OpenVPN Server intermittent responsiveness

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page Previous  1, 2
Author Message
Nightbridge
DD-WRT User


Joined: 09 Jan 2017
Posts: 76
Location: Dublin

PostPosted: Mon Jul 11, 2022 20:57    Post subject: Reply with quote
Thanks @the-joker. Where can I disable
It?
Sponsor
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Mon Jul 11, 2022 21:29    Post subject: Reply with quote
It may or may not be the implementation of either SFE/fast-classifier, CTF, or Flow Acceleration, but has VPN ever played well with NAT acceleration or QoS in DD-WRT? Rolling Eyes

@Nightbridge: it's on the main Setup page under WAN.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Nightbridge
DD-WRT User


Joined: 09 Jan 2017
Posts: 76
Location: Dublin

PostPosted: Mon Jul 11, 2022 21:38    Post subject: Reply with quote
Many thanks @kernel-panic69, I’ll give it a go.
Nightbridge
DD-WRT User


Joined: 09 Jan 2017
Posts: 76
Location: Dublin

PostPosted: Mon Jul 11, 2022 21:53    Post subject: Reply with quote
I can't find any Cut Through Forwarding in Setup -> Basic Setup -> WAN Setup. Have I misunderstood? @kernel-panic69
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Mon Jul 11, 2022 22:00    Post subject: Reply with quote
All you'll have is SFE, since the DIR-882 is MediaTek.

https://wikidevi.wi-cat.ru/D-Link_DIR-882_rev_A1

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
Nightbridge
DD-WRT User


Joined: 09 Jan 2017
Posts: 76
Location: Dublin

PostPosted: Mon Jul 11, 2022 22:02    Post subject: Reply with quote
Got it, many thanks for your reply @kernel-panic69
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Mon Jul 11, 2022 22:12    Post subject: Reply with quote

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
eibgrad
DD-WRT Guru


Joined: 18 Sep 2010
Posts: 9157

PostPosted: Tue Jul 12, 2022 5:21    Post subject: Reply with quote
egc wrote:
@eibgrad that is a good point.

I will talk to the boss, but they always want to look good in relation to the competition and looking good is that they can boast to have the biggest ( performance Smile )

Like you I have it disabled


Believe me, I understand the rationale from a competitive standpoint. But at least in the case of Merlin, if you enable features which are KNOWN not to work w/ CTF enabled (e.g., QoS or other AiProtection features), the firmware *silently* disables it.

To be fair, I don't know how extensive is this *awareness* of what does and doesn't work w/ CTF. But at least it does try to mitigate some known issues before users get themselves into trouble. But as far as I can tell, dd-wrt does nothing (i.e., the sfe variable in nvram remains 1 (sfe) or 2 (ctf)).

So to the extent we *know* what doesn't work, I'd be less unhappy if dd-wrt disabled SFE/CTF when appropriate (fwiw, freshtomato appears no better in this department).

But even so, I still prefer it being OFF given it has proven to be unpredictable as to when it might be affecting something negatively. Seems you always have to remind yourself when dealing w/ new problems, esp. something that appears to be correct, to disable it, just in case.

As I've said many times, the use of these hacks only proves your router is underpowered. It's just a gimmick meant to give the *illusion* your router is up to the task of managing the available bandwidth from your ISP, when in fact it is NOT!

P.S. I'm just venting. I realize you are just as aware as I am about this so-called feature.

_________________
ddwrt-ovpn-split-basic.sh (UPDATED!) * ddwrt-ovpn-split-advanced.sh (UPDATED!) * ddwrt-ovpn-client-killswitch.sh * ddwrt-ovpn-client-watchdog.sh * ddwrt-ovpn-remote-access.sh * ddwrt-ovpn-client-backup.sh * ddwrt-mount-usb-drives.sh * ddwrt-blacklist-domains.sh * ddwrt-wol-port-forward.sh * ddwrt-dns-monitor.sh (NEW!)
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14246
Location: Texas, USA

PostPosted: Tue Jul 12, 2022 10:49    Post subject: Reply with quote
I'm fairly certain, that if you look hard enough, you'll see where the whole SFE/CTF and QoS thing was changed and behavior isn't what it should be - and I think that was a result of certain users' input. Wasn't it so SFE could be enabled or disabled on the fly without having to reboot? I forget the details, but this definitely needs to be returned to expected behavior of disabling SFE/CTF/FA when QoS or other conflicting services are enabled. I personally don't care if a reboot would be required or not.
_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12917
Location: Netherlands

PostPosted: Tue Jul 12, 2022 11:10    Post subject: Reply with quote
A reboot is not necessarily per se, a simple rmmod should do (and set the SFE nvram parameter to off)

I know that if you create a VAP, SFE is turned off (does work on Atheros but not always on Broadcom)

I do not know about QoS, do not use it.

The problems with VPN and WireGuard are "just" some added latency at the start not detectable unless you use things like VoIP.

At the moment I have no time to look at it in detail Sad

I am updating my build system (not my favourite hobby, so I suck at it)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Goto page Previous  1, 2 Display posts from previous:    Page 2 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum