[Tutorial] How to setup a NordVPN OpenVPN client with dd-wrt

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next
Author Message
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 12:28    Post subject: Reply with quote
flakie wrote:
Tony S wrote:
I've just copied and pasted the tls & ca files, using Notepad++ and unfortunately, it's made no difference at all.
ITV, Channels 4 & 5 and TVPlayer all OK, except for BBC iPlayer, which is still blocked. Crying or Very sad


Can you get to bbc.co.uk?
Or does it revert to bbc.com?

If you can only get to bbc.com then your vpn has been blocked by the bbc.


I'm talking about streaming BBC via a Roku 3 box.

Via the desktop, it informs me that either that BBC is only available in the UK, or not available in my area.
It will load either BBC.com or .co.uk and goes as far as the iPlayer menu. It just won't stream anything.

BBC via the desktop is using NordVPN application on the computer.
BBC via the Roku 3 box is streaming via a Netgear 3700 VPN router.
Sponsor
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 12:31    Post subject: Reply with quote
egc wrote:
Well your OpenVPN connnection is working otherwise you would not see ITV etc.
So you do not have a certificate problem otherwise you would not have a connection at all

BBC block's a lot of VPN servers, since mid August all Private internet Access servers are blocked by the BBC (not by ITV etc.)and I heard also IPVanish is blocked.
So maybe the BBC block's your server also. Just try a different server


As I'm still within my 30 day money back guarantee period with NordVPN, I am considering cancelling Norv and trying Vanished VPN, as they 100% guarantee a VPN connection to BBC iPlayer.

Any comments ......
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Mon Oct 23, 2017 12:34    Post subject: Reply with quote
On a desktop browser, if it is blocked then usually bbc.co.uk will revert to bbc.com.
Also if going to .bbc.co.uk/iplayer and clicking on any video a message will be displayed "BBC iPlayer only works in the UK. Sorry, it’s due to rights issues."
Both or either mean the vpn is blocked

_________________
Router Model: Netgear R8000
Firmware: DD-WRT v3.0-r41813 std (12/29/19)
Modem: Super Hub 3.0
ISP: Virgin Media 350/35 Mbps

flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Mon Oct 23, 2017 12:41    Post subject: Reply with quote
Tony S wrote:
As I'm still within my 30 day money back guarantee period with NordVPN, I am considering cancelling Norv and trying Vanished VPN, as they 100% guarantee a VPN connection to BBC iPlayer.

Any comments ......


Sounds like a good plan.
I can confirm that IPVanish is blocked.

_________________
Router Model: Netgear R8000
Firmware: DD-WRT v3.0-r41813 std (12/29/19)
Modem: Super Hub 3.0
ISP: Virgin Media 350/35 Mbps

Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 12:46    Post subject: Reply with quote
flakie wrote:
Tony S wrote:
As I'm still within my 30 day money back guarantee period with NordVPN, I am considering cancelling Norv and trying Vanished VPN, as they 100% guarantee a VPN connection to BBC iPlayer.

Any comments ......


Sounds like a good plan.
I can confirm that IPVanish is blocked.


Thank you for the confirmation.
I'll bin Nord and give Vanished VPN a try.

I'll report my progress.
More later ............
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 13:51    Post subject: Reply with quote
One final confirmation regarding my DD-WRT set up, before I do bin NordVPN.

Under the Status > Openvpn tabs, I never have seen any communication confirmation.

According to the DD-WRT Open tutorial, I should receive the following message:
"To Verify the VPN is Working, Navigate to Status > OpenVPN
Under State, you should see the message: Client: CONNECTED SUCCESS".

I never see that message.
In my case, does that mean any particular thing?
flakie
DD-WRT User


Joined: 23 Sep 2017
Posts: 229
Location: Swindon, UK

PostPosted: Mon Oct 23, 2017 14:48    Post subject: Reply with quote
Tony S wrote:
One final confirmation regarding my DD-WRT set up, before I do bin NordVPN.

Under the Status > Openvpn tabs, I never have seen any communication confirmation.

According to the DD-WRT Open tutorial, I should receive the following message:
"To Verify the VPN is Working, Navigate to Status > OpenVPN
Under State, you should see the message: Client: CONNECTED SUCCESS".

I never see that message.
In my case, does that mean any particular thing?


Yes, you should do. I certainly do along with the vpn Local Address: and Remote Address: (which are both the same).
Have you verified your IP address at, for example, www.whatismyip.com?

_________________
Router Model: Netgear R8000
Firmware: DD-WRT v3.0-r41813 std (12/29/19)
Modem: Super Hub 3.0
ISP: Virgin Media 350/35 Mbps

egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12885
Location: Netherlands

PostPosted: Mon Oct 23, 2017 14:49    Post subject: Reply with quote
Tony S wrote:
One final confirmation regarding my DD-WRT set up, before I do bin NordVPN.

Under the Status > Openvpn tabs, I never have seen any communication confirmation.

According to the DD-WRT Open tutorial, I should receive the following message:
"To Verify the VPN is Working, Navigate to Status > OpenVPN
Under State, you should see the message: Client: CONNECTED SUCCESS".

I never see that message.
In my case, does that mean any particular thing?


Normally that signals an error in your setup mostly certificates (although I have seen comp-lzo also showing the same behavior). But there were a couple of builds with a bug where nothing was showed on the status tab, maybe you have one of them.
Use the latest build 33555 : ftp://ftp.dd-wrt.com/betas/2017/10-20-2017-r33555/ but research first if your router can take it.

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 15:55    Post subject: Reply with quote
Flakie .......... Yes, my IP address has been verified and is as it should be.

egc ....... Very interesting. I've just been e-mailed by the Tech team of NordVPN to inform me that the version of firmeware I have installed does indeed have a problem.
So according to them, I need to either upgrade or downgrade to s different version.
Very good timing on your behalf Very Happy

OK, more question time .......
How can I check to see if my Netgear WNDR 3700v4 will be compatible with the latest firmware build; 33555?

I currently have DD-WRT v3.0-r30949 std (12/15/16) installed.

**EDIT** I've just checked your link egc and my router is indeed listed.

How do I go about flashing the new firmware onto my router with the existing firmware already installed?
Plus, will there be any setting that will automatically change, that I won't know about?

Also, do I use the webflash.bin file or the factory.img file?

I'm sort of stepping into the dark arts here, mixed with a bit of voodoo Shocked

Extra information here: http://www.dd-wrt.com/phpBB2/viewtopic.php?p=1060405

Any help would be greatly appreciated .......
On top of the already excellent assistance given so far from everybody.
egc
DD-WRT Guru


Joined: 18 Mar 2014
Posts: 12885
Location: Netherlands

PostPosted: Mon Oct 23, 2017 17:31    Post subject: Reply with quote
Ok that is of course a totally different question
But you know this is two for the price of one Smile

Start reading : http://www.dd-wrt.com/wiki/index.php/Netgear_WNDR3700

Builds can be found at: ftp://ftp.dd-wrt.com/betas/2017/10-20-2017-r33555/netgear-wndr3700v4/

You can just use the .bin because you are coming from an earlier DDWRT build.

Build thread can be found at: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311799
I saw our resident guru posting succes with that router

Be sure to reset to defaults and put your settings in manually, yes it is a lot of work but it is for the best.

This is an Atheros based unit so post questions in the Atheros forum.

Well folks that is all for tonight otherwise the wife starts complaining Sad (perhaps we also should start a #metoo)

_________________
Routers:Netgear R7000, R6400v1, R6400v2, EA6900 (XvortexCFE), E2000, E1200v1, WRT54GS v1.
Install guide R6400v2, R6700v3,XR300:https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=316399
Install guide R7800/XR500: https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=320614
Forum Guide Lines (important read):https://forum.dd-wrt.com/phpBB2/viewtopic.php?t=324087
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Mon Oct 23, 2017 19:13    Post subject: Reply with quote
egc wrote:
Ok that is of course a totally different question
But you know this is two for the price of one Smile

Start reading : http://www.dd-wrt.com/wiki/index.php/Netgear_WNDR3700

Builds can be found at: ftp://ftp.dd-wrt.com/betas/2017/10-20-2017-r33555/netgear-wndr3700v4/

You can just use the .bin because you are coming from an earlier DDWRT build.

Build thread can be found at: http://www.dd-wrt.com/phpBB2/viewtopic.php?t=311799
I saw our resident guru posting succes with that router

Be sure to reset to defaults and put your settings in manually, yes it is a lot of work but it is for the best.

