Need Router Recommendation for VPN

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

ch33zw1z

Lifer
Nov 4, 2004
37,764
18,045
146
if this is your first run with DDWRT, read teh instructions a few times before trying the update.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
One last question that's been bugging me. You guys have talked about the router needing to encrypt data with processor. Will the ac66u be able to handle Netflix 4k? Otherwise, I'll get the ac68u.
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
From what I have read Netflix 4k needs 16-20 Mbps. The AC66u will not be able to achieve those speeds if it has to perform the openvpn encryption. If you are watching on a PC that is performing the encryption, then yes. I assume you are going to be using some other device and that would require the router cpu to perform all the hard work.

The AC68 does have the power to do the encryption and the R7000 has even more power to do it. According to this link, the ac66u was only able to do ~12Mbps. I don't know what the process is to flash the Asus routers to DD-WRT, but the Netgear only requires you to perform a factory reset through the Netgear router administrator settings page and then just upload the DD-WRT firmware of your choice on the Netgear upgrade page. The firmware upgrade and reboot will take about one minute. When it is finished, it is recommended to do a factory reset through the DD-WRT menu. Unlike routers of the past, no voodoo mumbojumbo is required.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Damn, I wasn't expecting to spend 2 bills on a new router. :O

Going to think about it and buy something before tomorrow.

Edit:
OKay, I found some instructions for the ac68u. Seems simple enough.
 
Last edited:

ch33zw1z

Lifer
Nov 4, 2004
37,764
18,045
146
TuSpock, read the article please. The "12Mbps" was specifically a speed test to a UK PIA server. As with all speed tests, YMMV. That's not the Asus router limiting the speeds....

here's a smallnetbuilder link to compare two high end soho devices. http://www.smallnetbuilder.com/wire...1900-first-look-netgear-r7000-a-asus-rt-ac68u

BeeBoop:

http://i.imgur.com/Y0jimXr.png - picture of page with firmware on it

http://www.dd-wrt.com/wiki/index.php/Installation - install instructions.

The instructions on the reddit page should probably work, never tried them. The method can be different, so make sure you're reading it through before attempting it.

I do the 30-30-30 reset before I kick it off and after the new firmware is on it.
 
Last edited:

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Thanks Ch33z, tuspa, and everyone else. I ordered the ac68u last night from Amazon.
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
TuSpock, read the article please. The "12Mbps" was specifically a speed test to a UK PIA server. As with all speed tests, YMMV. That's not the Asus router limiting the speeds....

here's a smallnetbuilder link to compare two high end soho devices. http://www.smallnetbuilder.com/wire...1900-first-look-netgear-r7000-a-asus-rt-ac68u

BeeBoop:

http://i.imgur.com/Y0jimXr.png - picture of page with firmware on it

http://www.dd-wrt.com/wiki/index.php/Installation - install instructions.

The instructions on the reddit page should probably work, never tried them. The method can be different, so make sure you're reading it through before attempting it.

I do the 30-30-30 reset before I kick it off and after the new firmware is on it.


The CPU on the ac66u does not have the power to achieve the op's stated goals and with PIA. The article was not about the ac68 with it's dual core 800mhz cpu. The article was about the single core 600mhz cpu on the ac66. I never said anything about Asus being the problem. There is a big difference between a 600mhz single core and a 800/1000mhz dual core when it comes to encryption and compression of a vpn tunnel. I would expect that the ac68 should be able to get around 36Mbps on a U.S. PIA server. The 600Mhz single core in the article was just about maxed out and it does not really matter what server it is connected to.

BeeBoop, the ac68 is a fine choice.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
If it makes any difference, I'll be watching on a UK server from the U.S. because they have Better Call Saul in 4k.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Haven't tried. I'll do it when I get home later.

Edit:
Speed seems to be fine depending on who I connect too. I've managed to find some at 18 to 28 MPbs download.
 
Last edited:

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
How do I set the time correctly in the Asus ac68 router? I don't understand the UTC options for time. I live in the central time zone. I also don't understand the months setting under UTC option. What should that be?
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
How do I set the time correctly in the Asus ac68 router? I don't understand the UTC options for time. I live in the central time zone. I also don't understand the months setting under UTC option. What should that be?

CST would be -06:00

Did you flash the router yet?
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Yup, I flashed it to dd-wrt. Than I did another flash but I had no idea what flash file to pick from Kong's data base so I did a random pick. I think it was Kong's data base at least.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
So I'm having a problem with PIA on the Asus AC68u router. Only one computer can connect to the internet when I enable PIA. All other devices will disconnect from the internet.
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
So I'm having a problem with PIA on the Asus AC68u router. Only one computer can connect to the internet when I enable PIA. All other devices will disconnect from the internet.

Set up openvpn client like you see here for PIA.

