    I can't speak for lets Encrypt but for me since the cert doesn't expire until 2028 renewal is not really important.

    90% sure though it will renew.
    Hi, i need some help with download master, i am facing issues with the same, righ now i am running 384.8_2 and i have attached a 1TB seagate HDD (NTFS) to it. I was able to install Download master and run it for couple of days, but of late i am not able to use it, get error "can’t establish a connection to the server at"
    what could be wrong,
    It does have a few issues that's why I never upgraded to it. Will wait to see what 384.10 brings when released.

    Which build u on?
    You are using a fan to cool your system, right?

    Annotation 2019-03-08 173348.jpg
    Possible that he has a fan. I have 2° more without fan and without overclocking.
    The R7000 is on a pad for notebooks, but I only put the fan on when the room temp becomes too high in summer.
    Yes it sits on a laptop cooling pad all year around.
    Hi David1, just wondering how's your experiencing with QoS went? I flashed stock FW to experience the QoS and it sorted my surveillant camera streaming issue but the webUI is very slow so I'm looking to flash back to vortex fw if the QoS works and stable? Thanks
    which cooler pad u using or wuld recommend in general?
    Lets Encrypt sends an email at least a week before, with a link, when you need to renew for free DDNS. Takes less than 30 seconds to follow the link, ignore the upsell and click OK to renew
    I think you meant free SSL (vice DDNS). My preference would be to fire and forget. I'm not a fan of the periodic reminders to update, whether DDNS or an SSL Cert. I'll look for a script we can run certbot on the R7000. It automatically renews i.e. fire and forget. The way things should be.
    Apologies if these have already been mentioned, but am seeing one or two issues with the 384.9 release for the R7000
    1: I use a time switch to reboot everything at about 2am .. this is an old legacy issue I had with the NG firmware but it has shown up an oddity with the Merlin. After one or two power off reboots, the LEDs go into stealth mode and need to be turned back on in the Tools Settings tab. No biggie but.
    2: if I enable access to the router to two fixed IP addresses at work, , when I get to work, I can access the router and its menu;s with no problem , BUT I loose all access when on the LAN (or WLAN) so I have to do a Factory reset (via the reset button ) and re-load the saved .cfg file.
    Anyone any ideas why ?
    Hi, sorry for late reply, its working well, some sites when i download from are not being catorgorized properly, but the majority are, if any devices are updating windows my gaming ping is unaffected which is great, VPN server does not seem to be working though but havent looked at that as i cannot use it due to being behind a CG-NAT.
    As for the webUI i also found it slow with other versions of the firmware, but i am overclocking to 1200 which seems to have helped alot

    edit: Am using FreshJR QOS fyi
    which merlin version u on?
    sorry double post..which merlin fw u on on yo r7000?
    Vortex 384.9
    n is freshjr qos workin for u ? which installation method u used?
    Yes its working,works slightly better than the original, even have the custom page on
    latest 8.8, used easy method, just ssh into router and run

    curl "" -o /jffs/scripts/FreshJR_QOS --create-dirs && curl "" -o /jffs/scripts/www_FreshJR_QoS_Stats.asp && sh /jffs/scripts/FreshJR_QOS -install
    If necessary, you can generate your pixelserv-tls cert to be valid longer than 10 years. :)
    oops...meant no-ip sends the reminder for free ddns renewal. Once that is complete, the LetsEncrypt SSL auto renews. thanks
    I am having an issue with the 2.4 Ghz network appearing offline.
    I updated to NG this week. I am on R7000_384.9_0. Following the instructions, I updated to
    380.70 then 384.9 (using the .trx file IIRC because it was an upgrade) then did a factory reset.

    The router itself can't see any 2.4 GHz networks in the site survey. My phone can't see the 2.4 GHz network. All my legacy devices are offline.

    Other than the SSID and the password, all the settings are default.

