What's new

[Fork] Asuswrt-Merlin 374.43 LTS releases (Archive)

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Next release is out!

LATEST RELEASE: Update-26E3
20-July-2017
Merlin fork 374.43_2-26E3j9527
Download http://bit.ly/1YdgUcP
============================
Following are the major changes (full changelog is in the zip files)

Update-26E3 Highlights

  • Updated versions of nano, dropbear, ipset for arm, dnscrypt and others
  • NEW: Samba - update to 3.6.25 which includes SMB2 support (enable on the USB servers page)
  • NEW: Support for IPSET 6 extended set types and options on the AC56/AC68. All set types/options listed in the IPSET 6 help page should now be supported. Thanks to @Adamm for his help in testing this set of changes and making sure I got it right :).
  • NEW: Miniupnp update to 2.0 with a new Port Forwarding syslog page which can track UPNP lease times.
  • NEW: Added inactivity timeout for SSH sessions, default set to 20min. This can be changed or disabled via a new option on the Administration>System page. (This has worked correctly in my fork testing as opposed to some problems seen on the latest Merlin builds).
  • NEW: An enhancement to force a revalidation of http credentials after an auto logoff or disconnect Note: When first loading V26 you will receive an http authentication challenge at the end of the firmware update. Future updates after V26 will not receive this challenge following the firmware update.
  • NEW: New OpenVPN client options for the way the 'VPN block routed clients if tunnel goes down' is handled, and an indicator on the VPN status page if the clients are being blocked. There are now three options
    • Always - the previous 'Yes' behavior, clients will be blocked even if the client is manually disabled
    • Only when client is enabled - clients will not be blocked if you manually disable the client
    • Never - never block clients if the tunnel is down
    If the clients are being blocked, it will now show on the VPN Status page.
  • Fixes for incorrect trigger rules generation with port ranges and iptables-save of trigger rules - @ColinTaylor
  • Fix formatting problem in Wireless Log when connect time reaches 100 hours - @ColinTaylor
  • Several backports from the latest Merlin builds in OpenVPN and Firewall support
As always, a reminder to have a backup of /jffs in case the jffs space needs to be reformatted due to increases in firmware size. SHA256
Code:
 615ae209746f326be046d0053753760d2a98887165ca8eccbbd35d3a72c84cbe RT-AC68U_3.0.0.4_374.43_2-26E3j9527.trx 2bbc867d261534393e60bf31d5986fbdf6a660617b6f1dfacf6b52b95baedf92 RT-AC56U_3.0.0.4_374.43_2-26E3j9527.trx ce422c1956a877418af639912c047f47ee3bd9bcba4caa96a513fd8cb59cf4ac RT-N16_3.0.0.4_374.43_2-26E3j9527.trx 259d56e03e487de2a26a09636edcc1c41a017fc3a56b3fc4de4137bda46c7949 RT-AC66U_3.0.0.4_374.43_2-26E3j9527.trx 85de01d9357187437537d70269e57b49fc00f1cf87cdcf3f0987920bb83a9489 RT-N66U_3.0.0.4_374.43_2-26E3j9527.trx
 
Last edited:
@john9527 do you know how this version would treat my case when I find the openvpn client disabled (not manually)?

Next release is out!

LATEST RELEASE: Update-26E3
20-July-2017
Merlin fork 374.43_2-26E3j9527
Download http://bit.ly/1UGjcOX
============================

Following are the major changes (full changelog is in the zip files)

Update-26E3 Highlights
  • Updated versions of nano, dropbear, ipset for arm, dnscrypt and others
  • NEW: Samba - update to 3.6.25 which includes SMB2 support (enable on the USB servers page)
  • NEW: Support for IPSET 6 extended set types and options on the AC56/AC68. All set types/options listed in the IPSET 6 help page should now be supported. Thanks to @Adamm for his help in testing this set of changes and making sure I got it right :).
  • NEW: Miniupnp update to 2.0 with a new Port Forwarding syslog page which can track UPNP lease times.
  • NEW: Added inactivity timeout for SSH sessions, default set to 20min. This can be changed or disabled via a new option on the Administration>System page. (This has worked correctly in my fork testing as opposed to some problems seen on the latest Merlin builds).
  • NEW: An enhancement to force a revalidation of http credentials after an auto logoff or disconnect
    Note: When first loading 26BA you will receive an http authentication challenge at the end of the firmware update. Future updates after 26BA will not receive this challenge following the firmware update.
  • NEW: New OpenVPN client options for the way the 'VPN block routed clients if tunnel goes down' is handled, and an indicator on the VPN status page if the clients are being blocked.
    There are now three options
    • Always - the previous 'Yes' behavior, clients will be blocked even if the client is manually disabled
    • Only when client is enabled - clients will not be blocked if you manually disable the client
    • Never - never block clients if the tunnel is down
    If the clients are being blocked, it will now show on the VPN Status page.
  • Fixes for incorrect trigger rules generation with port ranges and iptables-save of trigger rules - @ColinTaylor
  • Fix formatting problem in Wireless Log when connect time reaches 100 hours - @ColinTaylor
  • Several backports from the latest Merlin builds in OpenVPN and Firewall support

