DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Critical Firmware Release

More
24 Jan 2017 13:01 #13 by lesd
Replied by lesd on topic Re: Critical Firmware Release

aweaton wrote: WAN1 is monitored using a ping detect (setup in WAN >> Internet Access) to ping Google DNS and Open DNS.



Please could you explain that? I cannot see how to do this.

Les

Please Log in or Create an account to join the conversation.

  • hornbyp
  • User
  • User
More
24 Jan 2017 13:51 #14 by hornbyp
Replied by hornbyp on topic Re: Critical Firmware Release

qwaz01 wrote: Does anyone have any information regarding the critical firmware release for almost all DrayTek routers?



The latest Vigor 2860n (3.8.4.2) firmware appears to have INTRODUCED a Security bug (though it may have fixed others). This issue was actually spotted by my ISP! (Virgin Media).

Reported as case #DQ597435; this is the response I got from Draytek support :-

Draytek Support wrote: I'm looking into this case at the moment as a priority, thank you very much for bringing it to our attention. The current work around is to downgrade the router to 3.8.2.3 which seems to be working as expected. I have raised the case with the software engineers and will keep you informed.

Older firmware link:
http://www.draytek.co.uk/download/support/v2860_3823_BT.zip



From what I can tell, the equivalent update for the Vigor 2830n (3.6.8.6) does NOT suffer from the same issue. I don't know about any other models.

Please Log in or Create an account to join the conversation.

More
24 Jan 2017 17:41 #15 by admin
Replied by admin on topic Re: Critical Firmware Release
This seems strange. It should be be accessible WAN side but should be limited only to the management IP/subnet you enter. As 3.8.4.2 was only to address security improvements, it should be otherwise identical to 3.8.4.1 so any problem was likely in that too. I think the better solution is to set long/complex private/public community strings.



Forum Administrator

Please Log in or Create an account to join the conversation.

  • david@pogus.co.uk
  • User
  • User
More
31 Jan 2017 08:05 #16 by david@pogus.co.uk
Replied by david@pogus.co.uk on topic Re: Critical Firmware Release
I am finding some issues with the new critical firmware (2860n+). After applying it, I have internet connectivity, but not to everything. Speedtest.net (both the Windows app and the website version) will complete the download test but record no upload, also I cannot connect to a remote PC using LogMeIn. I have made no other change and have tried all the different firmware options (v1, v2 & v3) with v2 giving the best stability. Have tried a power cycle with pause (5 mins). My ISP is PlusNet (UK). I have made no other changes to settings. Any suggestions/ideas?
I am thinking I might have to revert to the earlier firmware.
thanks
David

Please Log in or Create an account to join the conversation.

More
31 Jan 2017 09:59 #17 by piste basher
Replied by piste basher on topic Re: Critical Firmware Release
I'm on 3.8.4.3_BT and it's stable, no problems with connections as far as I can tell (just tried your Speedtest suggestion and I use several remote desktop connections). Do you have any firewall rules or route policies that would affect yours?

Please Log in or Create an account to join the conversation.

More
31 Jan 2017 10:18 #18 by admin
Replied by admin on topic Re: Critical Firmware Release
turn off hardware acceleration...seems to cause more trouble than benefits for some



Forum Administrator

Please Log in or Create an account to join the conversation.