apply using non chromium and chromium based browsers... Cool reported in my post already Cool

CTRL+F5 or clear your cache. Google APIs FTW!

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
colnago
DD-WRT User


Joined: 23 Oct 2014
Posts: 102

PostPosted: Tue Sep 21, 2021 0:06    Post subject: Reply with quote
EA-8500, not reset. OpenVPN client. Wifi is good.

I notice that -r47461 and -r47474 have different DNS behaviour. I have a local PiHole and block outbound on port 53 for all but it. There are suddenly requests out to cloudflared and another DNS server with these recent builds. This goes away if I revert to -r47381. I would not care but there is an annoying DNS lookup failure when going to new sites in a browser. Then the second try succeeds. This may be IPv6-related, as I see IPv6 addresses on an nslookup to a new site, but my router does not have it enabled, nor does my PiHole, so I cannot yet explain the source.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14208
Location: Texas, USA

PostPosted: Tue Sep 21, 2021 0:13    Post subject: Reply with quote
I know that dnsmasq was recently updated.

https://svn.dd-wrt.com/search?q=dnsmasq

Don't see anything glaring in the commits since the last release that was committed to DD-WRT, but I am not looking that hard.

There is also the matter of browsers now having in-browser settings for secure DNS that must be addressed.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
colnago
DD-WRT User


Joined: 23 Oct 2014
Posts: 102

PostPosted: Tue Sep 21, 2021 0:20    Post subject: Reply with quote
Thanks kernel-panic69, that made me think.

I realized I had "Use DNSMasq for DNS" checked. I unchecked it and the nslookup now shows my PiHole as the server. No delay.
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14208
Location: Texas, USA

PostPosted: Tue Sep 21, 2021 0:21    Post subject: Reply with quote
Perhaps an anomaly that happened or something overlooked. I have noticed a few quirks, but no show-stoppers yet.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
ccbrianf
DD-WRT User


Joined: 10 Jun 2015
Posts: 59

PostPosted: Tue Sep 21, 2021 2:01    Post subject: Reply with quote
colnago wrote:
EA-8500, not reset. Wifi is good.

I notice that -r47461 and -r47474 have different DNS behaviour. I have a local PiHole and block outbound on port 53 for all but it. There are suddenly requests out to cloudflared and another DNS server with these recent builds. This goes away if I revert to -r47381. I would not care but there is an annoying DNS lookup failure when going to new sites in a browser. Then the second try succeeds.


I agree Wifi is good.

I have a similar setup with a PiHole and DNS blocked for all but dnsmasq localhost to stubby on the router out to the internet. The PiHole is directed only to the router dnsmasq.

I wouldn't have found the leaking LAN IPs I just reported if I wasn't looking for the cause of a sporadic browser DNS lookup failure very similar to yours that succeeds on reload. BTW, I have use-application-dns.net set to return NXDOMAIN in dnsmasq so Firefox won't use DoH.
iMAK
DD-WRT User


Joined: 06 Nov 2011
Posts: 81

PostPosted: Tue Sep 21, 2021 5:19    Post subject: Reply with quote
mrjcd wrote:
Linksys EA8500 ...main gateway
DD-WRT v3.0-r47474 std (09/20/21)
Linux 4.9.282 #466 SMP Mon Sep 20 04:24:30 +07 2021 armv7l
GUI install over r47449
35 static leases
local DNS
ovpn server
HFSC CAKE
smaba share 32GB ext4
2.4 & 5GHz radios good both using ath10k Vanilla FW
VLAN on 1 port + wlan0.1 via br1
br1 uses different DNS (9.9.9.9 WoodyNet shit)
dont't ask why ...just somepin I stared doing long time back
main net & all other router/devices connected to it uses--
unbound
http://dnssec.vs.uni-due.de/

Twisted Evil
http://www.dnssec-or-not.com/


everything is working very nicely -- uptime 10.46
/cpu/scaling_governor set to 'ondemand'
ondemand/up_threshold set to '35'

#

EA8500
switch / ovpn server / samba share x2 ext4 flash drive
GUI install over r47461
all good -- uptime 10:49

#

Netgear WNDR3700 V4
DD-WRT v3.0-r47474 std (09/20/21)
Linux 3.18.140-d6 #126895 Mon Sep 20 11:31:53 +07 2021 mips
used as switch / ovpn server
all ok
GUI install over r47461
all good -- uptime 8:40


As my Buffalo WZR-HP-G300NH is aging albeit is still solidly working, do you recommend Linksys EA8500? It will be connected to my Huawei 5G CPE Pro main router.

