VPN on and internet works on computers but not on phone

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
gigaaaaaahertz
DD-WRT Novice


Joined: 11 Jul 2021
Posts: 3

PostPosted: Mon Jul 12, 2021 7:19    Post subject: VPN on and internet works on computers but not on phone Reply with quote
I flashed my Netgear r7000 with DD-WRT and set up a CyberGhost VPN connection on it. CyberGhost vouch for DD-WRT and have detailed instructions on how to set it up so I know the VPN details are correct. I got the internet working and connected to the VPN via the router just fine on both of my Mac computers but am having trouble connecting to the internet on my Galaxy s20. I can connect to wifi but after it connects it tells me 'connected without internet'. I have a Google mesh wifi point in bridge mode connected to my Netgear r7000 and the same thing happens when I try to connect directly to the router or to the Google Wifi. The computers work just fine and when I test my IP address it comes back as from a CyberGhost server.

Netgear r7000 > VPN > Google Wifi (bridge mode) > Clients in DHCP

Not sure what the problem might be or what settings or connections to look at because I'm a relative newbie when it comes to this kind of thing. I can follow instructions alright but get stuck at troubleshooting networking problems.
Sponsor
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12881
Location: Netherlands

PostPosted: Mon Jul 12, 2021 7:48    Post subject: Reply with quote
Welcome to the forum Smile

To get the best out of DDWRT and the forum read the forum guidelines with helpful pointers:
https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087

If you have not already read the forum guidelines, please do !!

What build number are you using?

I do not know any VPN provider with accurate and up to date instructions to set up for DDWRT but of course cyberghost can be the exception.

What instructions did you use?

To check the VPN show a picture of the OVPN settings page (whole page) and the OVPN status page after you have enabled System Log/syslogd on Services page.

To test if you are connected to the right ip address you can surf to: ipleak.net
What does your phone show?

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
gigaaaaaahertz
DD-WRT Novice


Joined: 11 Jul 2021
Posts: 3

PostPosted: Mon Jul 12, 2021 21:29    Post subject: Reply with quote
I'll read up on the guidelines now! Thanks.

Pretty sure I'm using the latest build.
Firmware: DD-WRT v3.0-r44715 std (11/03/20)

I used these instructions
https://support.cyberghostvpn.com/hc/en-us/articles/213811885-Router-How-to-Set-Up-OpenVPN-on-DD-WRT-Routers

And according to this article my router is officially supported.
https://support.cyberghostvpn.com/hc/en-us/articles/360011039059-Router-FlashRouters-Privacy-App-DD-WRT-

Quote:

To test if you are connected to the right ip address you can surf to: ipleak.net
What does your phone show?


My phone can't show anything because it doesn't connect to the internet through the wifi. I made a bit of progress, now instead of Android saying my wifi is 'connected without internet' it just says 'connected'. I did this by changing Static DNS 1 and 2 to Cloudflare 1.1.1.1 and 1.0.0.1. Not sure what change this makes.

OPVN Status
Quote:

State
Client: CONNECTED SUCCESS
Local Address: 10.22.4.58
Remote Address: 10.22.4.58

Status
VPN Client Stats
TUN/TAP read bytes 421256
TUN/TAP write bytes 252361
TCP/UDP read bytes 317896
TCP/UDP write bytes 513992
Auth read bytes 252361

