What's new

Kamoj Kamoj Add-on Beta testing II

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Hi all This is my 1st post so please go easy!!!

A big thanks from me goes out to Kamoj and Voxel for all their hours of hard work and effort.

I own a XR500 and XR700. My network is built around the 6 ethernet ports on the XR700 and i really dont like to pull apart the network to change it. However i am sick and tired of the XR series they are some of the Best home level routers i have used. However the support is Dire promise after promise. Bug after Bug. there are so many people sick with the time it is taking and some of the issues are big i have thrown the towel in with them. The Dumo and NG firmwares dont see to fit very well togther at all. Plus dumo cant do anything without NG agreeing.

I tried DD-wrt on the xr routers which was very good, however i found that as they are not DD-wrt core routers the firmware seemed buggy and crashed alot. Most on the firware i would never use anyways and so went a little over my head.

I looked around and found R9000 which the XR700 is a clone of, and discovered Voxel and Kamoj. I dicided on a used R9000 incase i was no better off. the router arrived yesterday and uploaded the firmware all i can say is whooo. It would appear between Voxel and Kamoj you have unleashed the power of these routers and what they should be like. Also its more click click go rather than messsing around with settings.

I do have a couple of questions

1) when installing the lastest Voxel and Kamoj, i lost the LACP/Link Aggregation - i use this to my switch . Is this hidden somewhere
2) I use HMA VPN, in hybrid mode on the XR700 - understand on Kamoj is sort back to front which i have discovered. However there is no pre config for HMA so do just set that part manually?

3) i might have solved this one but. I noticed a big drop in Internet speed with the R9000 on stock/Voxel firmware. Looking around on Google it seems to suggest this could be with QOS on???? i normally get 67-69meg and at the moment i am down to about 13meg. sometimes it goes right up then back down again. Is there anyother settings i should be looking at?


Finally, sorry this post is so long i am just so happy i have found these guys and what they are offereing. Once i sort the above i am so looking forward to the DHCP renewel working for once . which will be one of many fixes which will make this router Kick Arse
Hello,

Voxel/Kamoj has made a huge difference on my R9000 as well. I may be able to help with a couple of your questions...

I don't now about the link aggregation settings as I have never used LAG.

I am not sure exactly what you are asking about OpenVPN. But yes, at Kamoj Menu --> OpenVPN Client --> Create/Edit an OpenVPN Client ...just enter the config from HMA into the field where it says "Type or Paste the contents of your .ovpn file here". Add your username and password in the boxes above and give the config a name. Hit "Create/Save.." and your config is good to go. You still need to set the options and start the VPN in the fields at the top of the page...

My internet is very slow and I do get some benefit from QOS. I have heard some people with faster internet get better performance with QOS off but that seems like a big difference. Maybe others know more... I only wish my internet was fast enough to find out for myself!

If you haven't already done so, I suggest checking out the Voxel Readme and the Kamoj FAQ.txt (available from the Kamoj System Information Menu).

Best wishes,
BL
 
Hi, and thanks for all your input.
I would be happy to look at your issue with WG.
I'm busy 10 days from now, but please contact me again after that if you are still interested!
@kamoj add on works very well for me, it is very stable and I face no disconnection. There is a specific behaviour which I can trigger to result in no internet both via VPN or WAN. I found it by mistake and the only proper way to show it is to let e.g. @kamoj run my WG config which I will terminate by generating new config on the same server IP. Once @kamoj is back to development, I will see if he is interested in debugging it.
 
The timeout is decided by an nvram parameter.
Default is 60 seconds which should be enough - or too much?
But you can change it with e.g.:
Code:
nvram set kamoj_download_timeout=20
nvram commit

Interesting. I can see how the "inaccurate bandwidth monitoring" notification would be useful when NSS is enabled. Even though you may not get accurate results, at least you can monitor the relative usage and see for example if one device is using a lot more bandwidth than normal.

BTW, the Addon continues to work well for me. It has had to do a couple restarts recently but they went well. The only issue I have had is just the Voxel and Kamoj release notes not pulling in on the System Information page. I get the following:
"R9000:
Voxel releasenote not found."
"R9000:
Kamoj release_notes.txt not found."
The web ui (on Vivaldi browser) will also lock up if I get impatient and hit the information button again (or another one) before the request for release information completes...but a page refresh takes care of that.

