Newer builds of DD-WRT blocking WebGUI access?

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
strwbrrysam
DD-WRT Novice


Joined: 16 Apr 2021
Posts: 29

PostPosted: Wed Mar 22, 2023 23:55    Post subject: Newer builds of DD-WRT blocking WebGUI access? Reply with quote
Hello everyone, hope you all are doing well.

I'll first try to give a very brief description of the issue, to see if someone can immediately spot the problem. If you require more information from me to help solve this, I'll definitely provide them later but I dont want to clutter the post too much too early.

The situation is this:

Site A:
DD-WRT router running build 47528
Ubuntu box hosting OpenVPN server, in TAP configuration

Site B:
DD-WRT router running build 52081
Router is also running OpenVPN Client, connected with TAP Bridge back to Site A

Please excuse the vagueness, everything related to VPN is working and this is not a question related to VPN.

I have noticed that computers from Site B can access Site A Router WebGUI
BUT
Computers from Site A CANNOT access Site B Router WebGUI.

I know that something within DD-WRT has changed since build 47528 to affect WebGUI access from traffic inbound on tap1 interface (if the router is acting as VPN client)
Because after immediately noticing the issue, I re-flashed Site B Router from 52081 to 47528 to match Site A and everything is working again.

So my very simple question is this:
Does anyone know what changed in recent months?
Is there a way to make Site B allow WebGUI from traffic inbound on VPN tunnel?
This issue is also affect the ability to perform iperf3 tests (only transferring data one way)
but for some reason pings still work 100% fine.

If this is a security change, can someone please explain to me the logic behind the change?
I am a newbie but I want to learn more about everything!

Thank you for your time!
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Thu Mar 23, 2023 9:17    Post subject: Reply with quote
TAP (bridged setup) is not very much used. A routed setup and nowadays WireGuard (faster and easier than OpenVPN) are the VPN connections mostly used

As a TAP setup is supposed to be bridged there should be no boundaries between the sites.

It does assume the sites are on the same subnet to work.

OpenVPN documentation is a sticky in this forum, the OpenVPN *Server* setup guide has a paragraph about TAP setup (also to setup the client side) you might take a look there to see if that gives you any clues.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
strwbrrysam
DD-WRT Novice


Joined: 16 Apr 2021
Posts: 29

PostPosted: Thu Mar 23, 2023 14:32    Post subject: Reply with quote
egc wrote:

OpenVPN documentation is a sticky in this forum, the OpenVPN *Server* setup guide has a paragraph about TAP setup (also to setup the client side) you might take a look there to see if that gives you any clues.


Thank you for your swift response, egc. This isn't the first time you've answered my posts so I very much appreciate the help.

I was a little worried you might say that, so I'd just like to clarify the situation. Despite the fact that I am very much NOT a professional, calling myself a Newbie when it comes to dd-wrt/openvpn might be selling myself a little short here.

I just wanted to clarify that even though the example I showed only consisted of two sites, the reality is that I am currently managing a mesh of five locations. I have spent countless hours researching and tinkering to get Openvpn to work months ago, and everything is absolutely PERFECT and does exactly what we need it to do. I opted for TAP because we like having having printers/scanners and other devices broadcast over the network. It's a mix of work and play and sometimes my friends and I play older games remotely that don't seem to work between routed subnets no matter how hard we tried.

Anyway, my point is this:
This wasn't REALLY a troubleshooting post. More of a note and hoping to find a solution so other people can search for it on the forum/google.

All I know is that something changed between builds 47528 and 52081 that is now preventing WebGUI access and possibly other services from working properly through the VPN tunnel, even though pings are allowed. I don't think one needs to be an expert at dd-wrt to realize this because there have been new options added to the Openvpn client on dd-wrt since 47528.
For example: the "Source Routing (PBR)" options.

I just wish to learn more about what is happening under the hood to try and see for myself what changed.

When I am trying to access the router's webgui from the other site's computers, the browser can clearly find the IP, almost like it's loading, but the packets are being dropped by firewall. I've investigated iptables but can't seem to see anything. Again, on 47528 and older builds, this is no issue. Everything works as intended.

Perhaps there are more verbose troubleshooting commands you can provide?
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12874
Location: Netherlands

PostPosted: Thu Mar 23, 2023 15:18    Post subject: Reply with quote
I just did a quick test with two DDWRT routers one as OpenVPN server and the other as OpenVPN client with a TAP (bridged setup) and I had no problem connecting to the GUI from either side.

The GUI has been overhauled maybe it is a browser problem as you can ping the router, so some things to try:
clear browser cache (CTRL + F5)
Us another browse, Chrome can be picky, try FireFox of Waterfox classic
Use incognito mode

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
dale_gribble39
DD-WRT Guru


Joined: 11 Jun 2022
Posts: 1927

PostPosted: Thu Mar 23, 2023 15:50    Post subject: Reply with quote
Ensure you are using http://your.router.ip.here instead of https (unless it is enabled). Modern browsers seem to default to https-only with no http fallback as well. Mixed versions of DD-WRT may also hinder functionality, but to each their own. Also, to be quite clear, reporting an issue without being on the current release is forum fodder most of the time, anyway.

https://ftp.dd-wrt.com/dd-wrtv2/downloads/betas/2023/03-23-2023-r52095/

_________________
"The woods are lovely, dark and deep,
But I have promises to keep,
And miles to go before I sleep,
And miles to go before I sleep." - Robert Frost

"I am one of the noticeable ones - notice me" - Dale Frances McKenzie Bozzio

<fact>code knows no gender</fact>

This is me, knowing I've ruffled your feathers, and not giving a ****
Some people are still hard-headed.

--------------------------------------
Mac Pro (Mid 2012) - Two 2.4GHz 6-Core Intel Xeon E5645 processors 64GB 1333MHz DDR3 ECC SDRAM OpenSUSE Leap 15.5
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum