ZyXEL / Keenetic VOX - Discussion | [Adslmodem] [wifirouter]



Rep: (4)
ZyXEL Keenetic VOX - Discussion


A photo:
Attached ImageAttached Image
Description:
Main features

Internet access and service providers
Internet Center Keenetic Vox is designed to access the Internet via a dedicated line or ADSL Ethernet over providers, using any connection types: PPPoE, VPN (PPTP and L2TP), 802.1X, VLAN 802.1Q, IPv4 / IPv6.Firmennaya ZyXEL Link Duo technology allows computers on your home network to simultaneously access and Internet access, and location-based services provider for a dedicated line. Processor 700 MHz MediaTek RT63368F c hardware network accelerator and 2 NDMS newest operating system provide Internet keeper high load carrying capacity for a file-sharing networks, such as BitTorrent.


Wi-Fi 802.11n 300 Mbps / s Wireless network
Internet Center allows you to organize high-speed wireless network to work together on the Internet and your home network with laptops, Cmartfon and any other Wi-Fi devices standard IEEE 802.11n. Two integrated omni-directional antennas provide wide area network coverage Wi-Fi and high quality wireless communication at speeds up to 300 Mbit / s. The default network is configured with a maximum protection of WPA2-AES and supports fast secure wireless connection for improved WPS technology (Wi-Fi Protected Setup) by pressing on the center of the web button. For guest devices, you can turn Wi-Fi network intended only for accessing the Internet without access to the devices and the information on the home network.


IP-telephony for two telephones or fax
Keenetic Vox is equipped with modern IP-telephony gateway SIP v2 standard with two FXS-ports, which can connect any analog telephone, for example that you use at home and make calls via the Internet to your friends all over the world. It suffices to choose a suitable your SIP-telephony operator, to register on their website and properly configure the Internet Center.


Secure Internet with Yandex.DNS
Yandeks.DNS - a free service provided by the company Yandex, blocking dangerous sites and adult sites. Pre-installed applications' Internet filter Yandeks.DNS "Internet center will protect all your home devices from sites that distribute malicious files. When you try to go to a dangerous website, you will see a message about blocking access.


Multifunctional USB Host
You can connect to the Internet center USB-modem 3G / 4G, USB-drive, the USB-printer, and all users on your wired and wireless home network can access the connected devices. From USB-drives can use FTP-server and BitTorrent-Client, which allows be in the file-sharing network 24 hours a day, freeing up the computer from this problem.


Parental control with SkyDNS cloud service
The SkyDNS Internet Filter application, which uses SkyDNS cloud service, will allow you to monitor your children's online activity and protect them from unwanted websites and online services. You choose the categories of sites that are available for visiting, and apply the filtering profile you created to the devices you need on your home network.


Internet with your participation
With internet center Keenetic Vox you can realize the most daring online projects: open to friends access to your home game, file, or Web server, install the network camera for remote monitoring or even open their Internet radio station. For added convenience, an Internet Point integrated client DNS-master service, DynDNS and NO-IP. It will allow to connect from the Internet to embedded applications, Internet center and outdoor services home network, using your own domain name, for example my.homeip.net. Ability to manually or automatically (by UPnP) port forwarding provides a complete part of your computer to file-sharing networks, and video game consoles - in online games.
Specifications:
Design features:
Processor 700 MHz MediaTek RT63368 network hardware accelerator
DDR SDRAM memory is 128 MB
2 internal omni-directional Wi-Fi antenna
4 Ethernet port (10BASE-T / 100BASE-T) - to the Internet and home devices
1 ADSL port - for the Internet
2 telephone sockets FXS - analog phones or fax machines
2 USB 2.0 Type A - for 3G / 4G compatible of USB-modems, disk drives and printers
Wi-Fi wireless control button
FN button Flexible
Power button
Reset Button
7 status indicators

Connectivity:
Connect to your ISP using ADSL, Ethernet, Wi-Fi or through a 3G / 4G external USB-modem.
Simultaneous connection to several providers for backup Internet access
Functions and protocols

IPoE / PPPoE / PPTP / L2TP
Supporting multiple PPP-tunnels
PAP / CHAP / MS-CHAP / MS-CHAP v2 / 802.1X
MPPE (Auto / 40/56/128)
A fully-functional implementation of VLAN IEEE 802.1Q
Automatic selection ADSL modulation
Automatic selection G.hs speed (G.994.1)
RADSL (ANSI T1.413 Issue 2)
G.dmt / G.lite / ADSL2 / ADSL2 +
Annex A / M / L
TVport technology
Link Duo Technology
DHCP (client / server)
Work with static IP address
Dual Stack IPv4 + IPv6
6in4 tunnel for access to IPv6 from IPv4 networks
Reassigning Network Interface Roles
Route table (DHCP / manual)
Firewall with connection control and flexible filtering rules
Forwarding ports to select destination port on a LAN (manual / UPnP)
IGMPv1 / IGMPv2, IGMP snooping, UDP proxy
VPN-transit compound (PPTP or L2TP)
DynDNS client service, NO-IP
Built-in Internet filter Yandex.DNS
Parental control SkyDNS