2myuw7b.jpg


For Server, use any one of the following:

United States (US VPN)
us-california.privateinternetaccess.com
us-east.privateinternetaccess.com
us-midwest.privateinternetaccess.com
us-texas.privateinternetaccess.com
us-florida.privateinternetaccess.com
us-seattle.privateinternetaccess.com
us-west.privateinternetaccess.com
us-siliconvalley.privateinternetaccess.com

United Kingdom (GB VPN)
uk-london.privateinternetaccess.com
uk-southampton.privateinternetaccess.com

Canada (CA VPN)
ca-toronto.privateinternetaccess.com
ca.privateinternetaccess.com

Australia (AU VPN)
aus.privateinternetaccess.com
aus-melbourne.privateinternetaccess.com

Netherlands (NL VPN)
nl.privateinternetaccess.com

Switzerland (CH VPN)
swiss.privateinternetaccess.com

Sweden (SE VPN)
sweden.privateinternetaccess.com

France (FR VPN)
france.privateinternetaccess.com

Germany (DE VPN)
germany.privateinternetaccess.com

Romania (RO VPN)
ro.privateinternetaccess.com

Hong Kong (HK VPN)
hk.privateinternetaccess.com

Singapore (SG VPN)
sg.privateinternetaccess.com

Japan (JP VPN)
japan.privateinternetaccess.com

Israel (IL VPN)
israel.privateinternetaccess.com

Mexico (MX VPN)
mexico.privateinternetaccess.com

The port and encryption cipher can be either of the following

1196
AES-128CB

or

1194
Blowfish CBC

Additional Config:

persist-key
persist-tun
tls-client
remote-cert-tls server

For Policy Based Routing, use the IP's you want to go through the tunnel. If none are entered, everything should go through.

CA Cert should be all of the following including the all the -----

-----BEGIN CERTIFICATE-----

-----END CERTIFICATE-----


If you want to route only some ip's through the vpn and use policy based routing you can create a firewall script to act as a kill switch for those ip's to prevent using the wan gateway. Set it up like the following using your local ip's.

29cpboy.jpg


iptables -I FORWARD -s 192.168.1.5 -o $(nvram get wan_iface) -j REJECT
iptables -I FORWARD -s 192.168.1.102 -o $(nvram get wan_iface) -j REJECT
iptables -I FORWARD -s 192.168.1.105 -o $(nvram get wan_iface) -j REJECT
iptables -I FORWARD -s 192.168.1.116 -o $(nvram get wan_iface) -j REJECT
iptables -I FORWARD -s 192.168.1.117 -o $(nvram get wan_iface) -j REJECT

etc.

Hope this helps.
 
Last edited:

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
What build are you using? Can u link me to the exact file to download? I like how you have the Username and Password already in the settings. I have to run a command for my setup.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Thanks for your help. I tried your settings but it didn't work, couldn't even connect to the VPN. I can connect using what PIA customer support gave me but not your setup.

Something is blocking my connections. I just can't figure it out. ARRGG! I can only connect to the VPN with one computer, the computer that I setup the VPN changes. Other devices will not connect to the internet but they are able to connect to the router. So at least that much is working.

Edit
Hopefully your build will fix my issues.
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
Try the new build and if you have problems, post a screenshot of the Services/VPN tab and the Administration/Commands tab.

Blur your login credentials and wan ip of course.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
http://www.imagebam.com/image/5e3993400504427

http://www.imagebam.com/image/4ef42c400504429

http://www.imagebam.com/image/33ffc4400504432

I was able to connect but the same thing happened. Only one PC was able to connect to the VPN but the others were not, internet was blocked on others. I could however access the router on my surface pro. The surface pro was not able to connect to the VPN. The pro had no access to the internet when VPN is on. The surface pro wireless connection was the only other computer I checked.

I didn't edit anything in the Admin/Command prompt because I am assuming the code is used to enter in the username/password, which is why I wanted your firmware.

Also, I'll have to finish this tomorrow if you have any updated suggestions. Thanks for the helping!
 

TuSpockShakur

Senior member
May 28, 2014
244
1
51
Set the MTU to 1500, anything lower will cause errors on the Status/OpenVPN tab.
All of your settings look good otherwise. If you first tried to use one of the older scripts to setup your tunnel from the Administration/Commands page it might be possible that some of those settings are still in nvram. I would suggest that you either ssh or telnet in to your router and issue " erase nvram " command followed by " reboot " command. A reset via the Administration/Factory Defaults page is more of a soft reset.

If you are not familiar with using SSH or Telnet, I suggest installing a program called Putty. Connect to SSH on port 22 or Telnet on port 23 and use login root and the password you set on your initial dd-wrt login. You will be in a BusyBox terminal and from there issue your commands one at a time " erase nvram " followed by " reboot ". Telnet is on by default, SSH has to be enabled under Services "Secure Shell".

If problems still exist you will need to migrate further questions to the source.
 

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
Frustrating. Not working. I mean I am unable to log into putty. I think i'm going to return this router and get the r7000.

Edit:
I am unable to log into putty with my username and password.

Edit 2:
On second thought. I'm going to return this router and get a normal one because I've only been able to get 10mb download from all the servers that I've connected too. That's not enough for Netflix 4k. I'll just wait the 2 weeks for Better Call Saul. This is just too much trouble.
 
Last edited:

BeeBoop

Golden Member
Feb 5, 2013
1,677
0
0
I installed it and got locked out. The username and password changed to something unknown. Didn't want to do a 30-30-30 reset or deal with it anymore. It's in the box to get shipped back tomorrow.