What's new

[Release] Asuswrt-Merlin 384.7 is now available

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

I too am experiencing the upgrade issue where it uploads the firmware fine, presents NO error message and then goes back to the main page showing the previous firmware version.
-I am currently on version 384.5 on my RT-AC68U
-I tried going directly to version 384.7 with no success. After that I tried going to 384.6 with the same results. No errors, but stays at previous firmware level
- Once the upgrade is tried, it seems to wipe out all settings
- I have nothing plugged in the USB ports and never have
- I have tried an initialization and then upgrading but it is the same behavior
-Never had a problem with these upgrades before this

Any suggestions?
You are using ASUS RT-AC68U router and not other brand?
Coz the new firmware only support ASUS router.
 
I am thinking of upgrading my RT-AC68U (non-T-mobile) running 3.0.0.4.374.43_2-26E3j9527 (Merlin-John) on a 1.0.2.0 CFE to this version. Will I lose any CFE mod's? Can I revert back to John's if the new version doesn't work for me? I'm having Dual-WAN issues....
 
afraid ddns doesn't work

Oct 12 22:08:41 watchdog: start ddns.
Oct 12 22:08:41 rc_service: watchdog 275:notify_rc start_ddns
Oct 12 22:08:41 start_ddns: update FREEDNS.AFRAID.ORG default@freedns.afraid.org, wan_unit 0
Oct 12 22:08:41 inadyn[1954]: In-a-dyn version 2.5 -- Dynamic DNS update client.
Oct 12 22:08:42 inadyn[1954]: Update forced for alias xxxxxxxx.xxx, new IP# xxxxxxxxxxxxxx
Oct 12 22:08:44 inadyn[1954]: HTTP(S) Transaction failed, error 36: Temporary network error (HTTPS send)
 
Hello. I have an RT-AC68U and just updated to 384.7. I cannot get the the new DDNS client with HTTPS to work with Namecheap. I have verified via other methods Namecheap's DDNS is updating with my current credentials. I have also rebooted the router since the install. Here's what the log shows (host name and IP redacted):

Oct 12 08:26:36 start_ddns: update WWW.NAMECHEAP.COM namecheap, wan_unit 0
Oct 12 08:26:37 inadyn[2357]: In-a-dyn version 2.5 -- Dynamic DNS update client.
Oct 12 08:26:37 inadyn[2357]: Failed resolving hostname test: Name or service not known
Oct 12 08:26:37 inadyn[2357]: Update forced for alias test, new IP# x.x.x.x
Oct 12 08:26:38 inadyn[2357]: Updating cache for test

There's a problem with the namecheap setup and the new DDNS client. For now you will have to provide a modified inadyn.conf to resolve it.

https://github.com/RMerl/asuswrt-merlin.ng/issues/212
 
afraid ddns doesn't work

Afraid working fine here, it's what I use myself. "Temporary network error" seem to imply an issue on your end, or a temporary problem with their servers.

Code:
admin@Stargate88:/tmp/home/root# tail /tmp/syslog.log
Oct 12 15:13:41 inadyn[4031]: SSL connection using ECDHE-RSA-AES128-GCM-SHA256
Oct 12 15:13:41 inadyn[4031]: SSL server cert subject: /OU=Domain Control Validated/OU=EssentialSSL/CN=freedns.afraid.org
Oct 12 15:13:41 inadyn[4031]: SSL server cert issuer: /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
Oct 12 15:13:41 inadyn[4031]: Fetching account API key, connecting to freedns.afraid.org([69.197.18.161]:443)
Oct 12 15:13:41 inadyn[4031]: Fetching account API key, initiating HTTPS ...
Oct 12 15:13:41 inadyn[4031]: SSL connection using ECDHE-RSA-AES128-GCM-SHA256
Oct 12 15:13:41 inadyn[4031]: SSL server cert subject: /OU=Domain Control Validated/OU=EssentialSSL/CN=freedns.afraid.org
Oct 12 15:13:41 inadyn[4031]: SSL server cert issuer: /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Domain Validation Secure Server CA
Oct 12 15:13:42 inadyn[4031]: Successful alias table update for domain.mooo.com => new IP# 23.x.y.z
Oct 12 15:13:42 inadyn[4031]: Updating cache for domain.mooo.com
 
Afraid working fine here, it's what I use myself. "Temporary network error" seem to imply an issue on your end, or a temporary problem with their servers.

I dont know how to fix this, the log is filled with these "errors"

Code:
Oct 12 22:33:23 watchdog: start ddns.
Oct 12 22:33:23 rc_service: watchdog 275:notify_rc start_ddns
Oct 12 22:33:23 start_ddns: update FREEDNS.AFRAID.ORG default@freedns.afraid.org, wan_unit 0
Oct 12 22:33:23 inadyn[2868]: In-a-dyn version 2.5 -- Dynamic DNS update client.
Oct 12 22:33:24 inadyn[2868]: Update forced for alias test.com, new IP# 12.34.56.78
Oct 12 22:33:27 inadyn[2868]: HTTP(S) Transaction failed, error 36: Temporary network error (HTTPS send)
Oct 12 22:33:54 watchdog: start ddns.
Oct 12 22:33:54 rc_service: watchdog 275:notify_rc start_ddns
Oct 12 22:33:54 start_ddns: update FREEDNS.AFRAID.ORG default@freedns.afraid.org, wan_unit 0
Oct 12 22:33:54 inadyn[2885]: In-a-dyn version 2.5 -- Dynamic DNS update client.
Oct 12 22:33:55 inadyn[2885]: Update forced for alias test.com, new IP# 12.34.56.78
Oct 12 22:33:57 inadyn[2885]: HTTP(S) Transaction failed, error 36: Temporary network error (HTTPS send)
Oct 12 22:34:05 dnsmasq-dhcp[258]: DHCPSOLICIT(br0) 00:03:00:01:30:cd:a7:21:92:be 
Oct 12 22:34:23 watchdog: start ddns.
Oct 12 22:34:23 rc_service: watchdog 275:notify_rc start_ddns
Oct 12 22:34:23 start_ddns: update FREEDNS.AFRAID.ORG default@freedns.afraid.org, wan_unit 0
Oct 12 22:34:24 inadyn[2905]: In-a-dyn version 2.5 -- Dynamic DNS update client.
Oct 12 22:34:25 inadyn[2905]: Update forced for alias test.com, new IP# 12.34.56.78
Oct 12 22:34:27 inadyn[2905]: HTTP(S) Transaction failed, error 36: Temporary network error (HTTPS send)

So for example lets say my domain on afraid is "test.com" and I have some "sub1.test.com" and "sub2.test.com" as subdomains.

"Method to retrieve WAN IP" set to internal
"Server" set to FREEDNS.AFRAID.ORG
"Host Name" filled with "test.com"
"User Name or E-mail Address" was filled with my afraid account username, let's say "testaccount" tried with email as well, same outcome
"Password or DDNS Key" was filled with my afraid account password
"Enable wildcard" set to yes

And I'm using a HTTPS/SSL Certitficate which was generated by Let's Encrypt but was imported into the router, not created by the router.

Code:
Status : OK
Issued to : test.com
SAN : test.com sub1.test.com sub2.test.com
Issued by : Let's Encrypt Authority X3
Expires on : 2018/12/12
 
Last edited:
There's a problem with the namecheap setup and the new DDNS client. For now you will have to provide a modified inadyn.conf to resolve it.

https://github.com/RMerl/asuswrt-merlin.ng/issues/212

OK, thanks for the response Merlin! Awesome now having DDNS over TLS (and also the DNS rebind protection feature in the last release).

I am hoping that the NTP server connections will also be encrypted at some point. I found this on the net:

https://tools.ietf.org/html/draft-ietf-ntp-using-nts-for-ntp-13

Best Regards,
Jake
 
I am thinking of upgrading my RT-AC68U (non-T-mobile) running 3.0.0.4.374.43_2-26E3j9527 (Merlin-John) on a 1.0.2.0 CFE to this version. Will I lose any CFE mod's? Can I revert back to John's if the new version doesn't work for me? I'm having Dual-WAN issues....
which CFE-mods?
OC and region free will stay as before, at least on mine till now.
Better to use restauration tool for change between John and Merlin (or stock) and make factory reset and real power cycles.
 
which CFE-mods?
OC and region free will stay as before, at least on mine till now.
Better to use restauration tool for change between John and Merlin (or stock) and make factory reset and real power cycles.

My mods are for country (region free #a), dB power settings, antenna dB, but no overclocking. Under what type of firmware upgrade cycles are CFE's overwritten?
 
My mods are for country (region free #a), dB power settings, antenna dB, but no overclocking. Under what type of firmware upgrade cycles are CFE's overwritten?
not 'fully' converted TM's with data in mtd5.
 
Hi, thanks for all that you do for everyone using the firmware. I noticed you've added freedns.afraid.org DDNS service and you're saying that all DDNS services are now encrypted, which is awesome. So is this new service you've added one that logs data like ASUS' DDNS service suggests that it does? Hope that's not off topic.


Sent from my iPhone using Tapatalk Pro
 
You can kick it to my curb if you want--I don't need the newest of everything.

The AC-3200 is still supported by ASUS. I don't think it's sliding off anything.

True, it is holding at 384.6 just now on RMerlin's firmware, and I'm not techie enough to really know why that is. Is it expected that there will ever be an RMerlin release after 384.6? That I don't know.
 
Is there any point using the DNSSEC features when you're using a VPN in a OpenVPN profile?
 
So is this new service you've added one that logs data like ASUS' DDNS service suggests that it does?

AsusDDNS doesn't log anything beside your IP address, which is the same for every single DDNS service (otherwise, how else are they supposed to be able to associate your IP address with your hostname).
 
Is there any point using the DNSSEC features when you're using a VPN in a OpenVPN profile?

The goal behind DNSSEC is not to encrypt, it's to sign queries to ensure they haven't been modified.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top