New Build - 10/17/2025 - r62365

Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Author Message
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 6309

PostPosted: Fri Oct 17, 2025 14:51    Post subject: New Build - 10/17/2025 - r62365 Reply with quote
Welcome to Marvell r62365 beta release thread for reporting, feedback to developers and community benefit.
Please do not flash builds until installation is understood, risks involved and device specific recovery methods.
Avoid discussions, create threads for questions, general problems or use search; this thread is not for support.
List router model & version or revision, operating & wireless modes & exact filename/firmware image flashed.


CLI Flash: 'cd /tmp' then 'wget {file URL}' (http only) or 'curl -O {file URL}' (http, https, ftp) 'write {file} linux' then 'reboot'.

Downloads: HTTPS, FTP

Trac SVN: repository since last build r62324 (mirror)

OpenVPN 2.6.14: Changelog, Guides, Server, PBR, DNS, Kill Switch, Watchdog, Reverse PBR, Client, Multiple, tips, scripts.
WireGuard 1.0.20211208/Tools: Changelog, Guides, Client, Server, Adv, PBR, KS, tips, scripts. Thanks BS egc & eibgrad!

Notes: ...
r61542 r61557 r61613 r61648 r61711 r61745 r61848 r61915 r61920 r61954 r61970 r61981 r62032 r62036 r62104 r62157
r62170 r62192 r62240 r62268 r62324 r62365

Issues, observations, and/or workarounds reported:
WebUI: Clear history or use a portable. Temporary cache bypass: Ctrl+F5, Cmd+Shift+R or new private window/incognito.
Please report findings with steps needed to reproduce, configuration, clients, output, logs and important information below!

Important:
Detail issues & relevant configs, logs: syslog klog 'dmesg' 'cat /tmp/var/log/messages' nvram set console_debug=1, serial.
• Firewall NAT: 'iptables -vnL' 'iptables -t nat -vnL' 'iptables -t mangle -vnL' & 'cat /tmp/.ipt'. Debug Analyze: strace tcpdump.
• Gremlins: reboot. cold boot. Reset & reconfigure not restore backup. Search Trac & discuss in forum before opening tickets.
• Include operating & wireless modes (e.g. Gateway, Router, AP, SB, WDS, Mesh) and applicable configurations to reproduce.

Example Template:
Code:
[b]Router/Version: [/b]
[b]File/Kernel: [/b]
[b]Previous/Reset: [/b]
[b]Mode/Status: [/b]
[b]Issues/Errors: [/b]
Sponsor
greenphantom61
DD-WRT Novice


Joined: 29 Mar 2011
Posts: 31

PostPosted: Sat Oct 18, 2025 0:35    Post subject: Reply with quote
Router/Version: Linksys WRT3200ACM
Firmware: DD-WRT v3.0-r62365 std (10/17/25)
File/Kernel: Linux 6.1.156-rt28 #183 SMP Fri Oct 17 07:50:01 +07 2025 armv7l
Previous/Reset: r62268, No reset
Mode/Status: AP/Gateway, No VPN, Stable, SFE disabled,wlan0 5GHz AC/N Mixed VHT80 WPA2-Personal-CCMP, wlan1 2.4Ghz N-only HT40 WPA2-Personal-CCMP, DDNS (SSL/TLS)
Issues/Errors: None
ewo32
DD-WRT User


Joined: 11 Nov 2023
Posts: 200

PostPosted: Sat Oct 18, 2025 10:40    Post subject: Reply with quote
Update method: CLI / SSH flash from konsole over wireless
Router/Version: Linksys WRT32X
File/Kernel: ddwrt-linksys-wrt32x-webflash.bin / Linux 6.1.156-rt28 #183 SMP Fri Oct 17 07:50:01 +07 2025 armv7l
Previous/Reset: 62324 / No, last reset at 61848
Mode/Status: Gateway, AP, PPPoE, SFE disabled, WAN to ONT, ignore WAN DNS, non-default router IP, SmartDNS for DoT (single host, dualstack IP enabled), DDNS (TLS enabled), wireguard server (preshared key, non-default port), SSHD (public key only, non-default port), telnet disabled, no VAP, wlan0 5GHz VHT80 AC only, wlan1 2.4GHz HT20 N only, wlan2 disabled, WPA2 Personal CCMP-128 all radios / Working
Issues/Errors: None
MBehr
DD-WRT User