Log
Clientlog:
20210713 07:25:17 W DEPRECATED OPTION: ncp-disable. Disabling cipher negotiation is a deprecated debug feature that will be removed in OpenVPN 2.6
20210713 07:25:17 W DEPRECATED OPTION: --cipher set to 'AES-256-CBC' but missing in --data-ciphers (AES-128-GCM:AES-256-GCM:AES-128-CBC). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-256-CBC' to --data-ciphers or change --cipher 'AES-256-CBC' to --data-ciphers-fallback 'AES-256-CBC' to silence this warning.
20210713 07:25:17 W WARNING: Using --management on a TCP port WITHOUT passwords is STRONGLY discouraged and considered insecure
20210713 07:25:17 W WARNING: file '/tmp/openvpncl/client.key' is group or others accessible
20210713 07:25:17 W WARNING: file '/tmp/openvpncl/credentials' is group or others accessible
20210713 07:25:17 Current Parameter Settings:
20210713 07:25:17 config = '/tmp/openvpncl/openvpn.conf'
20210713 07:25:17 mode = 0
20210713 07:25:17 NOTE: --mute triggered...
20210713 07:25:17 234 variation(s) on previous 3 message(s) suppressed by --mute
20210713 07:25:17 I OpenVPN 2.5.0 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Nov 3 2020
20210713 07:25:17 I library versions: OpenSSL 1.1.1h 22 Sep 2020 LZO 2.09
20210713 07:25:17 MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:16
20210713 07:25:17 W NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
20210713 07:25:17 Control Channel MTU parms [ L:1621 D:1212 EF:38 EB:0 ET:0 EL:3 ]
20210713 07:25:17 Data Channel MTU parms [ L:1621 D:1450 EF:121 EB:406 ET:0 EL:3 ]
20210713 07:25:17 Local Options String (VER=V4): 'V4 dev-type tun link-mtu 1569 tun-mtu 1500 proto UDPv4 cipher AES-256-CBC auth SHA256 keysize 256 key-method 2 tls-client'
20210713 07:25:17 Expected Remote Options String (VER=V4): 'V4 dev-type tun link-mtu 1569 tun-mtu 1500 proto UDPv4 cipher AES-256-CBC auth SHA256 keysize 256 key-method 2 tls-server'
20210713 07:25:17 I TCP/UDP: Preserving recently used remote address: [AF_INET]202.60.80.85:443
20210713 07:25:17 Socket Buffers: R=[180224->180224] S=[180224->180224]
20210713 07:25:17 I UDPv4 link local: (not bound)
20210713 07:25:17 I UDPv4 link remote: [AF_INET]202.60.80.85:443
20210713 07:25:17 TLS: Initial packet from [AF_INET]202.60.80.85:443 sid=338af5ff 0a56dc15
20210713 07:25:17 W WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
20210713 07:25:17 VERIFY KU OK
20210713 07:25:17 Validating certificate extended key usage
20210713 07:25:17 ++ Certificate has EKU (str) TLS Web Server Authentication expects TLS Web Server Authentication
20210713 07:25:17 NOTE: --mute triggered...
20210713 07:25:18 2 variation(s) on previous 3 message(s) suppressed by --mute
20210713 07:25:18 W WARNING: 'link-mtu' is used inconsistently local='link-mtu 1569' remote='link-mtu 1549'
20210713 07:25:18 W WARNING: 'auth' is used inconsistently local='auth SHA256' remote='auth [null-digest]'
20210713 07:25:18 W WARNING: 'keysize' is used inconsistently local='keysize 256' remote='keysize 128'
20210713 07:25:18 Control Channel: TLSv1.3 cipher TLSv1.3 TLS_AES_256_GCM_SHA384 4096 bit RSA
20210713 07:25:18 I [sydney-rack407.nodes.gen4.ninja] Peer Connection Initiated with [AF_INET]202.60.80.85:443
20210713 07:25:19 SENT CONTROL [sydney-rack407.nodes.gen4.ninja]: 'PUSH_REQUEST' (status=1)
20210713 07:25:19 PUSH: Received control message: 'PUSH_REPLY redirect-gateway def1 route-ipv6 2000::/3 dhcp-option DNS 10.0.0.243 route-gateway 10.22.4.1 topology subnet ping 10 ping-restart 60 ifconfig 10.22.4.58 255.255.255.0 peer-id 4'
20210713 07:25:19 W WARNING: You have specified redirect-gateway and redirect-private at the same time (or the same option multiple times). This is not well supported and may lead to unexpected results
20210713 07:25:19 OPTIONS IMPORT: timers and/or timeouts modified
20210713 07:25:19 OPTIONS IMPORT: --ifconfig/up options modified
20210713 07:25:19 OPTIONS IMPORT: route options modified
20210713 07:25:19 NOTE: --mute triggered...
20210713 07:25:19 4 variation(s) on previous 3 message(s) suppressed by --mute
20210713 07:25:19 Outgoing Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
20210713 07:25:19 Outgoing Data Channel: Using 256 bit message hash 'SHA256' for HMAC authentication
20210713 07:25:19 Incoming Data Channel: Cipher 'AES-256-CBC' initialized with 256 bit key
20210713 07:25:19 NOTE: --mute triggered...
20210713 07:25:19 1 variation(s) on previous 3 message(s) suppressed by --mute
20210713 07:25:19 net_route_v4_best_gw query: dst 0.0.0.0
20210713 07:25:19 net_route_v4_best_gw result: via 10.20.25.231 dev ppp0
20210713 07:25:19 GDG6: remote_host_ipv6=n/a
20210713 07:25:19 net_route_v6_best_gw query: dst ::
20210713 07:25:19 W sitnl_send: rtnl: generic error (-95): Not supported
20210713 07:25:19 I TUN/TAP device tun1 opened
20210713 07:25:19 do_ifconfig ipv4=1 ipv6=0
20210713 07:25:19 I net_iface_mtu_set: mtu 1500 for tun1
20210713 07:25:19 I net_iface_up: set tun1 up
20210713 07:25:19 I net_addr_v4_add: 10.22.4.58/24 dev tun1
20210713 07:25:24 net_route_v4_add: 202.60.80.85/32 via 10.20.25.231 dev [NULL] table 0 metric -1
20210713 07:25:24 net_route_v4_add: 0.0.0.0/1 via 10.22.4.1 dev [NULL] table 0 metric -1
20210713 07:25:24 net_route_v4_add: 128.0.0.0/1 via 10.22.4.1 dev [NULL] table 0 metric -1
20210713 07:25:24 I WARNING: OpenVPN was configured to add an IPv6 route. However no IPv6 has been configured for tun1 therefore the route installation may fail or may not work as expected.
20210713 07:25:24 I add_route_ipv6(2000::/3 -> :: metric -1) dev tun1
20210713 07:25:24 net_route_v6_add: 2000::/3 via :: dev tun1 table 0 metric -1
20210713 07:25:24 W sitnl_send: rtnl: generic error (-95): Not supported
20210713 07:25:24 W ERROR: Linux IPv6 route can't be added
20210713 07:25:24 I Initialization Sequence Completed
20210713 07:26:52 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:52 D MANAGEMENT: CMD 'state'
20210713 07:26:52 MANAGEMENT: Client disconnected
20210713 07:26:52 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:52 D MANAGEMENT: CMD 'state'
20210713 07:26:52 MANAGEMENT: Client disconnected
20210713 07:26:52 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:52 D MANAGEMENT: CMD 'state'
20210713 07:26:52 MANAGEMENT: Client disconnected
20210713 07:26:52 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:52 D MANAGEMENT: CMD 'status 2'
20210713 07:26:52 MANAGEMENT: Client disconnected
20210713 07:26:52 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:52 D MANAGEMENT: CMD 'log 500'
20210713 07:26:52 MANAGEMENT: Client disconnected
20210713 07:26:57 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:57 D MANAGEMENT: CMD 'state'
20210713 07:26:57 MANAGEMENT: Client disconnected
20210713 07:26:57 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:57 D MANAGEMENT: CMD 'state'
20210713 07:26:57 MANAGEMENT: Client disconnected
20210713 07:26:57 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:57 D MANAGEMENT: CMD 'state'
20210713 07:26:57 MANAGEMENT: Client disconnected
20210713 07:26:57 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:57 D MANAGEMENT: CMD 'status 2'
20210713 07:26:57 MANAGEMENT: Client disconnected
20210713 07:26:57 MANAGEMENT: Client connected from [AF_INET]127.0.0.1:16
20210713 07:26:57 D MANAGEMENT: CMD 'log 500'
19700101 11:00:00


