101

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Przecież ci napisał:

Options error: No client-side authentication method is specified.  You must use either --cert/--key, --pkcs12, or --auth-user-pass

Zepsułeś konfig, bo nie ma certyfikatu lub hasła.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

102

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dziwne, zrobiłem identycznie jak ostatnio w routerze NEXX, haslo jest dobre,a certyfikat chyba jest w pliku .ovpn ktory tez jest na routerze.

103

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Albo nie zmodyfikowałeś auth-user-pass

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

104

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

masakra, co ślepemu po oczach, jednego slesha zjadłem

105

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Cześć
Może ktoś pomoże a mianowicie vpn działa mi z jakieś pól godziny a potem przestaje, i mam brak netu restart routera pomaga, w logread jako ostatnie mam:

daemon.notice netifd: wan (1551): udhcpc: sending renew to 89.249.14.162

ale wcześniej jest jeszcze to:

Fri Feb 15 20:28:25 2019 daemon.notice netifd: wan (1551): udhcpc: sending renew to 89.249.14.162
Fri Feb 15 20:28:25 2019 daemon.notice netifd: wan (1551): udhcpc: lease of 100.82.35.149 obtained, lease time 3600

proszę o wyrozumiałość jestem mało zaawansowanym użytkownikiem.

106

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

W/w komunikaty są normalnie, masz jakiś wan na dhcp, co jakiś czas następuje odświeżenie dzierżawy.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

107

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Tzn musi się tak wieszać i nie ma na to żadnej rady? bardzo irytujące przy oglądaniu na netflixie

po tym komunikacie na końcu:

daemon.notice netifd: wan (1551): udhcpc: sending renew to 89.249.14.162

to już się nic nie dzieje do póki nie zrestartuje routera, tak jak by się nie odświeżało

108

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Sprawdziłeś co w końcu ci siada? Jeżeli wan nie odświeża adresu i w ogóle nie masz internetu to wal do dostawcy. Jeżeli zaś vpn się zawiesza przy odnowieniu wanu to sobie zrób skrypt który restartuje openvpn.  Przykład takiego skryptu masz np. tutaj: https://github.com/ericpaulbishop/gargo … 27-openvpn

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

109

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Witam. Mam wykupionego klienta nordvpn. Próbowałem zrobić według ich configów ale nie chciało ruszyć. Zrobiłem według @Cezarego i w końcu ruszył vpn, ale po chwili nie mam nigdzie internetu. Po restarcie brak internetu. Wyłączenie custom config internet powraca. Wersja @cezarego OpenWrt 18.06 luci.
To są logi po restarcie:

root@OpenWrt:~# logread
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is enabled
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' is enabled
Thu Jul  4 18:52:00 2019 daemon.notice netifd: bridge 'br-lan' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'lan' has link connectivity
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Network device 'eth0' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: VLAN 'eth0.1' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Network device 'lo' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'loopback' has link connectivity
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Network device 'eth1' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: VLAN 'eth1.2' link is up
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan' has link connectivity
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is setting up now
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' has link connectivity
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan6' is setting up now
Thu Jul  4 18:52:00 2019 user.notice firewall: Reloading firewall due to ifup of lan (br-lan)
Thu Jul  4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: started, v1.28.4
Thu Jul  4 18:52:00 2019 daemon.err odhcp6c[2027]: Failed to send RS (Address not available)
Thu Jul  4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: sending discover
Thu Jul  4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: sending select for 10.9.146.169
Thu Jul  4 18:52:00 2019 daemon.notice netifd: wan (2023): udhcpc: lease of 10.9.146.169 obtained, lease time 3600
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688694] ieee80211 phy1: regdomain: ETSI
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688701] ieee80211 phy1: Channel: 1: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688706] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688709] ieee80211 phy1: Channel: 2: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688714] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688717] ieee80211 phy1: Channel: 3: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688722] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688725] ieee80211 phy1: Channel: 4: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688730] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688732] ieee80211 phy1: Channel: 5: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688737] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688740] ieee80211 phy1: Channel: 6: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688745] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688748] ieee80211 phy1: Channel: 7: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688753] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688756] ieee80211 phy1: Channel: 8: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688760] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688763] ieee80211 phy1: Channel: 9: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688768] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688771] ieee80211 phy1: Channel: 10: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688776] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688779] ieee80211 phy1: Channel: 11: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688784] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688787] ieee80211 phy1: Channel: 12: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688792] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688795] ieee80211 phy1: Channel: 13: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688799] ieee80211 phy1: a a a a a a a a a a a a 0 0 0 0
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688820] ieee80211 phy0: regdomain: ETSI
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688823] ieee80211 phy0: Channel: 36: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688828] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688833] ieee80211 phy0: Channel: 40: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688840] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688843] ieee80211 phy0: Channel: 44: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688848] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688850] ieee80211 phy0: Channel: 48: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688855] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688858] ieee80211 phy0: Channel: 52: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688863] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688874] ieee80211 phy0: Channel: 56: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688888] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688901] ieee80211 phy0: Channel: 60: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688907] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688917] ieee80211 phy0: Channel: 64: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688929] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688933] ieee80211 phy0: Channel: 100: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688938] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688941] ieee80211 phy0: Channel: 104: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688946] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688949] ieee80211 phy0: Channel: 108: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688961] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688974] ieee80211 phy0: Channel: 112: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.688994] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689001] ieee80211 phy0: Channel: 116: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689021] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689025] ieee80211 phy0: Channel: 120: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689030] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689033] ieee80211 phy0: Channel: 124: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689038] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689041] ieee80211 phy0: Channel: 128: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689046] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689048] ieee80211 phy0: Channel: 132: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689053] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689066] ieee80211 phy0: Channel: 136: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689075] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689079] ieee80211 phy0: Channel: 140: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689087] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689091] ieee80211 phy0: Channel: 149: 0x0 0x0 0xf
Thu Jul  4 18:52:00 2019 kern.debug kernel: [   13.689096] ieee80211 phy0: d d d d d d d d e e e e e e e e
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/dhcp
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/network reload dependency on /etc/config/radvd
Thu Jul  4 18:52:00 2019 user.notice mac80211: Failed command: iw phy phy0 set antenna all all
Thu Jul  4 18:52:00 2019 daemon.notice netifd: radio0 (1966): command failed: Not supported (-95)
Thu Jul  4 18:52:00 2019 user.notice mac80211: Failed command: iw phy phy0 set distance 0
Thu Jul  4 18:52:00 2019 daemon.notice netifd: Interface 'wan' is now up
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: reading /tmp/resolv.conf.auto
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain test
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain onion
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain localhost
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain local
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain invalid
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain bind
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using local addresses only for domain lan
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using nameserver 83.175.144.9#53
Thu Jul  4 18:52:00 2019 daemon.info dnsmasq[1685]: using nameserver 83.175.144.14#53
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/wireless reload dependency on /etc/config/network
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/luci-splash
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/qos
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/firewall reload dependency on /etc/config/miniupnpd
Thu Jul  4 18:52:00 2019 user.notice firewall: Reloading firewall due to ifup of wan (eth1.2)
Thu Jul  4 18:52:00 2019 daemon.err hostapd: Configuration file: /var/run/hostapd-phy0.conf
Thu Jul  4 18:52:00 2019 user.notice ucitrack: Setting up /etc/config/dhcp reload dependency on /etc/config/odhcpd
Thu Jul  4 18:52:01 2019 user.notice ucitrack: Setting up non-init /etc/config/fstab reload handler: /sbin/block mount
Thu Jul  4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload trigger for non-procd /etc/init.d/led
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.056305] ieee80211 phy0: change: 0xffffffff
Thu Jul  4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/luci_statistics
Thu Jul  4 18:52:01 2019 daemon.err odhcp6c[2027]: Failed to send DHCPV6 message to ff02::1:2 (Address not available)
Thu Jul  4 18:52:01 2019 user.notice ucitrack: Setting up /etc/config/system reload dependency on /etc/config/dhcp
Thu Jul  4 18:52:01 2019 kern.info kernel: [   14.194376] IPv6: ADDRCONF(NETDEV_UP): wlan0: link is not ready
Thu Jul  4 18:52:01 2019 kern.info kernel: [   14.200360] IPv6: ADDRCONF(NETDEV_CHANGE): br-lan: link becomes ready
Thu Jul  4 18:52:01 2019 kern.info kernel: [   14.216581] br-lan: port 2(wlan0) entered blocking state
Thu Jul  4 18:52:01 2019 kern.info kernel: [   14.221959] br-lan: port 2(wlan0) entered disabled state
Thu Jul  4 18:52:01 2019 kern.info kernel: [   14.227427] device wlan0 entered promiscuous mode
Thu Jul  4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state UNINITIALIZED->COUNTRY_UPDATE
Thu Jul  4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state COUNTRY_UPDATE->HT_SCAN
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.252993] ieee80211 phy0: change: 0x100
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.261468] ieee80211 phy0: change: 0x60
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: OpenVPN 2.4.5 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: library versions: OpenSSL 1.0.2s  28 May 2019, LZO 2.10
Thu Jul  4 18:52:01 2019 daemon.warn openvpn(custom_config)[2895]: WARNING: --ping should normally be used with --ping-restart or --ping-exit
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: TCP/UDP: Preserving recently used remote address: [AF_INET]95.174.67.211:1194
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Socket Buffers: R=[163840->163840] S=[163840->163840]
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: UDP link local: (not bound)
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: UDP link remote: [AF_INET]95.174.67.211:1194
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: TLS: Initial packet from [AF_INET]95.174.67.211:1194, sid=a19ad2bc 321f1a26
Thu Jul  4 18:52:01 2019 daemon.warn openvpn(custom_config)[2895]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu Jul  4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led WAN
Thu Jul  4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 1
Thu Jul  4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 2
Thu Jul  4 18:52:01 2019 daemon.notice procd: /etc/rc.d/S96led: setting up led USB 2 SS
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA3
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY KU OK
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Validating certificate extended key usage
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY EKU OK
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: VERIFY OK: depth=0, CN=nl370.nordvpn.com
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.531297] ieee80211 phy0: change: 0x40
Thu Jul  4 18:52:01 2019 user.notice mac80211: Failed command: iw phy phy1 set antenna all all
Thu Jul  4 18:52:01 2019 daemon.notice netifd: radio1 (1967): command failed: Not supported (-95)
Thu Jul  4 18:52:01 2019 user.notice mac80211: Failed command: iw phy phy1 set distance 0
Thu Jul  4 18:52:01 2019 user.notice ddns-scripts[2598]: myddns_ipv4: PID '2598' started at 2019-07-04 18:52
Thu Jul  4 18:52:01 2019 daemon.notice hostapd: wlan0: interface state HT_SCAN->DFS
Thu Jul  4 18:52:01 2019 daemon.notice hostapd: wlan0: DFS-CAC-START freq=5260 chan=52 sec_chan=1, width=1, seg0=58, seg1=0, cac_time=60s
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.751352] ieee80211 phy0: change: 0x60
Thu Jul  4 18:52:01 2019 daemon.info procd: - init complete -
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA
Thu Jul  4 18:52:01 2019 daemon.notice openvpn(custom_config)[2895]: [nl370.nordvpn.com] Peer Connection Initiated with [AF_INET]95.174.67.211:1194
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.855515] ieee80211 phy0: change: 0x100
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.864614] ieee80211 phy0: change: 0x100
Thu Jul  4 18:52:01 2019 kern.debug kernel: [   14.873664] ieee80211 phy0: change: 0x42
Thu Jul  4 18:52:02 2019 kern.debug kernel: [   14.979353] ieee80211 phy0: change: 0x40
Thu Jul  4 18:52:02 2019 daemon.err hostapd: Configuration file: /var/run/hostapd-phy1.conf
Thu Jul  4 18:52:02 2019 kern.debug kernel: [   15.206300] ieee80211 phy1: change: 0xffffffff
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.323604] IPv6: ADDRCONF(NETDEV_UP): wlan1: link is not ready
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.331087] br-lan: port 3(wlan1) entered blocking state
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.336466] br-lan: port 3(wlan1) entered disabled state
Thu Jul  4 18:52:02 2019 daemon.notice hostapd: wlan1: interface state UNINITIALIZED->COUNTRY_UPDATE
Thu Jul  4 18:52:02 2019 daemon.err hostapd: Using interface wlan1 with hwaddr 16:91:82:31:94:04 and ssid "HIUMAN"
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.341966] device wlan1 entered promiscuous mode
Thu Jul  4 18:52:02 2019 kern.debug kernel: [   15.412384] ieee80211 phy1: change: 0x100
Thu Jul  4 18:52:02 2019 kern.debug kernel: [   15.421327] ieee80211 phy1: change: 0x42
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.588751] IPv6: ADDRCONF(NETDEV_CHANGE): wlan1: link becomes ready
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.595214] br-lan: port 3(wlan1) entered blocking state
Thu Jul  4 18:52:02 2019 kern.info kernel: [   15.600550] br-lan: port 3(wlan1) entered forwarding state
Thu Jul  4 18:52:02 2019 daemon.notice hostapd: wlan1: interface state COUNTRY_UPDATE->ENABLED
Thu Jul  4 18:52:02 2019 daemon.notice hostapd: wlan1: AP-ENABLED
Thu Jul  4 18:52:02 2019 user.warn ddns-scripts[2598]: myddns_ipv4: Service section disabled! - TERMINATE
Thu Jul  4 18:52:02 2019 daemon.notice netifd: Network device 'wlan1' link is up
Thu Jul  4 18:52:02 2019 user.warn ddns-scripts[2598]: myddns_ipv4: PID '2598' exit WITH ERROR '1' at 2019-07-04 18:52
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: SENT CONTROL [nl370.nordvpn.com]: 'PUSH_REQUEST' (status=1)
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 103.86.96.100,dhcp-option DNS 103.86.99.100,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway 10.8.2.1,topology subnet,ping 60,ping-restart 180,ifconfig 10.8.2.10 255.255.255.0,peer-id 8,cipher AES-256-GCM'
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: timers and/or timeouts modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: explicit notify parm(s) modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: compression parms modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Socket Buffers: R=[163840->327680] S=[163840->327680]
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --ifconfig/up options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: route options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: route-related options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: peer-id set
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: adjusting link_mtu to 1657
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: OPTIONS IMPORT: data channel crypto options modified
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Data Channel: using negotiated cipher 'AES-256-GCM'
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: TUN/TAP device tun0 opened
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: TUN/TAP TX queue length set to 100
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/ifconfig tun0 10.8.2.10 netmask 255.255.255.0 mtu 1500 broadcast 10.8.2.255
Thu Jul  4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is enabled
Thu Jul  4 19:13:26 2019 daemon.notice netifd: Network device 'tun0' link is up
Thu Jul  4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' has link connectivity
Thu Jul  4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is setting up now
Thu Jul  4 19:13:26 2019 daemon.notice netifd: Interface 'vpn' is now up
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 95.174.67.211 netmask 255.255.255.255 gw 10.9.147.254
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.8.2.1
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.8.2.1
Thu Jul  4 19:13:26 2019 daemon.notice openvpn(custom_config)[2895]: Initialization Sequence Completed
Thu Jul  4 19:13:26 2019 user.notice firewall: Reloading firewall due to ifup of vpn (tun0)
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[1685]: exiting on receipt of SIGTERM
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: started, version 2.80 cachesize 150
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: DNS service limited to local subnets
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: compile time options: IPv6 GNU-getopt no-DBus no-i18n no-IDN DHCP no-DHCPv6 no-Lua TFTP no-conntrack no-ipset no-auth no-DNSSEC no-ID loop-detect inotify dumpfile
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq-dhcp[4354]: DHCP, IP range 192.168.1.100 -- 192.168.1.249, lease time 12h
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain test
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain onion
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain localhost
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain local
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain invalid
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain bind
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain lan
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: reading /tmp/resolv.conf.auto
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain test
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain onion
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain localhost
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain local
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain invalid
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain bind
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using local addresses only for domain lan
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using nameserver 83.175.144.9#53
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: using nameserver 83.175.144.14#53
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul  4 19:13:28 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul  4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 IEEE 802.11: authenticated
Thu Jul  4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 IEEE 802.11: associated (aid 1)
Thu Jul  4 19:13:31 2019 daemon.notice hostapd: wlan1: AP-STA-CONNECTED 88:32:9b:b8:ff:d9
Thu Jul  4 19:13:31 2019 daemon.info hostapd: wlan1: STA 88:32:9b:b8:ff:d9 WPA: pairwise key handshake completed (RSN)
Thu Jul  4 19:13:32 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.205 88:32:9b:b8:ff:d9
Thu Jul  4 19:13:32 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.205 88:32:9b:b8:ff:d9 android-390527fd6d0f0b05
Thu Jul  4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPDISCOVER(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul  4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPOFFER(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul  4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab
Thu Jul  4 19:13:39 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.247 00:90:a9:e8:cf:ab WdMyCloud
Thu Jul  4 19:14:30 2019 kern.debug kernel: [   79.831249] ieee80211 phy0: change: 0x40
Thu Jul  4 19:14:30 2019 kern.info kernel: [   79.854776] nf_conntrack: default automatic helper assignment has been turned off for security reasons and CT-based  firewall rule not found. Use the iptables CT target to attach helpers instead.
Thu Jul  4 19:14:30 2019 kern.debug kernel: [   79.950251] ieee80211 phy0: change: 0x100
Thu Jul  4 19:14:30 2019 daemon.notice hostapd: wlan0: DFS-CAC-COMPLETED success=1 freq=5260 ht_enabled=0 chan_offset=0 chan_width=3 cf1=5290 cf2=0
Thu Jul  4 19:14:30 2019 daemon.err hostapd: Using interface wlan0 with hwaddr 16:91:82:31:94:05 and ssid "HIUMAN_5GHz"
Thu Jul  4 19:14:30 2019 kern.debug kernel: [   80.012407] ieee80211 phy0: change: 0x100
Thu Jul  4 19:14:30 2019 kern.debug kernel: [   80.021242] ieee80211 phy0: change: 0x42
Thu Jul  4 19:14:31 2019 kern.debug kernel: [   80.125251] ieee80211 phy0: change: 0x40
Thu Jul  4 19:14:31 2019 kern.info kernel: [   80.319376] IPv6: ADDRCONF(NETDEV_CHANGE): wlan0: link becomes ready
Thu Jul  4 19:14:31 2019 kern.info kernel: [   80.325864] br-lan: port 2(wlan0) entered blocking state
Thu Jul  4 19:14:31 2019 kern.info kernel: [   80.331205] br-lan: port 2(wlan0) entered forwarding state
Thu Jul  4 19:14:31 2019 daemon.notice hostapd: wlan0: interface state DFS->ENABLED
Thu Jul  4 19:14:31 2019 daemon.notice hostapd: wlan0: AP-ENABLED
Thu Jul  4 19:14:31 2019 daemon.notice netifd: Network device 'wlan0' link is up
Thu Jul  4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 IEEE 802.11: authenticated
Thu Jul  4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 IEEE 802.11: associated (aid 2)
Thu Jul  4 19:15:06 2019 daemon.notice hostapd: wlan1: AP-STA-CONNECTED b4:cd:27:a3:ed:01
Thu Jul  4 19:15:06 2019 daemon.info hostapd: wlan1: STA b4:cd:27:a3:ed:01 WPA: pairwise key handshake completed (RSN)
Thu Jul  4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01
Thu Jul  4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01 Honor_9_Lite-f4617896554a
Thu Jul  4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01
Thu Jul  4 19:15:07 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.123 b4:cd:27:a3:ed:01 Honor_9_Lite-f4617896554a
Thu Jul  4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 IEEE 802.11: authenticated
Thu Jul  4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 IEEE 802.11: associated (aid 1)
Thu Jul  4 19:15:09 2019 daemon.notice hostapd: wlan0: AP-STA-CONNECTED f0:03:8c:d8:a9:d5
Thu Jul  4 19:15:09 2019 daemon.info hostapd: wlan0: STA f0:03:8c:d8:a9:d5 WPA: pairwise key handshake completed (RSN)
Thu Jul  4 19:15:09 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:09 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul  4 19:15:09 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 0 addresses
Thu Jul  4 19:15:09 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul  4 19:15:09 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul  4 19:15:10 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:11 2019 daemon.warn odhcpd[1825]: DHCPV6 REQUEST IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:11 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul  4 19:15:11 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 1 addresses
Thu Jul  4 19:15:11 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul  4 19:15:11 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul  4 19:15:12 2019 daemon.warn odhcpd[1825]: DHCPV6 CONFIRM IA_NA from 000100012479923188d7f6969cb2 on br-lan: not on-link fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:12 2019 daemon.warn odhcpd[1825]: DHCPV6 SOLICIT IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:12 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul  4 19:15:12 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 0 addresses
Thu Jul  4 19:15:12 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul  4 19:15:12 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul  4 19:15:13 2019 daemon.warn odhcpd[1825]: DHCPV6 REQUEST IA_NA from 000100012479923188d7f6969cb2 on br-lan: ok fd8c:72b0:d940::bca/128
Thu Jul  4 19:15:13 2019 daemon.info dnsmasq[4354]: read /etc/hosts - 4 addresses
Thu Jul  4 19:15:13 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/odhcpd - 1 addresses
Thu Jul  4 19:15:13 2019 daemon.info dnsmasq[4354]: read /tmp/hosts/dhcp.cfg01411c - 4 addresses
Thu Jul  4 19:15:13 2019 daemon.info dnsmasq-dhcp[4354]: read /etc/ethers - 0 addresses
Thu Jul  4 19:15:14 2019 kern.debug kernel: [  123.674398] ieee80211 phy0: Mac80211 start BA f0:03:8c:d8:a9:d5
Thu Jul  4 19:15:14 2019 daemon.info dnsmasq-dhcp[4354]: DHCPREQUEST(br-lan) 192.168.1.129 f0:03:8c:d8:a9:d5
Thu Jul  4 19:15:14 2019 daemon.info dnsmasq-dhcp[4354]: DHCPACK(br-lan) 192.168.1.129 f0:03:8c:d8:a9:d5 DESKTOP-OC3A6OM
Thu Jul  4 19:16:01 2019 daemon.err uhttpd[1919]: luci: accepted login on /admin for root from 192.168.1.129
root@OpenWrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula_prefix='fd8c:72b0:d940::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0.1'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.ifname='eth1.2'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.ifname='eth1.2'
network.wan6.proto='dhcpv6'
network.@switch[0]=switch
network.@switch[0].name='switch0'
network.@switch[0].reset='1'
network.@switch[0].enable_vlan='1'
network.@switch_vlan[0]=switch_vlan
network.@switch_vlan[0].device='switch0'
network.@switch_vlan[0].vlan='1'
network.@switch_vlan[0].ports='0 1 2 3 5t'
network.@switch_vlan[1]=switch_vlan
network.@switch_vlan[1].device='switch0'
network.@switch_vlan[1].vlan='2'
network.@switch_vlan[1].ports='4 6t'
network.vpn=interface
network.vpn.ifname='tun0'
network.vpn.proto='none'
 root@OpenWrt:~# uci show firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='REJECT'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].network='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].network='wan' 'wan6'
firewall.@zone[1].input='REJECT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].forward='REJECT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].src='lan'
firewall.@forwarding[0].dest='wan'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@zone[2]=zone
firewall.@zone[2].name='vpn'
firewall.@zone[2].input='ACCEPT'
firewall.@zone[2].forward='ACCEPT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].network='vpn'
firewall.@zone[2].masq='1'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].src='lan'
firewall.@forwarding[1].dest='vpn'
client
dev tun
proto udp
remote 95.174.67.211 1194
remote 185.104.184.228 1194
remote 192.230.46.140 1194
remote 193.9.113.133 1194
resolv-retry 10
remote-random
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no

