@thelonelycoder ... would it be trivial to add a breakdown of stats by client? (Mainly to figure out TLS errors) Or is that more challenging to log than it seems on the surface?
Yes, I did all that. Should I re-create the CA cert?
That's not required. You state that you imported the certificate into the Firefox certificate store, but did you also import the certificate into the Windows certificate store (I assume you're using Windows)?
Did dnsmasq restart successfully?i just buy RT-AC68U and install asus merlin ng, amtm, skynet and diversion
i enable diversion, use pixelserv-tls and standard+ blocking
then once i turn on ad-blocking, my internet is gone
am i missing something here?
tail /opt/var/log/dnsmasq.log
I just did an M&M reset on RMerlin's 384.13 firmware and added Jack Yaz's uiDivStats so I can see blocked domains in the routers GUI.
I've been using Diversion and uiDivStats for a long time and never seen the entry that keeps popping up and growing. It's DHCPREQUEST(br0).
I don't believe it's supposed to be there as I have never seen it before. Anyone have any ideas what it is and how to stop it from being in my top 10 requested domains list?
attached a photo:
I just did an M&M reset on RMerlin's 384.13 firmware and added Jack Yaz's uiDivStats so I can see blocked domains in the routers GUI.
I've been using Diversion and uiDivStats for a long time and never seen the entry that keeps popping up and growing. It's DHCPREQUEST(br0).
I don't believe it's supposed to be there as I have never seen it before. Anyone have any ideas what it is and how to stop it from being in my top 10 requested domains list?
That's the reason, set Hide DHCP/RA queries to Yes.Test with changing (a guess)LAN/DHCP-Server/Hide DHCP/RA queries=yes
It would complicate the stats function considerably if it would need to gather these additional data points.@thelonelycoder ... would it be trivial to add a breakdown of stats by client? (Mainly to figure out TLS errors) Or is that more challenging to log than it seems on the surface?
I see someone else found away to make dnsmasq logs to grow infinitely large in a short period of time.That's the reason, set Hide DHCP/RA queries to Yes.
This struck me as odd, since I log my DHCP queries and haven't seen this problem in regular Diversion stats reports. So I went poking and it seems this particular stats compilation can be broken by DHCP requests in the log as well as dnsmasq log-extra being enabled since the client LAN IP appears in every line. Would it work for @thelonelycoder and @Jack Yaz to grep for only query lines?That's the reason, set Hide DHCP/RA queries to Yes.
/opt/bin/grep -a " query.* from $i$" $dnsmasqLog | awk '{print $(NF-2)}' |
I don't think this is anything to do with Diversion.Hmmm, it doesn't happen when I do a power off/on cycle. I only have three things plugged into the router: a switch (with loop back protection), my desk-top computer, and a hardlink to an AImesh unit. Could the AImesh be causing this?
Probably best to open a separate thread about this as there's no particular reason to think it's related to Diversion."Are you saying that after power cycling the router you no longer have the problem?"
That is correct. If I do a power off/on cycle it boots up beautifully. I even see the lines that sets pixel server. On the other hand, reboot is a nightmare.
Hmm. It doesn't appear so based on my certificates. I also did a search from the top level for anything that contains "pixel" and it returned nothing.
I followed the steps as outlined below:
Windows: Chrome/Edge/IE
The follow procedure will import your CA cert and trust it system wide.
Restart browser to take effect.
- Open your browser. Visit http://pixelserv ip/ca.crt. Make sure you replace pixelserv ip with the actual IP address of pixelserv.
- Find the downloaded file, ca.crt.
- Double click on `ca.crt' to view the certificate.
- Click "Install Certificate.." and select "Local Machine".
- Click "Place all certificate in the following store" on next screen.
- Click "Browse..." and select "Trusted Root Certification Authorities".
- Click "Next" and then "Finish" on next screen.
-------------------------------------------
I also just tried to manually import using MMC using this Windows guide. I must have taken a wrong step somewhere.
When I imported the Pixelserv CA into Windows, I chose Current User (since it was on a work computer I didn't want to mess with the Local Machine). It shows up in Control Panel / Internet Options / Content / Certificates / Trusted Root Certificates.I'm still struggling with this. I re-created the cert and re-imported. Yet it still doesn't appear on any of my computers within the Certificate Manager. I'm about to reset my router and wipe my JFFS so I can start fresh. Before I do though, I'd love to know if there might be something else less nuclear.
When I imported the Pixelserv CA into Windows, I chose Current User (since it was on a work computer I didn't want to mess with the Local Machine). It shows up in Control Panel / Internet Options / Content / Certificates / Trusted Root Certificates.
Welcome To SNBForums
SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.
If you'd like to post a question, simply register and have at it!
While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!