Davidc502- wrt1200ac wrt1900acx wrt3200acm wrt32x builds

New (Potential) user here for wrt3200acm, currently using dd-wrt r.42410, I would like to know before I switch (as I have heard great things about openwrt and Davidc builds), Can I have a few questions answered? Assuming yes:

  1. As I work from my home office and use cisco anyconnect to connect via VPN passthru, as I have read, is that this is possible via installing the kmod-nf-nathelper-extra package (which seems to be included in Davidc builds). True? Any config I would need to do?
  2. Firewall rules: I understand that basic 'out of box' zones are pretty good (e.g. wan to lan ports should be blocked/closed). Is this true? Are thee any shared FW rules to prevent DOS/Brute force?
  3. Wifi:
    a.I see that the latest marvel drivers are included. I assume these are the FW blobs and not the proprietary linksys drivers?
    b. Has anyone seen any performance differences vs dd-wrt ?
    c. Are there any recommended wifi settings published for wrt3200acm? e.g. 2,4: 20 vs 40, cts/rts protection
    d. Beamforming function/work?
  4. Can assume I can run CRON startup scripts to schedule reboots? Or is there an option built into luci?
  5. Final q (thx for your patience): Is it safer to install from stock? re. I am running ddwrt on partition 2 so I would change to partition 1 and effectively replace ddwrt.

Same here. I'd love to see WireGuard included in these builds. As soon as @davidc502 is ready to include them, I'd be happy to help test.

Welcome to the community @steve2088

  1. The package should not be needed, but you can always install it later if you find out differently. It is an available package.
  2. For DOS and DDOS, you can't stop it with ANY software because if someone decides to stuff the pipe, you are finished regardless if this option is checked or not. What this might have implied at one time was the half-open syn attack, and the kernel we are on now should have built in protection against it anyway. As for brute force, that's going to depend on if you leave SSH/HTTPS open to the internet. If locked down the Brute force isn't an issue anyway.
    3a. Eh, it's an ugly answer between yes and no, but really I'm not the best person to answer this question by far.
    3b. This answer will vary from person to person. Test for yourself to see what is best for you.
    3c. Wifi is generally stable on both radio's, and will generally give decent performance. At this time I don't recommend 160mhz width on 5Ghz, but feel free to test. DD-WRT may have a 3rd radio as an option on the 3200acm. This is not supported on this build.
    3d. Beamforming? Snake-Oil and MU-MIMO also another form of Snake-Oil. But yes, beamforming is a part of a 802.11ac standard, and it works on the 3200acm.
    [4]. Yes and Yes
    [5]. Good question here. When installing from DD-WRT, use the .img, and do not save any settings. OpenWrt should automatically be installed on the other partition fresh with no saved configurations from DD-WRT. You should be able to boot back to DD-WRT if you want and vice versa.
1 Like

Im having a strange issue where dnscrypt seems to be working but every time i upgrade it takes a while before i get an "A" https://cmdns.dev.dns-oarc.net/ when testing. I always start off with a C and "Invalid DNSSEC Signature". Even testing ESNI doesnt seem to be working right when i test it here https://www.cloudflare.com/ssl/encrypted-sni/ (though every other test shows up encrypted).
There are no dnsleaks: https://dnsleaktest.com/results.html. Only 1 server is found.

I am using cloudflare. tried google and cloudflare-ipv6 and get different results. anyone else have any issues after an upgrade? running on the latest version

root@wrt32x:~# dnscrypt-proxy -config /etc/dnscrypt-proxy2/dnscrypt-proxy.toml -list
[2020-03-06 15:46:27] [NOTICE] dnscrypt-proxy 2.0.39
[2020-03-06 15:46:27] [NOTICE] Network connectivity detected
[2020-03-06 15:46:27] [NOTICE] Source [public-resolvers] loaded
[2020-03-06 15:46:27] [NOTICE] Source [relays] loaded
cloudflare

1 Like

¡Hi Davidc502!

Thank you for your releases, are great because it makes easy for everybody to get the best of our routers.

It's been a while since i have asked in this forum for some help to fix problems with latest releases with no avail. I just installed your latest release and things doesn't seem to get better, at least in my case, because on guest network it still been shown as dissasociated:
image
uPNP still not working on our gaming consoles (XBox One, shows as moderated NAT), and port forwarding seems to be failing too.
This problems was not on very older releases, so i don't know why happens now. Please tell me how can I fix this

I really want to use the latest release at least for dnscrypt2 and Software flow offloading, and so on...
Please help!

@sunchar
Can you describe your wan setup? Have you tried to start from the scratch with a default config?

Since yesteday I'm running the latest build and everything is working absolutely fine on my end (Guest-Wifi, upnp@ps4, port forwarding, dnscrypt, aso).
I do have a feeling that the non-working port forwarding and upnp is somehow related to your wan-setup. In my case I'm on using pppoe (VDSL@bridged modem) and I never had any issues with upnp and port forwarding in any of davidc's builds.
I did had some problems with a couple firewall traffic rules (added via luci) a couple of builds ago but once I manually fixed them everything started to work again...

How did you fix them rules in the end.

Hi Kherby!

I´m assuming that the problem is with latest releases (I have tested with latest 3), because when use older version (In my case r7360) I have not any problem, i only happens when upgrading.
I have started from scratch (Last night was my latest try) and nothing changes. So that is why always go back to r7360.

Any advice?

Thanks!

I've deleted and re added the (custom) traffic rules via luci.

1 Like

Hey Guys,

I have a WRT1900acs. When I install the stock OpenWRT firmware, my wifi has a high latency on speedtest.net but if I install David's firmware the latency is low.

Why is that? Forgive me if this has been brought up, as I couldn't really find the cause?

Thank you

PS. I'm very happy with David's firmware, thank you David for continuing to improve it.

Do this :slight_smile:

Thank you lopov.

I'm surprised they still haven't fixed the current stock openwrt wrt1900acs v2 firmware, with the TX AMSDU fix.

Anyways thanks again

1 Like

With default config, WAN is not connecting for me on WRT3200ACM, tried DHCP client and static configuration but it won't work

I disabled software off loading on my setup because for some reason it was causing a delay between my echo and harmony hub. example told echo to mute tv and it would take about 3mins to respond...no issue with software
offloading turned off. Using WRT3200ACM.

3 Likes

Hehe, was just about to post exactly the same thing. Took me all f*cking weekend to diagnose the issue. WRT32X running r12235 here :rofl:

Oddly, issuing commands from the Harmony remote seemed to work okay; it was getting Alexa to do stuff for me ("turn tv on", "change to channel 101", etc.) that introduced the delay. I've been sat poring over tcpdump output trying to figure out what the hell was wrong with it :weary:

This is an interesting find. I've never noticed a bug like that with software flow offloading, but can't help but wonder I've had other weirdness in the past but not pinned down. This actually could be an upstream bug that should be reported, could be OpenWrt or at the kernel level.

Snap! I'm using r12235 too. :joy:

I know this may sound like a silly question but who do we report it to?

The delays were quite variable, anything from 10s to 2 or 3 minutes. I've got a sneaky suspicion it has something to do with NAT, as this was the only other thing I could find online that sounded vaguely similar: https://community.smartthings.com/t/resolved-logitech-harmony-hub-integration-slow-to-execute/98973

I've now also got a feeling this is linked with the SIP problems I was having last week, too, as the same solution is listed for SIP problems with those Draytek routers. Could be coincidence, could be correlation.

Time passes...

I tell you what, though: I just disabled the SIP port forwarding rules I had to add and restarted the VOIP basestation and it registered straight away.

There is definitely a problem with NAT and software flow offloading here.

right now Im using the david502 but I have a Roku and some times I will delay. I thought my problem was in the Wifi Roku has a adhoc wifi setup. or maybe it is a nat. my thoughts it would be interesting to find out what packets controllers are sending back to home? I have had this problem for over a yr now. I have had the 1900ac and wrt32x same problem.