Wireless Wi-Fi network:
IEEE 802.11b / g
IEEE 802.11n MIMO 2x2 300 Mbit / s
Frequency Range - 2.4 GHz
WEP / WPA-PSK / WPA2-PSK network protection, MAC access control
Pre-configured Wi-Fi Protection
Multiple SSID
Quick WPS Setup
Wi-Fi Multimedia (WMM)

IP-telephony:
Supports SIP (RFC 3261) version 2
Supported voice compression protocols (codecs): G.711 (PCM A-Law and m-Law), G.729a / b, G.726
Support T.38 FAX Relay
SDP (RFC 2327)
RTP (RFC 1889)
RTCP (RFC 1890)
Suppression pauses in the conversation (VAD);
Comfort Noise Generation (CNG)
Echo cancellation G.168 (8 - 16 msec)
Automatic gain adjustment signal (AGC)
Definition and generation of DTMF tones
SIP ALG mode for the operation of SIP-telephony services in a network with NAT is

USB:
Supported by more than 60 models of 3G and 4G USB-modem (LTE)
Network use of USB-drives with file systems FAT / FAT32 / NTFS / EXT2 / EXT3 / HFS +
Microsoft Windows Network Sharing
FTP-server access from the Internet
BitTorrent Client Transmission
DLNA media server
Network printing on a compatible USB printer (except GDI printers)

Diagnosis and management:
Web configurator in Russian
Professional configuration interface via the command line (Cisco like CLI)
Configuration text file
Backup and restore configuration
Online update features and components
System log

Physical parameters:
Dimensions - 175 x 117 x 32 mm
Weight - 0.24 kg without power adapter
terms of Use

Operating temperature:
from 0 to +40 В° C
Relative humidity:
from 20 to 95% non-condensing
supply voltage: 100-240 V AC, 50/60 Hz

Equipment:
Internet Center Keenetic Vox
Power adapter
ADSL splitter
Ethernet cable
telephone cable
Instructions for use
Warranty card
1 year warranty

http://zyxel.ru/keenetic-vox
Instructions:
Firmware:
Useful links:

There is no curator in the subject. For questions about filling caps, please contactSpec_spb in QMS or moderators section through a button Pictureunder the messages. How to do it right, what would you understand the first time, well describedhere.

Post has been editedstp101 - 26.07.19, 23:14
Reason for editing: Stable 2.11.D.3.0-0 unofficial version of the firmware from 07.23.2019 to Keenetic VOX



Rep: (4)
Do not hold back - bought on trial ... Nuu what to say:
firmware should immediately update at least to 2.04.C.5.0-7 - leave glitches with the configuration and settings display, updated through the web without glitches
by cable 100Mb / s pulls
e3372s modem (stitched in HiLink) picked up speed too "full" ... but not two modems plug directly into it, USB ports are very close to each other - it is necessary to use a cable
MultiWAN`a not only redundant channels
SIP seems working fine, there are all the basic tincture .... BUT one: one line - one SIP account

That's all that checked ... about the reliability too early to say anything, but as long as it feels good: yes2:



Rep: (4)
I got a glitch on the phone - do not re-occur after a preset time ... had to use a STUN server.



Rep: (0)
I bought this device. I have a VPN channel going home to my office, a static ip. I could not run it - does not connect to the internet - gateway sees, and then nothing. I downloaded the latest firmware by another modem. I could zakonnektitsya BUT !!! - at the gateway does not store the data - every time you need to restart the drive in the new gateway address. The modem does not see the update server, although the Internet sees that the standard method does not update. Built-in torrent client does not work at all - does not download.
Crude software on the modem? Although, if it will work, then clearly THING ...
Wrote to tech support, I will wait for the results.
Maybe I got a defective, is it possible?



Rep: (0)
I need help on this device! Constantly breaks the connection to Yota :( I understand that this device is still intended for other purposes, but also under the Yota modem is working quite well.
Who can tell the novice where and how to fix it? I will try to unsubscribe and technical support Zyxel.



Rep: (1)
Someone tried Multiphone on the device?



Rep: (10)
2 months of trouble-free operation at Rostelecom
14 / 2.5 readily drags ADSL 2+ annex m mode
ddns enabled and VPN server
and sip dialer through zadarma

visyaki once a month, but not critical, and Asus dlinki Wesley me more often.



Rep: (0)
It should be in the office for about three months, an Internet through 4g modem from a megaphone (m150-2) and Multiphone.

On the internet there are practically no complaints, everything is stable enough, except for one lack - no type of network switching function of the modem.
And actually all good 4g, just until beginning to lag and bandwidth drops to 256kbps} -), the brain switch to an older modem at the network is simply not enough, and to switch from a PC ... not very convenient.
It seems there is a variant with flashing the modem, but not yet tried. : Blush:

About MultiFon worth mentioning separately (in fact because of it and purchase the device).
How to connect or configure MultiFon on zuksele simply do not have, and do not understand this business person is going bit by bit information is difficult. : Angry:

But the fact that it was found, was assembled about this configuration: happy::
Attached Image
Attached Image

But even so, from the SIP megaphone refused to work without the firmware update with C6 to C7. There is generally a separate story brick that was truereinstatedyet updated. : Download:

And yet, yes, Multiphone works, but:
- the link will be lost at night (really miss reload, SIP Auto-does not always work);
- the priority of an incoming call CAM switches and all calls start to go to the mobile phone, that is going nowhere;
- it is simply a server does not authorize ...

Actually, as a replacement for home phone is not bad: smoke: (can be placed and a landline number), but if you put in the office, it is better to go to the corporate sigment Megaphone or other SIP operator, and there is of course different prices.

Post has been editedRIIDERR - 15.10.15, 10:42



Rep: (1)
Masyanich @ 11.09.2015, 08:32*
2 months of trouble-free operation at Rostelecom


Share settings Line1, please.
I set up on a subject 2 account onlaym, Rostelecom and sipnet. The first can normally work out a half-day, day and a half days - and then falls off: Incoming do not go with the answer answerphone "This number does not exist", outgoing - employed. SIPNET while continuing to operate normally. Calls onlaymovskogo account on a PC softphone also are accepted and normal. Solved by restarting the router or break uplink (journal vAPP unloaded and loaded again, held accounts Registration on a server).

Line1 Settings:

SIP ID / Username: 2000227nomertelefona
Display name: Onlime
Local Port SIP: 5060

Authentication
Name: 2000227nomertelefona
The main SIP server
SIP Registrar: tel.moscow.rt.ru
port 5060
Proxy Server SIP: tel.moscow.rt.ru
port 5060
SIP Domain: empty
Realm: tel.moscow.rt.ru (field is required, a blank does not do, do not apply the settings)

SIP settings

Name User Agent: Keenetic VOX v2.04 (AAGN.2) C7
Duration of registration: 60
re-registration period: 30
RTP port range: 10000-65535
Enable PRACK: empty
Speed ​​dial numbers from #: Jackdaw standing
Enable MWI subscription: empty
The timer updates the session: Off
Use the backup SIP server if the primary is not available: empty
Use STUN: empty
Use outbound proxy: empty
Enable NAT Keep Alive: worth daw
Period NAT Keep Alive: 10
Max. number of unanswered requests: 4
DSCP to SIP (0-63): 32
DSCP for RTP (0-63): 40
DSCP for RTCP (0-63): 32
DTMF signaling method: RFC2833
RFC2833 Payload type: 101
Connecting vapp
Select Interface: Auto (default ISP Onlaym)

As I understand it, the problem with the settings specific to the data provider ip telephony sip at the gateway to the router, for another operator operates, and softphone (connection is not via a gateway router) also works.

Help, who experienced, or know how to solve.

Post has been editedpupkin11 - 24.10.15, 12:03



Rep: (4)
And I'm tired of fighting with the periodic "otvalivaniem" SIP ...: wallbash:
..postavil P-2304R-P1 - and began to sleep peacefully: ok:



Rep: (1)
* RIIDERR,

And what kind of firmware are C6 and C7? I have the latest beta B10 and it does not work MultiFon



Rep: (1)
Hello. Do not tell whether it is possible to change the type of this router with NATa Port Restricted to Address Restricted?



Rep: (16)
On Zyxel Keenetic DSL after upgrading to firmware 2.05.S2 longer displayed connection speed.

Attached Image

Does everyone have it?

Post has been editedAfeg - 26.12.15, 11:19



Rep: (0)
* Afega,
but a similar situation



Rep: (0)
Good day, someone at the VPN server use on this device has encountered the problem
mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [5] = 00
May December 12: 30: 18pptp [7936] MPPE required but can not negotiate MPPE key length
May December 12: 30: 18pptp [7936] Received bad configure-ack:
???
in the device is enabled (allowed to connect without encryption) client including optionally (connect even without encryption) and nevertheless fray in logs these records per second:
mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [5] = 00
May December 12: 30: 18pptp [7936] MPPE required but can not negotiate MPPE key length
May December 12: 30: 18pptp [7936] Received bad configure-ack:

May December 12: 30: 12ndmSyslog: the system log has been cleared.
May December 12: 30: 18pptpd [7935] CTRL: Client 192.168.1.33 control connection started
May December 12: 30: 18ndmkernel: fast vpn ctrl: c0a80121, 1
May December 12: 30: 18pptpd [7935] CTRL: Starting call (launching pppd, opening GRE)
May December 12: 30: 18pptp [7936] Plugin pptp.so loaded.
May December 12: 30: 18pptp [7936] PPTP plugin version 0.8.3 compiled against pppd 2.4.4-4
May December 12: 30: 18pptp [7936] pppd 2.4.4-4 started by root, uid 0
May December 12: 30: 18pptp [7936] Using interface vpn1
May December 12: 30: 18pptp [7936] Connect: vpn1<-->pptp (192.168.1.33)
May 12 12: 30: 18ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 18pptp [7936] MPPE required but can not negotiate MPPE key length
May December 12: 30: 18pptp [7936] Received bad configure-ack:
May December 12: 30: 18pptp [7936] local IP address 192.168.1.1
May December 12: 30: 18pptp [7936] remote IP address 172.16.1.33
May December 12: 30: 18ndhcpsVPN0: DHCPINFORM received for 172.16.1.33 from 00: 00: 00: 00: 00: 00.
May December 12: 30: 18ndhcpsVPN0: sending INFORM to 00: 00: 00: 00: 00: 00.
May 12 12: 30: 21ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 21pptp [7936] Received bad configure-ack:
May 12 12: 30: 24ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 24pptp [7936] Received bad configure-ack:
May 12 12: 30: 27ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 27pptp [7936] Received bad configure-ack:
May 12 12: 30: 30ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 30pptp [7936] Received bad configure-ack:
May 12 12: 30: 33ndmkernel: mppe_decomp_alloc: options rejected: o [0] = 12, o [1] = 06, o [2] = 00, o [3] = 00, o [4] = 00, o [ 5] = 00
May December 12: 30: 33pptp [7936] Received bad configure-ack:
May December 12: 30: 35pptp [7936] LCP terminated by peer () M - $ @ M- ^ G ^ @<M-Mt ^ @ ^ @ ^ @ ^ @)
May December 12: 30: 35pptp [7936] Connect time 0.3 minutes.
May December 12: 30: 35pptp [7936] Sent 26092 bytes, received 37568 bytes.
May December 12: 30: 35pptpd [7935] CTRL: Reaping child PPP [7936]
May December 12: 30: 35pptpd [7935] CTRL: Client pppd TERM sending
May December 12: 30: 35pptpd [7935] CTRL: Client pppd finish wait
May December 12: 30: 35pptp [7936] Modem hangup
May December 12: 30: 35pptp [7936] Connection terminated.
May December 12: 30: 35ndmkernel: fast vpn ctrl: c0a80121, 0
May December 12: 30: 35pptp [7936] Exit.
May December 12: 30: 35pptpd [7935] CTRL: Asked to free call when no call open, not handled well
May December 12: 30: 35pptpd [7935] CTRL: Could not write packet to client.
May December 12: 30: 35pptpd [7935] CTRL: Could not write packet to client.
May December 12: 30: 35pptpd [7935] CTRL: Client 192.168.1.33 control connection finished



Rep: (0)
Guys tell me,
1) whether the filtering function is implemented MAC addresses not yet WI-FI and wired through the RJ-45,
2) whether it is possible to add their own sites to filter.
3) create a group for full access or only specific sites or need to use a computer with the program already.
Thank.



Rep: (0)
A router generally like. I can not find how to set the "preferred 4G" When the time come across 4G, it goes to the 3G, back and forth manually. Uncomfortable.



Rep: (0)
Does not work with ZTE 823D modem from Tele2, although judging by the list shouldhttps://zyxel.ru/kb/3390/
It defines it as ZTE Technologies MSM 1405

Ineta not, and everything is good.

Upd. Inet is, after the automatic update OSes, which came unexpectedly!

Post has been editedwebzee - 16.01.17, 22:51



Rep: (0)
Who can tell? I'm not good at networking, but fated to watch the network, so to speak. Network this: 192.168.1.0, 14 computers, server does not have one of the computers with connection ADSL zukselom Net distributes the entire office, there two network cards, one to the modem (192.168.2.2 255.255.255.0), the other in the network (192.168. 1.1 255.255.255.0), a proxy SmallProxy, thanks to his inet divided, all have access to faloobmenniku on this computer, and an Internet through the same. All IPs are registered manually. Compound 2 via the network device Dlink 1016D, for a large room.
Everything worked fine until recently.
Now, in the accounting department needed crypto keys and vayfay box office, I think many have already faced with innovation.
Crypto does not pass through the proxy of any kind.
The accounting was decided to buy a router with ADSL wifi. We took the Kinetic Vox.

VOKS at address 192.168.3.1, 3 computer accounts automatically received from him IPs, united among themselves, 1c through the network running, encryption keys went very well. But! Of them do not have access to the organization's internal network.

Stuck inside network cable to the router, it would be all too magical, if earned!
No pings.
Tried to do the mask 255.255.252.0, the network to see each other, gave nothing.
Pings between networks do not go.
Tried NAT cut off at VOKS, cuts off the work in the accounting department.

Tell me, at least, where to dig?

It is clear that I can prescribe routes in VOKS if the internal network port on the router to assign ip, how to do? In short - HELP!

Once again I say, is not strong, not a scientist IT) All by online study set up a long time ago.

Thank you for your loyalty and constructive suggestions.



