I’m also having problems with the VPN Server on 382.2 beta on the 86u. I manually re-entered my VPN Server settings exactly from 380.69 on the 68u. Clients can connect to the VPN and have LAN access but no WAN access. In the router log I see the firewall is dropping all traffic coming from VPN clients to the WAN.
I thought this may have been some configuration issue on my end since I’m both changing routers (68u to 86u) and going from 380.69 to 382.2, but it looks like others are having the same issue.
Thanks for testing! My log:
Dec 31 16:59:40 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.211 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53840 DPT=443 SEQ=27694878 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514E530000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.81 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53852 DPT=443 SEQ=641561706 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514EE40000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.178 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53856 DPT=443 SEQ=2729921404 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514EF60000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=46.17.8.50 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53842 DPT=4444 SEQ=2946384967 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514F900000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.148 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53843 DPT=443 SEQ=1333241793 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514FA70000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.204 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53853 DPT=443 SEQ=2869663356 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514FE20000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.105 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53857 DPT=443 SEQ=579857362 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F514FF60000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.149 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53854 DPT=443 SEQ=1608778742 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F5150E10000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.111 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53858 DPT=443 SEQ=2296653628 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F5150F30000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.106 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53844 DPT=443 SEQ=3771742616 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F5151040000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.252.43.246 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53850 DPT=443 SEQ=919218667 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F5151880000000004020000) MARK=0x1
Dec 31 16:59:41 kernel: DROP IN=tun21 OUT=eth0 SRC=10.8.0.2 DST=17.248.145.145 LEN=64 TOS=0x00 PREC=0x00 TTL=63 ID=0 DF PROTO=TCP SPT=53851 DPT=443 SEQ=1139133888 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (02040550010303060101080A2F5151CC0000000004020000) MARK=0x1
OVPN Works here as well even with Redirect Internet Traffic = ALL (RT88U). Here is the config file automatically generated by Torguard's ovpn config file tool choosing ASUS firmware:
Code:
client
dev tun
proto udp
remote frank.gr.torguardvpnaccess.com 1215
remote-cert-tls server
auth SHA512
key-direction 1
setenv CLIENT_CERT 0
<tls-auth>
-----BEGIN OpenVPN Static key V1-----
770e8de5fc56e0248cc7b5aab56be80d
0e19cbf003c1b3ed68efbaf08613c3a1
a019dac6a4b84f13a6198f73229ffc21
fa512394e288f82aa2cf0180f01fb3eb
1a71e00a077a20f6d7a83633f5b4f47f
27e30617eaf8485dd8c722a8606d56b3
c183f65da5d3c9001a8cbdb96c793d93
6251098b24fe52a6dd2472e98cfccbc4
66e63520d63ade7a0eacc36208c3142a
1068236a52142fbb7b3ed83d785e12a2
8261bccfb3bcb62a8d2f6d18f5df5f36
52e59c5627d8d9c8f7877c4d7b08e19a
5c363556ba68d392be78b75152dd55ba
0f74d45089e84f77f4492d886524ea6c
82b9f4dd83d46528d4f5c3b51cfeaf28
38d938bd0597c426b0e440434f2c451f
-----END OpenVPN Static key V1-----
</tls-auth>
resolv-retry infinite
nobind
tls-version-min 1.2
cipher AES-256-GCM
auth-user-pass
comp-lzo adaptive
tun-mtu-extra 32
<ca>
-----BEGIN CERTIFICATE-----
MIIEwTCCA6mgAwIBAgIJAKROjebUHo0gMA0GCSqGSIb3DQEBBQUAMIGbMQswCQYD
VQQGEwJVUzELMAkGA1UECBMCRkwxEDAOBgNVBAcTB09ybGFuZG8xETAPBgNVBAoT
CFRvckd1YXJkMQwwCgYDVQQLEwNWUE4xEzARBgNVBAMTClRHLU9WUE4tQ0ExETAP
BgNVBCkTCFRvckd1YXJkMSQwIgYJKoZIhvcNAQkBFhVzeXNhZG1pbkB0b3JndWFy
ZC5uZXQwHhcNMTQwNDE3MTAwOTIzWhcNMjQwNDE0MTAwOTIzWjCBmzELMAkGA1UE
BhMCVVMxCzAJBgNVBAgTAkZMMRAwDgYDVQQHEwdPcmxhbmRvMREwDwYDVQQKEwhU
b3JHdWFyZDEMMAoGA1UECxMDVlBOMRMwEQYDVQQDEwpURy1PVlBOLUNBMREwDwYD
VQQpEwhUb3JHdWFyZDEkMCIGCSqGSIb3DQEJARYVc3lzYWRtaW5AdG9yZ3VhcmQu
bmV0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAws1hJzlbWKlm3DEO
XyQpmvtxwrsR4CIYMi8C6np5w74lTRYmGBcuuPqAT3ig2DnH9HNNFx1WWZbYO8pU
a1tdn7uYErJi4EP9/t2l3uXCNgoWYVdVP1j5EXIY1oacOv9srbNZHeWpxHIb1wZr
1i4sLsdaifOibgVZI91FATXGrVdFDaQb2OjyJrFW8b4xbC8pBJxQDzqPeu9mkVpu
OhBuU+dM+9h+8Bj0tpdAernEAt8CbHIywe9Rjm0JLrYmCPKuB5ldVgG3rYQWFa3X
YWjrWtr//nGM4f4WKOFc2PHWA2gI3JwdynTNLsB9NQi0N7hhR6lmtCMeqHlm0oAz
4Ad4gQIDAQABo4IBBDCCAQAwHQYDVR0OBBYEFJvAPA1gnlD/majxi+43jL0XDfqQ
MIHQBgNVHSMEgcgwgcWAFJvAPA1gnlD/majxi+43jL0XDfqQoYGhpIGeMIGbMQsw
CQYDVQQGEwJVUzELMAkGA1UECBMCRkwxEDAOBgNVBAcTB09ybGFuZG8xETAPBgNV
BAoTCFRvckd1YXJkMQwwCgYDVQQLEwNWUE4xEzARBgNVBAMTClRHLU9WUE4tQ0Ex
ETAPBgNVBCkTCFRvckd1YXJkMSQwIgYJKoZIhvcNAQkBFhVzeXNhZG1pbkB0b3Jn
dWFyZC5uZXSCCQCkTo3m1B6NIDAMBgNVHRMEBTADAQH/MA0GCSqGSIb3DQEBBQUA
A4IBAQBRG46DnL/8EAPbi/eOQli5WO7lRHYyZJdlLUMlsnwkp6Ul6BMJq8q3UX3z
+pqDf3wzj94y/IpGQgE4l0fgAdwf/C7F533TSwU/vi+5PDWfwD2WmGqVmcmXn6Rp
9Fwr+oryRw8GfsVBLZHTkWF1RZrRAr8hWZhNySGFwSXlEIicvNy+9mlFhk2Nb46w
ioZKc1Lc7/okeXNWHPv6Dlm39TcNBpGX/xNoWBzqs1EtA1ZGvMcQHsKLfi3Nbaab
BYe08KWsfeZA+ih4BZ6y2E+x84NYHRebqijXTtHp35coyXllBL/+LBoZ86hKszEx
F3pjGU0+8NzvdPUbKndhzyPPnHF1
-----END CERTIFICATE-----
</ca>
And your VPN settings inside the ASUS router/VPN server?