NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
bkeith4web
Sep 04, 2020Guide
Orbi RBR40 Openvpn problem with dev tap
Orbi RBR40 firmware 2.5.1.16 running OpenVPN. Just addressing UDP, not TCP for now. I can connect with both tun and tap, tun seems to work OK but not tap. TUN: vpn client gets assigned a different...
- Sep 04, 2020
Mstrbig, thanks for checking in on this. The problem turned out to be my Netgear access controls. I've turned those on to restrict network access to explicitly listed MAC addresses and failed to realize that the OpenVPN client install, when creating the new (virtual) network adapter that is usually renamed to 'NETGEAR-VPN', would also create a new MAC address associated with that adapter. Adding that MAC to my access list made the tap connection work correctly. So now I can see everything on my LAN, connect to the internet etc. Interestingly, the OpenVPN taskbary tray icon still does not show anything under 'Assigned IP' when using tap but as I said before, ipconfig shows the correct address and my router shows that IP address and new virtual MAC address connected, so apparently just a minor OpenVPN client tray bug.
I think tcp OpenVPN connections are still not working but haven't bothered trouble-shooting yet since udp works.
Regarding your questions, the equipment is all my own (Motorola SB6183 cable modem is purchased, not leased/rented), ISP is comcast, the Orbi is hard-wired to the cable modem and the only network firewall running is the Netgear Orbi (all computers are running anti-virus software). Those are all good areas to check, I use DDNS to track my public IP so I don't have a static one assigned from comcast. With ddwrt I specified routing table entries and firewall rules to handle tun OpenVPN connections for Samba shares, printers etc mainly because I use Android where tap is not supported but with the Orbi, I can't do any of that (not without a lot of work using undocumented access features anyway, and then it would be a bear to maintain). Fortunately Orbi seems to handle that automatically behind the scenes pretty well.
bkeith4web
Sep 04, 2020Guide
Mstrbig, thanks for checking in on this. The problem turned out to be my Netgear access controls. I've turned those on to restrict network access to explicitly listed MAC addresses and failed to realize that the OpenVPN client install, when creating the new (virtual) network adapter that is usually renamed to 'NETGEAR-VPN', would also create a new MAC address associated with that adapter. Adding that MAC to my access list made the tap connection work correctly. So now I can see everything on my LAN, connect to the internet etc. Interestingly, the OpenVPN taskbary tray icon still does not show anything under 'Assigned IP' when using tap but as I said before, ipconfig shows the correct address and my router shows that IP address and new virtual MAC address connected, so apparently just a minor OpenVPN client tray bug.
I think tcp OpenVPN connections are still not working but haven't bothered trouble-shooting yet since udp works.
Regarding your questions, the equipment is all my own (Motorola SB6183 cable modem is purchased, not leased/rented), ISP is comcast, the Orbi is hard-wired to the cable modem and the only network firewall running is the Netgear Orbi (all computers are running anti-virus software). Those are all good areas to check, I use DDNS to track my public IP so I don't have a static one assigned from comcast. With ddwrt I specified routing table entries and firewall rules to handle tun OpenVPN connections for Samba shares, printers etc mainly because I use Android where tap is not supported but with the Orbi, I can't do any of that (not without a lot of work using undocumented access features anyway, and then it would be a bear to maintain). Fortunately Orbi seems to handle that automatically behind the scenes pretty well.
Mstrbig
Sep 04, 2020Master
Glad you figured most of it out. Keep us posted.