Rep: (1058)
Official stable firmware version2.05.C.7.0-0 on 20/10/2017for VOX

Fixed vulnerability WPA2, known as Key Reinstallation Attacks (KRACK)

Changes
Version 2.05.C.7.0-0 (official release *) on 10/20/2017:
  • Wi-Fi: AP-Client "Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2, ACM CCS 2017" vulnerability fixed
  • updated OpenSSL to 1.0.2l

* Officially released for Keenetic DSL and VOX, rebuilt in the beta and delta for Keenetic Start and 4G II

(with)https://forum.keenetic.net/

Attached fileKeenetic VOX_v2.05 (AAGN.0) C7.zip(7.76 MB)

Mirror:
cloud.mail - v2.04, v2.05, v2.06, v2.07, v2.08, v2.09 Firmware Keenetic
yandex.disk - v2.04, v2.05, v2.06, v2.07, v2.08, v2.09 Firmware Keenetic
Picture


Post has been editedenpa - 01.11.17, 12:41



Rep: (1058)
Firmware 2.11 for router ZyXEL Keenetic VOX

Attached Image

Before installing the firmware, be sure to dobackup firmware and startup-config - here1, here2

After updating the router to 2.11, it is recommended to do Reset to factory settings , configure the router from scratch.

* Experimental firmware (Debug version)

Component kit
acl
base
chilli
cifs
cloud
cloudcontrol
components
config-ap
config-client
config-repeater
corewireless
ddns
dhcpd
dlna
dpi
easyconfig
eoip
fat
ftp
gre
hfsplus
igmp
interface-extras
ipip
ipsec
kabinet
l2tp
madwimax
miniupnpd
nathelper-ftp
nathelper-h323
nathelper-pptp
nathelper-rtsp
nathelper-sip
netflow
nortondns
ntced
ntfs
openvpn
opkg
opkg-kmod-audio
opkg-kmod-dvb-tuner
opkg-kmod-fs
opkg-kmod-netfilter
opkg-kmod-netfilter-addons
opkg-kmod-tc
opkg-kmod-usbip
opkg-kmod-video
pingcheck
ppe
ppp
pppoe
pppoe3g
pptp
skydns
storage
telephony
trafficcontrol
transmission
tunnel
usb
usbdsl
usblte
usbmodem
usbnet
usbserial
vpnserver
vpnserver-l2tp
ydns

Changes
Version 2.11.A.1.0-0 of 09.09.2017:

Experimental version , in branch 2.10, active work has been suspended due to preparations for the release of the official beta, see change log 2.10

  • L2TP / IPsec server added (details in separate topic)
  • Norton ConnectSafe DNS component added, configured via CLI in the nortondns section, similar to yandexdns
  • the Internet indicator (globe) lights up according to the results of connection to popular Internet sites: show internet status
  • Transmission: fixed a number of GUI errors: returned context menu, remaining free space, fixed nested directories (reported by @esa)
  • DECT: Early Media support added - music from server when dialing
  • DECT: added support for Easy Intercom - internal call without dialing when two handsets are registered
  • Chilli: Fixed the appearance of extra fields when switching profiles
  • Chilli: walled garden size increased to 64 entries
  • Web: Added inclusion of WifiMaster1 / AccessPoint1 in the guest segment (reported by @enpa)

Version 2.11.A.1.0-1 of 09/11/2017:

  • fixed spontaneous system reboot (reported by @KorDen)
  • Transmission: fixed error tr_crypto error: 05066066: lib (5): func (102): reason (102) (reported @enpa)
  • DECT: fixed reset of missed call notification (reported by @KorDen)

Version 2.11.A.2.0-0 dated 09.18.2017:

  • LLDP protocol support added, enabled automatically: interface {name} lldp disable - disable broadcasting on the specified interface
  • Captive Portal transferred to use the shaper from the trafficcontrol component.
  • fixed 100% CPU load when the guest network was turned on (reported by @ Sort44)
  • fixed TcpSocket certificate validation failed * error (reported by @Goblin)
  • IPsec: fixed reuse of addresses from the L2TP server pool (reported by @ Kinetic Guide)
  • IPsec: fixed disabling of NAT for L2TP server clients (reported @ Kinetic Guide)
  • IPv6: DHCP client starts independently of ICMPv6 RS (reported by @ Ivan Erokhin)
  • Web: fixed progress bar fading when installing updates
  • Web: the status of "Internet access" corresponds to show internet status

Version 2.11.A.3.0-0 dated 09.22.2017:

  • fixed kernel panic when accessing a disk through a VPN tunnel (reported by @enpa)
  • fixed IGMP snooping during multicast transmission to two or more TV ports
  • Fixed L2TP / IPsec server on big-endian platform (LTE, DSL, VOX)
  • IPsec: IKE SA and Phase2 SA lifetime configuration commands have been added: interface ipsec lifetime ipsec
  • Captive Portal: fixed error "packet dropped due to congestion" when working under load
  • Web: restored dependencies in the list of components
  • Added component "New web-interface design (beta)" * **
  • updated OpenSSL to 1.1.0f

* for all devices except Keenetic III, DSL, VOX and LTE
** appears in the list after upgrading to version 2.11.A.3.0-0 and higher

Version 2.11.A.3.0-1 of 09/23/2017:

  • DECT: TLS is disabled due to incompatibility with OpenSSL 1.1 (reported by @ iggo)

Version 2.11.A.3.0-2 of 09/26/2017:

  • fixed reboot when creating a wired connection (reported @enpa and also @ sokol2007)
  • removed gateway check if EasyConfig is not installed (reported by @BadWolf)
  • CIFS: Fixed the bug "Destructive crash" when creating a file from under Windows 10 (reported by @BeaViSs)
  • Transmission: HTTPS resumed (reported by @Unfaithful)
  • DECT: restored SIP TLS operation under OpenSSL 1.1
  • LLDP is disabled by default on public and protected interfaces.

Version 2.11.A.4.0-0 of 09/30/2017:

  • ACME client added to get a free certificate Let's Encrypt *: ip http ssl acme get [domain] - get a certificate for the specified domain name ** (default KeenDNS), ip http ssl acme revoke - revoke the certificate, ip http ssl acme list - print list of certificates, ip http ssl acme set-default - select the default certificate
  • added the command to disable NAT Loopback (at the request of @gaaronk): interface {name} no ip nat loopback
  • Added output of RSSI, CINR, RSRP, RSRQ parameters on Huawei E3372h modems
  • Fixed the likely cause of frame engine blocking when running Giga III and Ultra II with PPE on under load
  • Web: fixed bugs on the update page (reported @ r13)
  • Web: removed access point filter on # wireless.acl page (reported by @Andrey Kupreychik (Foxel))
  • Web: various new design fixes and improvements

* works in test mode using Let's Encrypt staging environment
** the name should be the web server kinetics on port 80
Version 2.11.A.4.0-1 dated 10.10.2017:

  • Wi-Fi: Peak TX performance of RT5392 / 5592 chips increased by 25% (Keenetic II, Giga II, Ultra, LTE, DSL, VOX)
  • Wi-Fi: fixed kernel crash on receiving MPDU packet more than 3840 bytes on RT3593 and MT7602E / 7612E (Keenetic Ultra, Air, Extra II, Giga III, Ultra II)
  • Wi-Fi: Fixed support for VHT40 (433Mbps) by the AP-Client on the MT7602E / 7612E (Keenetic Air, Extra II, Giga III, Ultra II)
  • Wi-Fi: updated MT7602E / 7612E microcode
  • Wi-Fi: AP-Client "Key Reinstallation Attacks: Forcing Nonce Reuse in WPA2, ACM CCS 2017" vulnerability fixed
  • Wi-Fi: Fixed Band Steering with dual-band Apple devices
  • added DNAT rules to outgoing OUTPUT traffic (as requested by @Ainvain)
  • Removed restarting of the DHCP client in case of disconnection of associated PPTP / L2TP connections with no global sign (reported by @enpa)
  • UPnP: fixed the bug "getifaddr: broken XML in NDM response" when working through CdcEthernet (reported by @Mobis FromPNZ)
  • DECT: fixed SIP INFO processing
  • DECT: fixed dialing rules test
  • DECT: Removed the appearance of "Insert DECT Dongle" when changing settings
  • Http:setting up access to the web interface automatically opens port 443
  • Transmission: changing peer-port via RPC / GUI is saved in the main config
  • restored Keenetic DSL and VOX assembly

Version 2.11.A.4.0-2 dated 10/14/2017:

  • reduced DHCP renew rate when working in conjunction with L2TP (reported by @ Ret-xc7)
  • fixed cyclic reconnections E3372h (reported by @ TheRock666)
  • CIFS: added resetting the BUSY flag on Xerox Phaser 3140 printers (reported by @ Vasily Piskaryov)
  • VoIP: SIP client improved when connected via USB-modem (Keenetic III, DSL, VOX)
  • DECT: Improved DTMF Recognition Quality
  • Web: added L2TP / IPsec VPN server component with a new design settings page
  • Web: added auto-updates daw
  • Web: added Wi-Fi Tx-Burst jackdaw
  • Improved performance of the network kernel stack when IGMP snooping
  • nginx updated to version 1.13.6

Version 2.11.A.5.0-0 of 10/21/2017:

  • DECT: improved support for incoming calls for handsets - Panasonic KX-TGA710, Panasonic KX-TGA131, Panasonic KX-A115, Gigaset SL450HX
  • DECT: Increased the supported length of the names of the tubes and lines to 50 characters
  • DECT: fixed web interface hang-up when re-registering a handset
  • Web (beta): Fixed L2TP / IPsec VPN server setup page
  • Web (beta): OpenVPN support added

Version 2.11.A.6.0-0 of 10/27/2017:

  • Added new KeenDNS domains with automatic SSL certificate receipt
  • Let's Encrypt Production Environment mode is enabled for obtaining white DST Root CA X3 SSL certificates
  • Automatic redirection is enabled for domains with an SSL certificate, with the option of disconnecting:
  • no ip http ssl redirect
  • added brute force protection HTTPS
  • fixed global priority when configuring VPN connections (reported by @enpa)
  • increased limit of registered hosts from 64 to 256
  • Added support for arbitrary Keenetic LTE init commands (as requested by @Luice Carol):
  • interface UsbLte0 lte init {string}
  • Web (beta): added form-based authorization and "Exit" button
  • Web (beta): the segment setting logic has been completely redesigned.
  • Web (beta): interactive language switching implemented
  • IPsec: added support for special characters in the PSK key
  • IPsec: added rekey process control commands to eliminate potential traffic loss:
  • crypto ipsec rekey make-before - enable installation of new SA until the previous ones break
  • crypto ipsec rekey delete-delay {delay} - wait for delay seconds before deleting outdated SAs after receiving the DELETE command from the remote side
  • DLNA: the force_sort_criteria option is enabled (asked by @ Alexander Sukhorukov)
  • DECT: fixed SIP registration interval setting

Version 2.11.A.6.0-1 of 11/03/2017:

  • Web (beta): implemented the ability to add a port in several segments
  • Web (beta): added HTTPS icon when choosing keenetic.pro and keenetic.link domains
  • Web (beta): added button to enable auto updates
  • Web (beta): fixed cloud service switch
  • Web (beta): fixed system time settings
  • DLNA: DSF / DFF audio format support added (at the request of @ a.tishin1982 @ mail.ru)
  • DLNA: root container configuration command was added (at the request of @m__a__l): dlna container (browse | music | video | images), no dlna container — disable the setting
  • ASIX AX88772 USB adapter support restored, AX88179 and Realtek 8150/52/53 support added (at the request of @ vasek00)
  • updated OpenSSL to 1.1.0g

Version 2.11.A.7.0-0 of 11/08/2017:

  • kernel crash fixed during intensive traffic transmission through CDC NCM modem fixed
  • Added support for accelerating the processing of traffic in ppe software from USB-Ethernet dongles on Realtek 8152/8153 chips
  • L2TP, PPTP: added sending LCP TERMREQ to reduce the possibility of a "too many connections" error when reconnecting
  • AFP: fixed bug "AVAHI": unexpectedly stopped (reported by @Lordmaster)
  • SIP: SIP ALG Direct Media configuration command added, disabled by default: [no] ip sip alg direct-media
  • Web (beta): if set, default
  • Web (beta): added transmission
  • Web (beta): Fixed saving PPP connection settings

Version 2.11.A.8.0-1 dated 11/09/2017:

  • Fixed a redirect to a new design of the Web interface (reported @ r13)
  • component added - NetFlow sensor: interface {name} ip flow (ingress | egress | both) —to turn on the NetFlow sensor on the specified interface, ip flow-cache timeout active {timeout} —the storage time of active sessions in cache, in minutes (from 1 30, default 10), ip flow-cache timeout inactive {timeout} - the storage time of inactive sessions in the cache, in seconds (from 1 to 600, default 20), ip flow-export destination {address} {port} -
  • collector address and port
  • DLNA: force_sort_criteria option removed (asked @ r777ay)

Version 2.11.A.8.0-2 dated 11/11/2017:

  • Chilli: added commands :, interface {name} chilli lease {lease} - client IP lease time in seconds (default 600), interface {name} chilli nasmac {mac} - MAC address transmitted in the RADIUS attribute Called- Station-ID (the default MAC address of the guest network)
  • Web (beta): initial setup wizard added, displayed after reset to factory configuration
  • Web (beta): fixed wired PPP setting
  • Web (beta): fixed band-steering switch position
  • Web (beta): fixed adding and configuring users, including FTP
  • Web (beta): language switching fixed
  • DECT: fixed display of exported call history in Windows Notepad
  • DECT: fixed binding of tubes to lines
  • DECT: fixed the call history file path
  • DECT: added saving phone book in the same directory with call history (at the request of @KorDen)
  • DECT: limit set for maximum call log file size
  • Http:certificate receipt disabled if the Web server port is changed
  • Http:Fixed access to the proxy (ip http proxy) over HTTPS
  • added support for Huawei K5150 USB modem

Version 2.11.A.8.0-3 dated 11/11/2017:

  • fixed saving files via http / ci (reported by @enpa)

Version 2.11.A.8.0-4 of 11/13/2017:

  • Web (beta): fixed interface work in Android WebView
  • DECT: fixed the failure of the telephony module when displaying active calls

Version 2.11.A.8.0-5 of 11/18/2017:
  • CIFS: LLMNR support added (at the request of @ r13)
  • CIFS: Fixed reading of large files (reported by @Unfaithful)
  • Wi-Fi: fixed incorrectly assigning a MAC address to 5 GHz, which caused SSID visibility and connectivity issues (reported @JumpFire)
  • DECT: improved automatic recovery of the telephony module after a crash
  • DECT: improved synchronization of call history between the internal memory of the router and USB-drive
  • FTP:UTF-8 encoding is enabled for correct display of file names under Mac OS

Version 2.11.A.8.0-8 dated 11/25/2017:

  • Wi-Fi: Delayed when triggering Band Steering and associated gaps probe / auth response
  • DLNA: Premature service start and database reindexing with two or more drives eliminated
  • Chilli: added bandwidth limit for unregistered hosts
  • Web: fixed permissions designations (reported by @Roman_Petrov)

Version 2.11.A.9.0-0 of December 3, 2017:

  • The operation of E3276 USB modems on HiLink firmware was restored (attention: regression is possible in the work of other CdcEthernet modems)
  • IPv6: added blocking of IPv6 traffic when Internet access is denied by hosts
  • Wi-Fi: fixed indicator performance on Keenetic 4G III rev. B and Lite III rev. B
  • DLNA: added sorting command:
  • dlna sort (track | album | date | title | class) [ascending | descending]
  • IPsec: DHCP server is enabled for distributing INFORM options to L2TP clients (asked @Kynikovod)
  • IPsec: updated strongSwan to version 5.6.1
  • PPP: added command for setting the interval between repeated connections:
  • interface {name} reconnect-delay {sec} - in seconds from 3 to 600, default 3
  • SNMP: Enabled in access point mode
  • Web (beta): added ability to configure additional segments in access point mode
  • Web (beta): added Captive Portal section, updated profile list
  • Web (beta): connection priorities fixed

Version 2.11.A.9.0-1 of 12/05/2017:

  • Fixed Hotspot :: Account: system failed [0xcffd04b5] (reported @ r13)
  • Fixed Network :: ArpTable: system failed [0xcffd0445] (reported @ r13)
  • Fixed the error too many log arguments in a stream: ->IPv6 (% 1): [% 2] (reported by @enpa)
  • fixed UDP error Failed to set receive buffer (reported by @enpa)
  • Web: Fixed the operation of the page # dashboard.connections (reported by @ sokol2007 and also @iggo)
  • DNS: Removed RA flag from requests (reported @ r13)
  • DNS: an algorithm for sending queries based on the ranking of DNS servers by response rate is implemented
  • Opkg: opkg-kmod-tc kernel modules are in manual boot mode

Version 2.11.A.9.0-2 of December 7, 2017:

  • Fixed Hotspot :: Account: system failed [0xcffd04b7] (reported @ r13)
  • DNS: bug fixed Service: "Dns :: Proxy": unexpectedly stopped (reported by @enpa)
  • CIFS: fixed accessibility of the service from the guest network (reported by @ Oleksii)
  • VoIP: fixed 406 Not Acceptable bug with RTCP attribute in INVITE SDP

Version 2.11.A.9.0-3 of 09.12.2017:

  • Wi-Fi: fixed race condition and associated kernel crash in BssEntrySet function
  • Wi-Fi: improvements have been made to Band-Steering
  • CIFS: eliminated sending NetBIOS packets to public interfaces (reported by @ vasek00)
  • Web: fixed tab # usb.afp (reported by @AndreBA)
  • Web: # broadband.ppp tab restored (reported by @stitchix)
  • FTP:Added a default encoding setting, changing to UTF-8 caused a tntfs error "Failed to convert name to Unicode"
  • ip ftp client-charset {charset}
  • Added support for USB modem E5573, fixed work of similar modems on HiLink 22.323 firmware
  • Fixed picture fading when some Smart TV models work over the wire via Keenetic Start II, 4G III rev. B, Lite III rev. B, Air and Extra II

Version 2.11.A.9.0-4 dated 12.15.2017:

  • DNS: SkyDNS and Yandex.DNS "not available" bug fixed (reported @ r777ay)
  • IPsec: fixed StrongSwan launch (reported by @KorDen)
  • VoIP: fixed one-way audibility for incoming calls, the operator Mango Telecom
  • Web (beta): search feature added
  • Web (beta): Opkg support added

(c)https://forum.keenetic.net/

Attached fileKeenetic VOX_2.11.A.8.0-5.bin.zip(12.05 MB)

Attached fileKeenetic VOX_2.11.A.9.0-4.bin.zip(11.99 MB)

Mirror:
cloud.mail - v2.04, v2.05, v2.06, v2.07, 2.08, 2.09, 2.10, 2.11 (Test, Beta Firmware) All Keenetic
yandex.disk - v2.04, v2.05, v2.06, v2.07, 2.08, 2.09, 2.10, 2.11 (Test, Beta Firmware) All Keenetic

If there are problems with the firmware

Instructions

Picture


Post has been editedenpa - 20.12.17, 14:46
Reason for editing: 2.11.A.9.0-4 from 12/15/2017


Full version    

Help     rules

Time is now: 27/09/19, 15:56