What's new

RT-N66U 2022?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Tomato is your best bet, since John hasn't released updates in about a year. I consider its development to be dead at this point.
 
The 53D7 was released just last August and has proven stable for the supported routers, ime.
 
What I want to do is set up a router with the FreshTomato firmware (I already have it installed on an old Asus RT-N66U router) and then set it up as an OpenVPN client which connects to an OpenVPN server in a distant location (not a commercial VPN, just a server at another home). But I want it such that anything connected to it can ONLY send and receive data via the VPN, and NEVER under any circumstances via the local Internet connection. If for some reason the VPN isn't working, then as far as anything connected to the router is concerned the Internet should be down. We've seen this described as a "kill switch" and have found several pages that describe how to set one up (mostly by adding obscure lines to iptables) but none seem at all applicable to FreshTomato.

If possible please keep the explanation as simple as possible because I am no networking guru! This is for connecting one home to another. For example if something has to be done with iptables then I need to know how to do that and exactly what to put there, since I don't see anything about iptables in the FreshTomato configuration (does FreshTomato even use it?). To be honest I was hoping to find a checkbox somewhere in the VPN client configuration that said something like "limit connected devices to using this VPN only" or words to that effect, but of course it is never that simple. I actually feel like this is something that should be really easy but I just haven't found the way to do it.
 
Have you asked your questions on a Fresh Tomato board?

It would be surprising if that knowledge is here in these forums (hope I'm wrong!).
 
We've seen this described as a "kill switch"

I don't have FT running at the moment, but remember Kill Switch available in VPN Client, Routing Policy or something similar.
 
Thanks for the suggestion, I was not aware of this one.
If you do go the FT route on the N66U, I'd recommend sticking with the K26RT-N firmware and avoiding the K26RT-AC firmware version. I've used both and the AC version seems less stable than the N version. The router seemed to run hotter and freeze for no reason, requiring a hard restart (power off).

I actually put the N66U into storage for several years before finding John's builds. Then my parent's router crapped out so I put it at their house 'temporarily' but John's firmware was so good, the N66U has been serving the parents for nearly 3 additional years now (they have few wifi devices and no need for > 150mbps connectivity). John's firmware, like the Merlin it's based on, has been bulletproof and stable.

I do hope that John's okay and that he returns to keep supporting this router.
 
I am not having much luck with this FreshTomato, if I switch to john9527-LTS firmware, can anyone tell me how I can do the following under that firmware?

"What I want to do is set up a router with the FreshTomato firmware (I already have it installed on an old Asus RT-N66U router) and then set it up as an OpenVPN client which connects to an OpenVPN server in a distant location (not a commercial VPN, just a server at another home). But I want it such that anything connected to it can ONLY send and receive data via the VPN, and NEVER under any circumstances via the local Internet connection. If for some reason the VPN isn't working, then as far as anything connected to the router is concerned the Internet should be down. We've seen this described as a "kill switch" and have found several pages that describe how to set one up (mostly by adding obscure lines to iptables) but none seem at all applicable to FreshTomato.

If possible please keep the explanation as simple as possible because I am no networking guru! This is for connecting one home to another. For example if something has to be done with iptables then I need to know how to do that and exactly what to put there, since I don't see anything about iptables in the FreshTomato configuration (does FreshTomato even use it?). To be honest I was hoping to find a checkbox somewhere in the VPN client configuration that said something like "limit connected devices to using this VPN only" or words to that effect, but of course it is never that simple. I actually feel like this is something that should be really easy but I just haven't found the way to do it."

But now obviously it would be with the john9527-LTS firmware.

Thanks
 
DDWRT has OpenVPN and a kill switch in the GUI but honestly if you already have FT running I would ask on their forum. They are usually very helpful

Advantage of DDWRT is they also have WireGuard on most routers which is faster and easy to setup
 
DDWRT has OpenVPN and a kill switch in the GUI but honestly if you already have FT running I would ask on their forum. They are usually very helpful

Advantage of DDWRT is they also have WireGuard on most routers which is faster and easy to setup
Can you recommend a build of DD-WRT that works on the RT-N66U, I moved away from DD-WRT on that router years ago because I had nothing but issues.

Also I did ask in the Fresh Tomato Forum and I can't get any responds at all.
 
I have my AC68U running DDWRT because I needed faster VPN then the 30 Mb/s OpenVPN gave me and now with WireGuard I get around 100 MB/s, I am running the latest build 51154 without a problem but an AC68U is not the same as your RT-N66U, yours is MIPS older and slower.
On the FT forum is a user which switched to the latest DDWRT and reported it working, on the DDWRT forum read the forum guidelines, first forum first thread with useful information or just ask they will help you.
I am considering stepping up to a GT-AX6000 now WireGuard is finally available :)
 
I am not having much luck with this FreshTomato, if I switch to john9527-LTS firmware, can anyone tell me how I can do the following under that firmware?
I believe the following options should work for you.

Untitled.png
 
I tried updating to John's fork from Merlin 380.70, but the router gives an error about certificates and new regulations and refuses to upgrade.
Do I need to downgrade Merlin first to some specific version?
I tried both the oldest John's version RT-N66U_374.43_41EAj9527.trx and the newest RT-N66U_374.43_52E7j9527.trx
 
I tried updating to John's fork from Merlin 380.70, but the router gives an error about certificates and new regulations and refuses to upgrade.
Do I need to downgrade Merlin first to some specific version?
I tried both the oldest John's version RT-N66U_374.43_41EAj9527.trx and the newest RT-N66U_374.43_52E7j9527.trx
You need to flash the firmware with the router in rescue mode. This is mentioned in the installation instructions.
 
You need to flash the firmware with the router in rescue mode. This is mentioned in the installation instructions.
Ah, thank you! I didn't see this in the README or the release notes.
Another question: as the fork is based on 374.43 from 2014, did it pull in changes from the later from the main branch 380.70, where the last update was in 2018? Or should it be treated as a completely different beast?
 
Ah, thank you! I didn't see this in the README or the release notes.
Another question: as the fork is based on 374.43 from 2014, did it pull in changes from the later from the main branch 380.70, where the last update was in 2018? Or should it be treated as a completely different beast?
John used to monitor the changes that RMerlin was doing to his firmware (beyond even 380.70) and if appropriate apply them to his firmware. So as well as package updates you also got bug fixes, security updates, etc. He did not change the base GPL or add new features as that is against the LTS principle of this firmware. So this is a patched 374 firmware and not a 380 firmware.
 
Similar threads
Thread starter Title Forum Replies Date
L Can an original 2022 Asus Wrt be safe? Asuswrt-Merlin 25

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top