Ken21
September 24, 2026, 2:41pm
1
I've updated firmware on my flint 3 from 4.10.0 to 4.10.1.
My VPN clients now won't connect (orange)
My VPN servers are ok (Green)
Thu Sep 24 10:54:20 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient1 - 4 names
Thu Sep 24 11:03:28 2026 daemon.warn dnsmasq[1]: no servers found in /tmp/resolv.conf.d/resolv.conf.wgclient1, will retry
Thu Sep 24 11:03:28 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient1 - 4 names
Thu Sep 24 11:03:28 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient1 - 4 names
Thu Sep 24 11:03:50 2026 daemon.warn dnsmasq[1]: no servers found in /tmp/resolv.conf.d/resolv.conf.wgclient1, will retry
AI_bot
September 24, 2026, 2:41pm
2
Those dnsmasq messages do not show the actual WireGuard connection failure; they can occur because the VPN interface has not come up and therefore has not supplied a DNS server.
As a targeted test, stop the existing client and import one of the original WireGuard profiles again as a new profile, without deleting the old one. If the newly imported profile connects, the retained profile likely did not migrate correctly during the upgrade. If it also remains orange, please post the redacted VPN client connection log from one connection attempt, especially lines mentioning endpoint resolution, handshake, or wgclient1. Do not include private keys, public IP addresses, or the complete configuration file.
This reply was generated by AI. Please verify its accuracy.
GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.
Ken21
September 24, 2026, 6:18pm
3
I added a new connection. Here are the logs
Thu Sep 24 15:14:35 2026 daemon.notice netifd: Interface 'wgclient2' is setting up now
Thu Sep 24 15:14:37 2026 daemon.info dnsmasq[1]: reading /tmp/resolv.conf.d/resolv.conf.wgclient2
Thu Sep 24 15:14:37 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:14:37 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:15:06 2026 user.notice vpn-failover-watcher: action=trigger iface=wgclient2 source=setup-timeout reason=startup-connecting-timeout elapsed=30
Thu Sep 24 15:15:06 2026 user.notice vpn-failover-trigger: action=schedule iface=wgclient2 source=setup-timeout reason=startup-connecting-timeout tunnel_id=2885 delay=0s pid=24246
Thu Sep 24 15:15:07 2026 user.debug tunnel_id_2885: (tunnel-switch.sh:633) section=cfg0592bd, iface=wgclient2, via_type=wireguard, group_id=10006, shared_count=1
Thu Sep 24 15:15:26 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:15:26 2026 daemon.info dnsmasq[1]: reading /tmp/resolv.conf.d/resolv.conf.wgclient2
Thu Sep 24 15:15:26 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:16:08 2026 daemon.notice netifd: wgclient2 (28157): rm: can't remove '/tmp/wireguard/wgclient2_state': No such file or directory
Thu Sep 24 15:16:09 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:16:13 2026 daemon.notice netifd: Interface 'wgclient2' is now down
Thu Sep 24 15:16:13 2026 user.notice firewall: Reloading firewall due to ifdown of wgclient2 ()
Thu Sep 24 15:16:15 2026 user.notice vpn-failover-trigger: action=skip iface=wgclient2 source=hotplug reason=ifdown cause=iface_disabled
Thu Sep 24 15:17:15 2026 daemon.notice netifd: Interface 'wgclient2' is setting up now
Thu Sep 24 15:17:16 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 15:17:16 2026 daemon.info dnsmasq[1]: reading /tmp/resolv.conf.d/resolv.conf.wgclient2
Thu Sep 24 15:17:16 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
AI_bot
September 24, 2026, 6:18pm
4
The newly imported profile also timing out makes a retained-profile migration issue unlikely. The log only shows the 30-second startup timeout, not whether WireGuard completed a handshake.
While wgclient2 is orange—and within 30 seconds of starting it—connect by SSH and run:
wg show wgclient2 latest-handshakes
wg show wgclient2 transfer
Please report only whether the handshake value is 0 or a non-zero timestamp, whether transfer counters increase, or whether the command says the interface does not exist. Do not post keys or endpoint addresses. A non-zero handshake would point toward the firmware’s connection/health check after tunnel establishment; zero or a missing interface would narrow it to tunnel setup or handshake failure.
This reply was generated by AI. Please verify its accuracy.
GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.
Ken21
September 24, 2026, 9:10pm
5
With my vpn client disconnected, I connected and immediately produced a system log
Thu Sep 24 18:06:17 2026 daemon.notice netifd: Interface 'wgclient2' is setting up now
Thu Sep 24 18:06:17 2026 daemon.info dnsmasq[1]: exiting on receipt of SIGTERM
Thu Sep 24 18:06:17 2026 daemon.info dnsmasq[1]: exiting on receipt of SIGTERM
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: started, version 2.92 cachesize 1000
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: compile time options: IPv6 GNU-getopt no-DBus UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC no-ID loop-detect inotify dumpfile
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: UBus support enabled: connected to system bus
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: DHCP, IP range 192.168.56.100 -- 192.168.56.249, lease time 12h
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: IPv6 router advertisement enabled
Thu Sep 24 18:06:19 2026 daemon.warn dnsmasq[1]: no servers found in /tmp/resolv.conf.d/resolv.conf.wgclient1, will retry
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /etc/hosts - 12 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient1 - 4 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts.vpn/lan_hosts - 20 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: read /etc/ethers - 0 addresses
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: started, version 2.92 cachesize 1000
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: compile time options: IPv6 GNU-getopt no-DBus UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC no-ID loop-detect inotify dumpfile
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: UBus support enabled: connected to system bus
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: DHCP, IP range 192.168.56.100 -- 192.168.56.249, lease time 12h
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: IPv6 router advertisement enabled
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for test
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for onion
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for localhost
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for local
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for invalid
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for bind
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for lan
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: reading /tmp/resolv.conf.d/resolv.conf.auto
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using nameserver 1.1.1.1#53
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using nameserver 1.0.0.1#53
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for test
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for onion
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for localhost
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for local
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for invalid
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for bind
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for lan
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /etc/hosts - 12 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.cfg01411c - 4 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient1 - 4 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: read /etc/ethers - 0 addresses
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: started, version 2.92 cachesize 1000
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: compile time options: IPv6 GNU-getopt no-DBus UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC no-ID loop-detect inotify dumpfile
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: UBus support enabled: connected to system bus
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: DHCP, IP range 192.168.56.100 -- 192.168.56.249, lease time 12h
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: IPv6 router advertisement enabled
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for lan
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: reading /tmp/resolv.conf.d/resolv.conf.wgclient2
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using nameserver 162.252.172.57#53
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using nameserver 149.154.159.92#53
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: using only locally-known addresses for lan
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /etc/hosts - 12 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.wgclient2 - 4 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq[1]: read /tmp/hosts.vpn/lan_hosts - 20 names
Thu Sep 24 18:06:19 2026 daemon.info dnsmasq-dhcp[1]: read /etc/ethers - 0 addresses
AI_bot
September 24, 2026, 9:10pm
6
This log confirms that wgclient2 starts and its DNS servers are loaded, but it still does not show whether a WireGuard handshake occurs.
While the client is orange, please run this through SSH:
wg show wgclient2 latest-handshakes
Report only whether the value is 0, a non-zero timestamp, or the interface does not exist. That result will distinguish a handshake failure from the firmware failing its post-connection health check. Do not post keys or endpoint addresses.
This reply was generated by AI. Please verify its accuracy.
GL.iNet Technical Support reviews and responds to relevant threads on business days. Please allow time for a staff response.