Best wishes,
BL
 
I'm sorry you are a not happy beta-tester. But so good you found out and reported it here. Thank you!

The Bandwidth metering has always worked for me and several other users, even with NSS on.
So there is more in this than NSS.
I always use DNSCrypt, Aegis and VPN for all devices, e.g. and it measures bandwidth very accurate.

The add-on measurements are done using standard iptables settings, so I start to think about
if some other fixes with iptables or routing messes up something, like the order of the rules.
Have you added any own firewall or routing rules?

There is also the possibility for you to use the Netgear built-in "Traffic Meter"!
Have you tried it, and how does it compare with real values?

If that is true, the limitation and the required configuration should be flagged on the Bandwidth Usage page. Or perhaps access to the Bandwidth Usage page should be blocked unless hardware acceleration is disabled. Why have an ostensible feature that doesn't work?
 
Hi, good to see you here!
Some answers:
(Please never use the wording "latest" when talking about versions.)
1) Strange! It's left where it is in the stock GUI: ADVANCED: Advanced Setup: Ethernet Port Aggregation
3) Read the FAQ.txt and make a "better factory reset" to see if that fixes it.
DHCP renewal: ? I don't know about this issue. Sorry if I've missed. Can you point me in right direction again?

Hi all This is my 1st post so please go easy!!!
..
I do have a couple of questions

1) when installing the lastest Voxel and Kamoj, i lost the LACP/Link Aggregation - i use this to my switch . Is this hidden somewhere
2) I use HMA VPN, in hybrid mode on the XR700 - understand on Kamoj is sort back to front which i have discovered. However there is no pre config for HMA so do just set that part manually?

3) i might have solved this one but. I noticed a big drop in Internet speed with the R9000 on stock/Voxel firmware. Looking around on Google it seems to suggest this could be with QOS on???? i normally get 67-69meg and at the moment i am down to about 13meg. sometimes it goes right up then back down again. Is there anyother settings i should be looking at?

Finally, sorry this post is so long i am just so happy i have found these guys and what they are offereing. Once i sort the above i am so looking forward to the DHCP renewel working for once . which will be one of many fixes which will make this router Kick Arse
 
If it helps to reboot the router you can use the add-on supervision functions.
Hey @kamoj, thanks for the update ;) but i have a problem and it stems from way back when it was discussed how after a reboot wan port is orange and internet connection is down. My absolute cure was to pull the the cat5 and allow it to re-acquire its connection to the i-net. I just updated from b26 to b30 and although the wan led is white it still doesnt have a connection to the i-net requiring me to disconnect the wan cable and reconnect to acquire a connection. I'm going to go back and start over, trying to remedy it on my own. It would speed things up incredibly for me if someone recalls off the top of their head if a solid cause was found. Thanks for your hard-work and all the beta testers
oh yeah
r7800 with voxel's .85
 
I checked your logfile and things look ok.
If you still have issues with Surfshark, come back with more information/new logs.
And please - wait long time between pressing the buttons in the GUI (.i.e. no immediately. It might be that my implementation of handling the crappy web-server is not good.)
So have some patience please. Did you try to close the browser and open another one?

Hi Kamoj, experiencing a minor bug with the add-on, for the first time in several months.

Voxel V1.0.2.85SF, Kamoj V5.4b30

I turned on OpenVPN via the GUI button and my laptop lost internet connectivity within a minute, though I maintained intranet connectivity. Attempted to ping 1.1.1.1, no connection, but an ssh to the router confirmed the internet was still up, validated when I checked from another computer.

Both my laptop (no internet access) and the other computer (working internet) are connected over wifi, bypassing the VPN tunnel via NOVPN naming in LAN Setup.

Initially I thought something glitched with the Killswitch (all 3 killswitch settings plus the restart setting were active). Unchecked killswitch and unchecked OpenVPN Client. The box turned red, but the VPN tunnel Status remained a green check. That was a first. I rechecked OpenVPN, waited a few seconds and unchecked it a second time. Again, VPN tunnel Status remained a green check.

