Now I was doing a very short test of ar-750s and actual beta firmware with the follow results:
Antesting the openwrt-ar750s-3.203-0703.tar:
- Updated from working configuration to openwrt-ar750s-3.203-0703.tar
- got a vpn connection a at minimum no https traffic to outside was possible
- looked a little bit around on the settings without to see a misconfiguration
- doing a reboot which didnt help on this
- stopped antesting of openwrt-ar750s-3.203-0703.tar
Antesting the openwrt-ar750s-3.203-0703.tar:
- updated the router to openwrt-ar750s-3.203-0701.tar
- vpn are working
- http and https are working to outside
- Leaktest by router firmware by menu item offered cloudflare DNS, are still leaky. In this configuration a DNS from cloudflare are used which is the closest to the router location and not the closes one to the VPN endpoint position. So its still leaky. If I remember right from previous tests, this is also a way for getting slow unnecessary DNS answers. You can check the DNS leaks by p.e.
- My IP Address - BrowserLeaks
- https://ipleak.net
Testing of possible available non leaky configurations:
- If you select NextDNS against Coudflare by gl webmenue item, the DNS is not leaky, it mean you get answers from DNS server which are the closest to the VPN endpoint and not from DNS server which are the closes to your router position. The DNS is also fast on this way.
- If you configure by self a DNS server, p.e. a external one, re one which is offered from your VPN provider inside the vpn channel, its not leaky too and a fast depend on short ways.
My suggestion for this is:
- Deactivation of the Cloudflare DNS offered per menu item, as long as the implementation is leaky. Finally, presumably not every user checks what the router actually does when you use this and that menu item, but trusts that even before a firmware was released also tried times.
- Recall of the released and known DNS leaky firmware 3.201.
Replacement of the 3.201 firmware with a firmware that does not offer Cloudflare as a menu item, as long as it is not implemented in a non-leaky way.