What's new

Asus RT-AX86U with Wireguard VPN.

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

This seems to have been fixed in 388.2. See:
Well, I have read this post you posted and, consequently, enabled Flow Caché on my AX86U, but it throws a lot of kernel error messages in system log.

Are there more things I need to do?
Regards.
 
You seem to have a solution already ;)
 
You seem to have a solution already ;)
A temporary solution. I asked in the thread you kindly sent me (https://www.snbforums.com/threads/wg-server-test-with-flowcache-bypass.82746/page-5#post-842312), but it has worked only until this evening. I am using Wireguard Session Manager through entware and they told me to update it to last development version.

Now, my system log is flooded again with kernel error messages and I don't know what else I can do. I have already reported that on the other thread.
Regards.
 
Why are you routing all your traffic through a VPN?
If you live in a free, democratic country services like NordVPN don't really provide any additional security in a home environment.
Who said we live in a free world? The politicians? The big tech companies? The naive idiots who believe anything?

We are trapped and the snare gets pulled a little bit at a time.

You need to get one of these.
Hat

Get one for the cat too!
Cat hat
 
Was looking at SUrfshark

Now included in stock Asuswrt firmware:

 
I am using Wireguard Session Manager through entware and they told me to update it to last development version.

Now, my system log is flooded again with kernel error messages and I don't know what else I can do. I have already reported that on the other thread.
Regards.

I could be mistaken but I think you might need to switch from the Entware WireGuard Session Manager to the WireGuard that is now part of the firmware to properly utilize NAT acceleration (flow cache). Obviously get confirmation on this before making any changes though.
 
I could be mistaken but I think you might need to switch from the Entware WireGuard Session Manager to the WireGuard that is now part of the firmware to properly utilize NAT acceleration (flow cache). Obviously get confirmation on this before making any changes though.
Maybe you're right, but I was told by @ZebMcKayhan , one of the most great contributors of Session Manager, to update Session Manager to the last version.
However, Session Manager works in this way only for a few hours, then my AX-86U starts giving kernel error messages again.
The thing is that I want IPv6 connectivyty throug Wireguard and now I have it with Session Manager. I don't know if it is possible to redirect my LAN devices through firmware Wireguard, getting also IPv6 addresses to these devices.
Thank you, anyway.
 
Maybe you're right, but I was told by @ZebMcKayhan , one of the most great contributors of Session Manager, to update Session Manager to the last version.
However, Session Manager works in this way only for a few hours, then my AX-86U starts giving kernel error messages again.
The thing is that I want IPv6 connectivyty throug Wireguard and now I have it with Session Manager. I don't know if it is possible to redirect my LAN devices through firmware Wireguard, getting also IPv6 addresses to these devices.
Thank you, anyway.
Wgm includes the same bypass as the firmware in the latest dev release:
https://www.snbforums.com/threads/session-manager-4th-thread.81187/post-830683

However, this ASUS/Broadcom fix is for local/source/lan addresses only, so if you have rules with remoteIP your entire lan will be bypassed, just as with flowcache off.

In wgm its currently not for ipv6 which, if my memory serves, you were using so Im not sure how effective it will be for you.

You could always try to add the entry for ipv6 yourself, I could help with this, but I don't know if Asus included it.
 
However, this ASUS/Broadcom fix is for local/source/lan addresses only, so if you have rules with remoteIP your entire lan will be bypassed, just as with flowcache off.
What are you meaning with 'rules with remote IP'? I only have a Wireguard client on Session Manager with one IPSET rule to route my LAN clients to the Internet through that client.
 
What are you meaning with 'rules with remote IP'? I only have a Wireguard client on Session Manager with one IPSET rule to route my LAN clients to the Internet through that client.
Wireguard does not work with Broadcom hw accelleration, period. Not on merlin fw, not on asus fw. The only reason Asus could have fc turned on is that they implemented a fc bypass based on lan addresses in a file. Wireguard will not use hw accelleration but clients set to use wan can.

So, the only benefit would be if you using vpn fusion, vpn director or wgm rules for specific ipv4 lan addresses to vpn then other lan ips could benefit. Wireguard will never benefit.

Edit: if you only have acouple of devices enabled to use Wireguard I could help you figure out if ipv6 is possible to bypass fc which may help you to enable fc. But ipv6 is tricky, some scripting would be needed to figure out which ipv6 your particular device have and track changes and I stink at scripting.
 
Last edited:
Wireguard does not work with Broadcom hw accelleration, period. Not on merlin fw, not on asus fw. The only reason Asus could have fc turned on is that they implemented a fc bypass based on lan addresses in a file. Wireguard will not use hw accelleration but clients set to use wan can.

So, the only benefit would be if you using vpn fusion, vpn director or wgm rules for specific ipv4 lan addresses to vpn then other lan ips could benefit. Wireguard will never benefit.

Edit: if you only have acouple of devices enabled to use Wireguard I could help you figure out if ipv6 is possible to bypass fc which may help you to enable fc. But ipv6 is tricky, some scripting would be needed to figure out which ipv6 your particular device have and track changes and I stink at scripting.
I don't think I need bypass for none of my LAN devices.
Thank you, anyway.
 
Hi, now that my Asus RT-AX86U supports Wireguard VPN I am looking to try it out. From looking around Nord VPN seems a good choice as they support wireguard and they 'say' they have the fastest speeds and the most worldwide servers. I am on a 1gbps download fibre line and am wondering what kind of speeds I would get? And does ther geo location really work, like watching Netflix/ Prime Video in the USA and other countries? Thanks for any feedback!
I contacted Nord just last week. They say Wireguard is NOT supported on routers.
A shame they don't advertise that way.
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top