I have to admit that I am not a networking guru, but I need flexibility and customizations to manage my devices at home.

_________________
Buffalo WZR-HP-G300NH
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5695

PostPosted: Tue Sep 21, 2021 6:20    Post subject: Reply with quote
Router/Version: Linksys EA8500 / Box Rev.A00 PCB REV:205(XC) hw_rev=1 hw_ver=XB / r47474 (09/20/21)
File/Kernel: CLI Flash dd-wrt-webupgrade.bin / Linux 4.9.282 #466 SMP Mon Sep 20 04:24:30 +07 2021 armv7l
Previous/Reset: r47461 (09/17/21) / No
Mode/Status: AP Gateway / VaNiLLa Mixed 20 MHz Ch 1 & 149 TX Power 30 dBm Short Preamble ttraff disabled
Issues/Errors: No / No

R7500v2, EA8500(serial flash), R7800(XR450/XR500), R9000(XR700): EA8500 is solid, R7800 and R7500v2 offline.
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2968
Location: Germany

PostPosted: Tue Sep 21, 2021 7:12    Post subject: Reply with quote
Router/Version: R7800
File/Kernel: Linux 4.9.282 #468 SMP Mon Sep 20 06:45:38 +07 2021 armv7l
Previous/Reset: r47381 / no
Mode/Status: Gateway / working
Services Used: PPPoE,DHCP,DHCP-Reservation,Dnsmasq + PiHole,DDNS,SSH,WiFi 2,4Ghz + 5Ghz AP's + VAP's Vanilla,USB,Port forwarding,QoS
Issues/Errors: nothing so far

Jan 1 01:01:39 DD-WRT daemon.info dnsmasq[2054]: started, version 2.86 cache disabled

Sep 21 09:11:20 dnsmasq[85117]: started, version pi-hole-2.86 cachesize 10000
lexridge
DD-WRT Guru


Joined: 07 Jun 2006
Posts: 1061
Location: WV, USA

PostPosted: Tue Sep 21, 2021 13:38    Post subject: Reply with quote
Router/Version: EA8500
Previous/Reset: r47117/No
Mode/Status: Gateway
Issues/Errors: Yes

After flashing this, I now have 13 wireless channels on 2.4Ghz instead of the normal 11 channels. My Regulatory Domain is still set for United States, so I should only have 11 channels. Anyone else seeing this with the EA8500?

_________________
Linksys EA8500 (Internet Gateway, AP/VAP) - DD-WRT r53562
Features in use: WDS-AP, Multiple VLANs, Samba, WireGuard, Entware: mqtt, mlocate
Wireless 5ghz only

Netgear R7800 (WDS-AP, WAP, VAP) - DD-WRT r55779
Features in use: multiple VLANs over single trunk port

Linksys EA8500 WDS Station x2 - DD-WRT r55799

Netgear R6400v2 WAP, VAP 2.4ghz only w/VLANs over single trunk port. DD-WRT r55779

OSes: Fedora 38, 9 RPis (2,3,4,5), 20 ESP8266s: Straight from Amiga to Linux in '94, never having owned a Windows PC.

Forum member #248
ho1Aetoo
DD-WRT Guru


Joined: 19 Feb 2019
Posts: 2968
Location: Germany

PostPosted: Tue Sep 21, 2021 13:47    Post subject: Reply with quote
I have that on the R7800 also


Code:
root@DD-WRT:~# iw reg get
global
country US: DFS-UNSET
   (2400 - 2483 @ 40), (N/A, 30), (N/A)


should actually look like this

Code:
country US: DFS-FCC
   (2400 - 2472 @ 40), (30)


or was there some update that I do not know about?

https://git.kernel.org/pub/scm/linux/kernel/git/sforshee/wireless-regdb.git/tree/db.txt
Goto page Previous  1, 2, 3, 4  Next Display posts from previous:    Page 2 of 4
Post new topic   Reply to topic    DD-WRT Forum Index -> Atheros WiSOC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum