Jump to content
Not connected, Your IP: 216.73.217.154
Keeble

ANSWERED Asus Merlin VPN Network Unreachable

Recommended Posts

Posted ... (edited)

Hello!
I recently got AirVPN and have been using it to torrent, it's been working somewhat well until I realized the server I was using had god awful speeds (for reference I have gig speeds and it was giving me 50mbps up/down). So I wanted to change my config to another server, now the routers OpenVPN won't connect at all to the server. I uploaded multiple different configs and all say the same error, I've also tried different OPVN versions and have confirmed that my router uses v2.6. But everytime I try to connect it gives me an error of "ovpn-client1[7647]: sitnl_send: rtnl: generic error (-101): Network is unreachable"

Would anyone know whats going on? 
Thanks!

Full log:

Oct 16 10:44:35 ovpn-client1[7646]: OpenVPN 2.6.14 arm-buildroot-linux-gnueabi [SSL (OpenSSL)] [LZO] [LZ4] [EPOLL] [MH/PKTINFO] [AEAD]
Oct 16 10:44:35 ovpn-client1[7646]: library versions: OpenSSL 1.1.1w  11 Sep 2023, LZO 2.10
Oct 16 10:44:35 ovpn-client1[7647]: NOTE: the current --script-security setting may allow this configuration to call user-defined scripts
Oct 16 10:44:40 ovpn-client1[7647]: TCP/UDP: Preserving recently used remote address: [AF_INET]198.54.129.62:443
Oct 16 10:44:40 ovpn-client1[7647]: Socket Buffers: R=[524288->524288] S=[524288->524288]
Oct 16 10:44:40 ovpn-client1[7647]: UDPv4 link local: (not bound)
Oct 16 10:44:40 ovpn-client1[7647]: UDPv4 link remote: [AF_INET]198.54.129.62:443
Oct 16 10:44:40 ovpn-client1[7647]: TLS: Initial packet from [AF_INET]198.54.129.62:443, sid=b357b073 5b5c838a
Oct 16 10:44:40 ovpn-client1[7647]: VERIFY OK: depth=1, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=airvpn.org CA, emailAddress=info@airvpn.org
Oct 16 10:44:40 ovpn-client1[7647]: VERIFY KU OK
Oct 16 10:44:40 ovpn-client1[7647]: Validating certificate extended key usage
Oct 16 10:44:40 ovpn-client1[7647]: ++ Certificate has EKU (str) TLS Web Server Authentication, expects TLS Web Server Authentication
Oct 16 10:44:40 ovpn-client1[7647]: VERIFY EKU OK
Oct 16 10:44:40 ovpn-client1[7647]: VERIFY OK: depth=0, C=IT, ST=IT, L=Perugia, O=airvpn.org, CN=Sarin, emailAddress=info@airvpn.org
Oct 16 10:44:41 ovpn-client1[7647]: Control Channel: TLSv1.3, cipher TLSv1.3 TLS_CHACHA20_POLY1305_SHA256, peer certificate: 4096 bits RSA, signature: RSA-SHA512, peer temporary key: 253 bits X25519
Oct 16 10:44:41 ovpn-client1[7647]: [Sarin] Peer Connection Initiated with [AF_INET]198.54.129.62:443
Oct 16 10:44:41 ovpn-client1[7647]: TLS: move_session: dest=TM_ACTIVE src=TM_INITIAL reinit_src=1
Oct 16 10:44:41 ovpn-client1[7647]: TLS: tls_multi_process: initial untrusted session promoted to trusted
Oct 16 10:44:42 ovpn-client1[7647]: SENT CONTROL [Sarin]: 'PUSH_REQUEST' (status=1)
Oct 16 10:44:42 ovpn-client1[7647]: PUSH: Received control message: 'PUSH_REPLY,comp-lzo no,redirect-gateway ipv6 def1 bypass-dhcp,dhcp-option DNS 10.17.26.1,dhcp-option DNS6 fde6:7a:7d20:d1a::1,tun-ipv6,route-gateway 10.17.26.1,topology subnet,ping 10,ping-restart 60,ifconfig-ipv6 fde6:7a:7d20:d1a::1055/64 fde6:7a:7d20:d1a::1,ifconfig 10.17.26.87 255.255.255.0,peer-id 9,cipher CHACHA20-POLY1305,protocol-flags cc-exit tls-ekm dyn-tls-crypt,tun-mtu 1500'
Oct 16 10:44:42 ovpn-client1[7647]: OPTIONS IMPORT: --ifconfig/up options modified
Oct 16 10:44:42 ovpn-client1[7647]: OPTIONS IMPORT: route options modified
Oct 16 10:44:42 ovpn-client1[7647]: OPTIONS IMPORT: route-related options modified
Oct 16 10:44:42 ovpn-client1[7647]: OPTIONS IMPORT: --ip-win32 and/or --dhcp-option options modified
Oct 16 10:44:42 ovpn-client1[7647]: OPTIONS IMPORT: tun-mtu set to 1500
Oct 16 10:44:42 ovpn-client1[7647]: GDG6: remote_host_ipv6=n/a
Oct 16 10:44:42 ovpn-client1[7647]: net_route_v6_best_gw query: dst ::
Oct 16 10:44:42 ovpn-client1[7647]: sitnl_send: rtnl: generic error (-101): Network is unreachable
Oct 16 10:44:42 ovpn-client1[7647]: TUN/TAP device tun11 opened
Oct 16 10:44:42 ovpn-client1[7647]: TUN/TAP TX queue length set to 1000
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip link set dev tun11 up mtu 1500
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip link set dev tun11 up
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip addr add dev tun11 10.17.26.87/24
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip link set dev tun11 up mtu 1500
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip link set dev tun11 up
Oct 16 10:44:42 ovpn-client1[7647]: /usr/sbin/ip -6 addr add fde6:7a:7d20:d1a::1055/64 dev tun11
Oct 16 10:44:42 ovpn-client1[7647]: Linux ip -6 addr add failed: external program exited with error status: 2
Oct 16 10:44:42 ovpn-client1[7647]: Exiting due to fatal error
Edited ... by Keeble
added speed context

