How to setup a vpn server using a dd-wrt router
William Smith
Updated on March 29, 2026
We have previously covered how to set up a PPTP VPN Server using Debian Linux here on Sysadmin Geek, however if you are already utilizing a DD-WRT firmware based router in your network then you can easily configure your router to act as the PPTP VPN Server.
DD-WRT Configuration
Before setting up the VPN Server, you must first make sure your installed build of DD-WRT includes the PPTP VPN features. The DD-WRT feature list shows this as “PPTP / PPTP Client” on their chart. Check the installed version on your router (which you can see in the upper right corner on the configuration pages) against the chart. If the feature is not included in your build, you will need to flash your router with a DD-WRT version which does include the “PPTP / PPTP Client”.
To turn on the PPTP VPN Server, navigate to the Services tab and then the VPN sub-tab and select the option to enable the PPTP Server.
Once enabled, several previously hidden options will appear. Configure them as follows:
- Server IP: Public IP address of the router
- Client IP(s): List of local IP’s (respective to the VPN network) to use when assigning IP addresses to clients connecting through the VPN. In our example, we are setting aside 5 IP addresses (192.168.16.5, .6, .7, .8, .9) for use by the VPN clients.
- CHAP-Secrets: User name and passwords for VPN authentication. The format is “user * password *” (user[space]*[space]password[space]*), with each entry on its own line. In our example, there is just a single accepted user name (jfaulkner) and password (SecretPassword1).
You can view detailed documentation on all of these options by clicking the “Help more…” link on this page on the right side of the DD-WRT configuration.
Once you are finished, click the Apply Settings button to push the configuration through to your DD-WRT router and you are finished.
Connecting to the PPTP VPN Server
Once you have your DD-WRT router configured, all that is left is to simply connect your client computers to the VPN. For our example, we will be showing how this is done using Windows 7 Professional.
In the Network and Sharing Center of the Control Panel, click the option to set up a new network connection.
Select the option to connect to a workplace VPN.
If you have existing connections, they will be displayed here. For our example, we want to create a new connection.
Select the option to use your Internet connection to connect to the VPN.
Enter the domain or IP address of your VPN Server (the public IP address of the DD-WRT router configured above) and give a title to the VPN connection.
Enter the credentials for your VPN login which was configured in the DD-WRT router settings. Click Connect.
After a few moments, if everything is configured correctly, you should be connected to the PPTP VPN Server on the DD-WRT router.
Running ‘ipconfig’ on the local machine should show you are connected to both the VPN and your existing internet connection.
Once connected, you can now access all the resources on the VPN as though you were connected to the network locally.
Ранее мы рассмотрели как настроить PPTP VPN-сервер с помощью Debian Linux здесь, в Sysadmin Geek, однако, если вы уже используете маршрутизатор на основе прошивки DD-WRT в своей сети, вы можете легко настроить свой маршрутизатор для работы в качестве сервера PPTP VPN.
Конфигурация DD-WRT
Перед настройкой VPN-сервера вы должны сначала убедиться, что установленная вами сборка DD-WRT включает функции PPTP VPN. В списке функций DD-WRT это отображается как «Клиент PPTP / PPTP» на диаграмме. Сравните версию, установленную на вашем маршрутизаторе (которую вы можете увидеть в правом верхнем углу на страницах конфигурации), по таблице. Если эта функция не включена в вашу сборку, вам нужно будет прошить ваш маршрутизатор версией DD-WRT, которая включает «PPTP / PPTP Client».
Чтобы включить PPTP-сервер VPN, перейдите на вкладку «Службы», а затем во вложенную вкладку «VPN» и выберите параметр для включения PPTP-сервера.
После включения появятся несколько ранее скрытых параметров. Настройте их следующим образом:
- IP-адрес сервера: общедоступный IP-адрес маршрутизатора.
- Клиентские IP-адреса: список локальных IP-адресов (соответствующих сети VPN) для использования при назначении IP-адресов клиентам, подключающимся через VPN. В нашем примере мы выделяем 5 IP-адресов (192.168.16.5, .6, .7, .8, .9) для использования клиентами VPN.
- CHAP-Secrets: имя пользователя и пароли для аутентификации VPN. Формат: «пользователь * пароль *» (пользователь[space] * [space]пароль[space] *), где каждая запись находится в отдельной строке. В нашем примере есть только одно допустимое имя пользователя (jfaulkner) и пароль (SecretPassword1).
Вы можете просмотреть подробную документацию по всем этим параметрам, щелкнув ссылку «Help more…» на этой странице справа от конфигурации DD-WRT.
После завершения нажмите кнопку «Применить настройки», чтобы передать конфигурацию маршрутизатору DD-WRT, и все готово.
Подключение к PPTP VPN серверу
После того, как вы настроили маршрутизатор DD-WRT, все, что осталось – просто подключить клиентские компьютеры к VPN. В нашем примере мы покажем, как это делается с помощью Windows 7 Professional.
В Центре управления сетями и общим доступом на панели управления щелкните параметр, чтобы настроить новое сетевое подключение.
Выберите вариант подключения к VPN на рабочем месте.
Если у вас есть существующие подключения, они будут отображаться здесь. В нашем примере мы хотим создать новое соединение.
Выберите вариант использования подключения к Интернету для подключения к VPN.
Введите домен или IP-адрес своего VPN-сервера (публичный IP-адрес маршрутизатора DD-WRT, настроенный выше) и дайте название VPN-соединению.
Введите учетные данные для входа в VPN, которые были настроены в настройках маршрутизатора DD-WRT. Щелкните Подключиться.
Через несколько секунд, если все настроено правильно, вы должны подключиться к PPTP VPN серверу на маршрутизаторе DD-WRT.
Запуск «ipconfig» на локальном компьютере должен показать, что вы подключены как к VPN, так и к существующему интернет-соединению.
После подключения вы можете получить доступ ко всем ресурсам в VPN, как если бы вы были подключены к сети локально.
Interesting article about strength and security of PKI today Pro-Linux (german)
On DD-WRT, go to the Administration->Services and set PPTP server to active, save the changes, then set the IP of router (192.168.1.1) for the server IP, and under Client IP(s) set a range for connections. (192.168.1.20-29 for example of a ten client set up)
Under Chap Secret put in username * password * for example: testmachine * password1234 * ( The “*” are NOT a Placeholder, they must be there ! ) Use no capital letters. Also avoid using the # character since this breaks pptp. (This also applies to the router administration password that is included by default in the password file for pptpd.)
Now on your PC select Create new Connection under Control Panel -> Network Connections. Select Connect to Network at my Workplace, then select Virtual Private Connection, give it a name (home link). Select what applies, dial up or LAN. Type the WAN IP address of your router, it must be static address or an address through DynDNS.org or the likes. (Thanks loxza)
Then at connect window, type the username and password you used earlier under Chap Secret (in our example: testmachine:password1234 ). Use no capital letters.
If you have followed the above steps and still cannot connect to the VPN, try forwarding the PPTP Port (1723) with TCP protocol to the LAN IP Address of your router (i.e. 192.168.1.1). Although it seems like this is a weird approach since you are using your router to forward to itself, it often times allows the VPN connection to suceed.
For more information on setting up a VPN connection in Windows XP see this article.
For other Windows versions see this link.
If you have Problems to see your Network Neighbourhood or Programs like VNC and Remote Desktop are not working, then you should Disable the Loopback Adapter under Administration -> Management in your Router. If this does not work, then it is also useful to edit your new VPN Connection under Properties -> TCP/IP -> Advanced -> and select Use Standard Gateway of the Remote Network. With this Option you are fully inside the Router’s Network, all Traffic include your Surfing is then over your VPN Connect. With both Settings, you are fully integrated in the Remote LAN.
Я пытаюсь настроить VPN-сервер PPTP на своем маршрутизаторе DD-WRT за NAT (маршрутизатор ISP моего провайдера). Я много гуглил, но, похоже, не так много людей упоминают об этом точном сценарии ниже:
ИНТЕРНЕТ Интернет-провайдер DD WRT
Маршрутизатор ISP: WAN IP: xx.xxx.xx.xx подсеть: 192.168.1.xxx IP-маршрутизатор: 192.168.1.1
DD WRT (My Router): WAN IP: 192.168.1.10 подсеть: 10.170.1.xxx ip маршрутизатора: 10.170.1.1
VPN-сервер включен с секретным паролем PPTP: томас * пароль *
ISP-маршрутизатор – это то, чего я не могу коснуться. У меня нет логина к роутеру, и провайдер не собирается менять для меня какие-либо настройки (например, DMZ).
Я попытался подписаться на службу VPN (StrongVPN), и мой маршрутизатор DD-WRT подключился к этой VPN, чтобы он мог получить публичный IP-адрес WAN (скажем, 123.123.123.123). Мне удалось получить IP-адрес WAN, но когда я использую другой компьютер (из внешней сети) и подключаюсь к 123.123.123.123, по какой-то причине StrongVPN немедленно обрывает соединение.
Я сейчас очень расстроен и надеюсь, что некоторые сетевые эксперты могут пролить мне свет на это.
Ваша помощь приветствуется!
Серверу PPTP требуется TCP-порт 1723, а также IP-протокол 47 (GRE) для пересылки на него. Предполагая, что ваш ISP-маршрутизатор обрабатывает переадресацию портов, вы не сможете запустить PPTP-сервер через него без перенаправления портов на него.
Я не верю, что существуют какие-либо решения для VPN-серверов, которые будут работать без перенаправления соответствующих портов.
Могут быть и другие программные решения, имитирующие аналогичный интерфейс, но у меня нет рекомендаций по этому поводу, и рекомендации по программному обеспечению находятся за пределами компетенции этого сайта. Лучше всего было бы искать что-то вроде VPN server without port forwarding .
Существует аналогичная тема здесь , хотя это не относится к VPN, в зависимости от ваших требований , он все еще может быть полезным.
Я заметил, что проблема заключается в DD-WRT. Если вы хотите использовать службу VPN в микропрограмме DD-WRT, и в то же время, если ваш маршрутизатор находится за NAT и хочет установить другое VPN-клиентское подключение к сторонней службе VPN, DD-WRT почему-то не ‘ не отвечает правильно (наверное, из-за какой-то ошибки в прошивке DD-WRT).
Конечно, я не заинтересован в исправлении ошибок.
Я сделал обходной путь, который прекрасно работает. Я добавил дополнительный маршрутизатор DD-WRT.
ИНТЕРНЕТ Интернет-провайдер DD WRT DD-WRT
Давайте назовем их так: A B C D
Я настроил «C» так, чтобы это был сам VPN-клиент и соединения с третьим лицом vpn (PureVPN в моем случае) со статическим IP-адресом (например, 123.123.123.123). Затем я установил для этого DMZ, которая направляет все пакеты в «D».
Тогда «D» теперь по умолчанию является общедоступным, поскольку при выполнении команды ping или любых типов подключения к 123.123.123.123 просто будет идти «D». Я настроил VPN-сервис на “D” и бинго! Работает как шарм!
Для тех из вас, кто пытается сделать то же самое, просто чтобы дать вам голову. Первоначально у меня это работало, но каким-то образом, когда я пытаюсь установить VPN-соединение из внешнего мира, в мой VPN-сервис в «D», оно немедленно сбрасывает соединение.
Причина этого заключалась в том, что в: Безопасность> VPN Passthrough я включил все 3 сквозных перехода, которые, даже до сих пор, я думал, что имеет больше смысла: – IPSec Passthrough – PPTP Passthrough – L2TP Passthrough
Но в действительности вы должны отключить IPSec Passthrough и L2TP Passthrough, чтобы не дать VPN-серверу разорвать внешнее соединение.
Все еще не уверены, почему. Может быть, кто-то может объяснить? Но это не важно в рамках этого вопроса.
Why use VPN on just a handful of devices?
One of the major reasons probably why you might be using a VPN is to keep your online identity safe and secure. Using a VPN is easy. All you need to do is download the VPN client on your laptop/computer, connect to the VPN server and you are good to go. If you are using the internet on your iPhone or Android, the process is pretty simple too.
Most VPN providers like NordVPN provide you with an app for each of these platforms. You need to establish a connection via these apps, and that’s it. To know more about the supported devices, you can read this review.
But the problem arises when you want to connect your additional devices like an Apple TV to a VPN, and cannot figure out a convenient way to do so.
Further, what if you have 8 devices at home, all of which need to be connected to a VPN?
The ideal solution here is to connect your home router to a VPN, and you can then access the internet securely on each of your devices.
If you are using a DD-WRT router, here is an ultimate guide on how you can configure up the VPN on this router. The process isn’t trivial, but it is not overly complex either.
Let’s have a look.
Install DD-WRT
We’re assuming that your router doesn’t have DD-WRT. If that’s not the case, you can freely skip this step.
For the ones who do not have DD-WRT, follow the following steps (here) or perform the steps below.
- Visit and enter the model number of your router. If your router supports DD-WRT, you will be provided with all the details regarding firmware requirements that you need to download.
- Update your firmware, and reboot your router.
- Next, visit to set up your router. In here, you will be asked to provide a username and password.
- You will be then redirected to the next page. Click on Setup and provide the username and password you just created.
- The next page will provide you with all the basic details of the router including its name, IP address and DHCP settings.
- In the next dropdown, choose Automatic Configuration – DHCP.
Choose DHCP
- Do not touch the DHCP settings and leave them to default. Change the time settings according to your zone.
- Once this is done, click on the Wireless tab and configure your Wireless network.
Go to the Wireless Tab
Set Up Dynamic DNS
Now, you need to set up a DNS redirector for your dynamic WAN IP. The thing is that your ISP keeps on changing your IP address, until and unless you have paid it for a static IP.
This creates problems, as you will need to update your VPN settings every time your IP address gets changed.
Do not worry. There is a way out here. You can use a dynamic DNS service that creates a URL that reflects the updated IP provided by your ISP. Here are the steps you need to follow:
- Create a free account with afraid.org and go to subdomain menu.
Go to Subdomains
- In the next field, create a subdomain of your liking and then choose a domain from the dropdown. Create the Subdomain
- Next, enter your router’s WAN IP in the destination field. You can get the WAN IP from the DD-WRT page.
Enter your WAN IP
- Next, click Save and then click on DDNS.
Saving DDNS
- Now copy the URL provided to you on the next page next to the subdomain entry.
- Now, go back to your router page, and below Setup, click on DDNS tab.
- From the dropdown menu, select freedns.afraid.org and provide the required username and password.
- Provide the URL copied above in the hostname field, and enable the external IP check as Yes.
- In the Force Update Interval field, enter 10.
PPTP Configuration
- On your router page, click on Services > VPN.
- Enable the PPTP Server. Disable the Broadcast Support, and enable the MPPE Encryption.
- Provide your DNS configuration.
- WINS servers can be skipped.
- MTU and MRU settings should be left as it is.
- Use your router’s IP as the server IP.
Device Configuration
Next, go ahead, and set up your VPN on the device, and you are done! Here is how you can configure a Windows laptop.
- Start > Settings > Network and Internet > VPN
- Click on Add a VPN connection
- Under the VPN Provider, write Windows. Enter afraid.org DNS address in the Server name field. Or, you can enter your router’s WAN IP. Select PPTP in the VPN type dropdown.
- Type of sign-in info should be Username and Password.
- Next, provide the username and password.
- Click connect.
Wrapping Up
This brings us to the end of this tutorial. If you have any questions, let us know in the comments below.
You can set up your own VPN server at home or small office. Use it to securely connect to your network when you are outside.
- What is Virtual Private Server (VPS)?
- Is the private game server legal?
Network administration – Virtual private networks, Virtual Private Network, are not just for corporate networks. You can set up your own VPN server at home or small office . Use it to securely connect to your network when you’re outside, gaining access to shared folders and network computers. You can also see its usefulness in public networks or Wi-Fi hotspots, securing your traffic in front of snoopers.
One way to set up a VPN server is to simply load DD-WRT into your router, if it’s compatible. DD-WRT is a software replacement. It replaces the router’s brain, giving it a new control panel with more features, such as a VPN server. You can check the compatibility with your router here.
In this article, we will show you the DD-WRT Point-to-Point Tunneling Protocol (PPTP) feature. Although PPTP has many of the same vulnerabilities as other protocols, sometimes we can still accept some level of risk. In addition to easy configuration and management, PPTP is also supported in Windows.
However, there is one problem to keep in mind first, if you have to work with customer data or highly sensitive information then you definitely need to consider a safer VPN solution. Maybe after this tutorial we will show you how to set up OpenVPN in DD-WRT, this is a safe solution but the installation will be much more complicated. In addition, users must download and configure the client utility to connect.
Router
Start with Router Database. Type in the carrier or model number and hope it will provide you with a list of compatible software versions as well as variants. Not arbitrarily, please carefully follow all the installation instructions.
The most stable release of DD-WRT at the time of publication of this article is v24 SP1 (Build 10020), which is what we will use in this tutorial. These directions also work with v24 SP2 because we tested with Beta 13064 build.
Note that, you do not have to use the VPN variant if you just want to use PPTP VPN server or client; they are available in all variants except Mini. Special VPN variants allow you to get more secure OpenVPN servers and clients, so use it if you plan to try it later.
Enable PPTP VPN Server
To start, log in to the web control panel. Type the IP address 192.168.1.1 into the web browser. The first time you access the router, you will be prompted to create a username and password.
Click the Services tab and select the PPTP sub tab. In the PPTP Server area, select Enable . Then enter the IP address of the router (192.168.1.1) for Server IP.
For IP clients, enter an address if you only have one user. If there are multiple users, you can specify the address range. Should choose an address or range that does not conflict with the router’s IP and client IPs (192.168.1.100 – 192.168.1.149). An acceptable range might be 192.168.1.2-99 (192.168.1.2 – 192.168.1.99) or even 192.168.1.200-249 (192.168.1.200 – 192.168.1.249). Need to specify ranges with a shorter format; Do not group all addresses for an IP.
The CHAP-Secrets text box is where you specify usernames and passwords. Need to enter them in a special format: username, space, asterisk, password, space and asterisk. Here is an example:
joe * joespassword *
jane * janespassword *
If you are running a RADIUS / AAA server, you can verify the VPN user for it by enabling RADIUS and entering server details.
When all is done, click Apply Settings , then your changes will be saved and applied.
Kiểm TRA
Now we will test the VPN server on the local network:
In Windows XP, click Start> Connect to> Show all connections . Then on the window that appears, double-click New Connection Wizard . On the wizard, click Next . Click Connect to the network at my workplace and click Next . Select the Virtual Private Network connection and click Next . Type in a name for Company Name and click Next . Enter the internal IP of the router (192.168.1.1), click Next , and then click Finish . The login dialog box will appear, this is where you can enter the username and password you created on the server. Then click Connect and it will work.
In Windows 7, call Network and Sharing Center and click Set up a new connection or network . On the Wizard, select Connect to a workplace and click Next. Click Use my Internet connection (VPN) . On the next page, enter the router’s internal IP address (192.168.1.1), type in the destination name, and then click Next. You will be prompted for username and password. Enter the username and password you set before you configure the server and click Connect. Wait a minute, if successful, it will say that You are connected .
Create a Hostname for dynamic IP
If the DD-WRT router is connected to the Internet that has a changed IP address (also known as a dynamic address), then you will definitely want to set up a hostname (sub-domain). This allows you to get an Internet address (for example, myhomenet.getmyip.com ) that always points to the router’s current IP. Allows you to connect to the VPN server when out and about without having to worry about changing the IP. Conversely, if it has changed, someone must have physically checked the router and given you a new IP.
No-IP and Afraid.org are two free dynamic DNS services that you might consider now. When registering the service, you will have a host name, account name, and password. Launch the DD-WRT control panel, click Setup> DDNS and enter the required information. Then your router will always update the service and hostname with your current IP.
Don’t forget to use your hostname instead of Internet IP when configuring VPN client settings.
Configure remote access
To connect to your VPN server from the Internet when away, Windows must be configured to your Internet IP address (or hostname if you have created it), not a local IP address (192.168.1.1). If you follow the directions above and have created a connection from within the local network, then you can change the IP:
In Windows XP, click Start> Connect to> Show all connections . Then right-click on the VPN connection and select Properties .
In Windows 7, click the network icon, right-click the VPN connection from the list and select Properties .
Start connecting
Now everything is ready for you to go. The next time you need to access the network while you’re out and secure your traffic on a public network, you can use your VPN server. However, just remember that the remote router and the network must also allow VPN connections, which usually does not cause problems.
Step 1
Connect to VPN router using either an ethernet cable, or by joining the wireless network “dd-wrt”. Open a web browser, and load the following address:
The changes you must make to this initial page are as follows:
- Router Password, sub-option Router Username – set to root
- Router Password, sub-option Router Password – set to an easy to remember password of your choice
- Router Password, sub-option Re-enter to confirm – set to the same password
Click “Change Password” to finish this step.
Step 2
Navigate to the Services tab, and select sub-tab Services.
The changes you must make here are as follows:
- DNSMasq, sub-option DNSMasq – set to Disable
- Telnet, sub-option Telnet – set to Disable
- Wan Traffic Counter, sub-option ttraff Daemon – set to Disable
Click “Save Changes” to finish this step.
Step 3
Navigate to the Services tab, and select sub-tab Services.
The changes you must make here are as follows:
- UPnP Configuration, sub-option UPnP Service – set to Eanble
- UPnP Configuration, sub-option Clean port forwards at startup – set to Disable
Click “Save Changes” to finish this step.
Step 4
Navigate to the Basic, and select sub-tab Basic Setup.
The changes you must make here are as follows
- WAN Connection Type, sub-option Connection Type – set to PPTP (it will take a few moments for the rest of the options to load after selecting)
- WAN Connection Type, sub-option Use DHCP – set to Yes
- WAN Connection Type, sub-option Gateway (PPTP Server) – set to your StrongVPN server address (NOT the address in the example!)
- WAN Connection Type, sub-option User Name – set to your StrongVPN user name (NOT the user name in the example!)
- WAN Connection Type, sub-option Password – set to your StrongVPN password (NOT the password in the example!)
- WAN Connection Type, sub-option Disable Packet Reordering – set to Disable
- Optional Settings, sub-option Router Name – set to StrongVPN
- Router IP, sub-option Local IP Address – set to 192.168.9.1
- Network Address Server Settings, sub-option Static DNS 1 – set to 8.8.8.8
- Network Address Server Settings, sub-option Static DNS 2 – set to 8.8.4.4
- Network Address Server Settings, sub-option Use DNSMasq for DHCP – set to Unchecked
- Network Address Server Settings, sub-option Use DNSMasq for DNS – set to Unchecked
Click “Save Changes” to finish this step.
Step 5
Navigate to the Administration tab, and select sub-tab Managment (it should already be selected).
There are no changes to be made on this page – you must only scroll down and click ‘Reboot’ to finish this step.
Step 6
Within about 60 seconds, the DD-WRT router will complete rebooting and will now be accessible from a new address:
Load this new address, and re-enter your login details. Navigate to the Status tab, and select sub-tab WAN.
If all has gone correctly, the Login Status will be set to Connected.
TIP: You can use this page to connect and disconnect the VPN on demand, and to check the status of the VPN!
Ниже приведена инструкция по настройке Open VPN для DD-WRT Routers for Smart DNS Proxy VPN & SmartVPN networks.
Перед началом установки мы предполагаем следующие конфигурации;
- Вы уже протестировали OpenVPN на вашем ПК, чтобы убедиться, что ваша сетевая конфигурация и провайдер допускают OpenVPN соединения.
- Вы уже прошили маршрутизатор новейшей прошивкой DD-WRT v24-sp2. При подготовке данного руководства использовалась сборка DD-WRT v24-sp2 (12/22/14). Предыдущие или другие сборки могут содержать ошибки, предотвращающие OpenVPN соединения.
- Вы уже выполнили жесткий сброс или восстановление заводских настроек через административное меню.
- Маршрутизатор DD-WRT подключается к первому маршрутизатору через Wi-Fi или ethernet.
- При подключении к маршрутизатору DD-WRT через wi-fi или ethernet с компьютера можно получить доступ в Интернет.
- Локальный IP-адрес маршрутизатора DD-WRT – 192.168.1.1.
- Ваш первый маршрутизатор имеет другую подсеть локальной сети. 192.168.0.1
Начните процесс настройки со следующими инструкциями;
1. Подключитесь к маршрутизатору DD-WRT либо с помощью Ethernet-кабеля, либо путем подключения к беспроводной сети “dd-wrt”. Откройте веб-браузер и загрузите следующий адрес: Обратите внимание, что при подключении к маршрутизатору через Ethernet настройте сетевое подключение на автоматическое получение IP-адреса.
Проверьте прошивку DD-WRT. Версия программного обеспечения, которая была протестирована на работу на серверах VPN, представляет собой более новую сборку DD-WRT. Сборки или версии, отличные от v24-sp2 (12/22/14), могут иметь ошибки, предотвращающие OpenVPN соединения.
2. Перейдите в раздел “Настройка” и выберите “Базовая настройка”.
3. Снимите все три флажка “Use DNSMasq for DHCP”, “Use DNSMasq for DNS” и “DHCP-Authoritative” и введите 208.67.222.222 и 208.67.220.220, 8.8.8.8 и 8.8.4.4 в текстовое поле “Static DNS 1” , “Static DNS 2”, “Static DNS 3”, “Static DNS 4”, как показано на снимке экрана. Установите флажок “DHCP сервер”.
4. Применить настройки.
5. Нажмите кнопку “Безопасность”, затем “Брандмауэр” и установите для “Брандмауэра SPI” значение “Отключить” и нажмите кнопку “Применить настройки” для сохранения.
6. Перейдите в “Службы” и выберите “VPN”.
7. Установите “Запустить клиент OpenVPN” в положение “Включить”.
– Введите адрес VPN сервера в IP/Имя сервера.
– Введите номер порта. Для протокола TCP/UDP можно ввести один из следующих номеров портов: 53, 80, 443 или 1194.
– Установите устройство “Туннель” на TUN.
– Установите Протокол тоннеля на TCP или UDP. (Мы предлагаем вам использовать UDP для лучшей скорости)
– Установите шифрование в положение Blowfish CBC.
– Установите алгоритм Хэша на SHA1.
– Установите nsCertType на галочку.
– Установите для параметра “Дополнительные параметры” значение “Включить”.
– Установите шифр TLS в положение Нет.
– Установите LZO-сжатие на Адаптивный сайт.
– Установите Nat на Включить.
- Загрузите файл ЦС здесь и откройте его в Wordpad для Windows или TextEdit для Mac, затем COPY и PASTE
8. Перейдите на “Администрирование” и перезагрузите маршрутизатор.
После перезагрузки он должен автоматически подключиться к VPN. Пожалуйста, подождите до 1 минуты, чтобы установить OpenVPN соединение. Вы можете проверить состояние соединения, перейдя на вкладку “Статус” и “OpenVPN”. На вкладке “Клиент”: ПОДКЛЮЧЕНИЕ: СУКЦЕСС”.
ВАЖНОЕ ОБНОВЛЕНИЕ:
Для того, чтобы заставить его работать на новом клиенте OpenVPN на вашем маршрутизаторе DD-WRT, необходимо внести следующие коррективы:
torguard fastest serversCheck user testimonialsvpn router meo ycud here.PrivateVPN If you prefer a simpler service that can get the job done just as well as a fancy VPN, PrivateVPN is your guy.VyprVPN VyprVPN sports a set of impressive security features – most notably, their Chameleon technology that’s designed specifically to bypass DPI (Deep Packet Inspection) and the Great Firewall of China.vpn.ht firestickIt’s also armored with numerous security features, such as Double VPN to overcome restrictions in China, and it keeps zerovpn router meo ycud logs.If you are outside Poland, you have probably noticed that you can’t watch a lot of the content on streaming sites like ipla.Use their 30-day money-back guarantee and decide for yourself.radmin vpn trusted
vpn gratis yang bisa untuk netflixCheck user testimonialsvpn router meo ycud here.View PureVPN Deals 4.We recommend CyberGhost for a Polish IP address, but you’ll find several more great choices below.vpn i macIt’s important to keep in mind that they have had some privacy issues in the past, but if you’re just trying to access the BBC from China, this probably won’t pose a problem.View ExpressVPN Deals 3.Get 70% OFF NordVPN Now!ucl vpn cisco
softether mac clientPureVPN PureVPN boasts a network of 750+ servers in over 140 countries, including China and Hong Kong.ExpressVPN ExpressVPN is the fastest VPN around and is very popular among users for streaming content online even in challenging countries like China, thanks to its unbeatable encryption levels.It has a massive network of fast servers in 62 countries, including 500+ servers in the UK alone.vpn for mac miniThey also offer a special China VPN service, which can bypass the Great Firewall of China.NordVPN If you’re trying to unblock BBC in China, NordVPN is the perfect solution.This feature-packed, log-free VPN has an impressive network of 2000+ ultra-fast servers in over 90 countries with six servervpn router meo ycud locations in the UK.free vpn unlimited vpnify
SPONSORS
Sierra Madre Playhouse | 87 W Sierra Madre Blvd | Sierra Madre, California 91024 | (626) 355-4318
- Audition
- |
- Volunteer
- |
- Rentals
- |
- Videos & Photos
- |
- Press
- |
- Contact
- | Newsletter
Ранее мы рассмотрели, как настроить PPTP VPN-сервер с помощью Debian Linux здесь, на сайте yadmin Geek, однако, если вы уже используете маршрутизатор на основе прошивки DD-WRT в своей сети, вы можете
Содержание:
- Конфигурация DD-WRT
- Подключение к PPTP VPN серверу
Ранее мы рассмотрели, как настроить PPTP VPN-сервер с помощью Debian Linux здесь, на сайте Sysadmin Geek, однако, если вы уже используете маршрутизатор на основе прошивки DD-WRT в своей сети, вы можете легко настроить свой маршрутизатор для работы в качестве PPTP-сервера VPN. .
Конфигурация DD-WRT
Перед настройкой VPN-сервера вы должны сначала убедиться, что установленная вами сборка DD-WRT включает функции PPTP VPN. В списке функций DD-WRT это отображается как «Клиент PPTP / PPTP» на диаграмме. Сравните версию, установленную на вашем маршрутизаторе (которую вы можете увидеть в правом верхнем углу на страницах конфигурации), по таблице. Если эта функция не включена в вашу сборку, вам нужно будет прошить маршрутизатор версией DD-WRT, которая включает «PPTP / PPTP Client».
Чтобы включить PPTP-сервер VPN, перейдите на вкладку «Службы», а затем во вложенную вкладку «VPN» и выберите параметр для включения PPTP-сервера.
После включения появятся несколько ранее скрытых параметров. Настройте их следующим образом:
- IP-адрес сервера: общедоступный IP-адрес маршрутизатора.
- Клиентские IP-адреса: список локальных IP-адресов (соответствующих сети VPN) для использования при назначении IP-адресов клиентам, подключающимся через VPN. В нашем примере мы выделяем 5 IP-адресов (192.168.16.5, .6, .7, .8, .9) для использования клиентами VPN.
- CHAP-Secrets: имя пользователя и пароли для аутентификации VPN. Формат: «пользователь * пароль *» (пользователь [пробел] * [пробел] пароль [пробел] *), где каждая запись находится в отдельной строке. В нашем примере есть только одно допустимое имя пользователя (jfaulkner) и пароль (SecretPassword1).
Вы можете просмотреть подробную документацию по всем этим параметрам, щелкнув ссылку «Help more…» на этой странице справа от конфигурации DD-WRT.
По завершении нажмите кнопку «Применить настройки», чтобы передать конфигурацию на маршрутизатор DD-WRT, и все готово.
Подключение к PPTP VPN серверу
После того, как вы настроили маршрутизатор DD-WRT, все, что осталось – просто подключить клиентские компьютеры к VPN. В нашем примере мы покажем, как это делается с помощью Windows 7 Professional.
В Центре управления сетями и общим доступом на панели управления щелкните параметр, чтобы настроить новое сетевое подключение.
Выберите вариант подключения к VPN на рабочем месте.
Если у вас есть существующие подключения, они будут отображаться здесь. В нашем примере мы хотим создать новое соединение.
Выберите вариант использования подключения к Интернету для подключения к VPN.
Введите домен или IP-адрес своего VPN-сервера (публичный IP-адрес маршрутизатора DD-WRT, настроенный выше) и дайте название VPN-соединению.
Введите учетные данные для входа в VPN, который был настроен в настройках маршрутизатора DD-WRT. Щелкните Подключить.
Через несколько секунд, если все настроено правильно, вы должны подключиться к PPTP VPN серверу на маршрутизаторе DD-WRT.
Запуск «ipconfig» на локальном компьютере должен показать, что вы подключены как к VPN, так и к существующему интернет-соединению.
После подключения вы можете получить доступ ко всем ресурсам VPN, как если бы вы были подключены к сети локально.
для пользователей KeepSolid VPN Unlimited
Защитите свой маршрутизатор с прошивкой DD-WRT, используя первоклассный VPN-сервис!
DD-WRT – это проект прошивки с открытым исходным кодом, созданный, чтобы улучшить возможности маршрутизаторов. Эта альтернативная прошивка снимает ограничения стандартной прошивки маршрутизатора, предоставляя пользователям расширенные возможности по управлению сетью.
Хотите настроить первоклассную VPN-защиту на вашем роутере? В нашем руководстве вы узнаете, как настроить OpenVPN® на маршрутизаторе с прошивкой DD-WRT. Больше информации о функциях и технических характеристиках OpenVPN® вы можете найти в статье Что такое протокол OpenVPN®.
Примечание: Если на вашем маршрутизаторе нет прошивки DD-WRT, вы можете посетить страницу Там вы найдете все необходимые инструкции о том, как прошить роутер, какие маршрутизаторы поддерживаются и другую информацию.
I. Сгенерируйте конфигурации для настройки OpenVPN на DD-WRT
Первым шагом в настройке KeepSolid VPN Unlimited на роутере с прошивкой DD-WRT является создание файлов конфигурации в Личном кабинете. Для этого, выполните несколько простых шагов, указанных в данной инструкции.
Поскольку вы собираетесь настраивать OpenVPN® на своем маршрутизаторе DD-WRT, в поле Protocol выберите OpenVPN®. Будет сгенерирован нужный .ovpn файл, а также доменное имя выбранного VPN-сервера.
II. Настройте OpenVPN® клиент на роутере с DD-WRT
Если на вашем роутере уже заданы сетевые настройки вашего интернет-провайдера и настроен доступ к интернету, вы можете начать настройку OpenVPN® клиента. Выполните всего несколько простых шагов ниже:
1. Войдите в панель управления вашего роутера с DD-WRT. Если вы не знаете, как это сделать, ознакомьтесь с нашей подробной инструкцией о том, как зайти в настройки роутера.
2. Перейдите в раздел Services > VPN как показано ниже:
3. Здесь вам необходимо включить опцию OpenVPN® Client и заполнить поля следующим образом:
- Server IP or DNS Name: Введите имя сервера, которое вы найдете в поле Domain name при создании конфигураций в Личном кабинете.
- Port and Protocol: Выберите 1194 udp (используется для OpenVPN® по умолчанию)
- Tunnel device: Выберите TUN
- Encryption Cipher: AES-256-CBC
- Hash Algorithm: SHA512
- Advanced Options: Enabled
- TLS Cipher: TLS-DHE-RSA-WITH-AES-128-CBC-SHA или выше
- LZO Compression: No
- NAT: Enabled
- Firewall Protection: Disable
- Tunnel UDP MSS-Fix: Disable
- Additional Config section: Введите данные ниже:
4. Откройте ранее загруженный файл .ovpn в предпочитаемом текстовом редакторе и заполните поля следующим образом:
- CA cert – в файле конфигурации скопируйте раздел между и , включая строки ——BEGIN CERTIFICATE—— и ——END CERTIFICATE——, и вставьте его в это поле.
- Public Client cert – в файле конфигурации скопируйте раздел между и , включая строки ——BEGIN CERTIFICATE—— и ——END CERTIFICATE——, и вставьте его в это поле.
- Public Client key – в файле конфигурации скопируйте раздел между и , включая строки ——BEGIN PRIVATE KEY—— и ——END PRIVATE KEY———, и вставьте его в это поле.
5. Затем, нажмите Apply Settings в нижней части панели управления вашего роутера с DD-WRT. Это активирует VPN-соединение на вашем роутере. В случае возникновения проблем с DNS перейдите в Setup > Basic Setup > Network Setup > Static DNS1 and 2, и установите значения 8.8.8.8 и 8.8.4.4 соответственно.
Готово! Вы завершили настройку OpenVPN® на роутере с DD-WRT и активировали VPN-соединение. Наш VPN для DD-WRT теперь шифрует трафик всех устройств, подключенных к вашему маршрутизатору, позволяя вам наслаждаться анонимностью и безопасностью в сети.
Нужно настроить VPN на других устройствах? Посетите страницу Инструкции, чтобы найти нужное руководство или обратитесь в нашу службу поддержки. Мы будем рады помочь!
«OpenVPN» является зарегистрированным товарным знаком OpenVPN Inc.
Самое время попробовать VPN Unlimited!
Выберите подписку VPN Unlimited прямо сейчас, защитите ваш роутер и наслаждайтесь неограниченным доступом в сеть.
DD-WRT OpenVPN Manual Setup Guide
Navigate to the home page of your router – By default 192.168.1.1 .
Click on the Services tab. You may be asked to enter your router username and password.
Click on the VPN tab and then click on the Start OpenVPN Client button.
Enter the following configuration (as also shown in the screen shot below):
- Server IP/Name: Enter a server name from the server status page e.g. ch.gw.ivpn.net
- Port: 2049
- Tunnel Device: TUN
- Tunnel Protocol: UDP
Encryption cipher: AES-256 CBC
Hash Algorithm: SHA1
User Pass Authentication: Enable (If this option does not exist you will need to follow the steps in the appendix).
Enter your account ID that begins with letters ‘ivpnXXXXXXXX’ or ‘i-XXXX-XXXX-XXXX’ and any password.
Advanced options: Enable
TLS cipher: None
LZO Compression: No
NAT: Enable
Firewall Protection: Enable
Tls Auth Key: Download and paste the contents of the TLS-auth file.
Additional Config:
CA Cert: Download and paste the contents of the CA cert file.
Click the Save button, then click the Apply Settings button.
Navigate to Setup > Basic Setup .
Specify one of the following DNS servers in the Static DNS 1 field:
- 10.0.254.1 = redular DNS with no blocking
- 10.0.254.2 = standard AntiTracker to block advertising and malware domains
- 10.0.254.3 = AntiTracker Hardcore Mode to also block Google and Facebook
..and 198.245.51.147 in the Static DNS 2 field.
Click Save & Apply Settings .
Final steps
Reboot your router and wait for a minute or two for everything to settle, then reboot your computer system and check the status of the OpenVPN client in the Status > OpenVPN area.
Check the assigned public IP address on our website and run a leak test at from one of the devices connected to your DD-WRT router.
Please note: If you plan to use a Multi-hop setup please see this guide and replace the port number in Step 4 with the chosen Exit-hop server Multi-hop port.
Appendix
If you do not have the User Pass Authentication field in your DD-WRT version please follow the steps below:
Add the following line to your Additional Config field:
Save your configuration by clicking on the save button.
Click on the Adminstration tab and then the Commands tab. Enter the text shown in the box below replacing the username and password in quotes with your account ID (‘ivpnXXXXXXXX’ or ‘i-XXXX-XXXX-XXXX’) and any password. Click on Save startup to continue.
If the previous command worked correctly you should now see the contents above in a new section on the same page called Startup .
We have previously covered how to set up a PPTP VPN Server using Debian Linux here on Sysadmin Geek, however if you are already utilizing a DD-WRT firmware based router in your network then you can easily configure your router to act as the PPTP VPN Server.
DD-WRT Configuration
Before setting up the VPN Server, you must first make sure your installed build of DD-WRT includes the PPTP VPN features. The DD-WRT feature list shows this as “PPTP / PPTP Client” on their chart. Check the installed version on your router (which you can see in the upper right corner on the configuration pages) against the chart. If the feature is not included in your build, you will need to flash your router with a DD-WRT version which does include the “PPTP / PPTP Client”.
To turn on the PPTP VPN Server, navigate to the Services tab and then the VPN sub-tab and select the option to enable the PPTP Server.
Once enabled, several previously hidden options will appear. Configure them as follows:
- Server IP: Public IP address of the router
- Client IP(s): List of local IP’s (respective to the VPN network) to use when assigning IP addresses to clients connecting through the VPN. In our example, we are setting aside 5 IP addresses (192.168.16.5, .6, .7, .8, .9) for use by the VPN clients.
- CHAP-Secrets: User name and passwords for VPN authentication. The format is “user * password *” (user[space]*[space]password[space]*), with each entry on its own line. In our example, there is just a single accepted user name (jfaulkner) and password (SecretPassword1).
You can view detailed documentation on all of these options by clicking the “Help more…” link on this page on the right side of the DD-WRT configuration.
Once you are finished, click the Apply Settings button to push the configuration through to your DD-WRT router and you are finished.
Connect to a VPN the Easy Way With StrongVPN
Instead of setting up a complicated VPN at home, why not use a blazing fast VPN with easy-to-use clients for all your devices?
StrongVPN is not just blazing fast — fast enough to watch streaming video — but they have extremely strong security (hence the name). You can choose the level of encryption on the fly depending on whether you need top level security or the fastest connection for your videos.
And it’s all very inexpensive, as low as $5.83 per month. Plus, you can try it out for free. What’s there to lose?
Get StrongVPN and Secure Your Internet Today
Connecting to the PPTP VPN Server
Once you have your DD-WRT router configured, all that is left is to simply connect your client computers to the VPN. For our example, we will be showing how this is done using Windows 7 Professional.
In the Network and Sharing Center of the Control Panel, click the option to set up a new network connection.
Select the option to connect to a workplace VPN.
If you have existing connections, they will be displayed here. For our example, we want to create a new connection.
Select the option to use your Internet connection to connect to the VPN.
Enter the domain or IP address of your VPN Server (the public IP address of the DD-WRT router configured above) and give a title to the VPN connection.
Enter the credentials for your VPN login which was configured in the DD-WRT router settings. Click Connect.
After a few moments, if everything is configured correctly, you should be connected to the PPTP VPN Server on the DD-WRT router.
Running ‘ipconfig’ on the local machine should show you are connected to both the VPN and your existing internet connection.
Once connected, you can now access all the resources on the VPN as though you were connected to the network locally.
DD-WRT Build Features Diagram
More stories
Use Paint.NET to Remove Red Eye From Flash Photography
Paint.NET has a simple tool for doing this called the “Color Replacement Tool,” illustrated here. Shortcut key will give it to you.
How To Make the Mac OS X Finder Suck Less
The Finder is the most complained about application on the Mac, and rightly so—it’s just not very powerful, and often behaves in unexpected ways. Today, we’ll be taking a look at several tweaks that will make the Finder suck less.
Awesome Vintage-Style Star Wars Travel Posters [Images]
Steve Thomas has created an awesome set of eight Star Wars inspired travel posters using the vintage style from the early 20th century. If you are a Star Wars fan, then these will be a lot of fun for you to look at.
App Developers Caught Selling Facebook User Info to a Data Broker
Over the weekend Facebook revealed that a data broker was caught purchasing identifying user information from some of the platform’s app developers. This incident combined with the previous revelation that many popular .
Use Evernote Offline on Your iPhone or iPod Touch for Free
Would you like to use Evernote anywhere without having to upgrade to a Premium account? Premium Evernote subscribers can sync whole notebooks offline on iPhone, but here’s how you can get your most important notes anytime on any Evernote account.
BitTorrent for Beginners: Share Large Files Using Your Own Private Tracker
Want to share some large files with a few friends, but worried about how you’ll keep the file transfer private? Here’s how to use uTorrent as a simple tracker and share files privately with your friends.
Turn Your WordPress Blog Into a Tumblr-style Tumblog
Would you like to be able to make more unique link, quote, and image posts on your blog? Here’s how you can turn your WordPress site into a Tumblr-style blog for free.
Month in Geek: October 2010 Edition
Now that October is over and the trick-or-treating is finished, it is time to take a look back at our ten top articles for this past month.
The How-To Geek Guide to Learning Photoshop, Part 3: Layers
Your layer panel is one of the most important within Photoshop. Whenever you use Photoshop, you’ll work spend a lot of time working in it.
Week in Geek: Java Becomes New No. 1 Attack Target Edition
This week we learned how to secure a Linux PC by encrypting the hard drive, become familiar with the toolbox in Photoshop, improve battery life in Windows 7 with the built-in power troubleshooter, become familiar with the panels in Photoshop, print files from anywhere via any device with Dropbox,
PPTP VPN Setup for DD-WRT
If you don’t have a DD-WRT flashed router and would like to purchase one preconfigured with the EarthVPN DD-WRT application, our parther FlashRouters can help you. They provide a hassle free alternative to the somewhat technical process of selecting a compatible router and flashing DD-WRT on it yourself. Check out our Flashrouter Information Page for more information and special promotions!
PPTP can NOT be used concurrently with PPPoE or Static IP if you want to use DD-WRT flashed router as your main router. We recommend you to use DD-WRT flashed router as the second one.
We presume the following configurations:
- You have already tested PPTP VPN on your PC/Mac to ensure that your network configuration and ISP allows PPTP connections.
- You have already flashed your router with DD-WRT firmware v24.Builds newer than 15962 may have pptp client broken so be sure to upgrade or downgrade to a working one.Build 14896 have been used while preparing this tutorial.
- You have already hard reset(30/30/30 method) or restore the factory defaults via administration menu.
- Your DD-WRT router is connected to your first router via wifi or ethernet.
- When you connect to DD-WRT router via wi-fi or ethernet from your PC/MAC ,you can access internet.
- Your DD-WRT router local IP address is 192.168.1.1
- Your first router has different LAN subnet for ex. 192.168.0.1
Step:1 Connect to the dd-wrt router using either an Ethernet cable, or by joining the wireless network ‘dd-wrt’. Open a web browser, and load the following address: Note, set your network connection to obtain IP address automatically if you connect to your router via Ethernet.
Check your dd-wrt firmware.Minimum software version for VPN setup is v24.Builds newer than 15962 may have pptp client broken so be sure to upgrade or downgrade to a working one.Build 14896 have been used while preparing this tutorial.
Step:2 Go to Setup then select Basic Setup.
Step:3 Under WAN Connection Type select PPTP
Step:4 Under Use DHCP select Yes
Step:5 Under Gateway (PPTP Server)enter the EarthVPN server address you want to connect.Under User Name enter your VPN username. Under Password enter your VPN password.
Step:6 Enable PPTP or MPPE Encryption.
***You can try disabling/enabling Packet reordering for speed optimization***
Step:7 Disable STP.
***You can try entering “mppe required” without quotes into additonal pptp options textbox if your computer is able to connect via pptp protocol but your dd-wrt router is not connecting via pptp protocol***
- Enter an IP address for the DD-WRT wireless access point.Note, we presume this is the second router,Your first router has different LAN subnet for ex. 192.168.0.1
Step:9 Enable DHCP Server and uncheck all three checkboxes for ‘Use DNSMasq for DNCP’, ‘Use DNSMasq for DNS’ and ‘DHCP-Authoritative’
Step:10 Apply Settings
Step:11 Click on Security then Firewall and set SPI Firewall to Disable and click apply settings button to save.
Step:12 Click on VPN Passthrough and enable PPTP Passthrough
Step:13 Click Apply Settings.
Step:14 Click on Administration Tab scroll down and click on Reboot Router
After the router will reboot it should connect to the VPN automatically, now you can check the connection status by going to Status -> WAN tab If Login Status say Connected then it’s OK, if not click to connect wait for abut 30 seconds .
To check if your IP has been changed visit on your PC/MAC.
If you don’t have a DD-WRT flashed router and would like to purchase one preconfigured with the EarthVPN DD-WRT application, our partner FlashRouters can help you. They provide a hassle free alternative to the somewhat technical process of selecting a compatible router and flashing DD-WRT on it yourself. Check out our Flashrouter Information Page for more information and special promotions!
Before following this guide, you will need to install DD-WRT on your router. To do this, you will need to go to DD-WRT’s router database and search for your router’s model number to see if your router is compatible or find a beta build for your router. This guide uses KONG’s beta build of DD-WRT v3.0-r42335 on a Netgear R6700.
IMPORTANT NOTE: Certain beta builds may not work with OpenVPN. Please read the feedback in the build forum before installing a beta build. Also note, regardless of what model router you have or version of DD-WRT you are installing, there is a chance of bricking your router (i.e. rendering the router completely useless) if the process of putting DD-WRT on the router does not complete properly. Please thoroughly read and follow the related documentation regarding the updating procedure for your router to minimize the risk of bricking your router.
Initial DD-WRT Setup and Important Notes
Please check and consider the following before setting up your VPN connection in DD-WRT:
- If you are running a router-behind-router configuration, you will want to make sure your DD-WRT router is on a different subnet than any other router/modem on your network. This can be done by going to Setup/Basic Setup tab and changing your Local IP address to ‘192.168.8.1’ without quotes
- If you are running PPPoE on the router, you will not be able to make a VPN connection
- We suggest adding the following static DNS addresses: 198.18.0.1 and 8.8.8.8, on the basic setup tab
- Please check to ensure the NTP client is enabled and set to the correct time zone, which can be found at the bottom of the basic setup tab
Enable Syslogd so you can get logs if you run into any trouble with your setup. You can do this by going to Services tab and scrolling down to System Log, then Enable Syslogd.
Configuring the VPN Connection
To setup the VPN connection on your router, go to the Services/VPN tab, enable the OpenVPN Client, and set the connection up using the following settings:
- Server IP/Name: Choose a server from our server list and enter the address in this field
- Port: use 1194 or 443
- Tunnel Device: TUN
- Tunnel Protocol: UDP
- Encryption Cipher: AES-256-CBC
- Hash Algorithm: SHA256
- User Pass Authentication: Enable
- Username: YourPrivadoUsername
- Password: YourPrivadoPassword
- Advanced Options: Enable
- TLS Cipher: None
- Compression: Disabled
- NAT: Enable
- Copy and paste the following into your Additional Config:
persist-key
persist-tun
persist-remote-ip
keysize 256
remote-cert-tls server
- CA Cert: Copy and paste the following into the CA Cert box. The ca.crt is also attached HERE and at the very bottom of this guide if you are having difficulty copying this text.
—–BEGIN CERTIFICATE—–
MIIFKDCCAxCgAwIBAgIJAMtrmqZxIV/OMA0GCSqGSIb3DQEBDQUAMBIxEDAOBgNV
BAMMB1ByaXZhZG8wHhcNMjAwMTA4MjEyODQ1WhcNMzUwMTA5MjEyODQ1WjASMRAw
DgYDVQQDDAdQcml2YWRvMIICIjANBgkqhkiG9w0BAQEFAAOCAg8AMIICCgKCAgEA
xPwOgiwNJzZTnKIXwAB0TSu/Lu2qt2U2I8obtQjwhi/7OrfmbmYykSdro70al2XP
hnwAGGdCxW6LDnp0UN/IOhD11mgBPo14f5CLkBQjSJ6VN5miPbvK746LsNZl9H8r
QGvDuPo4CG9BfPZMiDRGlsMxij/jztzgT1gmuxQ7WHfFRcNzBas1dHa9hV/d3TU6
/t47x4SE/ljdcCtJiu7Zn6ODKQoys3mB7Luz2ngqUJWvkqsg+E4+3eJ0M8Hlbn5T
PaRJBID7DAdYo6Vs6xGCYr981ThFcmoIQ10js10yANrrfGAzd03b3TnLAgko0uQM
HjliMZL6L8sWOPHxyxJI0us88SFh4UgcFyRHKHPKux7w24SxAlZUYoUcTHp9VjG5
XvDKYxzgV2RdM4ulBGbQRQ3y3/CyddsyQYMvA55Ets0LfPaBvDIcct70iXijGsdv
lX1du3ArGpG7Vaje/RU4nbbGT6HYRdt5YyZfof288ukMOSj20nVcmS+c/4tqsxSe
rRb1aq5LOi1IemSkTMeC5gCbexk+L1vl7NT/58sxjGmu5bXwnvev/lIItfi2AlIT
rfUSEv19iDMKkeshwn/+sFJBMWYyluP+yJ56yR+MWoXvLlSWphLDTqq19yx3BZn0
P1tgbXoR0g8PTdJFcz8z3RIb7myVLYulV1oGG/3rka0CAwEAAaOBgDB+MB0GA1Ud
DgQWBBTFtJkZCVDuDAD6k5bJzefjJdO3DTBCBgNVHSMEOzA5gBTFtJkZCVDuDAD6
k5bJzefjJdO3DaEWpBQwEjEQMA4GA1UEAwwHUHJpdmFkb4IJAMtrmqZxIV/OMAwG
A1UdEwQFMAMBAf8wCwYDVR0PBAQDAgEGMA0GCSqGSIb3DQEBDQUAA4ICAQB7MUSX
MeBb9wlSv4sUaT1JHEwE26nlBw+TKmezfuPU5pBlY0LYr6qQZY95DHqsRJ7ByUzG
UrGo17dNGXlcuNc6TAaQQEDRPo6y+LVh2TWMk15TUMI+MkqryJtCret7xGvDigKY
MJgBy58HN3RAVr1B7cL9youwzLgc2Y/NcFKvnQJKeiIYAJ7g0CcnJiQvgZTS7xdw
kEBXfsngmUCIG320DLPEL+Ze0HiUrxwWljMRya6i40AeH3Zu2i532xX1wV5+cjA4
RJWIKg6ri/Q54iFGtZrA9/nc6y9uoQHkmz8cGyVUmJxFzMrrIICVqUtVRxLhkTMe
4UzwRWTBeGgtW4tS0yq1QonAKfOyjgRw/CeY55D2UGvnAFZdTadtYXS4Alu2P9zd
woEk3fzHiVmDjqfJVr5wz9383aABUFrPI3nz6ed/Z6LZflKh1k+DUDEp8NxU4klU
ULWsSOKoa5zGX51G8cdHxwQLImXvtGuN5eSR8jCTgxFZhdps/xes4KkyfIz9FMYG
748M+uOTgKITf4zdJ9BAyiQaOufVQZ8WjhWzWk9YHec9VqPkzpWNGkVjiRI5ewuX
wZzZ164tMv2hikBXSuUCnFz37/ZNwGlDi0oBdDszCk2GxccdFHHaCSmpjU5MrdJ+
5IhtTKGeTx+US2hTIVHQFIO99DmacxSYvLNcSQ==
—–END CERTIFICATE—–
Save and Apply the settings, then go to the Administration tab and click Reboot at the bottom of the page.
Check the VPN Connection
Once your router has finished booting up, verify you are connected by going to the Status/OpenVPN and/or checking your external IP address online.
Руководства по установке прошивки DD-WRT, список поддерживаемых устройств и т.п. доступны на официальном веб-сайте, вики и форуме.
Используйте прошивку с “openvpn” в имени. Рекомендуется использовать самую свежую прошивку.
Данное руководство составлено при использовании роутера ASUS RT-N12C1 и прошивки dd-wrt.v24-18777_NEWD-2_K2.6_openvpn_small.bin
И откройте его в текстовом редакторе.
Перейдите в Administration → Commands
Скопируйте следующий код в поле Commands, а затем нажмите Save Startup.
Перейдите в Services → Services. В разделе DNSMasq отключите No DNS Rebind.
Внизу страницы нажмите Save, а затем Reboot Router. Подождите 1-2 минуты до полной перезагрузки роутера.
Указанные выше шаги необходимы для установки внутренних DNS VPN-сервера, исключения утечки DNS, а также прозрачной поддержки доступа к .onion ресурсам.
Вы можете пропустить эти шаги и, перейдя в Setup → Basic Setup, в разделе Network Setup → Network Address Server Settings (DHCP) в поле Static DNS 1 прописать любые нужные вам DNS (например 8.8.8.8).
Перейдите в Services → VPN. В разделе OpenVPN Client включите Start OpenVPN Client.
Заполните необходимые поля в соответствии с указанными ниже рекомендациями:
Server IP/Name: используйте имя хоста или IP-адрес указанный в начале файла конфигурации со строкой remote
Port: 443
Tunnel Device: TUN Tunnel Protocol: TCP / UDP
Encryption Cipher: AES-256
Hash algorithm: SHA1
Advanced options: Enable
LZO compression: Adaptive
NAT: Enable
- TLS Auth key: содержимое в файле конфигурации
- CA Cert: содержимое в файле конфигурации
- Public Client Cert: содержимое в файле конфигурации
- Private Client Key: содержимое в файле конфигурации
Additional Config:
Также можно добавить адреса других VPN-серверов в поле Additional Config (при недоступности 1-го сервера будет осуществлено подключение к следующему серверу в списке). Рекомендуется добавить как имя хоста, так и IP-адрес сервера (указанные в файле конфигурации). Пример:
tcp-client – для подключения по протоколу TCP
udp – для подключения по протоколу UDP
Сохраните настройки нажав Save, а затем – Apply Settings. Будет осуществлено подключение к VPN-серверу (это может занять 1-15 секунд).
Посмотреть статус подключения вы можете в Status → OpenVPN:
Разрешение доступа в сеть через роутер только при подключенном VPN (kill switch)
Перейдите в Administration → Commands
Введите следующую команду для разрешения пропуска трафика только через сетевой интерфейс VPN для адресов из диапазона 192.168.1.0/24 (диапазон IP-адресов пользователей по умолчанию; посмотреть текущий диапазон можно в Setup → Basic Setup разделе Network Setup):
Показать альтернативный список команд
или можете использовать следующий список команд, если предыдущая команда не подошла:
Сохраните конфигурацию нажав Save Firewall. Возможно потребуется перезагрузка роутера.
Теперь доступ в Интернет будет возможен только когда роутер будет подключен к VPN.
Important! By setting up a L2TP VPN connection on a DD-WRT router your IP will be changed but your traffic will NOT be encrypted. That happens because the connection does not use IPSec.
In order to setup L2TP VPN on your DD-WRT router you have to flash your router with DD-WRT firmware and set router local IP address as 192.168.1.1. Also please check if you can connect to Internet via Wi-Ffi from this router. We also recommend to check VPN on your PC/Mac to ensure that your network configuration and ISP allow L2TP/IPsec connections.
Important: L2TP can NOT be used concurrently with PPPoE or Static IP if you use DD-WRT flashed router as main router. We recommend you to use DD-WRT flashed router as the second one.
Connect to your router. For that you have to put in your browser the following address:
Also you have to set your network connection to obtain IP address automatically if you connect to your router via Ethernet.
Configure your DD-WRT router to share your regular internet connection.
- Go to “Setup” tab and then select “Basic Setup” (1).
Select L2TP (2) from the “Connection Type” drop down menu.
In the “Gateway (PPTP server)” (3) type IP address or hostname of the TorGuard VPN server you want to connect to. You can find all the available servers in the package details in the Client area .
In the “Username” (4) and “Passwords” (5) fields enter your VPN username and password. Make sure you use your VPN username and password and NOT the client area credentials.
Select “Yes” (6) next to “Use DHCP”.
In the “Optional Settings” zone change MTU to “Manual” (7) and type the value 1460 (8) in the field and set “STP” (9) as “Disabled”.
In the “Network setup” enter the IP address for the DD-WRT access point (10). Important, if this is the second router then you must set a different Local IP address then your main router.
Select “DHCP Server” next to “DHCP Type” (11).
“Enable” DHCP server (12).
Make sure all other settings looks like in our screenshot.
Click on “Apply settings” (13). - Now go to the “Security” tab (14) and select “Firewall” (15). Here, set “SPI Firewall” to “Disable” (16).
- Go to “VPN Passthrough” (17) and select “Enabled” next to “L2TP Passthrough” (18). Click on “Apply settings” (19).
- Go to “Administration” tab (20). Scroll down and click on “Reboot router” button (21). This will reboot your router.
After the reboot VPN is set up. You can check the connection going to “Status” tab and select “WAN” from there. Login status should be “Connected”. If it says “Disconnected” click on “Connect” button and wait for about 1 minute. After that the connection should be established. You can check if you are connected to a VPN server by going to Whats My IP and see if your IP is changed.
Related Articles
STEP 1) Type the router’s local IP address into your web browser’s URL bar and login into your.
Setting up an OpenVPN connection manually on a DDWRT Router with TorGuard is very easy and can be.
Setting up an OpenVPN connection manually on a DD-WRT Router with TorGuard is very easy and can.
TorGuard’s anonymous VPN service will pretty much work on any device that supports an OpenVPN.
Wireguard is an extremely simple yet fast and modern VPN that utilizes state-of-the-art.
If you have read my previous article on VPNs you already know the advantages of using a VPN and the risks of not using one and hopefully you are using one now. If you haven’t subscribed to a VPN yet I leave you a link here for a great discount.
Many VPN providers, such as NordVPN, which is the one I’ve been using for years and recommend, provide apps for iPhone, Android and other systems to access their VPN servers. However, there are devices, such as an AppleTV, that do not have an app or other direct way to connect to a VPN server.
For this type of cases, having your home router connected to a VPN is the best solution. Furthermore, it’s much easier to have your home router connected to a VPN than to install a VPN application on each of the devices that connect to the Internet in your household.
Not all routers have the same way of connecting to a VPN or supporting the same protocols. Here’s how to set up a VPN on a DD-WRT router using the OpenVPN protocol. If you want to know more about DD-WRT or how to install it on a Linksys WRT1900ACS I recommend you to read this other post.
Choose a VPN server
Before starting to configure the router we must choose the VPN server to which it will connect. NordVPN does this very easily with its ‘Recommended Server’ tool. Here we can select the country we want to connect to, the type of server (in case we need a special requirement, such as P2P, Double VPN or Onion Over VPN) and the security protocol (OpenVPN UDP in our case). And we write down the name of the recommended server (eg. nl173.nordvpn.com).
Download the server certificate
Now is the time to download the certificate of the chosen VPN server. You can download all NordVPN server certificates from If you are using a different VPN provider, you should ask where to download the certificate from.
When you uncompress the NordVPN server certificate zip file you will find a huge list of files (9524 items at the time of writing this article) grouped in pairs of .crt and .key files. We will only need the pair of files that correspond to the chosen server (eg. nl173_nordvpn_com_ca.crt, nl173_nordvpn_com_tls.key).
Backup Configuration
This step is optional but my recommendation is to back up your current router configuration in case something goes wrong. Access the router interface (by default is 192.168.1.1.1), navigate to ‘Administration > Backup’ and click on the ‘Backup’ button.
Change DNS addresses
You’ve probably already made this change, but let’s double check just in case.
Navigate to ‘Setup > Basic Setup’ and under the ‘WAN Setup > WAN Connection Type’ section set the Static DNS servers to the DNS server addresses you trust. They could be from your VPN provider or another external service like the one I’ve chosen in this case, Cloudflare (1.1.1.1, 1.0.0.1).
Then, click on ‘Save’ and ‘Apply Settings’ buttons.
Disable IPv6
To prevent IPv6 leaks we’ll disable IPv6 on the router. Navigate to ‘Setup > IPV6’, set the ‘IPv6’ option to ‘Disable’ and then click on ‘Save’ and ‘Apply Settings’ buttons.
Set up OpenVPN Client
This is the core part of the configuration process. Navigate to ‘Services > VPN’ and under the ‘OpenVPN Client’ section set the ‘Start OpenVPN Client’ option to ‘Enable’ and then set the following options (if nothing is specified keep the default values):
Server IP/Name: the server we chose previously (nl173.nordvpn.com in out case)
Port: 1194
Tunnel Device: TUN
Tunnel Protocol: UDP
Encryption Cipher: AES-256-CBC
Hash Algorithm: SHA-512 (it could be SHA-1 on older servers)
User Pass Authentication: Enable
Username: the username of your VPN provider account
Password = the password of your VPN provider account
Advanced Options: Enable
TLS Cipher = None
LZO Compression = Yes
NAT = Enable
TLS Auth Key: here you should copy the content of the .key file you downloaded previously (in our case, nl173_nordvpn_com_tls.key)
Additional Config: copy the following commands into this text box
CA Cert: here you should copy the content of the .crt file you downloaded previously (in our case, nl173_nordvpn_com_ca.crt)
After entering all this data, click on ‘Save’ and ‘Apply Settings’ buttons.
Verify VPN
To verify that the VPN is working navigate to ‘Status > OpenVPN’ and under the ‘State’ section you should see the message: ‘Client: CONNECTED SUCCESS’.
After that you can go to an IP location web service, such as ip2location.com, to check your current IP address and location.
Create a kill-switch
To prevent the router from exposing us to an insecure connection if the connection to the VPN server is lost, we will create a kill-switch. This means that if for any reason the router cannot establish a connection to the VPN server, we will not have Internet connection until we fix the issue.
Navigate to ‘Administration > Commands’ and enter these commands into the ‘Commands’ text box:
Then click on ‘Save Firewall’ button.
Lastly, navigate to ‘Administration > Management’ and click on ‘Reboot router’ button.
This tutorial will show you how to set up PPTP VPN on DD-WRT Routers using the SmartyDNS VPN services. If you don’t have a SmartyDNS account, you can try our services for free for 3 days.
Here are the steps you should follow:
To setup PPTP VPN on DD-WRT router you will have to flash your router with DD-WRT firmware and set router local IP address as 192.168.1.1. Also, verify if you are able to connect to Internet via Wi-Fi from your DD-WRT router. Also, we recommend to check if your network configuration and ISP allow PPTP VPN connections on on your PC or Mac.
Connect to your router. To do that you have to enter the following address in your browser: Also, if you are connected to your router via Ethernet, set your network connection to obtain the IP address automatically.
There are two options to set up PPTP VPN on a DD-WRT router. Please select which option you prefer to use:
- Go to “Setup” tab and and choose “Basic Setup” (1).Then fill the fields and check the radio buttons with the following settings:
“Connection Type” (2): choose “PPTP”.
“Gateway (PPTP server)” (3): type the IP address of the SmartyDNS server you want to connect to.
You can find the entire list of all available servers in your account on our website, by going to your package from “Packages”. If you don’t have a SmartyDNS account, you can try our services for free for 3 days.
In the “Username” (4) and “Password” (5) fields type your VPN username and password.
To find your VPN username and password, sign in to your account on our website, go to “Setup” -> “VPN Username & Password“. If you don’t have a SmartyDNS account, you can try our services for free for 3 days.
“Use DHCP” (6): choose “Yes”.
“MPPE Encryption” (7): choose “Enable”.
“Packet Reordering” (8): choose “Enable”. Note: If your version of DD-WRT has the “PPTP encryption” option set to “Enable” as well.
“Dual-Access mode” (9): set to “No”.
“Receive IPTV” (10): chose “No”.
“Optional Settings” compartment:
“MTU”: change it to “Manual” (11) and type the value 1460 (12) in the next field.
“STP”: set it to “Disable” (13).
“Network setup” zone:
“Local IP Address” – enter the IP address for the DD-WRT access point (14). Note: if this is the second router then you have to set a different Local IP address then your main router.
“Network Address Server Settings (DHCP) zone:
“DHCP Type”: choose “DHCP Server” (15).
“DHCP Server”: choose “Enable” (16).
Verify all the settings and make sure that everything looks exactly like in our screenshot.
Click on “Apply settings” button (17).
Go to the “Security” tab (17) and choose “Firewall” (18). Then, set “SPI Firewall” to “Disable” (19).
Now go to “VPN Passthrough” (20) and choose “Enabled” (21) next to “PPTP Passthrough”. Then click on “Apply settings” button (22).
Then go to “Administration” tab (23) and scroll all the way down, then click on “Reboot router” button (24). This will reboot your router.
- Go to “Setup” tab and and choose “Basic Setup” (1).
In the “Network Address Server Settings (DHCP)” (2):“DHCP server”: choose “Enable” (3).
“Static DNS 1” (4): change to 8.8.8.8
“Static DNS 2” (5): change to 8.8.4.4
“Use DNSMasq for DNS” (6): make sure to untick the checkbox.
Now go to “Security” tab (7), then click on “Firewall” (8) and set the “SPI Firewall to “Disable” (9).
After that click on “VPN Passthrough” tab (10), then choose “Enable” for “PPTP Passthrough” (11), then click on “Apply settings” button (12).
Replace “IPADDRESS” with the IP address of the SmartyDNS server you want to connect to.
To find the entire list of all available servers, sign in to your account on our website, go to “Setup” -> “VPN Servers“. If you don’t have a SmartyDNS account, you can try our services for free for 3 days.
Type one more time the same hostname in the “Remote ID” field (10).
Once the reboot is completed your VPN connections is created. You can check the connection by going to “Status” tab and choosing “WAN”. You should see the “Connected” status. If it says “Disconnected” click on “Connect” button. The connection should be established in about 1 minute.
To check if you are connected to a VPN server, check if you IP address is changed.
VPN connections let you remotely access file or connect remote offices together via secure tunnels over the Internet. They can even come in handy to secure connections on public Internet ports or Wi-Fi hotspots, hiding Internet traffic from local eavesdroppers.
A VPN enables users to remotely access file or connect remote offices together via secure tunnels over the Internet. If you’re building a VPN for more than two-dozen VPN users, setting up a VPN server is a viable option. Find out how to do so using DD-WRTDD-WRT router firmware.
If you aren’t going to have more than two-dozen VPN users, you might consider setting up your own VPN server using the DD-WRT router firmware. If you have a compatible wireless router, you can load the firmware on it. This gives you an OpenVPN server and client, and many more cool features. You can then set it up for remote access connections or site-to-site connections to connect offices together.
DD-WRT supports two different VPN protocols: Point-to-Point Tunneling Protocol (PPTP), which is very popular but has vulnerabilities, and OpenVPN, which uses Secure Sockets Layer (SSL) and Transport Layer Security (TLS) for a much more secure solution. In this two-part tutorial, we will set up and use OpenVPN.
In this first of two articles, we will explain how to flash the router with the DD-WRT firmware, change the router’s IP and subnet for compatibly reasons, and create the SSL certificates. In the second installment, we will step through configuring the OpenVPN server, creating startup and firewall scripts, configuring the clients, and testing it out.
For the record, this tutorial was based off using the VPN variant of DD-WRT v24-SP2. It’s the build 13064, dated 10/10/09. For creating SSL certificates and for the clients, we used OpenVPN 2.1.1, released on 12/11/09. The steps for using other versions of the firmware or OpenVPN may vary.
Flash Router With the VPN Version of DD-WRT
First, make sure you’re using a wireless router that’s compatible with DD-WRT and has enough NVRAM storage space. You’ll want to follow the directions to flash or upload the VPN version of DD-WRT to your router.
To check the available NVRAM, you must use Telnet or SSH to get to the router. You can download and use PuTTY. Select Telnet as the Connection Type and enter the router’s IP address (192.168.1.1). Then, for the DD-WRT Login, enter “root.” If you’ve created a password via the Web-based control panel, use it; otherwise, the default is “admin”.
Once logged in via Telnet, enter the following command:
If you have more than 5,200 bytes left, you’re good to go.
Change the Router’s IP and Subnet
Remember, a VPN connection connects two or more networks. You should make sure each network’s subnet and IPs do not conflict. So if you are planning to use the VPN connections from public Internet or Wi-Fi hotspots, you should make sure your local network and VPN network aren’t set to a common subnet.
Since DD-WRT uses a very common IP of 192.168.1.1, we should change it:
Start by connecting to the router and bringing up the Web-based control panel by entering the IP address (192.168.1.1) into a Web browser. Then, click the Setup tab and in the Router IP area, change the Local IP Address to 192.168.2.1, and click Apply Settings.
Now you must use the new IP (192.168.2.1) to log in to the DD-WRT control panel.
Create server and client certificates
You must download and install OpenVPN on a PC using the Windows Installer. You can use Linux machines too, but we’re going the Windows route. Once installed, here’s how to get started:
- Open the Command Prompt: click Start, type cmd, and hit Enter.
- Then move to another directory by typing: cd C:Program FilesOpenVPNeasy-rsa
- Run a batch file to create configuration files by typing: init-config
- Keep this Command Prompt window open for later use.
Now, open a Computer window and browse to the following directory C:Program FilesOpenVPNeasy-rsa. Right-click the vars.bat file and click Edit. Then you must set all the following settings:
- KEY_COUNTRY
- KEY_PROVINCE
- KEY_CITY
- KEY_ORG
- KEY_EMAIL
You can change the default values, which is after the equal sign of each parameter. Be sure to save the changes when you’re done.
Go back to the Command Prompt window and initialize the PKI by entering the following commands one at a time:
After entering the last command, you’ll be prompted for the parameters you just set in the vars.bat file. Click Enter to accept those parameters. You can leave the Organizational Unit Name blank. However, you must enter a Common Name. Pretty much anything will work. I used “OpenVPN-CA”
Now you can generate a certificate and private key for the server by entering the following:
You’ll be prompted for parameters again. Accept the defaults for the ones you set in vars.bat. For the Common Name this time, enter “server.” Be sure to enter a secure password you’ll remember or store somewhere safe. When prompted to sign and commit the certificate, enter “y.”
Now, you can generate the certificates for the clients or computers that will be connecting to your OpenVPN server on the DD-WRT router. You must create one for each client. Just enter “build-key” followed by a space and a name. For example, for three clients:
Again, you’ll be prompted for the parameters. Choose a unique Common Name. You can use the certificate name, such as client1, client2 or client3.
Note: If you later find you must generate additional client certificates, return to the easy-rsa directory in a Command Prompt, type “vars,” and then go ahead with the build-key command, such as build-key client2.
Now you must generate the Diffie Hellman parameters by entering:
Finally, you should see all your certificates in the following directory: C:Program FilesOpenVPNeasy-rsakeys
Keep in mind, the ca, server, and all client keys should be kept private and secure.
Continue on to Part 2 to learn how to configure the server and clients.
Eric Geier is the Founder and CEO of NoWiresSecurity, which helps businesses easily protect their Wi-Fi with enterprise-level encryption by offering an outsourced RADIUS/802.1X authentication service. He is also the author of many networking and computing books, for brands such as For Dummies and Cisco Press.
- Messenger
Using your VPN through a router can help you get more from your VPN connection. Moreover, it allows you to use your existing VPN connection on an array of devices (wired and/or wireless). IT authorities usually advocate the use of VPN router because they assist in keeping data safe from sniffers and back-door hackers.
