bradbort
Senior Member
Having issues accessing cameras via OPENVPN Server on AX-86U on both Beta 2 and Beta 3. This is from OVPN client on Iphone. The logs from OPENVPN and SYSLOG follow. Anyone else having issues with OPENVPN Server on AX-86U?
Code:Dec 29 14:08:25 RT-AX86U-AC30 ovpn-server2[3021]: client/1.129.110.41:19678 SIGTERM[soft,remote-exit] received, client-instance exiting Dec 29 14:08:39 RT-AX86U-AC30 ovpn-server1[2734]: Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Dec 29 14:08:39 RT-AX86U-AC30 ovpn-server1[2734]: Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Dec 29 14:08:39 RT-AX86U-AC30 ovpn-server1[2734]: TCP connection established with [AF_INET]1.129.110.41:1714 Dec 29 14:08:39 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 TLS: Initial packet from [AF_INET]1.129.110.41:1714, sid=b24fb0c1 bef02c69 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=ASUS, OU=Home/Office, CN=RT-AX86U, emailAddress=me@asusrouter.lan Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 VERIFY OK: depth=0, C=TW, ST=TW, L=Taipei, O=ASUS, OU=Home/Office, CN=client, emailAddress=me@asusrouter.lan Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_VER=3.git::2952f561 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_PLAT=ios Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_NCP=2 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_TCPNL=1 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_PROTO=2 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_IPv6=0 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_GUI_VER=net.openvpn.connect.ios_3.2.2-3507 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_SSO=openurl Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 peer info: IV_BS64DL=1 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 PLUGIN_CALL: POST /usr/lib/openvpn-plugin-auth-pam.so/PLUGIN_AUTH_USER_PASS_VERIFY status=0 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 TLS: Username/Password authentication succeeded for username 'joescian' Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 Control Channel: TLSv1.3, cipher TLSv1.3 TLS_AES_256_GCM_SHA384, 2048 bit RSA Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: 1.129.110.41:1714 [client] Peer Connection Initiated with [AF_INET]1.129.110.41:1714 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 MULTI_sva: pool returned IPv4=10.8.0.2, IPv6=(Not enabled) Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 MULTI: Learn: 10.8.0.2 -> client/1.129.110.41:1714 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 MULTI: primary virtual IP for client/1.129.110.41:1714: 10.8.0.2 Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 Data Channel: using negotiated cipher 'AES-256-GCM' Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 PUSH: Received control message: 'PUSH_REQUEST' Dec 29 14:08:40 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 SENT CONTROL [client]: 'PUSH_REPLY,route 192.168.2.0 255.255.255.0 vpn_gateway 500,dhcp-option DOMAIN RT-AX86U-DOMAIN,dhcp-option DNS 192.168.2.242,redirect-gateway def1,route-gateway 10.8.0.1,topology subnet,ping 15,ping-restart 60,ifconfig 10.8.0.2 255.255.255.0,peer-id 0,cipher AES-256-GCM' (status=1) Dec 29 14:10:31 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 Connection reset, restarting [0] Dec 29 14:10:31 RT-AX86U-AC30 ovpn-server1[2734]: client/1.129.110.41:1714 SIGUSR1[soft,connection-reset] received, client-instance restarting Dec 29 14:10:33 RT-AX86U-AC30 ovpn-server2[3021]: 1.129.110.41:14158 Outgoing Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Dec 29 14:10:33 RT-AX86U-AC30 ovpn-server2[3021]: 1.129.110.41:14158 Incoming Control Channel Authentication: Using 160 bit message hash 'SHA1' for HMAC authentication Dec 29 14:10:33 RT-AX86U-AC30 ovpn-server2[3021]: 1.129.110.41:14158 TLS: Initial packet from [AF_INET]1.129.110.41:14158, sid=06b57b9f dd8734ca Dec 29 14:10:34 RT-AX86U-AC30 ovpn-server2[3021]: 1.129.110.41:14158 VERIFY OK: depth=1, C=TW, ST=TW, L=Taipei, O=ASUS, OU=Home/Office, CN=RT-AX86U, emailAddress=me@asusrouter.lan Dec 29 14:10:34 RT-AX86U-AC30 ovpn-server2[3021]: 1.129.110.41:14158 VERIFY OK: depth=0, C=TW, ST=TW, L=Taipei, O=ASUS, OU=Home/Office, CN=client, emailAddress=me@asusrouter.lan D
Code:Dec 29 14:07:51 RT-AX86U-AC30 kernel: CONSOLE: 077364.104 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:08:51 RT-AX86U-AC30 kernel: CONSOLE: 077423.796 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:09:51 RT-AX86U-AC30 kernel: CONSOLE: 077483.489 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:10:51 RT-AX86U-AC30 kernel: CONSOLE: 077543.182 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:11:51 RT-AX86U-AC30 kernel: CONSOLE: 077602.874 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:12:51 RT-AX86U-AC30 kernel: CONSOLE: 077662.568 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:13:51 RT-AX86U-AC30 kernel: CONSOLE: 077722.262 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy 1 Dec 29 14:14:42 RT-AX86U-AC30 kernel: wl0: random key value: FF71090D3A1EEA3215BE004E8EA680869EEBAF29E5FB0C3BA5C3CDB7FF6A67CB Dec 29 14:14:42 RT-AX86U-AC30 hostapd: eth6: STA 04:d4:c4:45:f4:41 IEEE 802.11: disassociated Dec 29 14:14:42 RT-AX86U-AC30 kernel: wl0: set timeout 5 secs to wait dev reg finish Dec 29 14:14:42 RT-AX86U-AC30 kernel: wfd_unregisterdevice Successfully unregistered ifidx 2 wfd_idx 0 Dec 29 14:14:42 RT-AX86U-AC30 kernel: br0: port 11(wds0.0.1) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: br0: port 10(wds0.0.1.0) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: br1: port 9(wds0.0.1.501) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: device wds0.0.1 left promiscuous mode Dec 29 14:14:42 RT-AX86U-AC30 kernel: br0: port 11(wds0.0.1) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: br0: port 10(wds0.0.1.0) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: br1: port 9(wds0.0.1.501) entered disabled state Dec 29 14:14:42 RT-AX86U-AC30 kernel: [0;33;41m[ERROR vlan] vlanIoctl ,657: Failed to delete VLAN device wds0.0.1.501[0m Dec 29 14:14:42 RT-AX86U-AC30 kernel: [0;33;41m[ERROR vlan] vlanIoctl ,657: Failed to delete VLAN device wds0.0.1.0[0m Dec 29 14:14:51 RT-AX86U-AC30 kernel: CONSOLE: 077781.957 wl1: wlc_ampdu_recv_addba_resp: 54:60:09:7c:93:9e: Failed. status 37 wsize 16 policy
It's out of necessity, not by choice. Asus has been working on that model's GPL for almost two weeks now, and I didn't want to delay any longer just for that model. Beside, those components are still compatible with the newer GPL code in use, and didn't require any special kludge or separate code branching.
I just updated to beta 3 after having run on the latest 386 stock firmware on the AX88U. I had run beta 2 in the past with no issues. Unfortunately, this time, I lost all access to the internet. I rebooted the router, but no joy. Then I rolled back to stock and was ok with internet access again.
Any ideas what could have happened? The router showed internet access was good. All devices, however were blocked. It's possible it was a 5 band issue, since all clients were on that band at the time.
I can try again in the AM, but if anyone has any ideas, that would be great.