• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

FlashRouters Support Portal

Prioritizing Privacy

  • SETUP GUIDES
    • Privacy Hero Router Setup Guide
    • ASUS-WRT Router Setup Guide
    • AsusWRT-Merlin Router Setup Guide
    • DD-WRT Router Setup Guide
    • ExpressVPN Router Setup Guide
    • GL.iNet Router Setup Guide
    • Roqos Core Router Setup Guide
  • TROUBLESHOOTING
    • Router Access
    • WiFi Connectivity
    • Internet Connection Issues
    • General VPN Issues
    • DD-WRT Firmware
    • TeamViewer Remote Support
  • FAQs
    • Router FAQs
    • VPN FAQs
    • Warranty and Returns FAQs
    • Sales FAQs
    • Shipping FAQs
    • Service Plan FAQs
  • Show Search
Hide Search

Search Results for: dns server

DNS Setup for DD-WRT FlashRouters

TeamFlashRouters · Apr 3, 2019 ·

The Domain Name System (DNS) is the phonebook of the Internet. DNS resolves website domain names (www.website.com) to IP Addresses so you don’t have to remember the IP Address of every site you visit.

We setup each FlashRouter with Google DNS (8.8.8.8 , 8.8.4.4) and/or OpenDNS (208.67.220.220 , 208.67.222.222) to prevent your ISP DNS from leaking when connected to the FlashRouter.

By using a trusted DNS server like those listed below, or from your trusted VPN service provider, you can prevent ISP’S from compiling your browsing data and selling it to third parties without your consent.

Recommended DNS servers

GoogleDNS

Primary DNS: 8.8.8.8

Secondary DNS: 8.8.4.4

OpenDNS

Primary DNS: 208.67.220.220

Secondary DNS: 208.67.222.222

Cloudfare

Primary DNS: 1.1.1.1

Secondary DNS: 1.0.0.1

Level 3

Primary DNS: 209.244.0.3

Secondary DNS: 209.244.0.4

How to change the DNS on your FlashRouter

We preset each FlashRouter with GoogleDNS and OpenDNS so there is no need to change the DNS servers unless you have reset the FlashRouter or want to use different DNS servers.

Navigate to Setup > Basic Setup

DNS Setup on DD-WRT FlashRouters
  1. Scroll down to Network Address Server Settings (DHCP).
  2. Enter in any combination of valid DNS servers into Statict DNS fields 1, 2, and 3.
  3. Click Apply Settings at the bottom of the page.
  4. Power cycle your FlashRouter off and back on.

DNS Leak Test

We recommend checking to see if your DNS is leaking when using VPN.

What is a DNS leak and how can I prevent a DNS leak in my router?

TeamFlashRouters · Jun 11, 2019 ·

What is a DNS leak?

A DNS Leak is an instance where your ISP receives DNS requests despite being connected to a VPN tunnel.

How do I check if my DNS is leaking?

  1. Perform the extended test on DNSLeakTest.com. Be sure to do so on multiple web browsers for best accuracy.
  2. Here you should only find one server and your ISP should not be listed as your actual ISP.
  3. If your actual ISP is not listed there is no DNS leak.

How can I prevent a DNS leak in DD-WRT?

Check your device's browser settings

Updates to web browsers have added DNS settings capabilities, while this often makes your browsing experience more secure it can also effect the results of a DNS leak test. You can go into your browser’s settings and search for “DNS” and disable the DNS of the browser for more accurate DNS leak test results.

A simple web search for “DNS settings [browser name]” should return helpful information for finding the setting in your browser.

Adjust DD-WRT settings

1. On the Setup > Basic Setup page of the DD-WRT settings check the Ignore WAN DNS box.

This setting may not appear in older DD-WRT firmware builds. If it is not appearing for you, upgrade your DD-WRT firmware.

DD-WRT Check Ignore WAN DNS

2. Lower on the same page check the Forced DNS Redirection box.

DD-WRT Check Forced DNS Redirection

3. Click Apply Settings at the bottom of the page and then wait a full minute and power the FlashRouter off and back on. Reconnect to the FlashRouter’s network once it boots back up and then make sure you are connected to VPN by going to https://whatismyipaddress.com then perform the DNS leak test again.

Adding your VPN provider’s DNS servers to the router’s configuration can be helpful as well. The DNS servers are typically found on the VPN provider’s website or you can reach out to their team for a recommendation of what DNS servers to enter.

DNS Setup for Asus Merlin

TeamFlashRouters · Jan 19, 2022 ·

Enter custom DNS servers in your Asus Merlin firmware to avoid using your ISP DNS, which will steal and collect your browsing data.

Login to Asus Merlin firmware settings in a browser on any computer or smart device.

1. Under Advanced Settings select LAN.

2. Click the DHCP Server tab.

3. In the DNS Server 1 and DNS Server 2 fields enter the DNS server that you wish to use.

Merlin DNS Setup

4. Click Apply and then reboot the router and reconnect to the network.

How do I check for static network settings on my devices?

TeamFlashRouters · May 8, 2019 ·

Static network settings set on a device from a previous connection will interfere with the FlashRouter’s network. Typically the FlashRouter’s network performs best when connected devices are set to automatically use the FlashRouter’s IP Address and DNS.

Make sure you are connected to the FlashRouter’s network via ethernet or WiFi. Keep in mind these instructions may vary based on your current software version.

Check for Static IP Address in Windows

1.  Open the Window search box, and search “Network Status”

Find Static DNS settings for FlashRouter DD-WRT in Windows Computer

2. Select “Change adapter optons”

Find Static DNS settings for FlashRouter DD-WRT in Windows Computer 2

3. Right click on the WiFi and/or ethernet adapter and select Properties.

Find Static DNS settings for FlashRouter DD-WRT in Windows Computer 3

4. Highlight Internet Protocol Version 4 (TCP/IPv4) and click Properties.

5. Delete the values entered for IP address, Subnet mask, Default gateway, Preferred DNS server, and Alternate DNS server.

6. Select Obtain an IP address automatically and Obtain DNS server address automatically.

7. Click OK.

Find Static DNS settings for FlashRouter DD-WRT in Windows Computer 4

Check for Static IP Address in Apple / Mac

1. Open System Preferences, and select Network.

Find Static DNS settings for FlashRouter DD-WRT Using a MAC Computer

2. Select the adapter that is connected via ethernet or wireless. This will vary based on your current connection.

3. Select Advanced.

Find Static DNS settings for FlashRouter DD-WRT Using a MAC Computer 2

4. Select the TCP/IP tab.

5. Set Configure IPv4 to Automatically.

Find Static DNS settings for FlashRouter DD-WRT Using a MAC Computer 4

6. Select the DNS field and highlight any DNS servers you see there. If they can be removed you should click the minus symbol below.

Find Static DNS settings for FlashRouter DD-WRT Using a MAC Computer 5

7. Click OK.

8. Click Apply.

Check for Static IP Address in iOS

1.  Open Settings

2. Select WiFi, and select the blue icon next to your current connection.

Select FlashRouters DD-WRT Wireless Network in order to Check Static IP Network Settings on iOS Mobile Device

3. Make sure Configure IP is set to Automatically.

Check Static IP Network Settings on iOS Mobile Device and set Configure IP to Automatic

Check for Static IP Address in Android

1. From the top of the screen, swipe down to display settings.

2. Select WiFi.

WiFi Icon and Settings in Android Mobile Device

3. Select your current network.

4. Select Advanced.

Advanced Settings Button in Android Mobile Device

5. Make sure that IP settings is set to DHCP.

Check Static IP DHCP Network Settings in Android Mobile Device

Router FAQs

admin · Jan 29, 2019 ·

Router FAQs

What is an IP Address?

An IP (Internet Protocol) Address is a numerical assignment for each device (cell phone, iPad, laptop computer, printer etc) inside a network that uses the Internet Protocol for communication. Internet Protocol is responsible for routing information packets across network boundaries. It is the main protocol establishing the Internet.

An IP address serves two predominant functions. First is to host or network interface identification. Second, it provides location addressing. To put it bluntly, an IP address tells wherever you are connecting, to whom you are visiting, and where you are located.

What is DNS?

DNS (Domain Name System) is a protocol within the TCP/IP protocol that uses a set of standards for how computers exchange data on the Internet and on many private networks.

The basic job of DNS is to convert a user-friendly domain name into an IP address that computers use to identify one another. Think of DNS like your cellphone contact list; you tap the name and the phone contacts to a phone number.

It is easier to remember flashrouters.com, rather than its IP address. Imagine if you had to remember all of the IP addresses of your favorite websites!

What is DNSMasq?

DNSMasq is a local DNS server that speeds up host-name searches from your computer/Internet connection after pressing enter.

Basically, DNSMasq gives the router some advanced enterprise functionality – caching DNS records locally so you have a faster browsing experience. Your computer only has to go to the router instead of repeatedly scouring the web for a commonly visited site.

What is Throughput and How Do I Improve it?

Throughput is the average rate of successful delivery of messages through a network. Simply put, throughput measures the speed of message delivery inside a network. If you think about it in relationship to networks and Internet connections, throughput defines the user experience. The key to a pleasing user experience is uninterrupted service and smooth data transfer.

In order to improve throughput,  you should get a router with more memory. If you notice that your network is running slowly due to congestion, you could probably benefit by upgrading your router to one with more memory. FlashMemory and RAM on a router add more room to prevent network congestion and improve throughput.

Most of FlashRouters‘ high-end units come with at least 8 MB of Flash memory and 64 MB of RAM which should be more than capable for providing for the average home users’ or small business will need in the future.

What is PPPoE?

PPPoE stands for Point-to-Point Protocol over Ethernet, a network protocol for encapsulating Point-to-Point Protocol (PPP) frames inside Ethernet frames. It is used mainly with DSL services where individual users connect to a DSL modem over Ethernet.

With PPPoE, users virtually “dial” from one machine to another over an Ethernet network, establish a point-to-point connection and then data packets are securely transported through the connection.

PPPoE offers an Internet service provider (ISP) an easier way to track exactly how much bandwidth you are using in case they want to charge for it in the future.

What is the Difference Between VPN Encryption and Wireless Network Security?

VPN Encryption: If you are connected to the VPN on your home network, then any data that flows over the Internet is entirely encrypted whether you are connected to the Internet either wired or wirelessly. This means that if your Local ISP was trying to see what you are browsing or downloading, they would not be able to see your data.

Wireless Network Security: If you leave your wireless network open or insecure, it does not matter whether Internet traffic is encrypted, because someone can directly see what you are doing on your network, or even worse, can go in and put a wireless password on your network, locking you out. They may also be able to access folders and files on your computer without your control.

Best thing to do is protect your wireless network with a WPA secured password along with your VPN connection.

Are FlashRouters Affected By the Shellshock Bug?

No.

According to our in-house testing and multiple DD-WRT community reports, we have found that the Shellshock vulnerability will not work on with DD-WRT or TomatoUSB installed router. The vulnerability is based on a shell called BASH (Bourne Again Shell) but DD-WRT & Tomato firmware use BusyBox which is confirmed to not have this issue.

Please be advised that if you are using Optware on your DD-WRT router there is a chance that implementation is BASH based. Only used trusted optware on your router.

SmartDNSProxy SmartDNS Setup

TeamFlashRouters · Jun 13, 2019 ·

SmartDNSProxy offers a SmartDNS service for unblocking geo-restricted content without the encryption of a VPN service. SmartDNS routes DNS servers to different regions which “tricks” the website to allow access to previously restricted content.

SmartDNS does not change your IP Address or provide the encryption that a VPN connection does. This can result in faster speeds and unblocked content.

SmartDNS and VPN should not be configured at the same time. When using a SmartDNS connection, make sure to disable your VPN connection on the FlashRouter.

Register your IP Address

If you are not already a SmartDNSProxy user Sign Up Now.

Click on Sign Up and fill in the requested information.

SmartDNSProxy SmartDNS Account Sign Up For DD-WRT FlashRouter

Access the e-mail you entered and Verify your new account.

SmartDNSProxy SmartDNS Activate DNS for DD-WRT FlashRouter

Your account will now be verified.

Activate SmartDNSProxy SmartDNS Service and Subscription

Login to SmartDNSProxy

SmartDNSProxy Server Location Addresses for FlashRouter DD-WRT Settings

Visit SmartDNSProxy’s DNS servers list and note the DNS servers of the location you would like to access content from.

Enter SmartDNSProxy SmartDNS servers on your FlashRouter

Navigate to Setup > Basic Setup

  1. Scroll down to Network Address Server Settings (DHCP).
  2. Enter in any combination of SmartDNSProxy SmartDNS servers you noted into Static DNS fields 1 and 2.
  3. Click Apply Settings at the bottom of the page.
  4. Reboot the FlashRouter.

Once the router is fully booted back up, you can access your desired regional content on any device that connects to the FlashRouter’s network.

ExpressVPN MediaStreamer SmartDNS Setup

TeamFlashRouters · Jun 13, 2019 ·

ExpressVPN offers a SmartDNS service known as MediaStreamer for unblocking geo-restricted content without the encryption of a VPN service. SmartDNS routes DNS servers to different regions which “tricks” the website to allow access to previously restricted content.

SmartDNS does not change your IP Address or provide the encryption that a VPN connection does. This can result in faster speeds and unblocked content.

SmartDNS and VPN should not both be configured at the same time. When using a SmartDNS connection make sure to disable your VPN connection on the FlashRouter.

Login to ExpressVPN

If you are not already a ExpressVPN user Sign Up Now.

Visit ExpressVPN website login page and successfully login.

Register your IP with ExpressVPN

Navigate to the DNS Settings tab on top right of the ExpressVPN Dashboard.

ExpressVPN MediaStreamer DNS Settings

Click on Register my IP address.

Register IP for ExpressVPN MediaStreamer use on FlashRouter DD-WRT

Navigate to the ExpressVPN Dashboard.

Finding ExpressVPN MediaStreamer Specific DNS Servers in ExpressVPN Dashboard

Click on Set Up on More Devices.

Finding ExpressVPN MediaStreamer Specific DNS Servers

Scroll down and click on MediaStreamer and note the DNS servers that appear on the right side of the page.

ExpressVPN MediaStreamer Specific DNS servers

Enter MediaStreamer SmartDNS servers on your FlashRouter

Navigate to Setup > Basic Setup

  1. Scroll down to Network Address Server Settings (DHCP).
  2. Enter in the MediaStreamer SmartDNS servers you noted into Static DNS fields 1 and 2.
  3. Click Apply Settings at the bottom of the page.
  4. Reboot the FlashRouter.

Once the FlashRouter has fully rebooted, you can now access your desired regional content on any device that connects to the FlashRouter’s network.

Getflix SmartDNS Setup

TeamFlashRouters · Apr 4, 2019 ·

Getflix offers a SmartDNS service for unblocking geo-restricted content without the encryption of a VPN service. SmartDNS routes DNS servers to different regions which “tricks” the website to allow access to previously restricted content.

SmartDNS does not change your IP Address or provide the encryption that a VPN connection does. This can result in faster speeds and unblocked content.

SmartDNS and VPN should not both be configured at the same time. When using a SmartDNS connection make sure to disable your VPN connection on the FlashRouter.

Login to Getflix

If you are not already a Getflix user Sign Up Now.

New customer Signup for GetFlix SmartDNS Service

Login to Getflix’s website login page.

Visit Getflix’s DNS servers list page and note the DNS servers of the location you would like to access content from.

Getflix DNS Server Location Addresses for FlashRouter DD-WRT Settings

Enter Getflix SmartDNS servers on your FlashRouter

Navigate to Setup > Basic Setup

  1. Scroll down to Network Address Server Settings (DHCP).
  2. Enter in any combination of Getflix SmartDNS servers you noted into Static DNS fields 1 and 2.
  3. Click Apply Settings at the bottom of the page.
  4. Reboot the FlashRouter.

Register your IP Address

When the router is fully booted back up visit your Getflix user dashboard and make sure your IP Address is registered with Getflix. If it is not click Force IP Update.

Register IP Address for Getflix use on FlashRouter DD-WRT

Once you are successfully registered you can now access your desired regional content on any device that connects to the FlashRouter’s network.

IVPN WireGuard Setup

TeamFlashRouters · Oct 13, 2021 ·

Preparing for IVPN WireGuard Setup

Verify your IVPN login information

If you are not already a IVPN user Sign Up Now.

Log in to your account on the IVPN website.

IVPN website login

DD-WRT Router Setup for IVPN WireGuard

Navigate to Setup > Tunnels 

Enter IVPN WireGuard settings

1. Click Add Tunnel.

2. Set Tunnel to Enable.

Setup - Tunnel - Enable Tunnel

3. Select Wireguard from the dropdown.

Setup - Tunnel - Select Wireguard

3. Set MTU to 1412.

IVPN Wireguard MTU setting

4. Click Generate Key.

Setup - Tunnel - Generate Key

9. Copy the Local Public Key.

IVPN Wireguard Local Public Key

10. In a new tab (leave the DD-WRT settings opened), go to your IVPN Account and click WireGuard and then click WireGuard Key Management.

IVPN Wireguard Key Management

11. Click Add New Key.

IVPN Wireguard Add New Key

12. Paste the copied Local Public key to the Public Key field and click Add Key.

IVPN Wireguard Paste Public Key

13.Copy the IP Address assigned to your public key and add it to the IP Addresses/Netmask(CIDR) field followed by a /32 subnet mask.

IVPN Wireguard copy IP Address
IVPN Wireguard paste IP Address

Certain DD-WRT builds will show two separate fields here: IP Address and Subnet Mask. If that is the case set the IP Address field to the Address without the /32 added and set the Subnet Mask to 255.255.255.255

14. Click Add Peer.

Setup - Tunnel - Add Peer

15. Set the Peer Tunnel IP to 0.0.0.0. Set Peer Tunnel DNS to 172.16.0.1

IVPN Wireguard Peer Tunnel IP and DNS

16. Set Endpoint to Enable.

IVPN Wireguard Enable Endpoint

17. Go to the IVPN Server Status page and copy the server name for the WireGuard server location you want to connect to.

IVPN Wireguard Endpoint server

Be sure to copy the WireGuard server address and not the OpenVPN server address.

18. Paste the server name you copied into the Endpoint Address field and set the Port to 2049.

IVPN Wireguard Endpoint Address

19. On the IVPN Server Status page copy the Public Key of the server location you entered. Paste the Public Key into the Peer Public Key field.

IVPN Wireguard copy server Public Key
IVPN Wireguard enter Peer Public Key

20. Leave Allowed IPs as 0.0.0.0/0. Set Router Allowed IP’s via tunnel to Enable. Set Persistent Keep Alive to 25.

IVPN Wireguard Peer settings

21. At the bottom of the page click Save and then click Apply Settings.

Set IVPN DNS servers

Navigate to Setup > Basic Setup

Set Static DNS 1 to 172.16.0.1

Set Static DNS 2 to 198.245.51.147

IVPN Wireguard Static DNS

Click Apply Settings.

Reboot the FlashRouter

Navigate to Administration > Management

Scroll to the bottom of the page and click the red Reboot Router button. Wait for the FlashRouter to reboot and then reconnect.

Verify a successful IVPN connection

Navigate to Setup > Tunnels

  1. You should Endpoint, Latest handshake, and Transfer in the WireGuard status area.
  2. Visit IVPN’s website to verify your status as using IVPN.

Back up your settings

Navigate to Administration > Backup

  1. Click the Backup button.
  2. A file named nvrambak.bin will be saved to your computer.
  3. You can load nvrambak.bin to restore your settings in the event of a reset.

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

Mullvad WireGuard Setup

TeamFlashRouters · Aug 19, 2021 ·

Preparing for Mullvad WireGuard Setup

Verify your Mullvad login information

If you are not already a Mullvad user Sign Up Now.

Log in to your account on the Mullvad website.

Mullvad Login

Select Manage ports and WireGuard Keys displayed on the account page.

Mullvad Manage ports and WireGuard Keys

DD-WRT Router Setup for Mullvad WireGuard

Navigate to Setup > Tunnels 

Enter Mullvad WireGuard settings

1. Click Add Tunnel.

2. Set Tunnel to Enable.

Setup - Tunnel - Enable Tunnel

3. Select Wireguard from the dropdown.

Setup - Tunnel - Select Wireguard

4. Click Add Peer.

Setup - Tunnel - Add Peer

5. Set Endpoint to Enable.

Setup - Tunnel - Enable Endpoint

6. Set Router Allowed IP’s via tunnel and Use Pre-shared Key to Disable.

Setup - Tunnel - Disable Preshare Key and Allow IP

7. Click Generate Key.

Setup - Tunnel - Generate Key

8. Set Advanced Settings to Enable.

Setup - Tunnel - Enable Advanced Settings

9. Copy the Local Private Key.

Setup - Tunnel - Copy Local Private Key

10. In a new tab (leave the DD-WRT settings opened), go to your Mullvad Account and click Manage Ports and WireGuard Keys.

Mullvad Account - Manage ports and Wireguard Keys

11. Click WireGuard configuration file.

Mullvad - Wireguard configuration file

12. Select Linux as your Platform.

Mullvad - Select Linux

13. Click Manage Keys.

Mullvad - Manage Keys

14. Paste the copied Local Private key to the Manage WireGuard Keys field and click Import Keys.

Mullvad - Import Key

15. Select your Country, City, and Server number that you want to connect to.

Mullvad - Select Location

16. Click Advanced Settings.

Mullvad - Advanced Settings

17. Set the Tunnel Traffic to Only IPv4.

Mullvad - Only IPv4

18. Click Download File.

Mullvad - Download Config

19. Open the config file that was downloaded to your computer with NotePad or Notepad++ for Windows or TextEdit for Mac.

20. In the downloaded config file under [Interface] enter the Address into the IP Addresses/Netmask(CIDR) field in the DD-WRT settings.

Config File - Copy IP Address
Setup - Tunnel - IP Address Netmask Note

Certain DD-WRT builds will show two separate fields here: IP Address and Subnet Mask. If that is the case set the IP Address field to the Address without the /32 added and set the Subnet Mask to 255.255.255.255

21. In the config file under [Peer] copy the PublicKey and paste it into the Peer Public Key field in the DD-WRT Settings.

Config File - Copy PublicKey
Setup - Tunnel - Paste Public Key

22. In the config file under [Peer] copy the Endpoint and paste it into the Endpoint Address field.

Config File - Endpoint
Setup - Tunnel - Endpoint Address

23. At the bottom of the page click Save and then click Apply Settings.

Enter Mullvad WireGuard Commands

Navigate to Administration > Commands

1. Copy and paste the text below and click Save Startup.

sleep 30
echo "Update route table on startup..."
WGSERVER=$(/usr/sbin/nvram get oet1_rem0)
WANGW=$(/usr/sbin/nvram get wan_gateway)
WANIF=$(/usr/sbin/nvram get wan_iface)
route add -host $WGSERVER gw $WANGW dev $WANIF
route del default
route add default dev oet1
ip route flush cache
mkdir -p /tmp/etc/config
ln -s /tmp/custom.sh /tmp/etc/config/wg-route-fix.wanup
echo "... Done route table update."

2. Copy and paste the text below and click Save Custom.

#!/bin/sh
sleep 5
echo "Update route table on wanup ..."
WGSERVER=$(/usr/sbin/nvram get oet1_rem0)
WANGW=$(/usr/sbin/nvram get wan_gateway)
WANIF=$(/usr/sbin/nvram get wan_iface)
route add -host $WGSERVER gw $WANGW dev $WANIF
route del default
route add default dev oet1
ip route flush cache
echo "... Done route table update."

3. Copy and paste the text below and click Save Firewall.

WANIF=$(/usr/sbin/nvram get wan_iface)
iptables -t nat -I POSTROUTING -o oet1 -j MASQUERADE
iptables -I FORWARD -i br0 -o $WANIF -m state –state NEW -j REJECT –reject-with icmp-host-prohibited
iptables -I FORWARD -i br0 -p tcp -o $WANIF -m state –state NEW -j REJECT –reject-with tcp-reset

Set Mullvad DNS servers

Navigate to Setup > Basic Setup

Set Static DNS 1 to 10.64.0.1

Set Static DNS 2 to 193.138.218.74

Setup - Basic Setup - Mullvad DNS

Click Apply Settings.

Reboot the FlashRouter

Navigate to Administration > Management

Scroll to the bottom of the page and click the red Reboot Router button. Wait for the FlashRouter to reboot and then reconnect.

Verify a successful Mullvad connection

Navigate to Setup > Tunnels

  1. You should see Endpoint, Latest handshake, and Transfer in the WireGuard status area.
  2. Visit Mullvad’s IP Check to verify your status as using Mullvad.

Back up your settings

Navigate to Administration > Backup

  1. Click the Backup button.
  2. A file named nvrambak.bin will be saved to your computer.
  3. You can load nvrambak.bin to restore your settings in the event of a reset.

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

NordVPN Merlin OpenVPN Setup

TeamFlashRouters · Jan 11, 2023 ·

Preparing for NordVPN Merlin Setup

Obtain your NordVPN manual Username and Password

If you are not already an NordVPN user Sign Up Now.

1. Log in to your account on the NordVPN website.

NordVPN login

2. Click NordVPN on the left hand side and then click Setup NordVPN manually.

NordVPN setup manually

3. Enter in the verification code that was sent to your email.

NordVPN verify code

4. Copy and paste your NordVPN manual username and password to a secure location. This is the username and password you will enter into the router settings to connect to NordVPN.

NordVPN credentials

Download your NordVPN .ovpn file

1. There are two options for obtaining the .ovpn file. The first and recommended is to navigate to NordVPN’s server recommendation page. Click Recommended Server to display the fastest server based on your actual location. You can adjust the country if you don’t want to connect to the recommended country.

Then click Show Available Protocols. Click Download Config next to OpenVPN UDP. This will download the .ovpn file to your computer for this server. Do not open this file.

NordVPN Recommended Server

The second method to obtain a server is for connecting to a specific server number that you know you want to use. This applies to NordVPN Dedicated IP servers if you are signed up for that service. Go to NordVPN’s .ovpn file page. Then search for the server number that you want to use and click Download UDP.

NordVPN Download Specific Server

Merlin Router Setup for NordVPN

Login to Asus Merlin firmware settings in a browser on any computer or smart device connected to the Merlin FlashRouter’s network.

1. Navigate to the VPN tab.

Merlin VPN Tab

2. Navigate to the VPN Client tab.

Merlin VPN Client Tab

3. Click Choose file and select the .ovpn file you downloaded earlier. Then click Upload.

Merlin Choose File Upload

4. Set Automatic Start at boot time to Yes if you want the VPN connection to begin automatically when the router is powered off and back on.

Merlin Automatic Start at boot time

5. In the Description field enter in the name you’d like to use for this OpenVPN Client profile. We typically advise entering in the location or server number here. Our example server was in us5835.nordvpn.com so I have entered in NordVPN us5835.

Merlin NordVPN Description

6. Set Accept DNS Configuration to Strict. Set Redirect Internet traffic through tunnel to Yes (all). Set Kill Switch to Yes or No depending on if you want the Internet to be killed if the VPN connection drops.

Merlin Accept DNS configuration Redirect Internet and Kill Switch

If you only want certain devices to connect to the OpenVPN Client profile you are setting up instead of all the devices connected to the FlashRouter’s network please set the Redirect Internet traffic through tunnel to VPN Director. Then complete the instructions on this page and then view our VPN Director guide.

7. Enter your NordVPN username and password that you obtained earlier in the Username and Password. Note that these are different from your NordVPN email login and password.

Merlin VPN Username and Password

8. Click Apply at the bottom of the page.

9. At the top of the page set the Service State toggle to ON to activate the VPN connection.

Merlin Service State All Providers

Verify a successful NordVPN connection

  1. You should now see a CONNECTED message.
  2. Visit NordVPN’s IP Check to verify your new IP address and virtual location.

In some cases you may notice that the location is not showing the same location as the server you have input in your router settings; this is because geo tracking tools are often tricked by VPN connections. As long as you see an IP address that is not the same as your normal Internet IP address then you are indeed connected to NordVPN.

How to change the NordVPN server

  1. Follow the steps at the top of the page to obtain a new .ovpn file.
  2. Then proceed with the settings same as initial setup.

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

ExpressVPN Merlin OpenVPN Setup

TeamFlashRouters · Jan 11, 2023 ·

Preparing for ExpressVPN Merlin Setup

Obtain your ExpressVPN OpenVPN Information

If you are not already an ExpressVPN user Sign Up Now.

1. Log in to your account on the ExpressVPN website.

ExpressVPN login page

2. Successfully log in with your account information. Select More.

3. Select Manual Configuration and copy the Username and Password that are displayed on the right hand side of the screen.

ExpressVPN Manual Configuration
ExpressVPN username and password

4. Click the Server Location that you want to connect to. This will download a .ovpn file to your computer that we will use later on. There is no need to open the file. For this example I have selected New York but feel free to select any server listed there.

ExpressVPN Download .ovpn file

Merlin Router Setup for ExpressVPN

Login to Asus Merlin firmware settings in a browser on any computer or smart device connected to the Merlin FlashRouter’s network.

1. Navigate to the VPN tab.

Merlin VPN Tab

2. Navigate to the VPN Client tab.

Merlin VPN Client Tab

3. Click Choose file and select the .ovpn file you downloaded earlier. Then click Upload.

Merlin Choose File Upload

4. Set Automatic Start at boot time to Yes if you want the VPN connection to begin automatically when the router is powered off and back on.

Merlin Automatic Start at boot time

5. In the Description field enter in the name you’d like to use for this OpenVPN Client profile. We typically advise entering in the location or server number here. Our example server was in New York so I have entered in ExpressVPN New York.

Merlin ExpressVPN Description

6. Set Accept DNS Configuration to Strict. Set Redirect Internet traffic through tunnel to Yes (all). Set Kill Switch to Yes or No depending on if you want the Internet to be killed if the VPN connection drops.

Merlin Accept DNS configuration Redirect Internet and Kill Switch

If you only want certain devices to connect to the OpenVPN Client profile you are setting up instead of all the devices connected to the FlashRouter’s network please set the Redirect Internet traffic through tunnel to VPN Director. Then complete the instructions on this page and then view our VPN Director guide.

7. Enter your ExpressVPN username and password that you obtained earlier in the Username and Password. Note that these are different from your ExpressVPN email login and password.

Merlin VPN Username and Password

8. Click Apply at the bottom of the page.

9. At the top of the page set the Service State toggle to ON to activate the VPN connection.

Merlin Service State

Verify a successful ExpressVPN connection

  1. You should now see a CONNECTED message.
  2. Visit ExpressVPN’s IP Check to verify your new IP address and virtual location.

In some cases you may notice that the location is not showing the same location as the server you have input in your router settings; this is because geo tracking tools are often tricked by VPN connections. As long as you see an IP address that is not the same as your normal Internet IP address then you are indeed connected to ExpressVPN.

How to change the ExpressVPN server

  1. Copy the new ExpressVPN server address from the below server list.
  2. Paste the server into the Server Address field.
  3. Click Apply at the bottom of the page.

ExpressVPN Server Addresses

Americas

usa-atlanta-ca-version-2.expressnetw.com
usa-boston-ca-version-2.expressnetw.com
usa-chicago-ca-version-2.expressnetw.com
usa-dallas-ca-version-2.expressnetw.com
usa-dallas-2-ca-version-2.expressnetw.com
usa-denver-ca-version-2.expressnetw.com
usa-kansascity-ca-version-2.expressnetw.com
usa-losangeles-ca-version-2.expressnetw.com
usa-losangeles-1-ca-version-2.expressnetw.com
usa-losangeles-2-ca-version-2.expressnetw.com
usa-losangeles-3-ca-version-2.expressnetw.com
usa-los-angeles-4-ca-version-2.expressnetw.com
usa-miami-ca-version-2.expressnetw.com
usa-miami-2-ca-version-2.expressnetw.com
usa-minneapolis-ca-version-2.expressnetw.com
usa-newjersey-1-ca-version-2.expressnetw.com
usa-newjersey-3-ca-version-2.expressnetw.com
usa-newyork-ca-version-2.expressnetw.com
us-new-york-2-ca-version-2.expressnetw.com
usa-phoenix-ca-version-2.expressnetw.com
usa-saltlakecity-ca-version-2.expressnetw.com
usa-sanfrancisco-ca-version-2.expressnetw.com
usa-sanjose-ca-version-2.expressnetw.com
usa-seattle-ca-version-2.expressnetw.com
usa-tampa-1-ca-version-2.expressnetw.com
usa-virginia-ca-version-2.expressnetw.com
usa-washingtondc-ca-version-2.expressnetw.com
usa-washingtondc-2-ca-version-2.expressnetw.com
canada-montreal-ca-version-2.expressnetw.com
canada-toronto-ca-version-2.expressnetw.com
canada-toronto-2-ca-version-2.expressnetw.com
canada-vancouver-ca-version-2.expressnetw.com
mexico-ca-version-2.expressnetw.com
argentina-ca-version-2.expressnetw.com
brazil-ca-version-2.expressnetw.com
brazil-2-ca-version-2.expressnetw.com
chile-ca-version-2.expressnetw.com
colombia-ca-version-2.expressnetw.com
costarica-ca-version-2.expressnetw.com
ecuador-ca-version-2.expressnetw.com
guatemala-ca-version-2.expressnetw.com
panama-ca-version-2.expressnetw.com
peru-ca-version-2.expressnetw.com
uruguay-ca-version-2.expressnetw.com
venezuela-ca-version-2.expressnetw.com

Europe

uk-berkshire-ca-version-2.expressnetw.com
uk-berkshire-2-ca-version-2.expressnetw.com
uk-docklands-ca-version-2.expressnetw.com
uk-east-london-ca-version-2.expressnetw.com
uk-kent-ca-version-2.expressnetw.com
uk-london-ca-version-2.expressnetw.com
france-paris-1-ca-version-2.expressnetw.com
france-paris-2-ca-version-2.expressnetw.com
france-strasbourg-ca-version-2.expressnetw.com
germany-darmstadt-ca-version-2.expressnetw.com
germany-frankfurt-1-ca-version-2.expressnetw.com
germany-frankfurt-2-ca-version-2.expressnetw.com
germany-nuremberg-ca-version-2.expressnetw.com
italy-cosenza-ca-version-2.expressnetw.com
italy-milan-ca-version-2.expressnetw.com
netherlands-amsterdam-ca-version-2.expressnetw.com
netherlands-rotterdam-ca-version-2.expressnetw.com
netherlands-thehague-ca-version-2.expressnetw.com
spain-barcelona-ca-version-2.expressnetw.com
spain-ca-version-2.expressnetw.com
sweden-ca-version-2.expressnetw.com
sweden-2-ca-version-2.expressnetw.com
switzerland-ca-version-2.expressnetw.com
switzerland-2-ca-version-2.expressnetw.com
albania-ca-version-2.expressnetw.com
andorra-ca-version-2.expressnetw.com
armenia-ca-version-2.expressnetw.com
austria-ca-version-2.expressnetw.com
azerbaijan-ca-version-2.expressnetw.com
belarus-ca-version-2.expressnetw.com
belgium-ca-version-2.expressnetw.com
bosniaandherzegovina-ca-version-2.expressnetw.com
bulgaria-ca-version-2.expressnetw.com
croatia-ca-version-2.expressnetw.com
cyprus-ca-version-2.expressnetw.com
czechrepublic-ca-version-2.expressnetw.com
denmark-ca-version-2.expressnetw.com
estonia-ca-version-2.expressnetw.com
finland-ca-version-2.expressnetw.com
georgia-ca-version-2.expressnetw.com
greece-ca-version-2.expressnetw.com
hungary-ca-version-2.expressnetw.com
iceland-ca-version-2.expressnetw.com
ireland-ca-version-2.expressnetw.com
isleofman-ca-version-2.expressnetw.com
jersey-ca-version-2.expressnetw.com
latvia-ca-version-2.expressnetw.com
liechtenstein-ca-version-2.expressnetw.com
lithuania-ca-version-2.expressnetw.com
luxembourg-ca-version-2.expressnetw.com
macedonia-ca-version-2.expressnetw.com
malta-ca-version-2.expressnetw.com
moldova-ca-version-2.expressnetw.com
monaco-ca-version-2.expressnetw.com
montenegro-ca-version-2.expressnetw.com
norway-ca-version-2.expressnetw.com
poland-ca-version-2.expressnetw.com
portugal-ca-version-2.expressnetw.com
romania-ca-version-2.expressnetw.com
serbia-ca-version-2.expressnetw.com
slovakia-ca-version-2.expressnetw.com
slovenia-ca-version-2.expressnetw.com
ukraine-ca-version-2.expressnetw.com

Asia Pacific

australia-brisbane-ca-version-2.expressnetw.com
australia-melbourne-ca-version-2.expressnetw.com
australia-perth-ca-version-2.expressnetw.com
australia-sydney-ca-version-2.expressnetw.com
australia-sydney-2-ca-version-2.expressnetw.com
australia-sydney-3-ca-version-2.expressnetw.com
hongkong-2-ca-version-2.expressnetw.com
hongkong4-ca-version-2.expressnetw.com
hongkong-1-ca-version-2.expressnetw.com
japan-tokyo-1-ca-version-2.expressnetw.com
japan-tokyo-2-ca-version-2.expressnetw.com
india-chennai-ca-version-2.expressnetw.com
india-mumbai-1-ca-version-2.expressnetw.com
singapore-cbd-ca-version-2.expressnetw.com
singapore-jurong-ca-version-2.expressnetw.com
southkorea-ca-version-2.expressnetw.com
southkorea2-ca-version-2.expressnetw.com
bangladesh-ca-version-2.expressnetw.com
bhutan-ca-version-2.expressnetw.com
brunei-ca-version-2.expressnetw.com
cambodia-ca-version-2.expressnetw.com
indonesia-ca-version-2.expressnetw.com
kazakhstan-ca-version-2.expressnetw.com
kyrgyzstan-ca-version-2.expressnetw.com
laos-ca-version-2.expressnetw.com
macau-ca-version-2.expressnetw.com
malaysia-ca-version-2.expressnetw.com
mongolia-ca-version-2.expressnetw.com
myanmar-ca-version-2.expressnetw.com
nepal-ca-version-2.expressnetw.com
newzealand-ca-version-2.expressnetw.com
pakistan-ca-version-2.expressnetw.com
ph-via-sing-ca-version-2.expressnetw.com
srilanka-ca-version-2.expressnetw.com
taiwan-3-ca-version-2.expressnetw.com
thailand-ca-version-2.expressnetw.com
vietnam-ca-version-2.expressnetw.com

Middle East and Africa

algeria-ca-version-2.expressnetw.com
israel-ca-version-2.expressnetw.com
kenya-ca-version-2.expressnetw.com
southafrica-ca-version-2.expressnetw.com

Merlin ExpressVPN change server location

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

Wireless Guest Network Setup – Bridged (Advanced)

TeamFlashRouters · Jun 12, 2019 ·

If you would like to prevent visitors from connecting to your main WiFi network then you can create a Bridged Guest Network that will prevent access to the main router. This setup also allows you to create different rules for different WiFi SSID’s in your home ranging from QoS controls, access restrictions, VPN network segmentation, and more.

Preparing for Wireless Guest Network Setup

If you have a Dual-band or Tri-Band router you can setup a WiFi Guest Network, creating a separate VLAN (virtual local area network) for your visitors, or in order to segment your VPN networks on any band you like. We recommend using the 2.4GHz network for your DD-WRT Guest Wireless Network so it is compatible with the most possible WiFi devices. Setting up a guest network for visitors in your home allows you to keep them off of your main WiFi network.

We recommend performing this setup while connected to the FlashRouter via ethernet cable. If your computer does not have an ethernet port and you must proceed via wireless connection to the FlashRouter pay attention to the wireless connection as you may need to rejoin the FlashRouter’s network after making changes.

DD-WRT Router Setup for Wireless Guest Network

Enter Wireless settings

Navigate to Wireless > Basic Settings

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Setting SSID for Guest Network
  1. Under the 2.4GHz or 5GHz Interface click the Add button.
  2. In the Wireless Network Name (SSID) field enter the unique network name of the guest network.
  3. Click Save.

Enter Wireless Security settings

Navigate to Wireless > Wireless Security

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Setting Guest Network Wireless Password
  1. Duplicate the wireless security settings that are set for the other bands for the newly created virtual interface.
  2. Click Apply Settings.
  3. Reboot your router.

Create Bridge

Navigate to Setup > Networking

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Create Bridge
  1. Under Create Bridge click Add. Name the newly created bridge br1.
  2. Click Apply Settings

Assign to Bridge

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Assign Bridge
  1. Under Assign to Bridge select br1 from the Assignment dropdown. Select wl1.1 or ath1.1 depending on your router model.
  2. Click Apply Settings.

Depending on the router model and WiFi band you are using, the wireless interfaces will be labelled differently.

This setting can be labelled wl1.1, ath0.1, wl2.1, and so on. Make sure when you get up to the bridge assignment section that you are using the correct guest network Virtual Interface.

Network Configuration br1

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Configure Bridge DNS Redirection
  1. Under Network Configuration br1 select Enable for Forced DNS Redirection.
  2. Set Optional DNS Target to 208.67.220.220
  3. Set IP Address to 192.168.12.1
  4. Set Subnet Mask to 255.255.255.0
  5. Click Apply Settings.

Multiple DHCP Server

Bridged Wireless Guest Network Setup on DD-WRT FlashRouter – Configure DHCP Server Settings
  1. Under Multiple DHCP Server click Add.
  2. Set the first dropdown to br1.
  3. Click Apply Settings.
  4. Reboot your router.

Firewall Rules

Navigate to Administration > Commands

  1. Copy the fire script from below and paste into the empty Commands shell
  2. Click Save Firewall.
  3. Wait one minute and then reboot your router.

iptables -I FORWARD -i br1 -o br0 -m state –state NEW -j DROP
iptables -I FORWARD -i br0 -o br1 -m state –state NEW -j DROP
iptables -I INPUT -i br1 -p tcp –dport telnet -j REJECT –reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp –dport ssh -j REJECT –reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp –dport www -j REJECT –reject-with tcp-reset
iptables -I INPUT -i br1 -p tcp –dport https -j REJECT –reject-with tcp-reset

You will now have a working Bridged Guest Network on the FlashRouter. By inputting the firewall rules, this will also prevent any guests on your network from gaining access to your router settings.

Back up your settings

Navigate to Administration > Backup

  1. Click the Backup button.
  2. A file named nvrambak.bin will be saved to your computer.
  3. You can load nvrambak.bin to restore your settings in the event of a reset.

TROUBLESHOOTING

Still having issues? Visit our Troubleshooting section to diagnose common problems here.

Troubleshoot Here

PrivateInternetAccess (PIA) Merlin OpenVPN Setup

TeamFlashRouters · Jan 11, 2023 ·

Preparing for PIA Merlin Setup

Download your PIA .ovpn file

If you are not already a PIA user Sign Up Now.

1. Log in to your account on the PIA website.

PIA login

2. Successfully log in with your account information then go to PIA’s OpenVPN Config Generator.

3. On the OpenVPN Configuration Generator select the following:

OpenVPN Version: OpenVPN 2.4 or newer

Select Platform: Linux

Select Region: Choose the server location you’d like to connect to

Select Port: Typically we recommend UDP/1198 RSA-2048 AES-128-CBC SHA1 for best speeds but feel free to select the one you want to use.

4. Click Generate to download the .ovpn file. Do not open this file once it is downloaded.

PIA Generate .ovpn file

Merlin Router Setup for PIA

Login to Asus Merlin firmware settings in a browser on any computer or smart device connected to the Merlin FlashRouter’s network.

1. Navigate to the VPN tab.

Merlin VPN Tab

2. Navigate to the VPN Client tab.

Merlin VPN Client Tab

3. Click Choose file and select the .ovpn file you downloaded earlier. Then click Upload.

Merlin Choose File Upload

4. Set Automatic Start at boot time to Yes if you want the VPN connection to begin automatically when the router is powered off and back on.

Merlin Automatic Start at boot time

5. In the Description field enter in the name you’d like to use for this OpenVPN Client profile. We typically advise entering in the location here. Our example server was in US East Streaming so I have entered in PIA US East Streaming.

PIA Description

6. Set Accept DNS Configuration to Strict. Set Redirect Internet traffic through tunnel to Yes (all). Set Kill Switch to Yes or No depending on if you want the Internet to be killed if the VPN connection drops.

Merlin Accept DNS configuration Redirect Internet and Kill Switch

If you only want certain devices to connect to the OpenVPN Client profile you are setting up instead of all the devices connected to the FlashRouter’s network please set the Redirect Internet traffic through tunnel to VPN Director. Then complete the instructions on this page and then view our VPN Director guide.

7. Enter your PIA account username and password.

Merlin VPN Username and Password

8. Click Apply at the bottom of the page.

9. At the top of the page set the Service State toggle to ON to activate the VPN connection.

Merlin Service State All Providers

Verify a successful PIA connection

  1. You should now see a CONNECTED message.
  2. Visit PIA’s IP Check to verify your new IP address and virtual location.

In some cases you may notice that the location is not showing the same location as the server you have input in your router settings; this is because geo tracking tools are often tricked by VPN connections. As long as you see an IP address that is not the same as your normal Internet IP address then you are indeed connected to PIA.

How to change the PIA server

  1. Follow the steps at the top of the page to obtain a new .ovpn file.
  2. Then proceed with the settings same as initial setup.

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

IPVanish Merlin OpenVPN Setup

TeamFlashRouters · Jan 11, 2023 ·

Preparing for IPVanish Merlin Setup

Download your IPVanish .ovpn file

If you are not already an IPVanish user Sign Up Now.

1. Log in to your account on the IPVanish website.

IPVanish login

2. Successfully log in with your account information then go to IPVanish .ovpn file page.

3. Click on the .ovpn file for the server location you want to use to dowloand the .ovpn file. Do not open this file.

IPVanish download ovpn

Merlin Router Setup for IPVanish

Login to Asus Merlin firmware settings in a browser on any computer or smart device connected to the Merlin FlashRouter’s network.

1. Navigate to the VPN tab.

Merlin VPN Tab

2. Navigate to the VPN Client tab.

Merlin VPN Client Tab

3. Click Choose file and select the .ovpn file you downloaded earlier. Then click Upload.

Merlin Choose File Upload

4. Set Automatic Start at boot time to Yes if you want the VPN connection to begin automatically when the router is powered off and back on.

Merlin Automatic Start at boot time

5. In the Description field enter in the name you’d like to use for this OpenVPN Client profile. We typically advise entering in the location here. Our example server was in nyc-a50 so I have entered in IPVanish a-50.

IPVanish Description

6. Set Accept DNS Configuration to Strict. Set Redirect Internet traffic through tunnel to Yes (all). Set Kill Switch to Yes or No depending on if you want the Internet to be killed if the VPN connection drops.

Merlin Accept DNS configuration Redirect Internet and Kill Switch

If you only want certain devices to connect to the OpenVPN Client profile you are setting up instead of all the devices connected to the FlashRouter’s network please set the Redirect Internet traffic through tunnel to VPN Director. Then complete the instructions on this page and then view our VPN Director guide.

7. Enter your IPVanish account email/username and password.

Merlin VPN Username and Password

8. Click Apply at the bottom of the page.

9. At the top of the page set the Service State toggle to ON to activate the VPN connection.

Merlin Service State All Providers

Verify a successful IPVanish connection

  1. You should now see a CONNECTED message.
  2. Visit IPVanish’s IP Check to verify your new IP address and virtual location.

In some cases you may notice that the location is not showing the same location as the server you have input in your router settings; this is because geo tracking tools are often tricked by VPN connections. As long as you see an IP address that is not the same as your normal Internet IP address then you are indeed connected to IPVanish.

How to change the IPVanish server

  1. Follow the steps at the top of the page to obtain a new .ovpn file.
  2. Then proceed with the settings same as initial setup.

TROUBLESHOOTING

Still having issues? Visit the VPN Troubleshooting section.

Troubleshoot Here

CyberGhost Merlin OpenVPN Setup

TeamFlashRouters · Mar 30, 2023 ·

Preparing for CyberGhost Setup

Obtain your CyberGhost OpenVPN information

If you are not already a CyberGhost user Sign Up Now.

1. Log in to your account on the CyberGhost website.

CyberGhost Website Login

2. Select VPN.

CyberGhost VPN

3. Click Configure New Device.

CyberGhost Configure Device

4. Set Protocol to OpenVPN. Select the Country you would like to connect to. Select the Server Group. Name the device in the Device Name field. Click Save Configuration.

CyberGhost protocol and location

5. Press View configuration.

CyberGhost view configuration

6. Copy the Username, and Password that appear to a notepad, since you will need this information later in the setup process. Click Download Configuration.

CyberGhost Website OpenVPN Configuration Files Generator 1

Open the folder that was downloaded. Then open the ca.crt the client.crt, and client.key files with NotePad++ for Windows or TextEdit for Apple. All CyberGhost servers have different keys and certificates.

Merlin Router Setup for CyberGhost

Login to Asus Merlin firmware settings in a browser on any computer or smart device connected to the Merlin FlashRouter’s network.

1. Navigate to the VPN tab.

Merlin VPN Tab

2. Navigate to the VPN Client tab.

Merlin VPN Client Tab

3. Click Choose file and select the .ovpn file from the folder you downloaded earlier. Then click Upload.

Merlin Choose File Upload

4. Set Automatic Start at boot time to Yes if you want the VPN connection to begin automatically when the router is powered off and back on.

Merlin Automatic Start at boot time

5. In the Description field enter in the name you’d like to use for this OpenVPN Client profile. We typically advise entering in the location here. Our example server was in USA so I have entered in CyberGhost USA.

Merlin CyberGhost Description field

6. Set Accept DNS Configuration to Strict. Set Redirect Internet traffic through tunnel to Yes (all). Set Kill Switch to Yes or No depending on if you want the Internet to be killed if the VPN connection drops.

Merlin Accept DNS configuration Redirect Internet and Kill Switch

If you only want certain devices to connect to the OpenVPN Client profile you are setting up instead of all the devices connected to the FlashRouter’s network please set the Redirect Internet traffic through tunnel to VPN Director. Then complete the instructions on this page and then view our VPN Director guide.

7. Enter your CyberGhost OpenVPN username and password that you obtained earlier. Do not enter your account login.

Merlin VPN Username and Password

8. Click the Edit button in the Keys and Certificates area.

Merlin Keys and Certificates Edit button

9. In the Certificate Authority field paste in the entire content of the ca.crt file.

—– BEGIN xxx —– / —– END xxx —– block (including those two lines).

Merlin Certificate Authority

10. In the Client Certificate field paste in the entire content of the client.crt file.

—– BEGIN xxx —– / —– END xxx —– block (including those two lines).

Merlin Client Certificate

11. In the Client Key field paste in the entire content of the client.key file.

—– BEGIN xxx —– / —– END xxx —– block (including those two lines).

Merlin Client Key

12. Click Save at the bottom of that window.

13. Click Apply at the bottom of the page.

14. At the top of the page set the Service State toggle to ON to activate the VPN connection.

Merlin Service State All Providers

Verify a successful CyberGhost connection

  1. You should now see a CONNECTED message.
  2. Visit What is my IP Address from a private/incognito browser to verify your new IP address and virtual location.

TROUBLESHOOTING

Still having issues? Visit the FR Privacy App Troubleshooting section.

Troubleshoot Here

Primary Sidebar

  • Troubleshooting
  • Router Access
  • Internet Connection Issues
  • WiFi Connectivity
  • General VPN Issues
  • TeamViewer Remote Support
  • DD-WRT Firmware
  • Facebook
  • Twitter
  • Instagram
  • Pinterest
  • YouTube

Footer