For what it's worth, my laptop did regain internet immediately after I unchecked the box. The log does reflect that OpenVPN status toggled to off, then immediately to back on. I wanted to check if any logs might be helpful beyond the open vpn log (attached). I believe if I shut down openvpn manually via ssh, that will take care of the issue, but I thought it might be interesting to look into.

I consistently run your latest release, and the performance has been outstanding. Thank you, Kamoj, for continually delivering functionality and value to my home!
 
Changes in kamoj-addon beta version 5.4b31
--------------------------------------------------
- Router Information: Added: "Reset Top" temperature history (@Luc_10)
- Router Information: Added: "WAN Information" with info about wan interface + protocol and VPN device
- System Information: Adapted "Aegis abuse list" to new Aegis log file format
- System Information: Updated: Addon processes. (Shows more Kamoj daemons)
- BASIC/ADVANCED Top: Added text "Language:"
- Settings 2: Added "Edit Samba Configuration"
- VPN Bypassing: Added: "Router it-self bypass VPN" (@R. Gerrits)
https://www.snbforums.com/threads/r7800-vpn-service.72979/post-693541
https://www.snbforums.com/threads/is-the-limit-of-vpn-client-39-on-kamoj.73384/post-697773
- DNS Privacy/Ad-Blocking: DNSCrypt 2: Enhanced stop function
- Restart Supervision: Enhanced restart of OpenVPN Client
- Settings: Wake-On-LAN (WOL): Added: Send also to all devices known by bypassing when using "*"
- speedtest.sh: Improved extern ip address detection.
- Added basic metrics the same way as in Aegis (@HELLO_wORLD). See FAQ.txt for more info.
- Experimental - only for "superusers" using OpenVPN Client to restart broken OpenVPN connection faster:
Added: addon_fast_openvpn_supervision.sh (nvram set kamoj_fast_openvpn_supervision=1)
- FAQ.txt updated
 
Thank you for the report!

I tested the WoL on my NAS, and it worked. I tested the program you used on my PC, but it did not detect the WoL package,
so I guess Windows (in my case) firewall something takes care of that. Actually I thought the package never leave the NIC.
You can try it from command line with the debug flag set like this:
Code:
/usr/bin/etherwake -D -i br0 10:36:5A:75:55:12

I always use DNSCrypt myself, and have never had any issue despite not turning it off when installing new add-on.
I suggest you look in the DNSCrypt log and the Supervision log to see what is wrong. That's what logs are for!

Several other things that I was able to try at last (considering the router has been quite busy during the pandemic isolation and online time spent).
I've tried the Wake-On-LAN option but it doesn't work with my desktop computer. I've used the computer MAC address (I used xx:xx:xx:xx:xx:xx format) and * but neither worked. I use this small utility http://magicpacket.free.fr/ to monitor if the magic WOL packet is properly received on the target machine.
View attachment 33915
I do not receive it using the WOL option from the add-on. I've always had WOL working with my older OpenWRT router so my BIOS, OS and network settings are correct.
.View attachment 33912

I've tried the option Unrestricted Port Forwarding hoping it will let me forward traffic to the router LAN address (192.168.1.1) when I've tried to SSH to the router Dropbear server from WAN.
View attachment 33913
I've set the router options too but I cannot establish SSH connection to the router. The router does accept the Port Forwarding rule to 192.168.1.1 to be set but connection from WAN is not possible.
View attachment 33914

Another glitch I experience is that when I uninstall the add-on without turning off DNSCrypt I don't have Internet access after restart. I have to install the add-on again (same or newer version) in order to restore the Internet access.
 
Thanks Kamoj,

1625759467726.png
 
Thanks @kamoj.

I started trying out AdGuard Home v0.106.3 with the 5.4b30 add-on and found that AGH was consuming a lot of RAM and causing my R7800 in router mode to begin using swap space in order not to run out of memory.