Share this post


Link to post

Looks a bit like IPv6 is disabled completely on the device, but your generated config requests a v6 address. When generating configs in the generator, tick Advanced and make sure to set IP layer exit on the right to IPv4 only.
Or, you know, simply enable IPv6. Much better solution, actually. There is no reason to disable it.


NOT AN AIRVPN TEAM MEMBER. USE TICKETS FOR PROFESSIONAL SUPPORT.

LZ1's New User Guide to AirVPN « Plenty of stuff for advanced users, too!

Want to contact me directly? All relevant methods are on my About me page.

Share this post


Link to post
25 minutes ago, Tech Jedi Alex said:

Looks a bit like IPv6 is disabled completely on the device, but your generated config requests a v6 address. When generating configs in the generator, tick Advanced and make sure to set IP layer exit on the right to IPv4 only.
Or, you know, simply enable IPv6. Much better solution, actually. There is no reason to disable it.

Ah that was it! I swore I tried a config with iPv6 disabled but I guess not. I just enabled it on my router and we're goin! Thank you!

Share this post


Link to post

Hope it's correct form to append to this thread for the sake of others?  Or should I start a new one?

I have just had this problem.  Yes, I have ip6 disabled in Merlin. 

The issue is the AirVPN configurator is not inserting the ip4 only commands into the .opvn file even when "ip4 only" is selected in Configurator. 

I have to add the following to the .opvn file:
pull-filter ignore "dhcp-option DNS6"
pull-filter ignore "tun-ipv6"
pull-filter ignore "ifconfig-ipv6"
pull-filter ignore "route-ipv6"
setenv UV_IPV6 no 
The last command being optional.

Is this by design? 

I had been told security was enhanced with ip4 only set on the Merlin side.  Per Perplexity AI:

"Merlin currently does not route IPv6 traffic through an external OpenVPN client reliably, so enabling IPv6 on the router while relying on OpenVPN can recreate the leak risk. The safest configuration for your existing hardware and goal is therefore to block IPv6 rather than attempt to tunnel it".

But this then causes a conflict with the Configurator generated .opvn file causing the vpn not to load.  Maybe because no one selects ip4 only in the Configurator any more?! Is this AI security claim false and should I just include ip6 in both Merlin and the Configurator?

Share this post


Link to post
1 hour ago, Hotgloblin said:

Hope it's correct form to append to this thread for the sake of others?  Or should I start a new one?


Please start your own and give as much info as you can on the problem, what you tried, what you try to achieve, etc.; this is a help thread for another user.
Simple formality. Hope it won't deter you :)

NOT AN AIRVPN TEAM MEMBER. USE TICKETS FOR PROFESSIONAL SUPPORT.

LZ1's New User Guide to AirVPN « Plenty of stuff for advanced users, too!

Want to contact me directly? All relevant methods are on my About me page.

Share this post


Link to post
Guest
This topic is now closed to further replies.

×
×
  • Create New...