    Any ideas?
    Did you try to flash 384.8_2 ?
    Am I the only one who cannot get the .chk file to flash on a R7000V2? everytime I try it tells me it needs to be a .img file. Trying to flash from a Mac and getting this error on multiple browsers. Did Netgear change something? If I can't get passed this, I cant run Merlin on this thing, which I really, really want to do
    You mean the R7000P? It's different hardware to the R7000. As far as I know, there's a DD-WRT firmware that will flash to the R7000P but that's all.
    At the login page, it says r7000V2 so that is all I know it as. I'll look at the stickers to see if I can get more details. Latest and all prior Netgear firmwares I try to flash give me the same error (.....must be a *.img file).... And yet, when I updated the firmware to the latest Netgear, through the search for an updated firmware and automatic update, that flash worked fine. But the I go out to their site and they are .chk files (in the manual download from the site).
    I'm an idiot, this is my buddies and I used to have an R7000. This is an R7500V2. My mistake as they look identical
    I really just want to set it up for my buddy as a repeater bridge as this is his old router and is running Merlin on his RT-AC86U. That's why I was pursuing Merlin, thinking this was a 7000. Not that its a 7500, I am guessing I will just set up DD-WRT on it as it seems pretty straightforward to set it up as a Repeater Bridge. This will help cover my buddies huge house. My 86U covers mine fine, but he needs something to extend wireless in the far corners of the house.
    Have you tried changing the Control channels? Try 1, 6 or 11 first...
    As Sl4fko said, hard code the channels and in most countries the only non-overlapping channels are 1,6 or 11.
    Some screen shots of your 2.4 basic and advanced settings might be helpful. Also, when in doubt clear it out. In other words, reset it to default and configure from scratch.
    No. What are the benefits?
    there are a few problems with 384.9, 384.8_2 is more stable, but i see merlin has
    There seems to be quite a few problems with 384.9, 348.8_2 is more stable and hopefully 384.10 should be coming out very soon hopefully
    [NEW] 384.10 brings to us a lot of internal component version updates.
    Very promising build... I'll check it out.
    I just flashed it, works great!
    Skynet and Diversion also working!
    So for the last time (I promise :D) I ask:

    Should I reset the router after updating to 384.10 from 384.9 (which seems to contain some major component updates) or is update and reboot the router enough?
    A router reset is not neccessary when going up from .9 to 10.

    When you skip a whole bunch of firmware updates or major changes like 380.70 to the NG code base then I would reset.

    The network map is still broken in this build but i'm going to try it regardless.
    what do u mean by network map? is it the connected devices list?
    yes its the list of connected devices.

    Granted i've been running it for a day now and it see's all my devices however I saw on the SNB forum someone said its still not fixed by asus yet.
    384.10 all working well here. No issues so far.

    Had an odd problem upgrading. I was on 384.8. Attempted to upgrade. Said it upgraded, but didn't (was still on 384.8). Tried upgrading to 384.9 - same result. Then tried resetting router. Couldn't wipe nvram using GUI. Tried holding reset button in for 30 seconds - did nothing.
    Couldn't change the LAN IP address either - it would show the new IP address in the GUI, but was still on the old IP address.
    Eventually used ssh to get into the router, and ran mtd-erase2 on the nvram. That worked. I could then upgrade.
    General rule of thumb for Asus firmware upgrades is to either A) remove any usb drives or B) reboot.
    There is a memory issue sometimes with Asus firmware and updates.
    May or maynot be what you experienced.
    Hello, I've been following and using this firmware for a few years now on two R7000 routers. Aside from not being able to AiMesh them, I've had no problems.

    After installing 384.10 on my spare R7000, I can't ssh. I get an error that I have never seen before:

    Someone could be eavesdropping on you right now (man-in-the-middle attack)!
    It is also possible that a host key has just been changed.
    The fingerprint for the ECDSA key sent by the remote host is
    Please contact your system administrator.
    Add correct host key in C:\\Users\\flipi/.ssh/known_hosts to get rid of this message.
    Offending ECDSA key in C:\\Users\\flipi/.ssh/known_hosts:1
    ECDSA host key for has changed and you have requested strict checking.
    Host key verification failed.
    Edit: So far the work around is to (surprisingly) use another computer.
    Last edited: Mar 29, 2019
    Most likely explanation is the ssh host key you have stored on your main computer is for your main router, not the R7000. When you plug-in your R7000, the host key doesn't match, hence the error. You need to delete the host key.
    Nah. Rebooted multiple times - the router for some reason wouldn't reboot after attempting the firmware upgrade, and told me to manually reboot.
    Never use the USB ports, so nothing plugged in there.

    No big deal - it's sorted now. Just mentioned it in case someone else has a similar problem.
    This firmware was the first one i've seen with a reboot manually message after the flash was done.
    Gotcha, I'll give that a shot. Thanks!
    I updated 384.10, and my printer and thermostat are offline again. Back to stock ... got my 2.4 Ghz band back now.
    I have always seen that message for the last few years except this one seems to actually reboot on it's own after the message.
    I'm still on 380.68_4 running skynet, diversion, and minidlna for media, open VPN clients, custom DNS and a few jffs scripts.

    It's rather old firmware, but everything works fine.

    I've reviewed the changelog notes for each of the newer firmware versions but can't see a burning reason to upgrade, but perhaps I missed something.

    Is there any reason for me to upgrade to a newer version, will I get better performance using VPN clients, or better features?

