× NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Announcements

Polls
What is your Experience with NETGEAR Insight cloud management?
0 Kudos

Orbi Firmware Upgrades Not Keeping Up With OpenVPN Security Standards

Greetings!

I am leveraging the VPN function on the Orbi which is using the OpenVPN. I have not been having a problem until around early last year when our connections using OpenVPN are now showing this error:

 

WARNING: Compression for receiving enabled. Compression has been used in the past to break encryption. Sent packets are not compressed unless "allow-compression yes" is also set.

DEPRECIATED OPTION: --cipher set to 'AES-128-CBC' but missing in --data-ciphers (AES-256-GCM: AES-128-GCM). Open VPN ignores --cipher for cipher negotiations

 

OpenVPN has made this change to remove compression way back in 2023-01. So this compression issue is preventing connection with VPN. Why hasn't NETGEAR been keeping up with this and making changes to VPN with Firmware upgrades. How can I fix this issue and get my VPN back up and running?

26 Comments
CrimpOn
Guru

You still don't understand what End of Life in Netgear terms is. No longer orderable new, no longer manufactured, but supported and maintained for five more years (at least).

 

Correct.  When Netgear posts on their web site, I foolishly believe that the words mean exactly what they say.

So, we can add to the list of Netgear failings that they are unable to state their End of Life policy correctly on the Netgear web site.

 

p.s. I still believe it will be a cold day in Hell before Netgear updates the OpenVPN software in the SXK80 product.

 

schumaku
Guru

Look @CrimpOn I've sent dozens of messages to earlier and current managers about the honestly useless an non-existing product lifecycle -:including the description of the negative impact on the user base due to this consumer garbage class EOL thinking in all management layers.

 

They still behave like a cheap Chinese hardware maker, not like a professional business class organisation.

schumaku
Guru

While looking around in the second source market for an affordable Orbi Pro for my home test environment (and the pure curiosity to see the issues and limitations like the non-up2date OpenVPN - non-workable with any OpenVPN systems in the field as of writing, and less the expected incomplete and broken https implementation) I found the Orbi Pro Wi-Fi 6 AC models SRR60 and SRS60 re still readily available - brand new from the distributor, not on some reseller stock - in the market. That much about what the misleading EOL list (updated in May 2024) is worth. Wonder when the newly appointed CTO - the emails are going through - will find the time to reply if the other mangers in charge for the SMB BU don't feel any responsibility in communicating and make engineering to do the job they are paid for. 

 

Yes, is DO understand what EOL entry on this list means: No longer orderable new from the factory. Most readers here don't.

ErwinL
NETGEAR Moderator

Hello 

 

Unfortunately when a Netgear product is already EOL it means the production of the said product has ended. We also stop providing software updates on the device so if any new issues surfaces relating to either software and hardware side of the product we normally advised them to get an upgraded model of similar product. Otherwise customers can only ask for replacement of their device with identical device model if needed.

 

Have a lovely day,
Erwin
Netgear Team

schumaku
Guru

Nobody is talking of -new- issues here @ErwinL 

 

So you tell us - officially and on behalf of Netgear - that existing stock can't no longer be maintained (software-wise), and existing users can request the replacement by an identical [much more Netgear]  have a language problem here and is maneuvering into a big trap. Identical ???

 

Not a lawyer, but please explain what an identical model is in your understanding, and in Netgear's still non-existing product life cycle publication for SMB devices. Is the idea -really- that Netgear does take the risks involved continuing selling these devices to customers - especially in the view that Netgear does -not- have any newer products with the feature set anywhere near to the Orbi Pro and Orbi Pro Wi-Fi 6 (just to name two examples).

 

A reasonable product life cycle documentation is https://www.cisco.com/c/en/us/products/eos-eol-policy.html 

 

Netgear must change and adopt right away. Otherwise, the complete Netgear business market is killed, obsolete, and the loyal system integrators must stop promoting and selling Netgear right now - because Netgear became this minute an untrusted vendor, not better than any lowest cost garbage manufacturer we find on the grab table at Walmart, Carrefour (Europe, Asia), Otto's (Switzeland), MediaMarkt/Saturn, ...

 

@YeZ @JohnHenkel wake up before it's to late!

schumaku
Guru

Or can we talk about the nightmare Netgear left in to the customers promoting the BR500, later BR200 - the marketing blush is still in the community in prominent locations. This was about the begin if the end where Netgear rendered hundreds of customer devices useless back then. Same now obsolete OpenVPN all over Netgear consumer and "busines" router offering, again rendering a lot of Netgear devices no longer worth the scrap metal value -! despite of the Insight licences still valid.

 

Simply the worst customer experience for business owners. Does Netgear seriously expect we will continue buying the expensive (but nice) M4300, M4250, M4350 Managed Business switches when not knowing these can be EOLed every minute? @LaurentMa @DavidGo 

 

What Netgear does is simply ways off from Business Class!

 

1000027259.png

ErwinL
NETGEAR Moderator

Hello @schumaku

 

Generally, when I said maintenance of software side of the device I mean the firmware updates. You will notice for some devices which are already EOL they have firmware updates posted long time ago. This means that Netgear does not provide updates of the firmware anymore. Anyone are free to switch from old firmware to the last one posted on our site.

 

When I refer to identical model, what I mean is the exact same model number of the device. I guess for some customer's requirements EOL devices still fits to what they only need and can continue using it. Netgear does not stop developing newer and better products, this is why in my perspective some became EOL. 

 

Have a lovely day,
Erwin
Netgear Team

schumaku
Guru

@ErwinL 

 

With all due respect: Like Netgear, you still don't understand. Of course, one can continue using it. However the lack of OpenVPN updates does render the these devices useless, and the same issue does exist - and started to exist when the newer and latest firmware were made available.

 

Different from professional business class product vendors, Netgear does still not publish any life cycle information. Three years would be industry standard, three years for announcements. So if you are happy talking about EOL, like your managers are. Useless. Consumer garbage.

 

-Kurt.

ErwinL
NETGEAR Moderator

Hello @schumaku

 

I think we would be asking the same question with other tech companies like Microsoft, Apple and the like. Where they stop support for updates on their previous OS. Some users still use their old OS for some specific software as well but why not just update instead of creating a whole new OS so users can continue with the software they want to use. I believe if OpenVPN is gone from the router it does not affect other features and functions which does not make the router useless. I think, generally there is reasonable plan why they are doing this. I myself have been repeatedly affected by this principles when dealing with tech updates of products from different companies I got at home. And I know the feeling and frustration at times but I got use to it and learned to accept such policies.

 

Have a lovely day,
Erwin
Netgear Team

FURRYe38
Guru

👍