Joined: 27 Nov 2018
Posts: 59

PostPosted: Sat Oct 18, 2025 16:21    Post subject: Reply with quote
Router/Version: WRT1900AC
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: none
Mode/Status: AP
Issues/Errors: none
Rickers
DD-WRT User


Joined: 10 May 2015
Posts: 165

PostPosted: Sun Oct 19, 2025 12:43    Post subject: Reply with quote
MBehr wrote:
Router/Version: WRT1900AC
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: none
Mode/Status: AP
Issues/Errors: none
Which version of 1900AC?
wrtbob
DD-WRT Novice


Joined: 31 Dec 2023
Posts: 15

PostPosted: Sun Oct 19, 2025 20:23    Post subject: Reply with quote
Router/Version: WRT1900AC v1
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: none
Mode/Status: AP
Issues/Errors: getting an error msg from wireguard and WAN is ok but no internet through the tunnel, reverting to r62192


Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard Killswitch on PBR activated for oet6 │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard NAT via oet6 for xxxxxxxxx enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard IPv4 internet access for xxxxxxxxxxxx/24 enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:46:02 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 15:46:03 is-mounted /opt/etc/Ipset mounted after 1 seconds │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan restored from /opt/etc/Ipset/ToWan for oet6 │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan fwmark:26 set to table:226 │
│Oct 19 15:46:03 root WireGuard adding local routes to table 26 │
│Oct 19 15:46:03 root WireGuard: DNSMasq restarted due to active ipset │
│Oct 19 15:46:03 dnsmasq exiting on receipt of SIGTERM │
│Oct 19 15:46:03 - [dnsmasq] : daemon successfully stopped │
│Oct 19 15:46:03 dnsmasq started, version UNKNOWN cachesize 1500


Oct 19 15:59:25 dnsmasq using only locally-known addresses for mask.icloud.com │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for use-application-dns.net │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for test │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for onion │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for localhost │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for local │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for invalid │
│Oct 19 15:59:25 dnsmasq using 1 more local addresses │
│Oct 19 15:59:25 dnsmasq read /etc/hosts - 10 names │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard NAT via oet1 for xxxxxxxxxxx enabled │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:59:26 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 16:00:51 httpd [httpd] : httpd SSL server started at port 443
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 13822
Location: Netherlands

PostPosted: Mon Oct 20, 2025 13:46    Post subject: Reply with quote
wrtbob wrote:
Router/Version: WRT1900AC v1
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: none
Mode/Status: AP
Issues/Errors: getting an error msg from wireguard and WAN is ok but no internet through the tunnel, reverting to r62192


Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard Killswitch on PBR activated for oet6 │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard NAT via oet6 for xxxxxxxxx enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard IPv4 internet access for xxxxxxxxxxxx/24 enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:46:02 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 15:46:03 is-mounted /opt/etc/Ipset mounted after 1 seconds │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan restored from /opt/etc/Ipset/ToWan for oet6 │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan fwmark:26 set to table:226 │
│Oct 19 15:46:03 root WireGuard adding local routes to table 26 │
│Oct 19 15:46:03 root WireGuard: DNSMasq restarted due to active ipset │
│Oct 19 15:46:03 dnsmasq exiting on receipt of SIGTERM │
│Oct 19 15:46:03 - [dnsmasq] : daemon successfully stopped │
│Oct 19 15:46:03 dnsmasq started, version UNKNOWN cachesize 1500


Oct 19 15:59:25 dnsmasq using only locally-known addresses for mask.icloud.com │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for use-application-dns.net │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for test │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for onion │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for localhost │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for local │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for invalid │
│Oct 19 15:59:25 dnsmasq using 1 more local addresses │
│Oct 19 15:59:25 dnsmasq read /etc/hosts - 10 names │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard NAT via oet1 for xxxxxxxxxxx enabled │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:59:26 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 16:00:51 httpd [httpd] : httpd SSL server started at port 443