Current settings:

Adguard Home Install checkbox checked
Adguard Home (DoH/DoT/DNSCrypt as configured) radio button selected
Adguard: Restart at connection failure checkbox checked

I was able to limit the amount of RAM used by AGH by setting both the Query logs retention and Statistics retention to 24 hours instead of the default 7 days. After that I did not see swap space being used any more, although RAM usage can approach 90%.

I used the "Backup config to USB" button to save the config file in /tmp/mnt/sda1/AdGuardHome/AdGuardHome.yaml

After upgrading to the 5.4b31 add-on, I was glad to see the AGH was still recognized as being installed. Going back into AGH settings page, the Query logs retention and Statistics retention settings had reverted back to the default value of 7 days. This was quickly addressed by using the "Restore config from USB" button.

If there's a way to automate the restore config from USB for AGH, please let me know.

Also, the AGH page shows the following errors but appears to be working:

Error: control/version.json | Couldn't get version check json from https://static.adguard.com/adguardhome/release/version.json: *fmt.wrapError updater: HTTP GET https://static.adguard.com/adguardhome/release/version.json: Get "https://static.adguard.com/adguardhome/release/version.json": x509: certificate signed by unknown authority | 502

If you're aware of a way to resolve the "x509: certificate signed by unknown authority" error above, please let me know as well.
 
You are welcome!

The restore of the AGH configuration file from USB was designed to work, but it's a bug making it not working.
Sorry, it will be fixed for next release.

I don't experience your x509 errors, so I don't know what is wrong.
Where do you see the error messages? Is there anything in the add-on AGH log-file?

The blocklist https://www.malwaredomainlist.com/hostslist/hosts.txt though gives an x509 error because the blocklist is too old:
"x509: certificate has expired or is not yet valid", so I should disable it as one of the default lists!

Thanks @kamoj.

I started trying out AdGuard Home v0.106.3 with the 5.4b30 add-on and found that AGH was consuming a lot of RAM and causing my R7800 in router mode to begin using swap space in order not to run out of memory.

Current settings:

Adguard Home Install checkbox checked
Adguard Home (DoH/DoT/DNSCrypt as configured) radio button selected
Adguard: Restart at connection failure checkbox checked

I was able to limit the amount of RAM used by AGH by setting both the Query logs retention and Statistics retention to 24 hours instead of the default 7 days. After that I did not see swap space being used any more, although RAM usage can approach 90%.

I used the "Backup config to USB" button to save the config file in /tmp/mnt/sda1/AdGuardHome/AdGuardHome.yaml

After upgrading to the 5.4b31 add-on, I was glad to see the AGH was still recognized as being installed. Going back into AGH settings page, the Query logs retention and Statistics retention settings had reverted back to the default value of 7 days. This was quickly addressed by using the "Restore config from USB" button.

If there's a way to automate the restore config from USB for AGH, please let me know.

Also, the AGH page shows the following errors but appears to be working:

Error: control/version.json | Couldn't get version check json from https://static.adguard.com/adguardhome/release/version.json: *fmt.wrapError updater: HTTP GET https://static.adguard.com/adguardhome/release/version.json: Get "https://static.adguard.com/adguardhome/release/version.json": x509: certificate signed by unknown authority | 502

If you're aware of a way to resolve the "x509: certificate signed by unknown authority" error above, please let me know as well.
 
You are welcome!

The restore of the AGH configuration file from USB was designed to work, but it's a bug making it not working.
Sorry, it will be fixed for next release.

I don't experience your x509 errors, so I don't know what is wrong.
Where do you see the error messages? Is there anything in the add-on AGH log-file?

The blocklist https://www.malwaredomainlist.com/hostslist/hosts.txt though gives an x509 error because the blocklist is too old:
"x509: certificate has expired or is not yet valid", so I should disable it as one of the default lists!
The log entries from /var/log/AdGuardHome.log file (attached) at startup do contain multilple "x509: certificate signed by unknown authority" messages, indicating that when whichever process is attempting to download from the various HTTPS URLs, it does not trust the certificate authorities used by those sites. The same messages are logged periodically afterwards.

Code:
root@R7800:/tmp/mnt/sda1/AdGuardHome$ cat /var/log/AdGuardHome.log
2021-07-08 11:47:14 [ADGUARD] adguard_home.sh 12265: 70.74:Information: Time is OK
2021-07-08 11:47:14 [ADGUARD] adguard_home.sh 12265: 71.07:INSTALL: Download Release archive:/tmp/AdGuardHome_linux_armv7.tar.gz https://static.adguard.com/adguardhome/release/AdGuardHome_linux_armv7.tar.gz
2021-07-08 11:47:16 [ADGUARD] adguard_home.sh 12265: 73.47:INSTALL: Release archive unpacked.
2021-07-08 11:47:17 [ADGUARD] adguard_home.sh 12265: 73.55:Install finished
2021-07-08 11:47:17 [ADGUARD] adguard_home.sh 13131: 73.59:Start called
2021-07-08 11:47:20 [ADGUARD] adguard_home.sh 13131: 76.70:Information: Time is OK
2021-07-08 11:47:20 [ADGUARD] adguard_home.sh 13131: 76.98:Adguard Home started. Accessible GUI: http://192.168.1.1:8080
2021/07/08 15:47:20.687917 [info] AdGuard Home, version v0.106.3
2021/07/08 15:47:20.696164 [info] Upgrade yaml: 7 to 8
2021/07/08 15:47:20.696227 [info] Upgrade yaml: 8 to 9
2021/07/08 15:47:20.696258 [info] Upgrade yaml: 9 to 10
2021/07/08 15:47:20.764237 [info] Initializing auth module: /tmp/addons/adguard_home/data/sessions.db
2021/07/08 15:47:20.764549 [info] auth: initialized.  users:1  sessions:0
2021/07/08 15:47:20.764612 [info] Initialize web module
2021/07/08 15:47:20.779919 [info] AdGuard Home is available on the following addresses:
2021/07/08 15:47:20.786480 [info] Go to http://127.0.0.1:8080
2021/07/08 15:47:20.786542 [info] Go to http://[::1]:8080
2021/07/08 15:47:20.786605 [info] Go to http://10.0.0.1:8080
2021/07/08 15:47:20.786605 [info] Go to http://192.168.2.197:8080
2021/07/08 15:47:20.786761 [info] Go to http://10.0.1.1:8080
2021/07/08 15:47:20.788885 [info] Starting the DNS proxy server
2021/07/08 15:47:20.788948 [info] Ratelimit is enabled and set to 100 rps
2021/07/08 15:47:20.788979 [info] The server is configured to refuse ANY requests
2021/07/08 15:47:20.789010 [info] DNS cache is enabled
2021/07/08 15:47:20.789042 [info] MaxGoroutines is set to 50
2021/07/08 15:47:20.789073 [info] Creating the UDP server socket
2021/07/08 15:47:20.789354 [info] Listening to udp://[::]:5300
2021/07/08 15:47:20.789385 [info] Creating a TCP server socket
2021/07/08 15:47:20.789510 [info] Listening to tcp://[::]:5300
2021/07/08 15:47:20.791072 [info] Entering the UDP listener loop on [::]:5300
2021/07/08 15:47:20.791103 [info] Entering the tcp listener loop on [::]:5300
2021/07/08 15:47:40.918939 [info] Couldn't request filter from URL https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt, skipping: Get "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt": x509: certificate signed by unknown authority
2021/07/08 15:47:40.919063 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/1.txt: no such file or directory
2021/07/08 15:47:41.277795 [info] Failed to update filter https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt: Get "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt": x509: certificate signed by unknown authority

2021/07/08 15:47:42.170547 [info] Couldn't request filter from URL https://adaway.org/hosts.txt, skipping: Get "https://adaway.org/hosts.txt": x509: certificate signed by unknown authority
2021/07/08 15:47:42.170672 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/2.txt: no such file or directory
2021/07/08 15:47:42.170735 [info] Failed to update filter https://adaway.org/hosts.txt: Get "https://adaway.org/hosts.txt": x509: certificate signed by unknown authority

2021/07/08 15:47:42.667267 [info] Couldn't request filter from URL https://www.malwaredomainlist.com/hostslist/hosts.txt, skipping: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T15:47:42Z is after 2021-03-10T17:07:53Z
2021/07/08 15:47:42.667455 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/4.txt: no such file or directory
2021/07/08 15:47:42.667486 [info] Failed to update filter https://www.malwaredomainlist.com/hostslist/hosts.txt: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T15:47:42Z is after 2021-03-10T17:07:53Z
 

Attachments

  • AdGuardHome.log.txt
    75.1 KB · Views: 121
I don't have your errors.
You can not download any blocklist ...
Your configuration may have become corrupt.
The AGH updates it (yaml) from version 7 to 10.
I would uninstall and install it again without using the old config file.
if that woks, try the old config file file and see if the errors come back.

The log entries from /var/log/AdGuardHome.log file (attached) at startup do contain multilple "x509: certificate signed by unknown authority" messages, indicating that when whichever process is attempting to download from the various HTTPS URLs, it does not trust the certificate authorities used by those sites. The same messages are logged periodically afterwards.

Code:
root@R7800:/tmp/mnt/sda1/AdGuardHome$ cat /var/log/AdGuardHome.log
2021-07-08 11:47:14 [ADGUARD] adguard_home.sh 12265: 70.74:Information: Time is OK
2021-07-08 11:47:14 [ADGUARD] adguard_home.sh 12265: 71.07:INSTALL: Download Release archive:/tmp/AdGuardHome_linux_armv7.tar.gz https://static.adguard.com/adguardhome/release/AdGuardHome_linux_armv7.tar.gz
2021-07-08 11:47:16 [ADGUARD] adguard_home.sh 12265: 73.47:INSTALL: Release archive unpacked.
2021-07-08 11:47:17 [ADGUARD] adguard_home.sh 12265: 73.55:Install finished
2021-07-08 11:47:17 [ADGUARD] adguard_home.sh 13131: 73.59:Start called
2021-07-08 11:47:20 [ADGUARD] adguard_home.sh 13131: 76.70:Information: Time is OK
2021-07-08 11:47:20 [ADGUARD] adguard_home.sh 13131: 76.98:Adguard Home started. Accessible GUI: http://192.168.1.1:8080
2021/07/08 15:47:20.687917 [info] AdGuard Home, version v0.106.3
2021/07/08 15:47:20.696164 [info] Upgrade yaml: 7 to 8
2021/07/08 15:47:20.696227 [info] Upgrade yaml: 8 to 9
2021/07/08 15:47:20.696258 [info] Upgrade yaml: 9 to 10
2021/07/08 15:47:20.764237 [info] Initializing auth module: /tmp/addons/adguard_home/data/sessions.db
2021/07/08 15:47:20.764549 [info] auth: initialized.  users:1  sessions:0
2021/07/08 15:47:20.764612 [info] Initialize web module
2021/07/08 15:47:20.779919 [info] AdGuard Home is available on the following addresses:
2021/07/08 15:47:20.786480 [info] Go to http://127.0.0.1:8080
2021/07/08 15:47:20.786542 [info] Go to http://[::1]:8080
2021/07/08 15:47:20.786605 [info] Go to http://10.0.0.1:8080
2021/07/08 15:47:20.786605 [info] Go to http://192.168.2.197:8080
2021/07/08 15:47:20.786761 [info] Go to http://10.0.1.1:8080
2021/07/08 15:47:20.788885 [info] Starting the DNS proxy server
2021/07/08 15:47:20.788948 [info] Ratelimit is enabled and set to 100 rps
2021/07/08 15:47:20.788979 [info] The server is configured to refuse ANY requests
2021/07/08 15:47:20.789010 [info] DNS cache is enabled
2021/07/08 15:47:20.789042 [info] MaxGoroutines is set to 50
2021/07/08 15:47:20.789073 [info] Creating the UDP server socket
2021/07/08 15:47:20.789354 [info] Listening to udp://[::]:5300
2021/07/08 15:47:20.789385 [info] Creating a TCP server socket
2021/07/08 15:47:20.789510 [info] Listening to tcp://[::]:5300
2021/07/08 15:47:20.791072 [info] Entering the UDP listener loop on [::]:5300
2021/07/08 15:47:20.791103 [info] Entering the tcp listener loop on [::]:5300
2021/07/08 15:47:40.918939 [info] Couldn't request filter from URL https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt, skipping: Get "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt": x509: certificate signed by unknown authority
2021/07/08 15:47:40.919063 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/1.txt: no such file or directory
2021/07/08 15:47:41.277795 [info] Failed to update filter https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt: Get "https://adguardteam.github.io/AdGuardSDNSFilter/Filters/filter.txt": x509: certificate signed by unknown authority

