• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Asus router Open VPN at router level not taking hold

Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
I've been getting great advisement from OneMoar in the past year on various networking queries, however might have hit a wall with this recent issue.

I own an Asus NT56U and I want to use Open VPN on it at the router level (to avoid using client software on each device in the home).

The default /stock style firmware does not support VPN client (only VPN server relay). However Padavan has a custom firmware at https://code.google.com/p/rt-n56u/ which supports VPN client.

I managed to flash and setup the firmware fine(like my previous stock firmware). Everything is running great, however cannot get it to work with the VPN.

For the testing I was using IBPVN, and the attached settings. The picture does not show the content of the Open VPN certificates & keys tab, however it has an entry. I took the ca.crt (Root CA Certificate) data from their support page.

Based on these settings it should be working and this straight forward approach is discussed in a blog here http://www.codyhiar.com/blog/vpn-all-your-traffic-with-asus-rt-n56u-padavan-private-internet-access/

Unfortunately when I save/apply and then check the WAN IP on the router (and or whatsmyip.com) it's not showing the VPN address. I've also tried rebooting the router.

Does any one run similar firmware or have VPN experience that could comment what I am missing? I don't know if this is IBVPN specific, but it should work with any.


Thanks
 

Attachments

  • Capture.jpg
    Capture.jpg
    162.9 KB · Views: 1,632

Aquinus

Resident Wat-man
Joined
Jan 28, 2012
Messages
13,147 (2.94/day)
Location
Concord, NH, USA
System Name Apollo
Processor Intel Core i9 9880H
Motherboard Some proprietary Apple thing.
Memory 64GB DDR4-2667
Video Card(s) AMD Radeon Pro 5600M, 8GB HBM2
Storage 1TB Apple NVMe, 4TB External
Display(s) Laptop @ 3072x1920 + 2x LG 5k Ultrafine TB3 displays
Case MacBook Pro (16", 2019)
Audio Device(s) AirPods Pro, Sennheiser HD 380s w/ FIIO Alpen 2, or Logitech 2.1 Speakers
Power Supply 96w Power Adapter
Mouse Logitech MX Master 3
Keyboard Logitech G915, GL Clicky
Software MacOS 12.1
For the sake of clarification: You're trying to use OpenVPN on your router as a client to connect to another OpenVPN server so all of the devices on your network can gain access to the other network via the VPN tunnel. Did I understand the problem attempting to be tackled, correctly?

With the config in your picture, you're saying that you want all internet traffic to go through the VPN tunnel, as opposed to just gaining access to the other network. A little more information on what you're trying to do (not how you're doing it,) might be helpful.
 
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
Hey,

You are correct. Instead of using the Open VPN software on each device, I'd rather do it on the router, so any device that comes onto my network (or already exists), is going over the VPN and not my regular IP.

I did set for all traffic to go through the VPN, as I want a full tunnel and not a split one.
 

Aquinus

Resident Wat-man
Joined
Jan 28, 2012
Messages
13,147 (2.94/day)
Location
Concord, NH, USA
System Name Apollo
Processor Intel Core i9 9880H
Motherboard Some proprietary Apple thing.
Memory 64GB DDR4-2667
Video Card(s) AMD Radeon Pro 5600M, 8GB HBM2
Storage 1TB Apple NVMe, 4TB External
Display(s) Laptop @ 3072x1920 + 2x LG 5k Ultrafine TB3 displays
Case MacBook Pro (16", 2019)
Audio Device(s) AirPods Pro, Sennheiser HD 380s w/ FIIO Alpen 2, or Logitech 2.1 Speakers
Power Supply 96w Power Adapter
Mouse Logitech MX Master 3
Keyboard Logitech G915, GL Clicky
Software MacOS 12.1
You are correct. Instead of using the Open VPN software on each device, I'd rather do it on the router, so any device that comes onto my network (or already exists), is going over the VPN and not my regular IP.
Is it even connecting with the creds you provided? Are there any logs you could provide? I know people who've done as you suggest with OpenVPN, the issue is that they were using Linux on both ends and had full control of OpenVPN settings. My memory is hazy on the matter but, I recall being told about a flag needing to be set in the OpenVPN server config to allow OpenVPN to act as a network bridge.

I'm not sure how limited the firmware is but, I would direct you to this: https://openvpn.net/index.php/open-source/documentation/miscellaneous/76-ethernet-bridging.html

Side note: Things like this is why my gateway is a tower running Linux.
 
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
The only thing I see in the logs (after I 'apply' the VPN settings) is this :

Jun 27 13:45:46 RT-N56U: starting OpenVPN client...
Jun 27 13:45:46 openvpn-cli[26191]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jun 27 13:46:48 openvpn-cli[26191]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts


The notification about security script repeats itself once every minute.


This is IBVPN's support and settings for DD-WRT, but it should work on this firmware in a similar fashion. http://www.ibvpn.com/billing/knowledgebase/36/DD-WRT-routers-OpenVPN-setup.html
Attached the script file (don't feel this entire thing is necessary - it's where I got the cert from though).

I haven't come across any thing discussing the requirement for bridging.
 

Attachments

  • IBVPN.txt
    3.7 KB · Views: 567
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
As a follow-up : Most of the VPN issues are/were related to cert/credentials authentication issues.
Because VPN providers use different scripts/methods for the same platform (ex: DD-WRT), it creates problems.

I've since ditched consumer routing and built a router /firewall box using pfSense and setup a VPN client properly.

Simple guide from our old friend Logan (not VPN related)
I love it when he walks into the garage with the low ceiling and at about 1:14 his eyes dart left and right. He looks like Bubbles from Trailer Park Boys.

"..very slow..very basic computers.."

 
Last edited:

INSTG8R

Vanguard Beta Tester
Joined
Nov 26, 2004
Messages
7,966 (1.12/day)
Location
Canuck in Norway
System Name Hellbox 5.1(same case new guts)
Processor Ryzen 7 5800X3D
Motherboard MSI X570S MAG Torpedo Max
Cooling TT Kandalf L.C.S.(Water/Air)EK Velocity CPU Block/Noctua EK Quantum DDC Pump/Res
Memory 2x16GB Gskill Trident Neo Z 3600 CL16
Video Card(s) Powercolor Hellhound 7900XTX
Storage 970 Evo Plus 500GB 2xSamsung 850 Evo 500GB RAID 0 1TB WD Blue Corsair MP600 Core 2TB
Display(s) Alienware QD-OLED 34” 3440x1440 144hz 10Bit VESA HDR 400
Case TT Kandalf L.C.S.
Audio Device(s) Soundblaster ZX/Logitech Z906 5.1
Power Supply Seasonic TX~’850 Platinum
Mouse G502 Hero
Keyboard G19s
VR HMD Oculus Quest 2
Software Win 10 Pro x64
I JUST bought an ASUS RT-N66U, It has OpenVPN built in you just need to provide your credentials it seems. The only "VPN" I use or know anything about is I pay $5 a month for a US DNS I put on my PS3 so I can get US netflix.
I can take some screen shots if you'd like to see the setup options?
 
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
Hi.

Different VPN services have different layers of connection and authentication. What may be a basic user/pass entry for your purposes, won't work for others.

Thanks for the offer though.
 

Kursah

Super Moderator
Staff member
Joined
Oct 15, 2006
Messages
14,673 (2.29/day)
Location
Missoula, MT, USA
System Name Kursah's Gaming Rig 2018 (2022 Upgrade) - Ryzen+ Edition | Gaming Laptop (Lenovo Legion 5i Pro 2022)
Processor R7 5800X @ Stock | i7 12700H @ Stock
Motherboard Asus ROG Strix X370-F Gaming BIOS 6203| Legion 5i Pro NM-E231
Cooling Noctua NH-U14S Push-Pull + NT-H1 | Stock Cooling
Memory TEAMGROUP T-Force Vulcan Z 32GB (2x16) DDR4 4000 @ 3600 18-20-20-42 1.35v | 32GB DDR5 4800 (2x16)
Video Card(s) Palit GeForce RTX 4070 JetStream 12GB | CPU-based Intel Iris XE + RTX 3070 8GB 150W
Storage 4TB SP UD90 NVME, 960GB SATA SSD, 2TB HDD | 1TB Samsung OEM NVME SSD + 4TB Crucial P3 Plus NVME SSD
Display(s) Acer 28" 4K VG280K x2 | 16" 2560x1600 built-in
Case Corsair 600C - Stock Fans on Low | Stock Metal/Plastic
Audio Device(s) Aune T1 mk1 > AKG K553 Pro + JVC HA-RX 700 (Equalizer APO + PeaceUI) | Bluetooth Earbuds (BX29)
Power Supply EVGA 750G2 Modular + APC Back-UPS Pro 1500 | 300W OEM (heavy use) or Lenovo Legion C135W GAN (light)
Mouse Logitech G502 | Logitech M330
Keyboard HyperX Alloy Core RGB | Built in Keyboard (Lenovo laptop KB FTW)
Software Windows 11 Pro x64 | Windows 11 Home x64
Do you have a static WAN IP or are you utilizing a DDNS service? I ended up having to utilize a DDNS service (I went with Afraid.org) and some scripting to update it my WAN IP using WGET.

I am using the OpenVPN server on my Asus AC66R, which has been solid, but it is somewhat limited...though there is enough to adjust in the advanced settings. I am using Merlin's modified AsusWRT firmware.

Right now I am working on setting up an old laptop that I slapped Xubuntu 14.04 on as a buddies' OpenVPN server and DDNS updater. I wish he had a budget so I could do a PFSense box for them, but I'm passing traffic through a router and to the laptop as a stop-gap until funds are there for something better. I will say that an OpenVPN server on Xubuntu is pretty good, a lot of terminal work, but so far it has been solid!

:toast:
 

INSTG8R

Vanguard Beta Tester
Joined
Nov 26, 2004
Messages
7,966 (1.12/day)
Location
Canuck in Norway
System Name Hellbox 5.1(same case new guts)
Processor Ryzen 7 5800X3D
Motherboard MSI X570S MAG Torpedo Max
Cooling TT Kandalf L.C.S.(Water/Air)EK Velocity CPU Block/Noctua EK Quantum DDC Pump/Res
Memory 2x16GB Gskill Trident Neo Z 3600 CL16
Video Card(s) Powercolor Hellhound 7900XTX
Storage 970 Evo Plus 500GB 2xSamsung 850 Evo 500GB RAID 0 1TB WD Blue Corsair MP600 Core 2TB
Display(s) Alienware QD-OLED 34” 3440x1440 144hz 10Bit VESA HDR 400
Case TT Kandalf L.C.S.
Audio Device(s) Soundblaster ZX/Logitech Z906 5.1
Power Supply Seasonic TX~’850 Platinum
Mouse G502 Hero
Keyboard G19s
VR HMD Oculus Quest 2
Software Win 10 Pro x64
Well I will show you anyway just so you can see it.

Edit: Looking at the pictures myself I didn't even notice it has config for both client and server.
 

Attachments

  • WRT.jpg
    WRT.jpg
    223.8 KB · Views: 898
  • WRT2.jpg
    WRT2.jpg
    230 KB · Views: 948
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
Do you have a static WAN IP or are you utilizing a DDNS service? I ended up having to utilize a DDNS service (I went with Afraid.org) and some scripting to update it my WAN IP using WGET.

I am using the OpenVPN server on my Asus AC66R, which has been solid, but it is somewhat limited...though there is enough to adjust in the advanced settings. I am using Merlin's modified AsusWRT firmware.

Right now I am working on setting up an old laptop that I slapped Xubuntu 14.04 on as a buddies' OpenVPN server and DDNS updater. I wish he had a budget so I could do a PFSense box for them, but I'm passing traffic through a router and to the laptop as a stop-gap until funds are there for something better. I will say that an OpenVPN server on Xubuntu is pretty good, a lot of terminal work, but so far it has been solid!

:toast:

It's PPPOE WAN.

Merlin's is good as far as alternatives to DD-WRT/Tomato go. OneMoar put me onto that (and some others), however whatever hardware/software you go with consumer wise, it just cannot handle the BDS cryptodev. Especially if using ciphers of AES 256 CBC or greater.
And for a good read on ciphers - http://crypto.stackexchange.com/questions/1098/is-blowfish-strong-enough-for-vpn-encryption

Too many VPN are still using Blowfish, which might be why some consumer routers get 'acceptable' speeds over a VPN. To me, anything less than 90-95% of your clearnet speed is not acceptable, unless you're connection is over 100mbps. Then I would say the acceptable range is 85-95% of clearnet speeds.


pfSense is cheap enough to do. I have it running on :

Setup:

pfSense 2.1.5 on :
Core 2 Duo E6600 at 3.0ghz
Gigabyte GA-EP43-DS3
4GB Gskill TT 800 DDR2
Silverstone Strider 650
Some old 40gb ATA hard disk running in UDMA 2
 
Joined
Jul 3, 2008
Messages
174 (0.03/day)
Processor Intel Core i7 5820k
Motherboard MSI X99S-GAMING7
Cooling Corsair H105
Memory 16GB G.SKILL DDR4
Video Card(s) Gigabyte GTX1070 Gaming G1
Storage Samsung 840 Evo 256GB
Display(s) Acer Predator XB271HU
Case Corsair 800D
Audio Device(s) ASUS XONAR
Power Supply Corsair HX850i
Mouse Logitech G502
Keyboard Filco Majestouch
Software Windows 10
To me, anything less than 90-95% of your clearnet speed is not acceptable, unless you're connection is over 100mbps. Then I would say the acceptable range is 85-95% of clearnet speeds.

Most VPN's will reduce wire performance by ~8% to 15% regardless how well the device can decrypt the data. The 15% end of the spectrum normally comes down to MTU sizes and other transmission/session protocol's overheads that may be in play.
 
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
Most VPN's will reduce wire performance by ~8% to 15% regardless how well the device can decrypt the data. The 15% end of the spectrum normally comes down to MTU sizes and other transmission/session protocol's overheads that may be in play.

What do you base the reduction in performance on?
 
Joined
Jul 3, 2008
Messages
174 (0.03/day)
Processor Intel Core i7 5820k
Motherboard MSI X99S-GAMING7
Cooling Corsair H105
Memory 16GB G.SKILL DDR4
Video Card(s) Gigabyte GTX1070 Gaming G1
Storage Samsung 840 Evo 256GB
Display(s) Acer Predator XB271HU
Case Corsair 800D
Audio Device(s) ASUS XONAR
Power Supply Corsair HX850i
Mouse Logitech G502
Keyboard Filco Majestouch
Software Windows 10
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
My understanding with Open VPN is that 128 Blowfish encryption is quite common - at least for all these popular provider/services.
But even then, you lose way more than 10% on a commercial router.

Meanwhile, moving up to pfSense, half decent hardware makes a huge difference -even with 256 encryption.

Maybe I don't fully understand the numbers and the science, however am a firm believer in building your own firewall/router box now - especially out of old computer parts.
 
Joined
Jun 20, 2007
Messages
3,942 (0.64/day)
System Name Widow
Processor Ryzen 7600x
Motherboard AsRock B650 HDVM.2
Cooling CPU : Corsair Hydro XC7 }{ GPU: EK FC 1080 via Magicool 360 III PRO > Photon 170 (D5)
Memory 32GB Gskill Flare X5
Video Card(s) GTX 1080 TI
Storage Samsung 9series NVM 2TB and Rust
Display(s) Predator X34P/Tempest X270OC @ 120hz / LG W3000h
Case Fractal Define S [Antec Skeleton hanging in hall of fame]
Audio Device(s) Asus Xonar Xense with AKG K612 cans on Monacor SA-100
Power Supply Seasonic X-850
Mouse Razer Naga 2014
Software Windows 11 Pro
Benchmark Scores FFXIV ARR Benchmark 12,883 on i7 2600k 15,098 on AM5 7600x
I thought about untangle, but between having VPN setup knowledge for pfSense and using it at work, it was the better option for me.

Either way, they're both great.
 

Solaris17

Super Dainty Moderator
Staff member
Joined
Aug 16, 2005
Messages
25,864 (3.79/day)
Location
Alabama
System Name Rocinante
Processor I9 14900KS
Motherboard EVGA z690 Dark KINGPIN (modded BIOS)
Cooling EK-AIO Elite 360 D-RGB
Memory 64GB Gskill Trident Z5 DDR5 6000 @6400
Video Card(s) MSI SUPRIM Liquid X 4090
Storage 1x 500GB 980 Pro | 1x 1TB 980 Pro | 1x 8TB Corsair MP400
Display(s) Odyssey OLED G9 G95SC
Case Lian Li o11 Evo Dynamic White
Audio Device(s) Moondrop S8's on Schiit Hel 2e
Power Supply Bequiet! Power Pro 12 1500w
Mouse Lamzu Atlantis mini (White)
Keyboard Monsgeek M3 Lavender, Akko Crystal Blues
VR HMD Quest 3
Software Windows 11
Benchmark Scores I dont have time for that.
I thought about untangle, but between having VPN setup knowledge for pfSense and using it at work, it was the better option for me.

Either way, they're both great.

Agreed I personally use OPNsense and I love it. building a custom box is probably the best decision iv ever made.
 
Top