Page 2 of 2

Re: Gargoyle NAT 'leaking' port 443?

Posted: Mon Mar 14, 2016 3:21 pm
by roadhawk
I just loaded OpenWRT Chaos Calmer 15.05 onto a TP-Link TL-WR1043N/ND v1 and configured only wifi encryption.

Exactly the same thing happens.

Tomorrow, stock firmware . . . stay tuned.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Tue Mar 15, 2016 5:18 am
by roadhawk
Latest TP-Link stock firmware on a TP-Link TL-WR1043N/ND v1.
An overnight test showed no leakage.

So, to summarize:

- Gargoyle 1.9.x : Leak
- OpenWRT 15.05 : Leak
- TP-Link TL-WR1043ND_V1_140319 : Clean

I'm thinking more in terms of a kernel issue than a missing iptables rule.

I suppose the next step would be to try BarrierBreaker and then possibly a DesignatedDriver snapshot. I can see my router getting bricked this week.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Tue Mar 15, 2016 2:24 pm
by nworbnhoj
@roadhawk I think that it is worth posting your findings over on the openwrt forum as the solution will need to be identified and resolved in openwrt before Garoyle users can see the fix.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Tue Mar 15, 2016 4:39 pm
by roadhawk
OpenWRT BarrierBreaker : Leak
OpenWRT DesignatedDriver : CLEAN

Sorted. So all we have to do is wait.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Tue Mar 15, 2016 5:22 pm
by Lantis
Interesting.
Most likely to do with a kernel change.
There are rumours that CC 15.05.1 (maintenance update) will be based on Kernel 4.4 (which DD uses).
I think it is more likely that it will use 3.18.27.
For reference, gargoyle uses 3.18.23.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Fri Mar 18, 2016 6:27 pm
by sigwx
Well, looks like 15.05.1 will have 3.18.23 if I'm reading the OpenWRT front page correctly...?

Re: Gargoyle NAT 'leaking' port 443?

Posted: Fri Mar 18, 2016 6:44 pm
by Lantis
Correct, but since then, the CC branch has been pushed to 3.18.27.
Just isn't part of any official release.

Re: Gargoyle NAT 'leaking' port 443?

Posted: Sat Mar 19, 2016 3:32 am
by tapper
3.18.23 has a bug in witch will put some devices in a bootloop