remote-cert-tls server

auth-user-pass /etc/openvpn/secret.txt
verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512

<ca>
-----BEGIN CERTIFICATE-----
MIIFCjCCAvKgAwIBAgIBATANBgkqhkiG9w0BAQ0FADA5MQswCQYDVQQGEwJQQTEQ
MA4GA1UEChMHTm9yZFZQTjEYMBYGA1UEAxMPTm9yZFZQTiBSb290IENBMB4XDTE2
MDEwMTAwMDAwMFoXDTM1MTIzMTIzNTk1OVowOTELMAkGA1UEBhMCUEExEDAOBgNV
BAoTB05vcmRWUE4xGDAWBgNVBAMTD05vcmRWUE4gUm9vdCBDQTCCAiIwDQYJKoZI
hvcNAQEBBQADggIPADCCAgoCggIBAMkr/BYhyo0F2upsIMXwC6QvkZps3NN2/eQF
kfQIS1gql0aejsKsEnmY0Kaon8uZCTXPsRH1gQNgg5D2gixdd1mJUvV3dE3y9FJr
XMoDkXdCGBodvKJyU6lcfEVF6/UxHcbBguZK9UtRHS9eJYm3rpL/5huQMCppX7kU
eQ8dpCwd3iKITqwd1ZudDqsWaU0vqzC2H55IyaZ/5/TnCk31Q1UP6BksbbuRcwOV
skEDsm6YoWDnn/IIzGOYnFJRzQH5jTz3j1QBvRIuQuBuvUkfhx1FEwhwZigrcxXu
MP+QgM54kezgziJUaZcOM2zF3lvrwMvXDMfNeIoJABv9ljw969xQ8czQCU5lMVmA
37ltv5Ec9U5hZuwk/9QO1Z+d/r6Jx0mlurS8gnCAKJgwa3kyZw6e4FZ8mYL4vpRR
hPdvRTWCMJkeB4yBHyhxUmTRgJHm6YR3D6hcFAc9cQcTEl/I60tMdz33G6m0O42s
Qt/+AR3YCY/RusWVBJB/qNS94EtNtj8iaebCQW1jHAhvGmFILVR9lzD0EzWKHkvy
WEjmUVRgCDd6Ne3eFRNS73gdv/C3l5boYySeu4exkEYVxVRn8DhCxs0MnkMHWFK6
MyzXCCn+JnWFDYPfDKHvpff/kLDobtPBf+Lbch5wQy9quY27xaj0XwLyjOltpiST
LWae/Q4vAgMBAAGjHTAbMAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMA0GCSqG
SIb3DQEBDQUAA4ICAQC9fUL2sZPxIN2mD32VeNySTgZlCEdVmlq471o/bDMP4B8g
DxsT9vB/iZriTIEe/ILoOQF0Aqp7AgNCcLcLAmbxXQkXYCCSB35Vp06u+eTWjG0/
pyS5V14stGtw+fA0DJp5ZJV4eqJ5LqxMlYvEZ/qKTEdoCeaXv2QEmN6dVqjDoTAo
k0t5u4YRXzEVCfXAC3ocplNdtCA72wjFJcSbfif4BSC8bDACTXtnPC7nD0VndZLp
+RiNLeiENhk0oTC+UVdSc+n2nJOzkCK0vYu0Ads4JGIB7g8IB3z2t9ICmsWrgnhd
NdcOe15BincrGA8avQ1cWXsfIKEjbrnEuEk9b5jel6NfHtPKoHc9mDpRdNPISeVa
wDBM1mJChneHt59Nh8Gah74+TM1jBsw4fhJPvoc7Atcg740JErb904mZfkIEmojC
VPhBHVQ9LHBAdM8qFI2kRK0IynOmAZhexlP/aT/kpEsEPyaZQlnBn3An1CRz8h0S
PApL8PytggYKeQmRhl499+6jLxcZ2IegLfqq41dzIjwHwTMplg+1pKIOVojpWA==
-----END CERTIFICATE-----
</ca>
key-direction 1
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
e685bdaf659a25a200e2b9e39e51ff03
0fc72cf1ce07232bd8b2be5e6c670143
f51e937e670eee09d4f2ea5a6e4e6996
5db852c275351b86fc4ca892d78ae002
d6f70d029bd79c4d1c26cf14e9588033
cf639f8a74809f29f72b9d58f9b8f5fe
fc7938eade40e9fed6cb92184abb2cc1
0eb1a296df243b251df0643d53724cdb
5a92a1d6cb817804c4a9319b57d53be5
80815bcfcb2df55018cc83fc43bc7ff8
2d51f9b88364776ee9d12fc85cc7ea5b
9741c4f598c485316db066d52db4540e
212e1518a9bd4828219e24b20d88f598
9427e7b372d348d352dc4c85e18cd4b9
3f8a56ddb2e64eb67adfc9b337157ff4
-----END OpenVPN Static key V1-----
</tls-auth>

110

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Wg niego on się połączył.

Sprawdź ten konfig openvpn na zwykłym windowsie czy działa i masz po nawiązaniu połączenia internet.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

111

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Tak łączy się i działa bez problemu bo używam go na kompie. Może trzeba coś w openwrt kliknąć. Ja dopiero zaczynam przygodę z openwrt dla tego moja wiedza jest 0.

112

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Nie, on się połączył. Pokaż po restarcie wyniki poleceń będąc zalogowanym do routera:

ifconfig
route -n
ping 8.8.8.8
ping google.com

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

113

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

root@OpenWrt:~# ifconfig
br-lan    Link encap:Ethernet  HWaddr 16:91:82:31:94:03
          inet addr:192.168.1.1  Bcast:192.168.1.255  Mask:255.255.255.0
          inet6 addr: fe80::1491:82ff:fe31:9403/64 Scope:Link
          inet6 addr: fd8c:72b0:d940::1/60 Scope:Global
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1228 errors:0 dropped:0 overruns:0 frame:0
          TX packets:600 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:208972 (204.0 KiB)  TX bytes:167735 (163.8 KiB)

eth0      Link encap:Ethernet  HWaddr 16:91:82:31:94:03
          inet6 addr: fe80::1491:82ff:fe31:9403/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:765 errors:0 dropped:0 overruns:0 frame:0
          TX packets:770 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:532
          RX bytes:220359 (215.1 KiB)  TX bytes:132525 (129.4 KiB)
          Interrupt:37

eth0.1    Link encap:Ethernet  HWaddr 16:91:82:31:94:03
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:759 errors:0 dropped:0 overruns:0 frame:0
          TX packets:748 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:205671 (200.8 KiB)  TX bytes:126451 (123.4 KiB)

eth1      Link encap:Ethernet  HWaddr 14:91:82:31:94:03
          inet6 addr: fe80::1691:82ff:fe31:9403/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1648 errors:0 dropped:0 overruns:0 frame:0
          TX packets:732 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:532
          RX bytes:228737 (223.3 KiB)  TX bytes:132786 (129.6 KiB)
          Interrupt:36

eth1.2    Link encap:Ethernet  HWaddr 14:91:82:31:94:03
          inet addr:10.9.146.169  Bcast:10.9.147.255  Mask:255.255.252.0
          inet6 addr: fe80::1691:82ff:fe31:9403/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1638 errors:0 dropped:0 overruns:0 frame:0
          TX packets:725 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:198577 (193.9 KiB)  TX bytes:129060 (126.0 KiB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:65536  Metric:1
          RX packets:33 errors:0 dropped:0 overruns:0 frame:0
          TX packets:33 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:3318 (3.2 KiB)  TX bytes:3318 (3.2 KiB)

tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
          inet addr:10.8.0.13  P-t-P:10.8.0.13  Mask:255.255.255.0
          inet6 addr: fe80::12a5:c5ee:92ef:bd11/64 Scope:Link
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
          RX packets:26 errors:0 dropped:0 overruns:0 frame:0
          TX packets:161 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:8355 (8.1 KiB)  TX bytes:14434 (14.0 KiB)

wlan0     Link encap:Ethernet  HWaddr 16:91:82:31:94:05
          inet6 addr: fe80::1491:82ff:fe31:9405/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:548 errors:0 dropped:0 overruns:0 frame:0
          TX packets:805 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:74433 (72.6 KiB)  TX bytes:272301 (265.9 KiB)

wlan1     Link encap:Ethernet  HWaddr 16:91:82:31:94:04
          inet6 addr: fe80::1491:82ff:fe31:9404/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:222 errors:0 dropped:0 overruns:0 frame:0
          TX packets:752 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:68250 (66.6 KiB)  TX bytes:205564 (200.7 KiB)
root@OpenWrt:~# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.8.0.1        128.0.0.0       UG    0      0        0 tun0
0.0.0.0         10.9.147.254    0.0.0.0         UG    0      0        0 eth1.2
10.8.0.0        0.0.0.0         255.255.255.0   U     0      0        0 tun0
10.9.144.0      0.0.0.0         255.255.252.0   U     0      0        0 eth1.2
95.174.67.211   10.9.147.254    255.255.255.255 UGH   0      0        0 eth1.2
128.0.0.0       10.8.0.1        128.0.0.0       UG    0      0        0 tun0
192.168.1.0     0.0.0.0         255.255.255.0   U     0      0        0 br-lan
root@OpenWrt:~# ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes
64 bytes from 8.8.8.8: seq=0 ttl=50 time=46.717 ms
64 bytes from 8.8.8.8: seq=1 ttl=50 time=45.272 ms
64 bytes from 8.8.8.8: seq=3 ttl=50 time=44.686 ms
64 bytes from 8.8.8.8: seq=4 ttl=50 time=46.467 ms
64 bytes from 8.8.8.8: seq=5 ttl=50 time=44.803 ms
64 bytes from 8.8.8.8: seq=6 ttl=50 time=44.950 ms
64 bytes from 8.8.8.8: seq=7 ttl=50 time=45.047 ms
64 bytes from 8.8.8.8: seq=8 ttl=50 time=46.032 ms
64 bytes from 8.8.8.8: seq=9 ttl=50 time=71.139 ms
64 bytes from 8.8.8.8: seq=10 ttl=50 time=45.030 ms
64 bytes from 8.8.8.8: seq=11 ttl=50 time=44.839 ms
64 bytes from 8.8.8.8: seq=12 ttl=50 time=44.662 ms
64 bytes from 8.8.8.8: seq=13 ttl=50 time=45.678 ms
64 bytes from 8.8.8.8: seq=14 ttl=50 time=45.377 ms
64 bytes from 8.8.8.8: seq=15 ttl=50 time=45.007 ms
64 bytes from 8.8.8.8: seq=16 ttl=50 time=45.631 ms
64 bytes from 8.8.8.8: seq=17 ttl=50 time=46.032 ms
64 bytes from 8.8.8.8: seq=18 ttl=50 time=44.699 ms
64 bytes from 8.8.8.8: seq=19 ttl=50 time=46.178 ms
64 bytes from 8.8.8.8: seq=20 ttl=50 time=45.787 ms
64 bytes from 8.8.8.8: seq=21 ttl=50 time=44.774 ms
64 bytes from 8.8.8.8: seq=22 ttl=50 time=45.063 ms
64 bytes from 8.8.8.8: seq=23 ttl=50 time=46.147 ms
64 bytes from 8.8.8.8: seq=24 ttl=50 time=45.996 ms
64 bytes from 8.8.8.8: seq=25 ttl=50 time=44.961 ms
64 bytes from 8.8.8.8: seq=26 ttl=50 time=45.471 ms
64 bytes from 8.8.8.8: seq=27 ttl=50 time=44.874 ms
64 bytes from 8.8.8.8: seq=28 ttl=50 time=45.225 ms
64 bytes from 8.8.8.8: seq=29 ttl=50 time=45.505 ms
64 bytes from 8.8.8.8: seq=30 ttl=50 time=44.694 ms
64 bytes from 8.8.8.8: seq=31 ttl=50 time=44.776 ms
64 bytes from 8.8.8.8: seq=32 ttl=50 time=44.744 ms
64 bytes from 8.8.8.8: seq=33 ttl=50 time=45.227 ms
64 bytes from 8.8.8.8: seq=34 ttl=50 time=44.758 ms
64 bytes from 8.8.8.8: seq=35 ttl=50 time=45.254 ms
64 bytes from 8.8.8.8: seq=36 ttl=50 time=45.057 ms
64 bytes from 8.8.8.8: seq=37 ttl=50 time=44.925 ms
64 bytes from 8.8.8.8: seq=38 ttl=50 time=45.383 ms
64 bytes from 8.8.8.8: seq=39 ttl=50 time=45.688 ms
64 bytes from 8.8.8.8: seq=40 ttl=50 time=45.003 ms
root@OpenWrt:~# ping google.com
ping: bad address 'google.com'

114

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dnsów tylko nie masz. Ustaw sobie jakieś w systemie (np. 8.8.8.8)

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

115 (edytowany przez hiuman 2019-07-04 20:30:19)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

W routerze mam ustawić? Serwisy/dynamiczne dns - tutaj?

Edit:
Już znalazłem.

116

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Nie, http://eko.one.pl/?p=openwrt-dns#wasneserwerydns  i pull-filter ignore "dhcp-option DNS" w konfigu openvpn.

Lub wręcz po prostu ustaw na kliencie.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

117

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dodanie DNS do routera poskutkowało. Dzięki.
A możesz mi powiedzieć jak skonfigurować VPN Bypass tak żeby jedno urządzenie po lanie szło w tunelu a reszta urządzeń bez vpn. Nie wiem co gdzie w pisać. Będę wdzięczny za pomoc.

118

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

A tak jak wpisałem w routerze sieć/ghcp,dns/przekierowania dns , tak nie może być,bo niby działa net i jestem w tunelu.

119

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Nie używam, ale wg tego https://forum.openwrt.org/t/vpn-bypass- … ci-ui/1106 po prostu wpisujesz ip które nie mają iść przez tunel.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

120

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Ok dzięki,będę próbował.

121

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Witam. OpenVpn działa ale co jakiś czas zawiesza mi połączenie z internetem. Nie działa ani po wifi ani po lan. Przez jakiś czas mogę się łączyć z routerem i próbowałem różnych restartów sieci czy routera ale bez skutecznie. Pomaga jedynie przywrócenie ustawień domyślnych routera,ale muszę wtedy ponownie ustawiać wszystko od nowa. Próbowałem z tymi skryptami ale nie wznawiało się połączenie -
https://github.com/ericpaulbishop/gargo … 27-openvpn
https://nordvpn.com/pl/tutorials/openwrt/openvpn/
Raz pomogło wyłączenie custom config ale następne razy już to nie działało.

Mam też inny problem , napiszę tutaj ( jeśli łamię regulamin) to proszę o przeniesienie.
W jaki sposób zmusić Radio0 5ghz do zmiany kanału. Jeśli chcę zmienić kanał na 140 to radio w ogóle się nie włącza. Próbuję na innych kanałach i też nie działa radio0. Po kilku takich zmianach w końcu załapie i to przeważnie na 136 ale w rzeczywistości jest na 36. Czasem uda się zmienić na inny ale to jest wtedy wielki cud. Próbowałem komend wifi down radio0 i wifi up radio0 ale radio nadal jest wyłączone.

122 (edytowany przez Cezary 2019-07-06 07:00:58)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Jeżeli zawiesza ci połączenie (a jesteś pewien że router nadal działa) to pisz do dostawcy. Kupiłeś usługę.

Wyższe kanały w polsce są na DFS, a tam możesz tylko HT20 ustawić, inaczej radio się nie uruchomi. Jak się uruchomi już - musisz poczekać parę minut aż sterownik upewni się że nie ma żadnych przeszkód na tych kanałach i dopiero wifi wstanie. Tak wszystkie (zgodne) urządzenia działają. Jedynie te cztery najniższe kanały od 36 są bez DFS. Ponad to jeszcze w zależności o tego czy ustawiasz VHT40, 80 czy 160 możesz to zrobić tylko na określonych kanałach.

Na przyszłość nie zaśmiecaj wątków i nie pisz w tym samym tylko zrób dwa oddzielne tematy na forum.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

123

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Dzięki za wyjaśnienie.

124 (edytowany przez Paweł458 2019-07-11 15:12:29)

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

Witam,
Mam podobny problem z konfiguracją NordVPN dla klienta OpenVPN w OpenWrt.
Przeprowadziłem konfigurację linijka po linijce zgodnie z instrukcją (https://nordvpn.com/pl/tutorials/openwrt/openvpn/) i potwierdziłem wpisy w configach.
OpenVPN poprawnie się łączy (przynajmniej tak mi się wydaje) ale jednocześnie odcina mnie od internetu, tak samo nie mogę pingować np. 8.8.8.8 ani google.com bezpośrednio z terminala routera hmm

Dodam tylko że jak dodam "route-noexec" w configu OpenVPN to wprawdzie dalej mam internet ale ruch nie przechodzi przez tunel VPN tylko normalnie idzie i wychodzi z "mojego IP".
Jak resetuję firewalla to mam kilka warningów:

root@OpenWrt:~# /etc/init.d/firewall restart
Warning: Unable to locate ipset utility, disabling ipset support
Warning: Section @zone[1] (wan) cannot resolve device of network 'wan6'
Warning: Section @zone[2] (vpnfirewall) cannot resolve device of network 'nordvpntun'
Warning: Section @zone[2] (vpnfirewall) has no device, network, subnet or extra options
 * Flushing IPv4 filter table
 * Flushing IPv4 nat table
 * Flushing IPv4 mangle table
 * Flushing IPv6 filter table
 * Flushing IPv6 mangle table
 * Flushing conntrack table ...
 * Populating IPv4 filter table
   * Rule 'Allow-DHCP-Renew'
   * Rule 'Allow-Ping'
   * Rule 'Allow-IGMP'
   * Rule 'Allow-IPSec-ESP'
   * Rule 'Allow-ISAKMP'
   * Forward 'lan' -> 'wan'
   * Forward 'wan' -> 'lan'
   * Forward 'lan' -> 'vpnfirewall'
   * Zone 'lan'
   * Zone 'wan'
   * Zone 'vpnfirewall'
 * Populating IPv4 nat table
   * Zone 'lan'
   * Zone 'wan'
   * Zone 'vpnfirewall'
 * Populating IPv4 mangle table
   * Zone 'lan'
   * Zone 'wan'
   * Zone 'vpnfirewall'
 * Populating IPv6 filter table
   * Rule 'Allow-DHCPv6'
   * Rule 'Allow-MLD'
   * Rule 'Allow-ICMPv6-Input'
   * Rule 'Allow-ICMPv6-Forward'
   * Rule 'Allow-IPSec-ESP'
   * Rule 'Allow-ISAKMP'
   * Forward 'lan' -> 'wan'
   * Forward 'wan' -> 'lan'
   * Forward 'lan' -> 'vpnfirewall'
   * Zone 'lan'
   * Zone 'wan'
   * Zone 'vpnfirewall'
 * Populating IPv6 mangle table
   * Zone 'lan'
   * Zone 'wan'
   * Zone 'vpnfirewall'
 * Set tcp_ecn to off
 * Set tcp_syncookies to on
 * Set tcp_window_scaling to on
 * Running script '/etc/firewall.user'

Z góry dziękuję za pomoc smile

Log

root@OpenWrt:~# logread
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: OpenVPN 2.4.5 arm-openwrt-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: library versions: OpenSSL 1.0.2q  20 Nov 2018, LZO 2.10
Thu Jul 11 14:08:34 2019 daemon.warn openvpn(nordvpn)[17965]: WARNING: --ping should normally be used with --ping-restart or --ping-exit
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: TCP/UDP: Preserving recently used remote address: [AF_INET]185.230.127.27:1194
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: Socket Buffers: R=[163840->163840] S=[163840->163840]
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: UDP link local: (not bound)
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: UDP link remote: [AF_INET]185.230.127.27:1194
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: TLS: Initial packet from [AF_INET]185.230.127.27:1194, sid=bd053a8c ca58b1ee
Thu Jul 11 14:08:34 2019 daemon.warn openvpn(nordvpn)[17965]: WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: VERIFY OK: depth=2, C=PA, O=NordVPN, CN=NordVPN Root CA
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: VERIFY OK: depth=1, C=PA, O=NordVPN, CN=NordVPN CA3
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: VERIFY KU OK
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: Validating certificate extended key usage
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: VERIFY EKU OK
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: VERIFY OK: depth=0, CN=de534.nordvpn.com
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 4096 bit RSA
Thu Jul 11 14:08:34 2019 daemon.notice openvpn(nordvpn)[17965]: [de534.nordvpn.com] Peer Connection Initiated with [AF_INET]185.230.127.27:1194
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: SENT CONTROL [de534.nordvpn.com]: 'PUSH_REQUEST' (status=1)
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: PUSH: Received control message: 'PUSH_REPLY,redirect-gateway def1,dhcp-option DNS 103.86.96.100,dhcp-option DNS 103.86.99.100,sndbuf 524288,rcvbuf 524288,explicit-exit-notify,comp-lzo no,route-gateway 10.8.0.1,topology subnet,ping 60,ping-restart 180,ifconfig 10.8.0.17 255.255.255.0,peer-id 5,cipher AES-256-GCM'
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: timers and/or timeouts modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: explicit notify parm(s) modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: compression parms modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: --sndbuf/--rcvbuf options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: Socket Buffers: R=[163840->327680] S=[163840->327680]
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: --ifconfig/up options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: route options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: route-related options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: peer-id set
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: adjusting link_mtu to 1657
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: OPTIONS IMPORT: data channel crypto options modified
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: Data Channel: using negotiated cipher 'AES-256-GCM'
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: TUN/TAP device tun0 opened
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: TUN/TAP TX queue length set to 100
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: do_ifconfig, tt->did_ifconfig_ipv6_setup=0
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: /sbin/ifconfig tun0 10.8.0.17 netmask 255.255.255.0 mtu 1500 broadcast 10.8.0.255
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: /sbin/route add -net 185.230.127.27 netmask 255.255.255.255 gw 192.168.1.1
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: /sbin/route add -net 0.0.0.0 netmask 128.0.0.0 gw 10.8.0.1
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: /sbin/route add -net 128.0.0.0 netmask 128.0.0.0 gw 10.8.0.1
Thu Jul 11 14:08:36 2019 daemon.notice openvpn(nordvpn)[17965]: Initialization Sequence Completed

network

root@OpenWrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula_prefix='fd97:f63a:e163::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0.1'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.wan=interface
network.wan.ifname='eth1.2'
network.wan.proto='dhcp'
network.wan.peerdns='0'
network.wan.force_link='1'
network.wan.dns='103.86.96.100' '103.86.99.100'
network.@switch[0]=switch
network.@switch[0].name='switch0'
network.@switch[0].reset='1'
network.@switch[0].enable_vlan='1'
network.@switch_vlan[0]=switch_vlan
network.@switch_vlan[0].device='switch0'
network.@switch_vlan[0].vlan='1'
network.@switch_vlan[0].ports='0 1 2 3 5t'
network.@switch_vlan[1]=switch_vlan
network.@switch_vlan[1].device='switch0'
network.@switch_vlan[1].vlan='2'
network.@switch_vlan[1].ports='4 6t'
network.nordvpntun=interface
network.nordvpntun.proto='none'
network.nordvpntun.ifname='tun0'

firewall

root@OpenWrt:~# uci show firewall
firewall.@defaults[0]=defaults
firewall.@defaults[0].syn_flood='1'
firewall.@defaults[0].input='ACCEPT'
firewall.@defaults[0].output='ACCEPT'
firewall.@defaults[0].forward='ACCEPT'
firewall.@zone[0]=zone
firewall.@zone[0].name='lan'
firewall.@zone[0].input='ACCEPT'
firewall.@zone[0].output='ACCEPT'
firewall.@zone[0].forward='ACCEPT'
firewall.@zone[0].masq='1'
firewall.@zone[0].network='lan'
firewall.@zone[1]=zone
firewall.@zone[1].name='wan'
firewall.@zone[1].input='ACCEPT'
firewall.@zone[1].output='ACCEPT'
firewall.@zone[1].masq='1'
firewall.@zone[1].mtu_fix='1'
firewall.@zone[1].forward='ACCEPT'
firewall.@zone[1].network='wan wan6'
firewall.@rule[0]=rule
firewall.@rule[0].name='Allow-DHCP-Renew'
firewall.@rule[0].src='wan'
firewall.@rule[0].proto='udp'
firewall.@rule[0].dest_port='68'
firewall.@rule[0].target='ACCEPT'
firewall.@rule[0].family='ipv4'
firewall.@rule[1]=rule
firewall.@rule[1].name='Allow-Ping'
firewall.@rule[1].src='wan'
firewall.@rule[1].proto='icmp'
firewall.@rule[1].icmp_type='echo-request'
firewall.@rule[1].family='ipv4'
firewall.@rule[1].target='ACCEPT'
firewall.@rule[2]=rule
firewall.@rule[2].name='Allow-IGMP'
firewall.@rule[2].src='wan'
firewall.@rule[2].proto='igmp'
firewall.@rule[2].family='ipv4'
firewall.@rule[2].target='ACCEPT'
firewall.@rule[3]=rule
firewall.@rule[3].name='Allow-DHCPv6'
firewall.@rule[3].src='wan'
firewall.@rule[3].proto='udp'
firewall.@rule[3].src_ip='fc00::/6'
firewall.@rule[3].dest_ip='fc00::/6'
firewall.@rule[3].dest_port='546'
firewall.@rule[3].family='ipv6'
firewall.@rule[3].target='ACCEPT'
firewall.@rule[4]=rule
firewall.@rule[4].name='Allow-MLD'
firewall.@rule[4].src='wan'
firewall.@rule[4].proto='icmp'
firewall.@rule[4].src_ip='fe80::/10'
firewall.@rule[4].icmp_type='130/0' '131/0' '132/0' '143/0'
firewall.@rule[4].family='ipv6'
firewall.@rule[4].target='ACCEPT'
firewall.@rule[5]=rule
firewall.@rule[5].name='Allow-ICMPv6-Input'
firewall.@rule[5].src='wan'
firewall.@rule[5].proto='icmp'
firewall.@rule[5].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type' 'router-solicitation' 'neighbour-solicitation' 'router-advertisement' 'neighbour-advertisement'
firewall.@rule[5].limit='1000/sec'
firewall.@rule[5].family='ipv6'
firewall.@rule[5].target='ACCEPT'
firewall.@rule[6]=rule
firewall.@rule[6].name='Allow-ICMPv6-Forward'
firewall.@rule[6].src='wan'
firewall.@rule[6].dest='*'
firewall.@rule[6].proto='icmp'
firewall.@rule[6].icmp_type='echo-request' 'echo-reply' 'destination-unreachable' 'packet-too-big' 'time-exceeded' 'bad-header' 'unknown-header-type'
firewall.@rule[6].limit='1000/sec'
firewall.@rule[6].family='ipv6'
firewall.@rule[6].target='ACCEPT'
firewall.@rule[7]=rule
firewall.@rule[7].name='Allow-IPSec-ESP'
firewall.@rule[7].src='wan'
firewall.@rule[7].dest='lan'
firewall.@rule[7].proto='esp'
firewall.@rule[7].target='ACCEPT'
firewall.@rule[8]=rule
firewall.@rule[8].name='Allow-ISAKMP'
firewall.@rule[8].src='wan'
firewall.@rule[8].dest='lan'
firewall.@rule[8].dest_port='500'
firewall.@rule[8].proto='udp'
firewall.@rule[8].target='ACCEPT'
firewall.@include[0]=include
firewall.@include[0].path='/etc/firewall.user'
firewall.@forwarding[0]=forwarding
firewall.@forwarding[0].dest='wan'
firewall.@forwarding[0].src='lan'
firewall.@forwarding[1]=forwarding
firewall.@forwarding[1].dest='lan'
firewall.@forwarding[1].src='wan'
firewall.@forwarding[2]=forwarding
firewall.@forwarding[2].src='lan'
firewall.@forwarding[2].dest='vpnfirewall'
firewall.@zone[2]=zone
firewall.@zone[2].name='vpnfirewall'
firewall.@zone[2].input='REJECT'
firewall.@zone[2].output='ACCEPT'
firewall.@zone[2].forward='REJECT'
firewall.@zone[2].masq='1'
firewall.@zone[2].mtu_fix='1'
firewall.@zone[2].network='nordvpntun'

plik konfiguracyjny OpenVPN

client
dev tun
proto udp
remote 185.230.127.27 1194
resolv-retry infinite
remote-random
nobind
tun-mtu 1500
tun-mtu-extra 32
mssfix 1450
persist-key
persist-tun
ping 15
ping-restart 0
ping-timer-rem
reneg-sec 0
comp-lzo no

remote-cert-tls server

auth-user-pass pass.txt
verb 3
pull
fast-io
cipher AES-256-CBC
auth SHA512

<ca>
-----BEGIN CERTIFICATE-----
MIIFCjCCAvKgAwIBAgIBATANBgkqhkiG9w0BAQ0FADA5MQswCQYDVQQGEwJQQTEQ
MA4GA1UEChMHTm9yZFZQTjEYMBYGA1UEAxMPTm9yZFZQTiBSb290IENBMB4XDTE2
MDEwMTAwMDAwMFoXDTM1MTIzMTIzNTk1OVowOTELMAkGA1UEBhMCUEExEDAOBgNV
BAoTB05vcmRWUE4xGDAWBgNVBAMTD05vcmRWUE4gUm9vdCBDQTCCAiIwDQYJKoZI
hvcNAQEBBQADggIPADCCAgoCggIBAMkr/BYhyo0F2upsIMXwC6QvkZps3NN2/eQF
kfQIS1gql0aejsKsEnmY0Kaon8uZCTXPsRH1gQNgg5D2gixdd1mJUvV3dE3y9FJr
XMoDkXdCGBodvKJyU6lcfEVF6/UxHcbBguZK9UtRHS9eJYm3rpL/5huQMCppX7kU
eQ8dpCwd3iKITqwd1ZudDqsWaU0vqzC2H55IyaZ/5/TnCk31Q1UP6BksbbuRcwOV
skEDsm6YoWDnn/IIzGOYnFJRzQH5jTz3j1QBvRIuQuBuvUkfhx1FEwhwZigrcxXu
MP+QgM54kezgziJUaZcOM2zF3lvrwMvXDMfNeIoJABv9ljw969xQ8czQCU5lMVmA
37ltv5Ec9U5hZuwk/9QO1Z+d/r6Jx0mlurS8gnCAKJgwa3kyZw6e4FZ8mYL4vpRR
hPdvRTWCMJkeB4yBHyhxUmTRgJHm6YR3D6hcFAc9cQcTEl/I60tMdz33G6m0O42s
Qt/+AR3YCY/RusWVBJB/qNS94EtNtj8iaebCQW1jHAhvGmFILVR9lzD0EzWKHkvy
WEjmUVRgCDd6Ne3eFRNS73gdv/C3l5boYySeu4exkEYVxVRn8DhCxs0MnkMHWFK6
MyzXCCn+JnWFDYPfDKHvpff/kLDobtPBf+Lbch5wQy9quY27xaj0XwLyjOltpiST
LWae/Q4vAgMBAAGjHTAbMAwGA1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMA0GCSqG
SIb3DQEBDQUAA4ICAQC9fUL2sZPxIN2mD32VeNySTgZlCEdVmlq471o/bDMP4B8g
nQesFRtXY2ZCjs50Jm73B2LViL9qlREmI6vE5IC8IsRBJSV4ce1WYxyXro5rmVg/
k6a10rlsbK/eg//GHoJxDdXDOokLUSnxt7gk3QKpX6eCdh67p0PuWm/7WUJQxH2S
DxsT9vB/iZriTIEe/ILoOQF0Aqp7AgNCcLcLAmbxXQkXYCCSB35Vp06u+eTWjG0/
pyS5V14stGtw+fA0DJp5ZJV4eqJ5LqxMlYvEZ/qKTEdoCeaXv2QEmN6dVqjDoTAo
k0t5u4YRXzEVCfXAC3ocplNdtCA72wjFJcSbfif4BSC8bDACTXtnPC7nD0VndZLp
+RiNLeiENhk0oTC+UVdSc+n2nJOzkCK0vYu0Ads4JGIB7g8IB3z2t9ICmsWrgnhd
NdcOe15BincrGA8avQ1cWXsfIKEjbrnEuEk9b5jel6NfHtPKoHc9mDpRdNPISeVa
wDBM1mJChneHt59Nh8Gah74+TM1jBsw4fhJPvoc7Atcg740JErb904mZfkIEmojC
VPhBHVQ9LHBAdM8qFI2kRK0IynOmAZhexlP/aT/kpEsEPyaZQlnBn3An1CRz8h0S
PApL8PytggYKeQmRhl499+6jLxcZ2IegLfqq41dzIjwHwTMplg+1pKIOVojpWA==
-----END CERTIFICATE-----
</ca>
key-direction 1
<tls-auth>
#
# 2048 bit OpenVPN static key
#
-----BEGIN OpenVPN Static key V1-----
e685bdaf659a25a200e2b9e39e51ff03
0fc72cf1ce07232bd8b2be5e6c670143
f51e937e670eee09d4f2ea5a6e4e6996
5db852c275351b86fc4ca892d78ae002
d6f70d029bd79c4d1c26cf14e9588033
cf639f8a74809f29f72b9d58f9b8f5fe
fc7938eade40e9fed6cb92184abb2cc1
0eb1a296df243b251df0643d53724cdb
5a92a1d6cb817804c4a9319b57d53be5
80815bcfcb2df55018cc83fc43bc7ff8
2d51f9b88364776ee9d12fc85cc7ea5b
9741c4f598c485316db066d52db4540e
212e1518a9bd4828219e24b20d88f598
a196c9de96012090e333519ae18d3509
9427e7b372d348d352dc4c85e18cd4b9
3f8a56ddb2e64eb67adfc9b337157ff4
-----END OpenVPN Static key V1-----
</tls-auth>

ifconfig

root@OpenWrt:~# ifconfig
br-lan    Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet addr:192.168.1.1  Bcast:192.168.1.255  Mask:255.255.255.0
          inet6 addr: XXXX:XXXX:XXX::1/60 Scope:Global
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1002994 errors:0 dropped:0 overruns:0 frame:0
          TX packets:1524188 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:319292307 (304.5 MiB)  TX bytes:3851800636 (3.5 GiB)

eth0      Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:12898 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:532
          RX bytes:0 (0.0 B)  TX bytes:2013013 (1.9 MiB)
          Interrupt:37

eth0.1    Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:0 errors:0 dropped:0 overruns:0 frame:0
          TX packets:11755 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:0 (0.0 B)  TX bytes:1799548 (1.7 MiB)

eth1      Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:2818168 errors:0 dropped:0 overruns:0 frame:0
          TX packets:961835 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:532
          RX bytes:3924032290 (3.6 GiB)  TX bytes:332141055 (316.7 MiB)
          Interrupt:36

eth1.2    Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet addr:192.168.1.223  Bcast:192.168.1.255  Mask:255.255.255.0
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:1509763 errors:0 dropped:0 overruns:0 frame:0
          TX packets:961761 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:3820932504 (3.5 GiB)  TX bytes:328282723 (313.0 MiB)

lo        Link encap:Local Loopback
          inet addr:127.0.0.1  Mask:255.0.0.0
          inet6 addr: ::1/128 Scope:Host
          UP LOOPBACK RUNNING  MTU:65536  Metric:1
          RX packets:24787 errors:0 dropped:0 overruns:0 frame:0
          TX packets:24787 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:3731233 (3.5 MiB)  TX bytes:3731233 (3.5 MiB)

tun0      Link encap:UNSPEC  HWaddr 00-00-00-00-00-00-00-00-00-00-00-00-00-00-00-00
          inet addr:10.8.0.17  P-t-P:10.8.0.17  Mask:255.255.255.0
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP POINTOPOINT RUNNING NOARP MULTICAST  MTU:1500  Metric:1
          RX packets:15 errors:0 dropped:0 overruns:0 frame:0
          TX packets:2362 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:100
          RX bytes:9960 (9.7 KiB)  TX bytes:197120 (192.5 KiB)

wlan0     Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:292601 errors:0 dropped:0 overruns:0 frame:0
          TX packets:958584 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:113039280 (107.8 MiB)  TX bytes:1316371887 (1.2 GiB)

wlan1     Link encap:Ethernet  HWaddr XX:XX:XX:XX:XX:XX
          inet6 addr: XXXX::XXXX:XXXX:XXXX:XXXX/64 Scope:Link
          UP BROADCAST RUNNING MULTICAST  MTU:1500  Metric:1
          RX packets:18832 errors:0 dropped:0 overruns:0 frame:0
          TX packets:29420 errors:0 dropped:0 overruns:0 carrier:0
          collisions:0 txqueuelen:1000
          RX bytes:3625144 (3.4 MiB)  TX bytes:13401015 (12.7 MiB)

route

root@OpenWrt:~# route -n
Kernel IP routing table
Destination     Gateway         Genmask         Flags Metric Ref    Use Iface
0.0.0.0         10.8.0.1        128.0.0.0       UG    0      0        0 tun0
0.0.0.0         192.168.1.1     0.0.0.0         UG    0      0        0 eth1.2
10.8.0.0        0.0.0.0         255.255.255.0   U     0      0        0 tun0
128.0.0.0       10.8.0.1        128.0.0.0       UG    0      0        0 tun0
185.230.127.27  192.168.1.1     255.255.255.255 UGH   0      0        0 br-lan
192.168.1.0     0.0.0.0         255.255.255.0   U     0      0        0 br-lan
192.168.1.0     0.0.0.0         255.255.255.0   U     0      0        0 eth1.2

ping

root@OpenWrt:~# ping 8.8.8.8
PING 8.8.8.8 (8.8.8.8): 56 data bytes
^C
--- 8.8.8.8 ping statistics ---
161 packets transmitted, 0 packets received, 100% packet loss

ping

root@OpenWrt:~# ping google.com
ping: bad address 'google.com'

125

Odp: Użycie komercyjnego klienta OpenVPN w OpenWrt.

No ale dlaczego tu piszesz? Kupiłeś usługę, nie działa ruch do vpn to pisz do nich, do ich wsparcia. Co my mamy wspólnego z NordVPN?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.