2021/07/08 15:47:42.170547 [info] Couldn't request filter from URL https://adaway.org/hosts.txt, skipping: Get "https://adaway.org/hosts.txt": x509: certificate signed by unknown authority
2021/07/08 15:47:42.170672 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/2.txt: no such file or directory
2021/07/08 15:47:42.170735 [info] Failed to update filter https://adaway.org/hosts.txt: Get "https://adaway.org/hosts.txt": x509: certificate signed by unknown authority

2021/07/08 15:47:42.667267 [info] Couldn't request filter from URL https://www.malwaredomainlist.com/hostslist/hosts.txt, skipping: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T15:47:42Z is after 2021-03-10T17:07:53Z
2021/07/08 15:47:42.667455 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/4.txt: no such file or directory
2021/07/08 15:47:42.667486 [info] Failed to update filter https://www.malwaredomainlist.com/hostslist/hosts.txt: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T15:47:42Z is after 2021-03-10T17:07:53Z
 
I don't have your errors.
You can not download any blocklist ...
Your configuration may have become corrupt.
The AGH updates it (yaml) from version 7 to 10.
I would uninstall and install it again without using the old config file.
if that woks, try the old config file file and see if the errors come back.
Thanks for looking into this issue. I have gotten the blocklist downloads to work by using opkg to install the ca-certificates and ca-bundle packages from Voxel's entware:

Code:
root@R7800:/tmp/mnt/sda1/AdGuardHome$ /opt/bin/opkg install ca-certificates
Installing ca-certificates (20210119-1) to root...
Downloading http://www.voxel-firmware.com/Downloads/Voxel/Entware/Entware-3x-Voxel/ca-certificates_20210119-1_all.ipk
Configuring ca-certificates.
root@R7800:/tmp/mnt/sda1/AdGuardHome$ /opt/bin/opkg install ca-bundle
Installing ca-bundle (20210119-1) to root...
Downloading http://www.voxel-firmware.com/Downloads/Voxel/Entware/Entware-3x-Voxel/ca-bundle_20210119-1_all.ipk
Configuring ca-bundle.
root@R7800:/tmp/mnt/sda1/AdGuardHome$

Then after changing DNS Filter/Encryption back to the "None - Not recommended" radio button, waiting for AGH to stop, then selecting the "Adguard Home (DoH/DoT/DNSCrypt as configured)" radio button again, the log entries indicate successful blocklist downloads.

Code:
2021/07/08 22:40:20.111941 [info] Received signal "terminated"
2021/07/08 22:40:20.111973 [info] Stopping AdGuard Home
2021/07/08 22:40:20.112004 [info] stopping http server...
2021-07-08 18:40:22 [ADGUARD] adguard_home.sh 3575: 24858.88:STOP: Restore dnsmasq config file
2021-07-08 18:40:22 [ADGUARD] adguard_home.sh 3575: 24858.98:STOP: Terminated.
[2021-07-08 18:40:22] adguard terminated by operator trigged addon
2021-07-08 18:41:02 [ADGUARD] adguard_home.sh 6552: 24898.53:Start called
2021-07-08 18:41:04 [ADGUARD] adguard_home.sh 6552: 24901.30:Information: Time is OK
2021-07-08 18:41:04 [ADGUARD] adguard_home.sh 6552: 24901.44:Adguard Home started. Accessible GUI: http://192.168.1.1:8080
[2021-07-08 18:41:05] adguard started by operator trigged addon
2021/07/08 22:41:05.135215 [info] AdGuard Home, version v0.106.3
2021/07/08 22:41:05.388480 [info] Initializing auth module: /tmp/addons/adguard_home/data/sessions.db
2021/07/08 22:41:05.388792 [info] auth: initialized.  users:1  sessions:1
2021/07/08 22:41:05.388855 [info] Initialize web module
2021/07/08 22:41:05.395946 [info] AdGuard Home is available on the following addresses:
2021/07/08 22:41:05.405818 [info] Go to http://127.0.0.1:8080
2021/07/08 22:41:05.405912 [info] Go to http://[::1]:8080
2021/07/08 22:41:05.405943 [info] Go to http://10.0.0.1:8080
2021/07/08 22:41:05.406006 [info] Go to http://192.168.2.197:8080
2021/07/08 22:41:05.406037 [info] Go to http://10.0.1.1:8080
2021/07/08 22:41:05.416534 [info] Starting the DNS proxy server
2021/07/08 22:41:05.416721 [info] Ratelimit is enabled and set to 100 rps
2021/07/08 22:41:05.416784 [info] The server is configured to refuse ANY requests
2021/07/08 22:41:05.416815 [info] DNS cache is enabled
2021/07/08 22:41:05.416846 [info] MaxGoroutines is set to 50
2021/07/08 22:41:05.416877 [info] Creating the UDP server socket
2021/07/08 22:41:05.417127 [info] Listening to udp://[::]:5300
2021/07/08 22:41:05.417159 [info] Creating a TCP server socket
2021/07/08 22:41:05.417284 [info] Listening to tcp://[::]:5300
2021/07/08 22:41:05.417627 [info] Entering the UDP listener loop on [::]:5300
2021/07/08 22:41:05.417877 [info] Entering the tcp listener loop on [::]:5300
2021/07/08 22:41:05.989823 [info] Filter 1 has been updated: 729602 bytes, 37768 rules
2021/07/08 22:41:05.989886 [info] Saving filter 1 contents to: /tmp/addons/adguard_home/data/filters/1.txt
2021/07/08 22:41:06.323407 [info] Filter 2 has been updated: 298799 bytes, 8227 rules
2021/07/08 22:41:06.323469 [info] Saving filter 2 contents to: /tmp/addons/adguard_home/data/filters/2.txt
2021/07/08 22:41:07.006412 [info] Couldn't request filter from URL https://www.malwaredomainlist.com/hostslist/hosts.txt, skipping: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T22:41:07Z is after 2021-03-10T17:07:53Z
2021/07/08 22:41:07.006568 [error] os.Chtimes(): chtimes /tmp/addons/adguard_home/data/filters/4.txt: no such file or directory
2021/07/08 22:41:07.006599 [info] Failed to update filter https://www.malwaredomainlist.com/hostslist/hosts.txt: Get "https://www.malwaredomainlist.com/hostslist/hosts.txt": x509: certificate has expired or is not yet valid: current time 2021-07-08T22:41:07Z is after 2021-03-10T17:07:53Z

2021/07/08 22:41:08.804350 [info] Filter 1590433492 has been updated: 334861 bytes, 8732 rules
2021/07/08 22:41:08.804413 [info] Saving filter 1590433492 contents to: /tmp/addons/adguard_home/data/filters/1590433492.txt
2021/07/08 22:41:09.548055 [info] Filter 1590435211 has been updated: 45816 bytes, 2886 rules
2021/07/08 22:41:09.548118 [info] Saving filter 1590435211 contents to: /tmp/addons/adguard_home/data/filters/1590435211.txt
2021/07/08 22:41:09.548274 [info] Updated filter #1.  Rules: 0 -> 37768
2021/07/08 22:41:09.548305 [info] Updated filter #2.  Rules: 0 -> 8227
2021/07/08 22:41:09.548336 [info] Updated filter #1590433492.  Rules: 0 -> 8732
2021/07/08 22:41:09.548368 [info] Updated filter #1590435211.  Rules: 0 -> 2886
2021/07/08 22:41:10.330811 [info] Filter 1584805914 has been updated: 3678 bytes, 191 rules
2021/07/08 22:41:10.330873 [info] Saving filter 1584805914 contents to: /tmp/addons/adguard_home/data/filters/1584805914.txt
2021/07/08 22:41:10.330998 [info] Updated filter #1584805914.  Rules: 0 -> 191
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top