Redacting private ip addresses is not necessary as those are private but it makes it more difficult to give support.
Are you sure it is build number 62192 which is working for you? Because after that build there have been no changes to Wireguard (of course a lot of other changes e.g. new kernel with iptables etc wich could trigger errors).
To diagnose the problem we need to see the the list from the troubleshooting section in the WireGuard Server setup guide (guides are a sticky in the Advanced networking forum):

Quote:
Send detailed information when asking for help:
Start with Screenshots of WireGuard page (whole page) and Basic Setup page (whole page).
If you use anything other than plain DNSMasq for DNS resolving also report that and add a screenshot of the Service > Services page.
If more detailed information is needed then show the output of the following commands (CLI, with telnet/putty) after you attempted to make a connection:
wg
wg showconf oet1 #if you have more tunnels dan also: wg showconf oetX where X is the tunnel number
ip route show
grep -E -i 'oet|wireguard|eop' /var/log/messages
iptables -vnL FORWARD | grep oet
iptables -vnL INPUT
iptables -vnL -t nat
iptables -vnL -t raw
get_wanface
nvram get wan_ipaddr


plus we need to see the log with debugging of the firewall enabled:
To enable debug logging of the WireGuard firewall:
Quote:
nvram set wg_debug_firewall=1 && nvram commit

To disable debug logging:
Quote:
nvram unset wg_debug_firewall && nvram commit

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
dplotz
DD-WRT User


Joined: 07 Jan 2025
Posts: 220
Location: Bethel Park, PA, USA

PostPosted: Mon Oct 20, 2025 14:33    Post subject: Reply with quote
Router/Version: Linksys WRT1900AC v1
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: DD-WRT v3.0-r61745 std (06/12/25), last reset r61745
Mode/Status: Gateway (SFE Disabled), Access Point (5GHZ-VHT80 AC/N mixed, WPA2/WPA3, domain:UNITED STATES), IPV6 (DHCP6 w/ prefix delegation), Entware, DOT via SmartDNS/DNSMasq, Wireguard Server
No WAN access from client machines after update, with SFE on or off. Rolled back to r61745.

Thank you Brainslayer.

_________________
Formerly dpp3530
Linksys MR7350
Gateway, 2 wired APs, NSS-ECM , Clock 1440MHz
VAPs on wlan0 and wlan1 for guest/IOT devices
IPv4 & IPv6 (Prefix Delegation)
Static Leases & DHCP
SmartDNS (DOT using NextDNS, Cloudflare), DNSMasq
Wireguard and OpenVPN server
2.4GHz: dd-wrt, AX Only, ACK Timing 1350, WPA3 SAE & WPA2 w/AES
5GHz: dd-wrt, AX/AC/N Mixed, ACK Timing 1350, WPA3 SAE & WPA2 w/AES
Verizon Fios, 500/500Mbps
wrtbob
DD-WRT Novice


Joined: 31 Dec 2023
Posts: 15

PostPosted: Mon Oct 20, 2025 18:56    Post subject: Reply with quote
egc wrote:
wrtbob wrote:
Router/Version: WRT1900AC v1
File/Kernel: DD-WRT v3.0-r62365 std (10/17/25)
Previous/Reset: none
Mode/Status: AP
Issues/Errors: getting an error msg from wireguard and WAN is ok but no internet through the tunnel, reverting to r62192


Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard PBR 192.168.xxx.xxx:IPv4 via oet6 table 26 │
│Oct 19 15:46:02 root WireGuard Killswitch on PBR activated for oet6 │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard NAT via oet6 for xxxxxxxxx enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard IPv4 internet access for xxxxxxxxxxxx/24 enabled │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:46:02 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:46:02 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 15:46:03 is-mounted /opt/etc/Ipset mounted after 1 seconds │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan restored from /opt/etc/Ipset/ToWan for oet6 │
│Oct 19 15:46:03 root WireGuard IPSET: ToWan fwmark:26 set to table:226 │
│Oct 19 15:46:03 root WireGuard adding local routes to table 26 │
│Oct 19 15:46:03 root WireGuard: DNSMasq restarted due to active ipset │
│Oct 19 15:46:03 dnsmasq exiting on receipt of SIGTERM │
│Oct 19 15:46:03 - [dnsmasq] : daemon successfully stopped │
│Oct 19 15:46:03 dnsmasq started, version UNKNOWN cachesize 1500


Oct 19 15:59:25 dnsmasq using only locally-known addresses for mask.icloud.com │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for use-application-dns.net │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for test │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for onion │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for localhost │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for local │
│Oct 19 15:59:25 dnsmasq using only locally-known addresses for invalid │
│Oct 19 15:59:25 dnsmasq using 1 more local addresses │
│Oct 19 15:59:25 dnsmasq read /etc/hosts - 10 names │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard NAT via oet1 for xxxxxxxxxxx enabled │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 eop-tunnel-firewall.sh Illegal instruction │
│Oct 19 15:59:26 root WireGuard released /tmp/oet-tunnels.lock for prewall │
│Oct 19 15:59:26 root WireGuard firewall removing temporary killswitch for IPv4 │
│Oct 19 16:00:51 httpd [httpd] : httpd SSL server started at port 443


Redacting private ip addresses is not necessary as those are private but it makes it more difficult to give support.
Are you sure it is build number 62192 which is working for you? Because after that build there have been no changes to Wireguard (of course a lot of other changes e.g. new kernel with iptables etc wich could trigger errors).
To diagnose the problem we need to see the the list from the troubleshooting section in the WireGuard Server setup guide (guides are a sticky in the Advanced networking forum):

Quote:
Send detailed information when asking for help:
Start with Screenshots of WireGuard page (whole page) and Basic Setup page (whole page).
If you use anything other than plain DNSMasq for DNS resolving also report that and add a screenshot of the Service > Services page.
If more detailed information is needed then show the output of the following commands (CLI, with telnet/putty) after you attempted to make a connection:
wg
wg showconf oet1 #if you have more tunnels dan also: wg showconf oetX where X is the tunnel number
ip route show
grep -E -i 'oet|wireguard|eop' /var/log/messages
iptables -vnL FORWARD | grep oet
iptables -vnL INPUT
iptables -vnL -t nat
iptables -vnL -t raw
get_wanface
nvram get wan_ipaddr


plus we need to see the log with debugging of the firewall enabled:
To enable debug logging of the WireGuard firewall:
Quote:
nvram set wg_debug_firewall=1 && nvram commit

To disable debug logging:
Quote:
nvram unset wg_debug_firewall && nvram commit





yes I upgraded from r62192 which works pretty well. I waited quite a while before upgrading from r57956 as with r59045 I couldn't properly generate freeradius certificates (maybe human error), indeed the first thing I checked was the wg changelog before posting. Should I reply here with the logs or create new post under Advanced networking forum?
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 13822
Location: Netherlands

PostPosted: Tue Oct 21, 2025 5:55    Post subject: Reply with quote
If you can make new thread and post in the Advanced Networking forum that would be great

Edit: make sure you disable SFE (shortcut forwarding engine) on the basic setup page

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
wrtbob
DD-WRT Novice


Joined: 31 Dec 2023
Posts: 15

PostPosted: Tue Oct 21, 2025 23:24    Post subject: Reply with quote
egc wrote:
If you can make new thread and post in the Advanced Networking forum that would be great

Edit: make sure you disable SFE (shortcut forwarding engine) on the basic setup page


Ok done. Thanks

https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=339155

_________________
Router Linksys WRT1900AC v1
DD-WRT v3.0-r62192 std
Linux 6.1.153-rt28 #354 SMP Fri Sep 26 03:27:50 +07 2025 armv7l
Freeradius Entware DNScrypt-Proxy2
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum