|
Are there any gigabit LAN, dual/multi wan, AND dual band routers coming to the market?
|
# ¿ Jul 13, 2012 01:28 |
|
|
# ¿ Apr 25, 2024 16:11 |
|
I have the following network setup: cable modem > Router > OpenVPN (dd-wrt) Router My problem is that clients connected to the OpenVPN router are leaking my ISP DNS. However if I remove the first Router so its just 'cable modem > Open VPN Router', then there are no DNS leaks. What the hell is going on?
|
# ¿ Aug 22, 2013 06:39 |
|
evol262 posted:You're going to have to actually post OpenVPN configs or more details to figure this out. It seems like the OpenVPN router is using the DNS settings of the first router as well as what its set to use, because if its 'just' the OpenVPN router and the modem it correctly only uses the OpenVPN's DNS (which are set as static DNS servers 1-3 in dd-wrt). Almost figured it has to do with using 2 routers than anything OpenVPN? My firewall script: code:
code:
|
# ¿ Aug 22, 2013 16:03 |
|
evol262 posted:This appears to have nothing to do with OpenVPN. You're probably not pushing options from the OpenVPN server (and those are the relevant configs). Assigning static DNS resolution to servers which may or may not be reachable without being connected to the VPN is the way to do it. If you want it to use those DNS servers, push them from the OpenVPN server and let the client figure out what to do when it's not connected. For what its worth the OpenVPN router's firewall rules will (should) not allow any traffic if it drops the OpenVPN connection. The router is also an OpenVPN client, not the server. 1. Yes, the OpenVPN router is assigned an address from the first router via DHCP. Their IPs are 192.168.0.1 (regular) and 192.168.1.1 (openvpn) 2. My /etc/resolve.conf is the same for both setups: code:
code:
uG fucked around with this message at 18:25 on Aug 22, 2013 |
# ¿ Aug 22, 2013 18:06 |
|
evol262 posted:Your iptables rules do absolutely nothing to stop non-VPN traffic. I disabled DNSMasq for DNS with the same results (although airvpn tutorial says to have it enabled https://airvpn.org/ddwrt/ ). Clients can dig that properly. I will install dig and try it on the OpenVPN router later today. Thanks for the suggestions thus far. Client dig: code:
code:
uG fucked around with this message at 19:33 on Aug 22, 2013 |
# ¿ Aug 22, 2013 19:15 |
|
evol262 posted:99% odds your router is using 192.168.0.1 as the primary resolver.
|
# ¿ Aug 23, 2013 16:35 |
|
wolrah posted:Didn't realize the next level up was so close, yeah I see no reason to bother with the GS108E when the T is only a few bucks more. http://www.amazon.com/gp/aw/d/B00BTKPRYO/ref=mp_s_a_1_10?qid=1390081746&sr=8-10&pi=AC_SX110_SY165_QL70 Mikrotik rb260gs is a nice managed switch for the money
|
# ¿ Jan 18, 2014 22:52 |
|
I've got an edgerouter lite that I recently upgraded and used the latest wizard to setup. I tried redoing this entire thing manually using the same tutorial I used to get this working before but with the same DNS problems. eth1 is WAN, eth0 goes to tun0, and eth2 is for non-tunneled internet access. My problem is that eth2 DNS will fail unless I manually set the DNS on whatever hardware (in this case a ps3) to the router IP. The router has DHCP set up for each interface's subnet and DNS forwarding on the interfaces. DNS on the tunneled connection, eth0, works fine but DNS1 and DNS2 on DHCP are set to external DNS servers. eth2 has DNS1 set to the router IP address, so I don't know what gives.
|
# ¿ Mar 21, 2014 04:50 |
|
I need a router that can maintain a 50Mb/s openvpn tunnel. I have an ERL3 but it maxes at 15Mb/s while maxing a single core (openvpn is single threaded). Do I have any options besides building a pfsense box?
|
# ¿ Apr 7, 2014 22:07 |
|
I know IPSec will be faster but I need to use openvpn, so I don't think the edge routers are going to cut it.
|
# ¿ Apr 8, 2014 02:52 |
|
|
# ¿ Apr 25, 2024 16:11 |
|
The hardware acceleration only works for IPSec apparently, but it does use AES. I could load balance between 2 openvpn tunnels to use the other CPU core but that still won't get me to 50Mb/s
|
# ¿ Apr 8, 2014 03:03 |