NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
j4x4
Oct 14, 2021Aspirant
Orbi CBR 750 with OpenVPN for home setup?
Hello, I got some great help from Netgear on my OpenVPN install. It's up and running on my Orbi. Next step is to install certificate authentication to secure the connection. Does anyone have experi...
CrimpOn
Oct 20, 2021Guru - Experienced User
It appears this is something out of Shakespeare, "full of sound and fury. signifying nothing."
I just now used OpenVPN 2.5.4 on Windows 10 to connect to my Orbi (using a Hot Spot from my smartphone).
The connection worked perfectly. I could access devices on the Orbi LAN, including the Orbi router itself. The OpenVPN log file contained this warning:
2021-10-20 21:41:38 WARNING: Compression for receiving enabled.
Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.
2021-10-20 21:41:38 DEPRECATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-256-GCM:AES-128-GCM). Future OpenVPN version will ignore --cipher for cipher negotiations. Add 'AES-128-CBC'
to --data-ciphers or change --cipher 'AES-128-CBC' to --data-ciphers-fallback 'AES-128-CBC' to silence this warning.
2021-10-20 21:41:39 WARNING: No server certificate verification method has been enabled. See https://?????? for more info.
2021-10-20 21:41:51 WARNING: this configuration may cache passwords in memory -- use the auth-nocache option to prevent this
Looking back through the OpenVPN log, this warning has appeared every time I have connected to my Orbi router using OpenVPN (going back months and months).
My guess is that Netgear could prevent this by updating OpenVPN to use a more modern encryption algorithm (AES-256-GCM)
I looked through the "Changes" notes on Voxel's firmware for the RBR50. It looks like he has updated OpenVPN to more current versions and improved the encryption used, which would possibly eliminate that warning. Does not apply to the RBR750, however. "oh, well."
Spoongooner
Jul 08, 2022Guide
to fix the cipher AES-128-CBC error message on mine...
right click on openvpn icon on toolbar.. click on edit config
change this
cipher AES-128-CBC
to this
cipher AES-128-GCM
I dont know if that good or bad.. but my error went away
also i figured out.. if you open the client.opvl file in notepad..
its the same as editing config file
hopefully that help someone...