VPN based routers usually come with a “Some Configuration Required” label on the box. Even though the best routers require minimal configuration, you will need to customize certain particulars. Here, you have a choice between two options.
To understand the true utility of routers, check out the best VPN for DD-WRT routers.
Option 1 – Purchase a Plug & Play VPN based Router
The best VPN service providers in the market team up with Router manufacturers to facilitate a smooth VPN experience all the way. For instance, South Carolina based Sabai Technology provides pre-configured routers with some of the best router supporting the Best VPNs in the market. Setting up VPN based routers like these is unimaginably easy!
You get an instruction manual with all the necessary details (user name, password and relevant details), round the clock tech support, and you can even ask support to remotely access your computer and setup your router for you.
Option 2 – Configure your Router
The best way to manually setup your router is to ask the VPN service provider for an illustrated tutorial. Ask your VPN service provider to give you a Router Support Package . This will contain all the necessary details required to setup your VPN based router.
The following instructions are for configuring a DD-WRT flashed router and can be used as a guideline for configuring a VPN on any other router. I always recommend the DD-WRT because it’s free, there is a lot of online-info on it (which makes it great for first-timers), and it supports routers by over 90 manufacturers.
Flashing the Router with DD-WRT Firmware
If your router does not have DD-WRT, make sure that you flash it with DD-WRT before you begin the process. Router flashing is a sensitive process and you need to be very careful because a slight bit of carelessness can turn your router from a high-tech data management device into a useless piece of plastic and wires.
There are three ways you can flash your router with DD-WRT firmware.
- Flashing via web-based graphic user interface (The longest method)
- Using Trivial File Transfer Protocol (The safest method)
- Using Command Line (Ideal for wireless flashing)
Setting-up & Configuring your DD-WRT Router
5 Minutes Review time
1) Plug your ADSL wire into your router’s WAN port, and your PC’s wire to one of the available LAN ports. At this point, your router will be the mediator between your PC to your ADSL.
2) Ensure that your VPN connection is fully functional. If you are not using the best VPN based router in the market, communicate extensively with your VPN service provider while configuring your router.
3) Access you router’s Control Panel from your PC and put all the details provided to you by your VPN service provider in front of you.
4) At this point, the router Control Panel will display System Information. Make sure the WAN IP and LAN IP received by your VPN-based router are correct.
5) Click on the Setup tab and then click on the Basic Setup sub-tab.
6) Your VPN service might need you to configure the Host Name, Domain Name, and Router IP details (Local IP Address and Subnet Mask).
7) Select your Connection Type (usually PPTP) and identify if the router will be using DHCP or not.
8) Enter the Gateway, User Name and Password. Hit Apply Settings and Save (in the same order).
9) Click on the Status tab on top and then click on the WAN sub-tab.
10) Look for the Login Status and hit Connect.
Troubleshooting your Routers VPN
Make sure you reboot your router after completing the setup process. Also, if you are setting up your DD-WRT routers on Mac OSX, make sure you enable ‘Force encryption’ from your router server settings. Use the Local Default Gateway if you feel that your internet connection is disconnecting every time you connect to the internet. Double check to make sure that the network client address is not the same as the subnet server. This may also be responsible for unexpected continuous disconnects.
For more trouble-shooting tips, either go to the official DD-WRT PPTP server configuration page, or talk to your router’s customer support for technical assistance. For this purpose I recommend that you go for a Router VPN that offers 24/7 customer support so that you always have somebody ready to help you.
Conclusion
While most VPN users remain content with a standard VPN connection running on their systems and/or smart phones, an increasing number of VPN users now use the best router VPN combination to enjoy a truly secured internet across the home.
Why do I recommend the use of a VPN based Router? My router allows me to safely use my VPN Connection with my Android Smartphone, my tablet, my XBox 360 and both my laptops all at the same time. The added flexibility and convenience, along with the usual safety of a VPN justify the price you pay for a router, many times over!
Key Takeaways
- A router allows you to simultaneously use your existing VPN connection on an array of devices
- VPN based Routers usually come with a Some Configuration Required label on the box
- South Carolina based Sabai Technology provides routers pre-configured with some of the best router supporting VPNs in the market
- If you decide to setup manually, ask your VPN service provider to give you a Router Support Package
- Ask the VPN service provider for an illustrated tutorial
- DD-WRT is free, has lot of information online and supports routers by over 90 manufacturers
Danish Pervez
Author
Danish Pervez’s Biography :
When the world sleeps, Danish Pervez is online researching consumer preferences and identifying next-gen trend waves. Experience in IT, combined with his diverse expertise in marketing and research – both traditional and digital – gives him an insight well worth reading and sharing.
3 Responses to How to Setup VPN on your DD-WRT Router [Updated January 2022]
Hi guys,
After receiving various queries about which is the best dd-wrt router, we have published an exclusive guide “Best DD-WRT Routers 2017“, in which you can discover the advantages of using dd-wrt router. Also, our dedicated blog will reveal the cheapest and most affordable routers that can cater your streaming and unblocking needs. I believe our guide will be beneficial for those who are already owning or planning to buy a DD-WRT router.
PPTP has major security weaknesses and is NOT an option for a “truly secured internet”. OpenVPN is the only sensible choice to run on your VPN based router.
Yes I admit PPTP has fallen behind a bit lately. But it really isn’t all that bad if all you wan’t to do is some casual unblocking and streaming.
OpenVPN is one of the best VPN protocols available on the market. Unfortunately it is not always available on all devices. In this tutorial we will show you how to set up OpenVPN on DD-WRT Routers but first let’s see what are our requirements and recommendations.
Requirements
In order to set up the OpenVPN you will need:
- A CactusVPN account. If you don’t have one you can try our services for free.
- Your VPN username and password. You can find them in your account on our website, by going to Settings.
- The configuration files. You can find them on the Downloads page on our website.
Recommendations
- Important! OpenVPN can NOT be used with PPPoE or Static IP if you use DD-WRT flashed router as main router. We recommend you to use DD-WRT flashed router as the second one.
If you still want to set up OpenVPN manually, go step-by-step through following instructions:
OpenVPN Setup instructions
You have to connect to your DD-WRT router using Ethernet cable, or Wi-Fi network. To open router menu write in browser’s address bar the router’s IP. Usually it is 192.168.1.1 but if this doesn’t work, please consult your router’s manual to find what is the Default Gateway Address. If you want to connect to the router via Ethernet first set your network connection to obtain IP address automatically.
Configure your DD-WRT router to share your regular internet connection.
- Go to “Security” tab (1) and select “Firewall” (2) from there. Make sure “SPI Firewall” is enabled (3).
Lower on this page you need to set “Log” to “Enable” (4) and set it to “High: (5). Now you should “Save” (6) and “Apply Settings” (7).
Now you should switch to “Services” tab (8), select “VPN” (9) from there and “Enable” (10) OpenVPN Client.
Here fill all the fields as shown below:Server IP/Name: CactusVPN server or IP (for example us3.cactusvpn.com)Port: 443 (or one of the following – 1194, 5555, 992)
Tunnel Device: TUN
Tunnel Porotocol: UDP
Encryption Cypher: AES-128-CBC
Hash Algorithm: SHA1
User Pass Authentication: Enable
In the “Username” and “Passwords” fields enter your VPN username and password.
You can find them in your account on our website, by going to Settings. Make sure you use your VPN username and password and NOT the website account credentials (What is the difference?).
Advanced options: Enable
TLS Cipher: None
LZO Compression: Disabled
Firewall Protection: Enable
Find the lines that begin with “ ” (12), “ ” (13) and “ ” (14).
Copy the text you see inside the and tags and paste it to the “Ca Cert” field (15). Then copy the text from to “Public Client Cert” field (16) and the text from to “Private Client Key” field (17). When you’ve finished “Save” (18) then “Apply Settings” (19).
Go to “Status” tab (20) and select “OpenVPN” (21). You should get the message “Client: CONNECTED SUCCESS” (22). This means the OpenVPN connection on DD-WRT router is created. You can use it right away!
Downloading the OpenVPN configuration files
Download the archive with OpenVPN configuration files and unpack it.
Log in to your DD_WRT router and enter at least two public DNS servers. You can either use Google’s DNS servers (8.8.8.8, 8.8.4.4) or any from the OpenNIC project. Then click on Save and Apply Settings .
Note: If you want, you can also use Perfect Privacy DNS servers (you can find the IPs on the server site in the customer area). These DNS servers will only resolve *.perfect-privacy.com domains when VPN is not connected which means that Internet access will not work without the VPN being connected. However, there will be no IP leak when using public name servers instead, since all DNS requests will be sent anonymized over the VPN tunnel while a VPN connection is established.
In the menu bar click on IPv6 next to the tab Basic Setup .
Set the options IPv6 and Radvd to enabled as shown on the picture on the left. Next click on Apply Settings .
VPN | OpenVPN on a router running DD-WRT’ >
Go to Services → VPN and configure the settings as follows:
- Start OpenVPN Client:
- Enable
- Server IP/Name:
- A Perfect Privacy server of your choice in this example zurich.perfect-privacy.com
- Port:
- Enter any valid port (148, 149, 150, 151, 1148, 1149, 1150 or 1151).
- Tunnel Device:
- TUN
- Tunnel Protocol:
- UDP
- Encryption Cipher:
- AES-256 CBC
- Hash Algorithm:
- SHA512
- User Pass Authentication:
- Enable
- Username:
- Your Perfect Privacy username
- Password:
- Your Perfect Privacy password
- Advanced Options:
- Enable
- TLS Cipher:
- TLS-DHE-RSA-WITH-AES-256-GCM-SHA384
- LZO Compression:
- Adaptive
- NAT:
- Enable
- Firewall Protection:
- Enable
- Tunnel UDP Fragment
- 1300ns
- CertType verification:
- Check the box
You can find the keys and certificates in the previously downloaded configuration. Open the *.ovpn file of the server you are using, in this case Zurich.ovpn.
Copy the content between the tags in the field TLS Auth Key .
Copy the content between the tags in the field CA Cert .
Copy the content between the tags in the field Public Client Cert .
Finally copy the content between the tags in the field Private Client Key.
When finished click on Save and Apply Settings .
CAUTION: This step activates the firewall protection (“kill switch”) which prevents traffic leaving your network in case the VPN connection was interrupted. If you also want to access the Internet with your router when no VPN is connected, you need to skip this step.
Go to Administration → Commands and enter the following lines:
Then click on Save Firewall .
The configuration is now finished.
Go to Administration → Management , scroll down to the bottom and click on Reboot Router .
You can verify that the VPN connection is working correctly by visiting our Check IP website.
Tests
If applicable please use our tests to verify your VPN connection:
Questions?
If you have any questions, comments or other feedback regarding this tutorial, please use the corresponding thread in our community forums.