Jump to content
Not connected, Your IP: 3.22.181.209
sdjh4dfgez7

FreshTomato: OpenVPN client connects to AirVPN server but Traffic is not beeing routed through

Recommended Posts

Posted ... (edited)

Hi,
I switched from AdvancedTomato to FreshTomato 2022.3 and unfortunately now the OpenVPN Connection is not working properly. Here is what I found so far:
I can connect to an AirVPN Server but I have no connection to any Website if I set up the IP of my computer to be routed through VPN but I can ping e.g. 8.8.8.8 from my Computer and get a respronse .If I disable the Routing Policy I can connect to any Website but of course through my ISP IP. Is it possible to be a DNS issue?
Here are screenshots of my OpenVPN and WAN settings:
image.png.88e5c7df57ae91ea15cef1f34014efde.png1.png.f9356d2f0e09b2678f2114855e8a87b1.pngimage.png.fcb40a1a8cf6c139871c1fc2d7af9061.pngimage.png.e25de5a3ae414b6233ae1cad34dfb894.png3.png.f08cbc25631445530b6a41a676b8a67d.png

 

 

Edited ... by sdjh4dfgez7

Share this post


Link to post

I don't use FreshTomato.

  1. What is the address of 192.168.1.28 in the Routing Policy?
  2. What happens if I change 192.168.1.28 to 192.168.1.1/26 (or /24)?

Share this post


Link to post

1. 192.168.1.28 is the IP of my PC.
2. I also tried 192.168.1.1/24 and 192.168.1.0/24. Both dont work. If I disable Routing policy, then I have access to the Internet, but through my ISP IP

Share this post


Link to post

re the openvpn setup

1) set accept DNS configuration to something like yes or exclusive.  that way you use AirVPN DNS.
2) AirVPN does not use compression so the two different compression settings you're using need to be gone.
3) I don't see anywhere that you're choosing the auth digest algorithm.  Is there another openvpn config page we're not seeing?  If you're using a tls-crypt config then you need to choose something different at "tls control channel security" and use sha512 for auth digest algorithm.  If using only tls-auth config then you have tls control channel security correct but auth digest is sha1.
3) I don't think your policy routing rule is correct but I've never used that OS.  It looks like you'd need to enable it at least.

Share this post


Link to post

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Loading...
  • Security Check
    Play CAPTCHA Audio
    Refresh Image

×
×
  • Create New...