Settings
https://imgur.com/a/rTywx8u
kernel-panic69
DD-WRT Guru


Joined: 08 May 2018
Posts: 14217
Location: Texas, USA

PostPosted: Mon Jul 12, 2021 21:55    Post subject: Reply with quote
gigaaaaaahertz wrote:
I'll read up on the guidelines now! Thanks.

Pretty sure I'm using the latest build.
Firmware: DD-WRT v3.0-r44715 std (11/03/20)

I used these instructions
https://support.cyberghostvpn.com/hc/en-us/articles/213811885-Router-How-to-Set-Up-OpenVPN-on-DD-WRT-Routers

And according to this article my router is officially supported.
https://support.cyberghostvpn.com/hc/en-us/articles/360011039059-Router-FlashRouters-Privacy-App-DD-WRT-


Zeroed in on the router database and a 3rd-party how-to article. Double-whammy. This is the current release as of this post:

https://download1.dd-wrt.com/dd-wrtv2/downloads/betas/2021/07-12-2021-r47040/netgear-r7000/

I'll let @egc discuss what guide to use... not like there ain't no stickies or anything in this area of the forum or anything.

_________________
"Life is but a fleeting moment, a vapor that vanishes quickly; All is vanity"
Contribute To DD-WRT
Pogo - A minimal level of ability is expected and needed...
DD-WRT Releases 2023 (PolitePol)
DD-WRT Releases 2023 (RSS Everything)

----------------------
Linux User #377467 counter.li.org / linuxcounter.net
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12881
Location: Netherlands

PostPosted: Tue Jul 13, 2021 8:20    Post subject: Reply with quote
Now you know why it is important to read the guidelines as @kp69 pointed out Smile

Your build is old and has security issues already so step up to the latest build.

Normally coming from an old build a reset after update and putting settings in manually is recommended.

In this case the build is not that old so I would just upgrade without reset (never use the GUI option "reset after update" if you want to reset do it after the update)

Regarding DNS, it is a good idea to tick/enable "Ignore WAN DNS" on setup page and fill in Static DNS 1 and 2 on setup page with known good DNS servers like 1.1.1.1 or 9.9.9.9 like you did.

OpenVPN instructions see the link in my signature for OpenVPN guides, of interest to you is the Client setup guide.

The Cyberghost instructions are outdated and wrong, fortunately it does not break OpenVPN.

I will attach updated instructions for the best setup, I do not have Cyberghost so can not test it so I can not give 100% guarantee.
*However* I do not see anything related to your Android phone problems, Wifi is not treated differently then wired clients.

My advice upgrade to a current build, setup DNS and Cyberghost as recommended and test again.

To test, you can simply disable the VPN on the router, your settings are retained.

Remember after enabling/disabling reboot the router and after that reboot your clients/phone.

Let me know how it worked out.

Have fun Smile

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum