What's new

perfect-privacy on Asus RT-AC68U doesn´t work

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Mightyous

Occasional Visitor
Hi folks,
i´ve tried PP (perfect-privacy) on my Asus with Merlin FW.
Ovpn import in webinterface, ca.crt open in an unix editor (Winvii) copy and paste in "Certificate Authority" the same to .key file under "Static Key" (don´t sure, is that right?).
PP have .p12 file too, don´t know how to use. Is this file important?
.ovpn file makes a custom configuration

tun-mtu 1500
fragment 1300
mssfix
auth SHA512
hand-window 120
inactive 604800
mute-replay-warnings
ns-cert-type server
persist-remote-ip
ping 5
ping-restart 120
remote-random
reneg-sec 3600
route-delay 2
route-method exe
script-security 2
tls-cipher DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-SHA256:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:DHE-RSA-CAMELLIA256-SHA:DHE-RSA-AES256-SHA:DHE-RSA-CAMELLIA128-SHA:DHE-RSA-AES128-SHA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA
tls-timeout 5
pkcs12 Montreal_cl.p12
register-dns

I´ve got this error

Oct 20 14:40:23 rc_service: httpd 30724:notify_rc start_vpnclient1
Oct 20 14:40:23 kernel: tun: Universal TUN/TAP device driver, 1.6
Oct 20 14:40:23 kernel: tun: (C) 1999-2004 Max Krasnyansky <maxk@qualcomm.com>
Oct 20 14:40:23 openvpn[30954]: Options error: Unrecognized option or missing parameter(s) in config.ovpn:46: register-dns (2.3.7)
Oct 20 14:40:23 openvpn[30954]: Use --help for more information.
Oct 20 14:40:23 syslog: VPN_LOG_ERROR: 433: Starting OpenVPN failed...
Oct 20 14:40:23 dnsmasq[30797]: read /etc/hosts - 6 addresses
Oct 20 14:40:23 dnsmasq[30797]: using nameserver 192.168.0.1#53 for domain local
Oct 20 14:40:23 dnsmasq[30797]: using nameserver 192.168.0.1#53 for domain fritz.box
Oct 20 14:40:23 dnsmasq[30797]: using nameserver 192.168.0.1#53
Oct 20 14:40:23 dnsmasq[30797]: exiting on receipt of SIGTERM
Oct 20 14:40:23 dnsmasq[30990]: started, version 2.73rc9 cachesize 1500
Oct 20 14:40:23 dnsmasq[30990]: warning: interface ppp1* does not currently exist
Oct 20 14:40:23 dnsmasq[30990]: asynchronous logging enabled, queue limit is 5 messages
Oct 20 14:40:23 dnsmasq-dhcp[30990]: DHCP, IP range 192.168.1.2 -- 192.168.1.254, lease time 1d
Oct 20 14:40:23 dnsmasq[30990]: read /etc/hosts - 6 addresses
Oct 20 14:40:23 dnsmasq[30990]: using nameserver 192.168.0.1#53 for domain local
Oct 20 14:40:23 dnsmasq[30990]: using nameserver 192.168.0.1#53 for domain fritz.box
Oct 20 14:40:23 dnsmasq[30990]: using nameserver 192.168.0.1#53

tried maually DNS 8.8.8.8 but the same problem.
When i delete

pkcs12 Montreal_cl.p12
register-dns

connection does work, but i still have my own IP.
 

Attachments

  • asus2.jpg
    asus2.jpg
    63.5 KB · Views: 606
PP ovpn files don't already contain all the certs and keys necessary?

if they do then you just need to upload, wait a second, then click apply to save. apply to save after any changes.
 
for PC doesn´t contain it, but i take .ovpn for android and that contains all certs and keys. thanks, that was a very good hint from you :)
 
for PC doesn´t contain it, but i take .ovpn for android and that contains all certs and keys. thanks, that was a very good hint from you :)

yes, since you are running openvpn on the router you would want to download ovpn config files for linux, not windows. if android worked, that's great. you might want to download linux config files to see if they differ from android.
 
linux doesn´t work. It contains .ca and .key file. Merlin FW open only .ovpn file. Any idea how to import key and ca automatic? I can it only open on a text editor, than copy&paste text inside file.
I think an automatic process doesn´t work. You have to copy this files on router flash/HDD and make it on telnet/ssh. can someone help me?

Next question. What does this mean?

WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this

warning: interface ppp1* does not currently exist
 
Last edited:

Similar threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top