This is an Atheros based unit so post questions in the Atheros forum.

Well folks that is all for tonight otherwise the wife starts complaining Sad (perhaps we also should start a #metoo)


Thank you egc Very Happy Much appreciated.
Enjoy your evening.
wajirah
DD-WRT Novice


Joined: 17 Sep 2017
Posts: 14

PostPosted: Tue Oct 24, 2017 17:09    Post subject: Reply with quote
Tony S wrote:
wajirah wrote:
@sploit I can understand your frustration. However I managed to get a good 3 year deal from nordvpn, and I don't mind tinkering with the router.

I am running the build 33375 (19 Sep 2017) and followed @usershmusername advice. For days my VPN connection is solid and there were no dropouts.

========================================================
My advice to newbies like me is to follow the tutorial in the nordvpn website;
https://nordvpn.com/tutorials/dd-wrt/openvpn-gui/

BUT replace their additional settings with:

tls-client
remote-cert-tls server
remote-random
nobind
tun-mtu-extra 32
persist-key
persist-tun
ping 60
ping-restart 120
reneg-sec 0

========================================================

Happy tinkering!


Wajirah ....

With the above text, did you manage to run openvpn, or just vpn?
Also, have you tried to stream BBC iPlayer?
If so, what were your results?


My openvpn client is running fine on TP-Link Archer c9 v1, dd-wrt build 10/17/17, CPU usage hovering around 50%. I am using the uk125 nordvpn server. Unfortunately iPlayer will not stream through uk125 server.
Tony S
DD-WRT Novice


Joined: 16 Oct 2017
Posts: 25

PostPosted: Tue Oct 24, 2017 17:19    Post subject: Reply with quote
Thanks Wajirah,

I have a very bad feeling that NordVPN has also been completely blocked [all the servers] by the BBC, just like most VPN providers Crying or Very sad

By the way, your DD-WRT formware looks to be close to the latest. What build number is it?
**Edit** OK I've just noticed that it's the same date as r33555, so I assume it's that one?
wajirah
DD-WRT Novice


Joined: 17 Sep 2017
Posts: 14

PostPosted: Tue Oct 24, 2017 17:30    Post subject: Reply with quote
Tony S wrote:
Thanks Wajirah,

I have a very bad feeling that NordVPN has also been completely blocked [all the servers] by the BBC, just like most VPN providers Crying or Very sad

By the way, your DD-WRT formware looks to be close to the latest. What build number is it?


you are correct! Netflix and amazon video seem to work fine though. I am running build 33525.

I have one problem with the router though. Reboot will not connect the openvpn client, I have to do it manually each time I reboot. I am no good at Linux. I think it is a problem with the firewall at boot time. If you are curious about the log:

Jan 1 00:00:11 DD-WRT daemon.warn openvpn[881]: WARNING: file '/tmp/openvpncl/ta.key' is group or others accessible
Jan 1 00:00:11 DD-WRT daemon.warn openvpn[881]: WARNING: file '/tmp/openvpncl/credentials' is group or others accessible
Jan 1 00:00:11 DD-WRT daemon.notice openvpn[881]: OpenVPN 2.4.4 arm-unknown-linux-gnu [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD] built on Oct 17 2017
Jan 1 00:00:11 DD-WRT daemon.notice openvpn[881]: library versions: OpenSSL 1.1.0f 25 May 2017, LZO 2.09
Jan 1 00:00:11 DD-WRT daemon.notice openvpn[946]: MANAGEMENT: TCP Socket listening on [AF_INET]127.0.0.1:16
Jan 1 00:00:11 DD-WRT daemon.warn openvpn[946]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Jan 1 00:00:11 DD-WRT daemon.notice openvpn[946]: Outgoing Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Jan 1 00:00:11 DD-WRT daemon.notice openvpn[946]: Incoming Control Channel Authentication: Using 512 bit message hash 'SHA512' for HMAC authentication
Jan 1 00:00:11 DD-WRT user.info : ttraff : traffic counter daemon successfully started
Jan 1 00:00:14 DD-WRT user.info : vpn modules : vpn modules successfully unloaded
Jan 1 00:00:14 DD-WRT user.info : vpn modules : nf_conntrack_proto_gre successfully loaded
Jan 1 00:00:14 DD-WRT user.info : vpn modules : nf_nat_proto_gre successfully loaded
Jan 1 00:00:14 DD-WRT daemon.notice openvpn[946]: TCP/UDP: Preserving recently used remote address: [AF_INET]185.169.255.9:1194
Jan 1 00:00:14 DD-WRT daemon.notice openvpn[946]: Socket Buffers: R=[180224->180224] S=[180224->180224]
Jan 1 00:00:14 DD-WRT daemon.notice openvpn[946]: UDPv4 link local: (not bound)
Jan 1 00:00:14 DD-WRT daemon.notice openvpn[946]: UDPv4 link remote: [AF_INET]185.169.255.9:1194
Jan 1 00:00:14 DD-WRT user.info : vpn modules : nf_conntrack_pptp successfully loaded
Jan 1 00:00:14 DD-WRT user.info : vpn modules : nf_nat_pptp successfully loaded
Jan 1 00:00:14 DD-WRT user.info : process_monitor successfully started
Jan 1 00:00:14 DD-WRT user.info : wland : WLAN daemon successfully stopped
Jan 1 00:00:14 DD-WRT user.info : wland : WLAN daemon successfully started
Jan 1 00:00:14 DD-WRT user.info : WAN is up. IP: 192.168.0.14
Jan 1 00:00:14 DD-WRT user.info : openvpn : OpenVPN daemon (Client) successfully stopped
Jan 1 00:00:14 DD-WRT daemon.err openvpn[946]: event_wait : Interrupted system call (code=4)
Jan 1 00:00:14 DD-WRT daemon.notice openvpn[946]: SIGTERM[hard,] received, process exiting
Oct 24 16:56:56 DD-WRT user.info : cron : cron daemon successfully stopped
Oct 24 16:56:57 DD-WRT daemon.debug process_monitor[1119]: Restarting cron (time sync change)
Oct 24 16:56:57 DD-WRT daemon.debug process_monitor[1119]: We need to re-update after 3600 seconds
Oct 24 16:56:57 DD-WRT daemon.info process_monitor[1119]: set timer: 3600 seconds, callback: ntp_main()
Oct 24 16:56:57 DD-WRT user.info : cron : cron daemon successfully started
Oct 24 16:56:57 DD-WRT cron.info cron[1136]: (CRON) STARTUP (fork ok)
Oct 24 16:57:03 DD-WRT user.info : NAS : NAS lan (wl0 interface) successfully started
Oct 24 16:57:03 DD-WRT user.info : NAS : NAS lan (wl1 interface) successfully started
Oct 24 16:57:03 DD-WRT user.info : syslogd : syslog daemon successfully stopped
Oct 24 17:57:03 DD-WRT syslog.info syslogd exiting
Oct 24 17:57:03 DD-WRT syslog.info syslogd started: BusyBox v1.27.2
Oct 24 16:57:03 DD-WRT user.info : httpd : http daemon successfully stopped
Oct 24 16:57:03 DD-WRT user.info : resetbutton : resetbutton daemon successfully stopped
Oct 24 16:57:03 DD-WRT user.info : resetbutton : resetbutton daemon successfully started
Oct 24 16:57:04 DD-WRT daemon.err openvpn[1317]: Options error: Unrecognized option or missing or extra parameter(s) in [CMD-LINE]:1: down-pre (2.4.4)

_________________
Router ModelTPLINK Archer C9
Firmware Version DD-WRT v3.0-r34080 std (12/14/17)
Linux 4.4.105 #2353 SMP Thu Dec 14 13:20:49 CET 2017 armv7l
wajirah
DD-WRT Novice


Joined: 17 Sep 2017
Posts: 14

PostPosted: Tue Oct 24, 2017 17:52    Post subject: Reply with quote
Just realised; It must be the system time causing the openvpn daemon to stall. I don't know how to set the correct time before the daemon runs Sad
_________________
Router ModelTPLINK Archer C9
Firmware Version DD-WRT v3.0-r34080 std (12/14/17)
Linux 4.4.105 #2353 SMP Thu Dec 14 13:20:49 CET 2017 armv7l
Goto page Previous  1, 2, 3, 4, 5, 6, 7, 8  Next Display posts from previous:    Page 6 of 8
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum