New Build - 02/13/2023 - r51679

Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.)
Goto page 1, 2  Next
Author Message
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Mon Feb 13, 2023 15:16    Post subject: New Build - 02/13/2023 - r51679 Reply with quote
Welcome to Marvell r51679 beta release thread for reporting, feedback to developers and community benefit.
Please do not flash builds until installation is understood, risks involved and device specific recovery methods.
Avoid discussions, create threads for questions, general problems or use search; this thread is not for support.
List router model & version or revision, operating & wireless modes & exact filename/firmware image flashed.


CLI Flash: 'cd /tmp' then 'wget {file URL}' (http only) or 'curl -O {file URL}' (http, https, ftp). 'write {file} linux' then 'reboot'.

Downloads: HTTPS, FTP

Trac SVN: repository since last build 51617 (mirror)

OpenVPN 2.6.0: Changelog, Guides, Server, PBR, DNS, Kill Switch, Watchdog, Reverse PBR, Client, Multiple, tips & scripts.
WireGuard 1.0.20211208/Tools: Changelog, Guides, Client, Server, Adv, PBR, KS, tips & scripts. Thanks BS egc & eibgrad!

Notes:
mDNS/Avahi 2022>2023 SC ProFTPD kernel syslog WG DD dnsmasq Transmission DNSCrypt Unbound FW wolfSSL Tor DRV
In-kernel SMB (ksmbd/tools 3.4.6/3.4.5): guest user is selectable. • WSD updateANTFS/NTFS3 kernel mode driver++++

Issues, observations, and/or workarounds reported:
WebUI: Clear history or use a portable. Temporary cache bypass: Ctrl+F5, Cmd+Shift+R or new private window/incognito.
Please report findings with steps needed to reproduce, configuration, clients, output, logs and important information below!

Important:
Detail issues & relevant configs, logs: syslog klog 'dmesg' 'cat /tmp/var/log/messages' nvram set console_debug=1, serial.
• Firewall NAT: 'iptables -vnL' 'iptables -t nat -vnL' 'iptables -t mangle -vnL' & 'cat /tmp/.ipt'. Misc: strace tcpdump wireshark.
• Gremlins: reboot. cold boot. Reset & reconfigure not restore backup. Search Trac & discuss in forum before opening tickets.
• Include operating & wireless modes (e.g. Gateway, Router, AP, SB, WDS, Mesh) and applicable configurations to reproduce.

Example Template:
Code:
[b]Router/Version: [/b]
[b]File/Kernel: [/b]
[b]Previous/Reset: [/b]
[b]Mode/Status: [/b]
[b]Issues/Errors: [/b]
Sponsor
Monza
DD-WRT User


Joined: 01 Jul 2018
Posts: 444

PostPosted: Mon Feb 13, 2023 21:22    Post subject: Reply with quote
Updated from r51617 to r51679 on my WRT1200 v1. VPN would not connect nor would the VPN tab show any data with everything else functional.

Disabled/Enabled a couple of times, rebooted twice after initial install/reboot with no luck. Reverted back to r51617 VPN connects and VPN tab shows data with everything else functional. (ExpressVPN)

Just a heads up. If no similar findings from others I will embrace "my setup" is flawed now and work from there.
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Mon Feb 13, 2023 21:43    Post subject: Reply with quote
Alozaros suggested remove ncp-disable from OpenVPN 2.6.0 config also --ncp-ciphers renamed to --data-ciphers.

Edit: confused two ncp options, fixed.


Last edited by blkt on Tue Feb 14, 2023 3:00; edited 1 time in total
Monza
DD-WRT User


Joined: 01 Jul 2018
Posts: 444

PostPosted: Mon Feb 13, 2023 22:59    Post subject: Reply with quote
Updated to r51679 again with same issue. SysLog for both below. Zero issues with VPN last few years. Must need some setup changes so I will contact ExpressVPN since I don't have "remove ncp-disable from OpenVPN 2.6.0 config" visible in my vpn setup. They make changes server side they said . . as I have not had to change my client setup for years. May need to update config info. Appears to be a ref to 2.6 in r51679 error. Thanks for the feedback.

r51617 SysLog VPN works
Dec 31 19:00:18 Router daemon.notice openvpn[1801]: OpenVPN 2.5.7 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Feb 9 2023
Dec 31 19:00:18 Router daemon.notice openvpn[1801]: library versions: OpenSSL 1.1.1s 1 Nov 2022, LZO 2.10

r51679 SysLog VPN won't load with following error with no OpenVPN version available.
Dec 31 19:00:17 Router daemon.err openvpn[1812]: Options error: Unrecognized option or missing or extra parameter(s) in /tmp/openvpncl/openvpn.conf:33: keysize (2.6.0)
blkt
DD-WRT Guru


Joined: 20 Jan 2019
Posts: 5700

PostPosted: Mon Feb 13, 2023 23:38    Post subject: Reply with quote
Aside from simple partition switch back to r51679, please show current config for others to diagnose or reproduce.

Plenty of deprecated options in 2.6 reference manual, is guesswork without relevant applicable config information.

--disable-occ
--cipher
--compress
--comp-lzo
--comp-noadapt
--secret
--opt-verify
--verify-hash
--link-mtu

Log error --keysize also deprecated https://community.openvpn.net/openvpn/wiki/DeprecatedOptions since 2.6:

--keysize
--ncp-disable
--inetd
--management-client-pf
--prng

https://openvpn.net/community-resources/reference-manual-for-openvpn-2-6/#unsupported-options since 2.5:

--client-cert-not-required (replaced with --verify-client-cert none)
--ifconfig-pool-linear (replaced with --topology p2p)
--ncp-ciphers (renamed to --data-ciphers)

--key-method
--no-iv
--no-replay
--ns-cert-type


Last edited by blkt on Tue Feb 14, 2023 3:32; edited 2 times in total
dpp3530
DD-WRT Guru


Joined: 12 Dec 2007
Posts: 780
Location: Pittsburgh, PA USA

PostPosted: Tue Feb 14, 2023 3:20    Post subject: Reply with quote
Router/Version: WRT1900AC v1
File/Kernel: DD-WRT v3.0-r51679 std (02/13/23)
Previous/Reset: DD-WRT v3.0-r51576 std (02/04/23), No reset this time.
Mode/Status: Gateway (SFE enabled), Access Point, IPV6 (DHCP6 w/ prefix delegation), Entware, DOT via SmartDNS, OpenVPN server, Wireguard Server
Issues/Errors:
Up 6 hours, nperf.com shows expected ISP speeds, both wired and wireless. OpenVPN, Wireguard, and DOT, all working as expected. Thanks Devs.

_________________
__________________________
Netgear R7800
DD-WRT v3.0 STD
Linksys WRT1900AC
DD-WRT v3.0 STD
oliver44
DD-WRT Guru


Joined: 01 Jun 2016
Posts: 504

PostPosted: Tue Feb 14, 2023 5:22    Post subject: Reply with quote
Router Model Linksys WRT1900ACS v2
Firmware Version DD-WRT v3.0-r51679 std (02/13/23)
Kernel Version Linux 4.9.337 #3631 SMP Mon Feb 13 03:30:31 +07 2023 armv7l
Current Time Tue, 14 Feb 2023 07:21:41
Uptime 7:06

update-browser waterfox, I switched from partition 1 from Linksys firmware, all ok
connection Type PPPoE - IPv6 Type DHCPv6 with Prefix Delegation 1Gbps
IPv6 Type DHCPv6 with Prefix Delegation-On - Ok
Operating Mode Gateway/AP
Shortcut Forwarding Engine-On
Schedule Reboot-On,
Web Access Protocol - HTTPS,
SSH (public key)-ok
Validate DNS Replies (DNSSEC)-ok
Port Forwarding - Ok,
USB - System Log -Ok
Schedule Reboot - At a Set Time - On

Wireless Interface 5GHz-Wireless Mode AP-Wireless Network Mode-AC/N, Width VHT 80 Mhz-Wireless Channel-36,Short GI, Short Preamble, Single User Beamforming, Radio Scheduling, Enable-WPA2/WPA3 Personal-CCMP-128 (AES), Regulatory Domain Romania , all-ok

Wireless Interface 2.4GHz-Wireless Mode AP-Wireless Network Mode-N, Width VHT 40 Mhz-Wireless Channel-6, Extension Channel Lower,TurboQAM (QAM256),Short Preamble, Short GI ,Threshold 784, Radio Scheduling, Enable-WPA2/WPA3 Personal-CCMP-128 (AES) all-ok!

After configuring the settings, I rebooted the router every time!

Validate DNS Replies (DNSSEC)

_________________
Internet provider https://en.wikipedia.org/wiki/RCS_%26_RDS 1Gbps
WDR3600 rev.1.5 - DD-Wrt
Linksys WRT1900ACS v.2 DD-Wrt/-OpenWrt



https://ipv6.chappell-family.com/ipv6tcptest/
https://en.internet.nl/connection/e91f490fe1c54cb2b78145c0ab0d2b5a/results
http://www.dnssec-or-not.com/
https://dnscheck.tools/#results
oliver44
DD-WRT Guru


Joined: 01 Jun 2016
Posts: 504

PostPosted: Tue Feb 14, 2023 8:02    Post subject: Reply with quote
speedtest
_________________
Internet provider https://en.wikipedia.org/wiki/RCS_%26_RDS 1Gbps
WDR3600 rev.1.5 - DD-Wrt
Linksys WRT1900ACS v.2 DD-Wrt/-OpenWrt



https://ipv6.chappell-family.com/ipv6tcptest/
https://en.internet.nl/connection/e91f490fe1c54cb2b78145c0ab0d2b5a/results
http://www.dnssec-or-not.com/
https://dnscheck.tools/#results
oliver44
DD-WRT Guru


Joined: 01 Jun 2016
Posts: 504

PostPosted: Tue Feb 14, 2023 8:27    Post subject: Reply with quote
congratulations to everyone who contributed to the implementation of ipv6 on ddwrt, in the test below ddwrt passes the test with default settings!
https://ipv6.chappell-family.com/ipv6tcptest/

_________________
Internet provider https://en.wikipedia.org/wiki/RCS_%26_RDS 1Gbps
WDR3600 rev.1.5 - DD-Wrt
Linksys WRT1900ACS v.2 DD-Wrt/-OpenWrt



https://ipv6.chappell-family.com/ipv6tcptest/
https://en.internet.nl/connection/e91f490fe1c54cb2b78145c0ab0d2b5a/results
http://www.dnssec-or-not.com/
https://dnscheck.tools/#results
Zyxx
DD-WRT Guru


Joined: 28 Dec 2018
Posts: 739

PostPosted: Wed Feb 15, 2023 10:42    Post subject: Reply with quote
Router/Version: Linksys WRT1900ACS v2
File: ddwrt-linksys-wrt1900acsv2-webflash.bin
Firmware: DD-WRT v3.0-r51679 std (02/13/23) (prev. DD-WRT v3.0-r51617 std (02/09/23))
Kernel: Linux 4.9.337 #3631 SMP Mon Feb 13 03:30:31 +07 2023 armv7l
Mode: Gateway, SFE enabled, Wifi disabled, Wireguard for external access, WAN to DSL Modem, samba to access USB3-ext4 SSD, Keep Alive reboot 5:00 in the morning
Reset: No
Status: Installed at release, OK. SSH fixed again, no iptables for firewall needed anymore Smile.

Load average 0.00, 0.00, 0.00, Temperatures CPU 68.9 °C / WL0 42.3 °C / WL1 43.8 °C
matjazk
DD-WRT User


Joined: 21 Aug 2019
Posts: 120
Location: Here, There And Everywhere

PostPosted: Wed Feb 15, 2023 15:13    Post subject: Reply with quote
Router/Version: Linksys WRT1200AC / v1
File/Kernel: DD-WRT v3.0-r51679 std (02/13/23) / Linux 4.9.337 #3631 SMP Mon Feb 13 03:30:31 +07 2023 armv7l
Previous/Reset: r51530 / No
Mode/Status: WAP, USB / Working OK
Issues/Errors: None so far (2 days uptime)

Web upgrade (get boot_part / set boot_part).
wrtloop
DD-WRT Novice


Joined: 09 Jan 2021
Posts: 13

PostPosted: Wed Feb 15, 2023 16:55    Post subject: Reply with quote
oliver44 wrote:
congratulations to everyone who contributed to the implementation of ipv6 on ddwrt, in the test below ddwrt passes the test with default settings!
https://ipv6.chappell-family.com/ipv6tcptest/


Hmm, I think that with ipv6 there is no NAT so you have tested the firewall on the host, where you run the browser. There is no ipv6 firewall by default running on dd-wrt.
dpp3530
DD-WRT Guru


Joined: 12 Dec 2007
Posts: 780
Location: Pittsburgh, PA USA

PostPosted: Wed Feb 15, 2023 17:13    Post subject: Reply with quote
wrtloop wrote:
Hmm, I think that with ipv6 there is no NAT so you have tested the firewall on the host, where you run the browser. There is no ipv6 firewall by default running on dd-wrt.


Don't confuse NAT and firewall. There most certainly is IPV6 firewalling on DD-WRT, but you're correct, NAT is unnecesary. I turned off the Windows Firewall on my desktop and ran the same port scan. Only difference was that it got a ping reply.

If you want to see the firewall rules, go to the CLI and run the commands:

Code:
ip6tables -vnL INPUT
ip6tables -vnL OUTPUT
ip6tables -vnL FORWARD

_________________
__________________________
Netgear R7800
DD-WRT v3.0 STD
Linksys WRT1900AC
DD-WRT v3.0 STD
wrtloop
DD-WRT Novice


Joined: 09 Jan 2021
Posts: 13

PostPosted: Wed Feb 15, 2023 17:26    Post subject: Reply with quote
dpp3530 wrote:
wrtloop wrote:
Hmm, I think that with ipv6 there is no NAT so you have tested the firewall on the host, where you run the browser. There is no ipv6 firewall by default running on dd-wrt.


Don't confuse NAT and firewall. There most certainly is IPV6 firewalling on DD-WRT, but you're correct, NAT is unnecessary. I turned off the Windows Firewall on my desktop and ran the same port scan. Only difference was that it got a ping reply.

If you want to see the firewall rules, go to the CLI and run the commands:

Code:
ip6tables -vnL INPUT
ip6tables -vnL OUTPUT
ip6tables -vnL FORWARD


Thank you for the clarification. This addition of ip6tables rules must have been a relatively recent event. Since my RPi connected to dd-wrt LAN used to be completely exposed to the internet on ipv6. I tested it now and it is safe behind the dd-wrt now.

Thanks go to the developers.
oliver44
DD-WRT Guru


Joined: 01 Jun 2016
Posts: 504

PostPosted: Wed Feb 15, 2023 18:34    Post subject: Reply with quote
OpenWrt with the default settings does not pass this test on ipv6, ddwrt made a big step in implementation in my opinion.

Congratulations once again and thank you for your work!

_________________
Internet provider https://en.wikipedia.org/wiki/RCS_%26_RDS 1Gbps
WDR3600 rev.1.5 - DD-Wrt
Linksys WRT1900ACS v.2 DD-Wrt/-OpenWrt



https://ipv6.chappell-family.com/ipv6tcptest/
https://en.internet.nl/connection/e91f490fe1c54cb2b78145c0ab0d2b5a/results
http://www.dnssec-or-not.com/
https://dnscheck.tools/#results
Goto page 1, 2  Next Display posts from previous:    Page 1 of 2
Post new topic   Reply to topic    DD-WRT Forum Index -> Marvell MVEBU based Hardware (WRT1900AC etc.) All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum