Asus (Asuswrt-Merlin)
Merlin firmware, Entware, installation and specifics of Asus routers.
Requirements
Section titled “Requirements”- Asuswrt-Merlin on a Broadcom model. The stock firmware runs no user scripts: the rules are then restored only by the watcher, within 15 seconds after every restart of the firewall.
- Architectures:
arm64(RT-AX86U, RT-AX88U, GT-AX6000 and other HND models) andarmv7(RT-AX58U, RT-AC68U and others). Models without an FPU, like RT-AC68U, get thearmv5build of the core. - Entware on an ext4 USB drive and about 70 MB free on it: the Mihomo core is about 40 MB, yq about 15 MB.
- Other proxies (XRAYUI and similar) stopped and removed from autostart, see migrating.
- UDP through the proxy needs the TPROXY module of the firmware. Without it UDP goes directly and TCP through Redirect, the Exodus log tells about it.
Preparation
Section titled “Preparation”-
Firmware. Check the model in the list of supported devices, download the firmware from asuswrt-merlin.net and flash it on Administration → Firmware Upgrade by the official guide.
-
SSH. Administration → System → Enable SSH: LAN only.
-
JFFS. Enable JFFS custom scripts and configs (Administration → System) must be on. When it is off, the installer turns it on.
-
Entware. Plug in an ext4 USB drive, log in over SSH, run
amtmand install Entware withep. More in the Merlin wiki: amtm and Entware.
Install & update
Section titled “Install & update”In the SSH console of the router:
curl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/asuswrt/install.sh | shThe installer installs curl jq ca-bundle lighttpd lighttpd-mod-cgi from Entware; iptables, ipset and openssl are of the firmware, iptables and ipset match its kernel. At the end it prints the address of the web UI, http://192.168.50.1:9099/ with the default address of the router.
To update, run the same command or use the Updates page of the web UI. Installer options are on the Installer options page.
Asus specifics
Section titled “Asus specifics”- The firmware restores its iptables tables without third-party rules on every restart of the firewall: a reconnect of the WAN, a change in the web interface. The installer adds a line marked
# exodusto/jffs/scripts/firewall-startand/jffs/scripts/nat-startright after the shebang, the lines of other scripts are kept. The watcher checks the rules every 15 seconds too. /jffs/scripts/unmountstops the proxy before its USB drive is unmounted: the rules must not stay without the core.- Wi-Fi networks are the radios (
wl0,wl1,wl2) and the guest networks (wl0.1and others): the devices connected to them on this router, fromwl assoclist, synced every 30 seconds. Clients of AiMesh nodes are not seen. Device names come from the client list of the router (custom_clientlist), DHCP and its network map. - The proxied traffic goes to the router itself, past the filtering of forwarded traffic. With Respect parental control it is checked by the parental control chain of the firmware (
PControls): blocked devices and time scheduling apply to it too. Content filters of AiProtection do not see inside the proxied traffic. router.asus.com,www.asusrouter.comandwww.asusnetwork.netresolve to the router, names of the local domain are asked from the router.- The route table of TPROXY is 7892: tables 111–115 belong to the VPN clients of Merlin.
Uninstall
Section titled “Uninstall”curl -fsSL https://raw.githubusercontent.com/prettyleaf/openwrt-exodus/asuswrt/uninstall.sh | shThe lines of Exodus are removed from /jffs/scripts, the lines of other scripts are kept. With KEEP_CONFIG=1 before sh the settings, profiles and subscriptions in /opt/etc/exodus are kept. Entware packages are not removed.