As always, a reminder to have a backup of /jffs in case the jffs space needs to be reformatted due to increases in firmware size.

SHA256
Code:
615ae209746f326be046d0053753760d2a98887165ca8eccbbd35d3a72c84cbe  RT-AC68U_3.0.0.4_374.43_2-26E3j9527.trx
2bbc867d261534393e60bf31d5986fbdf6a660617b6f1dfacf6b52b95baedf92  RT-AC56U_3.0.0.4_374.43_2-26E3j9527.trx
ce422c1956a877418af639912c047f47ee3bd9bcba4caa96a513fd8cb59cf4ac  RT-N16_3.0.0.4_374.43_2-26E3j9527.trx
259d56e03e487de2a26a09636edcc1c41a017fc3a56b3fc4de4137bda46c7949  RT-AC66U_3.0.0.4_374.43_2-26E3j9527.trx
85de01d9357187437537d70269e57b49fc00f1cf87cdcf3f0987920bb83a9489  RT-N66U_3.0.0.4_374.43_2-26E3j9527.trx
 
@john9527, thanks a lot for the 26E3 update.

I am at work now, cannot wait to go home and update my router.


Sent from my iPhone using Tapatalk
 
@john9527 do you know how this version would treat my case when I find the openvpn client disabled (not manually)?
The NordVPN problem is a bit different. It looks like after the re-negotiation the server (or client, but I think server) stops talking. It then takes 6 minutes for the everyone to discover something is wrong...then it restarts successfully. But during that 6 minutes, the tunnel is still technically 'up'. So the client never really goes down except for maybe the short time when it actually 'ping-restarts'. So, you will still likely see pretty much the same behavior regardless of this setting.
 
But sometimes after the 6 minutes it reconnects, sometimes not, and I think in that case I find the client disabled in the gui.

The NordVPN problem is a bit different. It looks like after the re-negotiation the server (or client, but I think server) stops talking. It then takes 6 minutes for the everyone to discover something is wrong...then it restarts successfully. But during that 6 minutes, the tunnel is still technically 'up'. So the client never really goes down except for maybe the short time when it actually 'ping-restarts'. So, you will still likely see pretty much the same behavior regardless of this setting.
 
Well I am glad this is out as I am sad to report that same damn bug of loosing connection was back. Hoping this respolves it...
 
Just update my rt-ac68u to 26e3. Cleared nvram then restored default, applied my setting same as V25E8 "overclocking cpu/ram to 1400,800 , and unlock wireless channels/region", entered my vpn config and vpn just won't start/connect at all by click the on switch or even automatically after rebooting.


Jul 27 23:44:39 HTTP login: login 'admin' successful from xxx.xxx.x.xx:80
Jul 27 23:47:08 rc_service: httpd 570:notify_rc start_vpnclient1
Jul 27 23:47:08 rc_service: waiting "" via ...
Jul 27 23:47:33 rc_service: skip the event: start_vpnclient1.
Jul 27 23:49:32 rc_service: httpd 570:notify_rc start_vpnclient1
Jul 27 23:49:32 rc_service: waiting "" via ...
Jul 27 23:49:57 rc_service: skip the event: start_vpnclient1.
Jul 27 23:53:29 rc_service: httpd 570:notify_rc start_vpnclient2
Jul 27 23:53:29 rc_service: waiting "" via ...
Jul 27 23:53:54 rc_service: skip the event: start_vpnclient2.
Jul 27 23:57:06 rc_service: httpd 570:notify_rc start_vpnclient1
Jul 27 23:57:06 rc_service: waiting "" via ...
Jul 27 23:57:31 rc_service: skip the event: start_vpnclient1.





I created and entered same config in client 2 = same issue
I have two different vpn account pia and torguard, tried both with different gateways/servers = same issue
Rebooted the router = same issue
power off router, wait 5min, power on router = same issue

Everything was working fine in V25E8 using same configuration. I updated to 26e3 to take advantage of the auto logout fix, which by the way works awesome in 26e3. Now, I am in a dilemma!!!!!!!!!

Any help will be appreciated!!!

EDIT:

my vpn custom configuration:

tls-client
persist-key
persist-tun
remote-cert-tls server
verb 3
fast-io
sndbuf 524288
rcvbuf 524288
comp-lzo yes
comp-noadapt
auth-nocache
disable-occ
reneg-sec 0
auth-retry nointeract
 
Last edited:
Any help will be appreciated!!!
There is another service that is 'hung' trying to start that is preventing the vpn from starting. Please post your entire syslog to a file sharing site and send a link via PM.

I test with PIA and NordVPN and don't see any problems with things getting started.
 
I can't access my USB attached drives today. IDK if is from 26E3. They show up on the "Network" menu. Show up under "Network Place(Samba) Share / Cloud Disc
I see this in the log: Any Clues? Rebooted router, computer, toggled enable share, toggled enable guest login. I keep guest login enabled. IDK
Jul 28 17:47:28 smbd[919]: [2017/07/28 17:47:28.248478, 0] auth/auth_util.c:722(get_guest_info3)
Jul 28 17:47:28 smbd[919]: SamInfo3_for_guest: Unable to locate guest account [admin]!
Jul 28 17:47:28 smbd[919]: [2017/07/28 17:47:28.248970, 0] smbd/server.c:1255(smbd_main)
Jul 28 17:47:28 smbd[919]: ERROR: failed to setup guest info.
Jul 28 17:49:12 rc_service: httpd 661:notify_rc restart_samba
Jul 28 17:49:12 Samba Server: smb daemon is stopped
Jul 28 17:49:12 kernel: gro disabled
Jul 28 17:49:12 kernel: gro enabled with interval 2
Jul 28 17:49:12 Samba Server: daemon is started
Jul 28 17:49:13 smbd[937]: [2017/07/28 17:49:13.009445, 0] auth/auth_util.c:722(get_guest_info3)
Jul 28 17:49:13 smbd[937]: SamInfo3_for_guest: Unable to locate guest account [admin]!
Jul 28 17:49:13 smbd[937]: [2017/07/28 17:49:13.009903, 0] smbd/server.c:1255(smbd_main)
Jul 28 17:49:13 smbd[937]: ERROR: failed to setup guest info.
Jul 28 17:51:21 HTTP login: logout successful (port 80 disconnected)
Jul 28 17:54:54 HTTP login: login '*******' successful from 192.168.1.2:80
Jul 28 17:57:33 sd-idle-2.6[475]: spinning down /dev/sda
Jul 28 17:57:34 sd-idle-2.6[475]: spinning down /dev/sdb
 
Last edited:
I can't access my USB attached drives today.
Interesting....have you changed your default login from 'admin'? It looks like this may be part of the Samba36 changes (pretty unbelievable that nobody has ran across it before now on Merlin). Thanks for providing the syslog!

If you did change the login name, I think this should be a 'workaround'.

Make a /jffs/scripts/smb.postconf with the following contents.....replace the 'xxxx' with your new login name
Code:
 #!/bin/sh
CONFIG=$1
source /usr/sbin/helper.sh

pc_replace "guest account = admin" "guest account = xxxx" $CONFIG

exit
 
Interesting....have you changed your default login from 'admin'? It looks like this may be part of the Samba36 changes (pretty unbelievable that nobody has ran across it before now on Merlin). Thanks for providing the syslog!

If you did change the login name, I think this should be a 'workaround'.

Make a /jffs/scripts/smb.postconf with the following contents.....replace the 'xxxx' with your new login name
Code:
 #!/bin/sh
CONFIG=$1
source /usr/sbin/helper.sh

pc_replace "guest account = admin" "guest account = xxxx" $CONFIG

exit
Yes, my login name is not admin
 
There is another service that is 'hung' trying to start that is preventing the vpn from starting. Please post your entire syslog to a file sharing site and send a link via PM.

I test with PIA and NordVPN and don't see any problems with things getting started.


@john9527 i just PMed you the log per your request.

btw, I powered down the router all night and i just turned on next day afternoon, and guess what vpn is connected now. I toggled the on/off switch multiple times and vpn disconnects and reconnect without a single issue.
I told myself that since it is working now, I will clean install the firmware again. I put the router in recovery mode, uploaded V26E3 using asus restoration tool, then factory reset to default, re-did the same config and setting i mentioned in my first post, and -----wait for it------ the same vpn issue is back again cannot connect at all.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top