Version 1.13.0 : Based on OpenWrt 19.07.8

The latest news about Gargoyle

Moderator: Moderators

Lantis
Moderator
Posts: 6735
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by Lantis »

Can you provide your router model and the error messsages please?
A copy of the /etc/opkg.conf would also be helpful.

Thanks
http://lantisproject.com/downloads/gargoyle_ispyisail.php for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

ViBE
Posts: 194
Joined: Sun Apr 19, 2015 6:58 pm

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ViBE »

does anybody managed out how to connect with modems via NCM protocol? mine cannot connect and i have no clue why.

ispyisail
Moderator
Posts: 5180
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ispyisail »

It appears that OpenVPN is broken with 1.13.0

Installed OpenVPN as a server on my linksys wrt32x and seemed to be working as expected.

Installed as a client on my c7 v5 and it created a brick. Reset the router twice with the same result. In the end I'm running 1.13.0 on this router without openvpn and it seams to run ok?

Another router c7 v2 running 1.12.x tried to connect to wrt32x (1.13.0) as a openvpn client and it says connected but nothing is connected.

Lantis
Moderator
Posts: 6735
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by Lantis »

Brick as in its completely unresponsive? I’m not sure how installing it would cause that unless it’s not got enough space? How much free space before you install and what does openvpn report its size is?

Can you pull the logs from the client install? Openvpn is usually pretty good at describing what is wrong with errors.
http://lantisproject.com/downloads/gargoyle_ispyisail.php for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

ispyisail
Moderator
Posts: 5180
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ispyisail »

Brick as in its completely unresponsive?
I would describe it as the router becoming really slow. The client PC would have trouble pulling a IP address. When it did I had trouble access the gargoyle web page. Over the coarse of a few hours I gave up and reset the router.

Even with a fresh reset 1.13.0 is feels really slow on the c7 v5

ispyisail
Moderator
Posts: 5180
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ispyisail »

Its doing something

Code: Select all

Wed Jun 15 08:23:07 2022 daemon.notice hostapd: wlan1: AP-STA-DISCONNECTED 90:f1:57:52:87:dd
Wed Jun 15 08:23:07 2022 daemon.info hostapd: wlan1: STA 90:f1:57:52:87:dd IEEE 802.11: disassociated due to inactivity
Wed Jun 15 08:23:08 2022 daemon.info hostapd: wlan1: STA 90:f1:57:52:87:dd IEEE 802.11: deauthenticated due to inactivity (timer DEAUTH/REMOVE)
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=1, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY KU OK
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Validating certificate extended key usage
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY EKU OK
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=0, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 08:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 1024 bit RSA
Wed Jun 15 09:26:21 2022 daemon.info dnsmasq-dhcp[23015]: DHCPREQUEST(br-lan) 192.168.10.113 1c:1b:0d:09:b6:97
Wed Jun 15 09:26:21 2022 daemon.info dnsmasq-dhcp[23015]: DHCPACK(br-lan) 192.168.10.113 1c:1b:0d:09:b6:97 DESKTOP-PEQ4EJ3
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: TLS: soft reset sec=0 bytes=11076/-1 pkts=284/0
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=1, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY KU OK
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Validating certificate extended key usage
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY EKU OK
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=0, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 09:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 1024 bit RSA
Wed Jun 15 09:49:14 2022 daemon.info dnsmasq-dhcp[23015]: DHCPREQUEST(br-lan) 192.168.10.149 4c:60:de:e4:2d:9b
Wed Jun 15 09:49:14 2022 daemon.info dnsmasq-dhcp[23015]: DHCPACK(br-lan) 192.168.10.149 4c:60:de:e4:2d:9b
Wed Jun 15 10:12:25 2022 daemon.info dnsmasq-dhcp[23015]: DHCPREQUEST(br-lan) 192.168.10.101 00:19:ba:0c:34:b0
Wed Jun 15 10:12:25 2022 daemon.info dnsmasq-dhcp[23015]: DHCPACK(br-lan) 192.168.10.101 00:19:ba:0c:34:b0 Alarm
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=1, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY KU OK
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Validating certificate extended key usage
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY EKU OK
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: VERIFY OK: depth=0, C=??, ST=UnknownProvince, L=UnknownCity, O=UnknownOrg, OU=UnknownOrgUnit, CN=fnagklzcqbgcgdy, name=fnagklzcqbgcgdy, emailAddress=fnagklzcqbgcgdy@mjbbmycvriyedmb.com
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Outgoing Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Incoming Data Channel: Cipher 'AES-256-GCM' initialized with 256 bit key
Wed Jun 15 10:27:10 2022 daemon.notice openvpn(custom_config)[23982]: Control Channel: TLSv1.2, cipher TLSv1/SSLv3 ECDHE-RSA-AES256-GCM-SHA384, 1024 bit RSA

ispyisail
Moderator
Posts: 5180
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ispyisail »

OpenVPN server 192.168.1.1 (Ver 1.13.0)

OpenVPN Client 192.168.10.1 (ver 1.12.x)

The Client says connected

Image

But when I ping 192.168.1.1 (from the client side) I get nothing

ispyisail
Moderator
Posts: 5180
Joined: Mon Apr 06, 2009 3:15 am
Location: New Zealand

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by ispyisail »

I've done some more testing.

OpenVPN Installed 1.3.0 on C7 v2 and router was stable unlike the C7 v5. (suspect flash space problem) but OpenVPN still does not work.

Thought I would try Wireguard, It just worked out of the box.

Lantis
Moderator
Posts: 6735
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by Lantis »

ispyisail wrote:
Tue Jun 14, 2022 6:54 pm
Brick as in its completely unresponsive?
I would describe it as the router becoming really slow. The client PC would have trouble pulling a IP address. When it did I had trouble access the gargoyle web page. Over the coarse of a few hours I gave up and reset the router.

Even with a fresh reset 1.13.0 is feels really slow on the c7 v5
Shouldn’t be like that on a fresh reset after the first few minutes.
You could try running “top” and looking at what the process with the most cpu usage is.
Is it running like this before or after you enable wifi? If after, have you tried without using WPA3?
http://lantisproject.com/downloads/gargoyle_ispyisail.php for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

Lantis
Moderator
Posts: 6735
Joined: Mon Jan 05, 2015 5:33 am
Location: Australia

Re: Version 1.13.0 : Based on OpenWrt 19.07.8

Post by Lantis »

ispyisail wrote:
Wed Jun 15, 2022 1:12 am
I've done some more testing.

OpenVPN Installed 1.3.0 on C7 v2 and router was stable unlike the C7 v5. (suspect flash space problem) but OpenVPN still does not work.

Thought I would try Wireguard, It just worked out of the box.
The logs looked ok.
Would maybe need to see both client and server logs to see if they agree.

For what it is worth, I’ve also switched to WireGuard. It is so much simpler to set up and is fast.
But I want openvpn to work for those that want to use it, so I’m happy to try and get to the bottom of it. In the past week I’ve been working on openvpn 2.5.3 for Gargoyle which came with a whole lot of changes to manage.
http://lantisproject.com/downloads/gargoyle_ispyisail.php for the latest releases
Please be respectful when posting. I do this in my free time on a volunteer basis.

Post Reply