    Apart from the fact that your router/network is wide open to multiple known exploits, which are being exploited by hackers, then it's fine...

    Remember, a router is just a computer running an OS, that intern runs your network, your gateway to the Internet. It's no different to running a Windows 98 PC with no firewall and no AV software. If you don't care about such things, then you have nothing to worry about.
    I'm not much better. I'm running 380.70 with skynet, OpenVPN clients, custom DNS and a few jffs scripts. Everything works great. I would like to update OpenVPN, but not sure what other advantages there are to upgrading.

    What are the "multiple known exploits" (that have been discovered since this FW was distributed)?
    Open SSL has had some recent exploits, I'm sure if you dig into the open source libraries included in the firmware you'll find other issues.

    Not necessarily exploiting this routers firmware, but it's made up of lots of components.

    If you go back and look at the changelog for every firmware released after 380.70 merlin's list what was fixed what is still outstanding etc.

    You are going to be missing a ton of the CVE exploits that have been patched.


    382.1_2 (2-Dec-2017)
    - FIXED: Security issues CVE-2017-15275, CVE-2017-12163 and
    CVE-2017-12150 (backported to Samba 3.6 and 3.5)
    Since 384.10 I am also seeing these associate/ disassociate events (WLCEVENTD) that are also discussed on the Merlin forums. It does not seem to be a bug but just an event that did not get logged before.
    Hope this goes away or can be switched off in one of the upcoming versions.
    I'm also seeing these events.
    Also my WLAN disconnects and connects several times... Never had these problems before.
    Apr  3 17:35:20 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    Apr  3 17:37:52 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    Apr  3 17:40:53 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    Apr  3 17:43:58 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    Apr  3 17:49:58 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    Apr  3 17:51:17 WLCEVENTD: eth1: Assoc 24:05:0F:8F:XX:XX
    I'm not seeing any of this in my log currently most just skynet stuff.

    However my Primary Wan connection changed a couple weeks ago from a Cable DHCP setup to PPPOE Fiber so its possible why i'm not seeing them.
    WLCEVENTD is wireless lan connection events, it shows all ur devices connecting and disconnecting from wireless
    384.10_2 - some bugfixes
    After going through the whole log I found two entries with this one for my Laptop on 5 Ghz N and one for my Blackberry Keyone.

    I just updated to 10_2 so lets see if they continue. My network is primary wired devices so this isn't a huge deal for me.
    Does it work now with 384.10 or 384.10_2?
    Hi. Question.

    There is a problem, that I do not really know what causes it and how I could solve it.

    Whenever I change certain settings (for example enable Asus Feature BWDPI...) I somehow loose WAN connection (Internet status: Disabled in Network Map). The router just isn't connected to internet anymore. My connection type is PPPoE (ISP modem/router in bridge mode, ip, my main router's ip Google public DNS, running amtm, Diversion, Skynet, Stubby.

    I am currently on 384.10_2, however it has happened before on earlier firmware versions...

    What could be the cause?

    Thanks Again Mak. Will update soon. Did the Network Map ever get fixed?
    By network map do you mean the "connected clients"?
    Works fine on current build.
    "Site survey" also works.
    Yes Mike, That's what I meant. I thought I read somewhere in previous posts there was a problem with this feature. Maybe I'm just seeing things. Thanks.
    Nope. The list semi-populates, but is a complete mess in regards to actually showing you what is connected.
    Its actually been working well for me on 10 and 10_2.

    I only seen once instance where I know a device was connected and it wasn't listed then when I hit view list and gave it a min to refresh the device came up.

    But its 50/50 for most right now and still an issue.
    Yeah, if I leave the list up on the screen, devices constantly come and go, even wired ones. Hopefully the bug will get squished some time in the next release or two ;-)
    I have an R6700 that I 'converted' to an R7000 using telnet enable. I forget the exact steps I took, but it's running advanced tomato right now.

    Can I install this firmware on my R6700 that thinks it's an R7000 w/o reverting to the stock netgear firmware first?

    I had to leave the Netgear firmware because they came out with an update that slowed down my USB HDD that I had plugged into the router to approximately 1MB/s over the LAN. Wifi was still fine, but that was unacceptable.

    So, I changed the R6700 to R7000 so I could use advanced tomato and now things are fine, but I was thinking maybe they could be better with this?

    Anyways, thanks for any info.
    Greetings for everyone i'm new in the forum i ask apologize for my english recently i installed the NG Branch: 384.10_2 on R7000 so far is very stable good wifi signal output, coverage etc, one problem also noticed when i want to setup samba share with password i'm unable to connect to my shared folder no popup window to enter the password nothing, but in network places i see my shared folder. If i remove the password from samba then i can connect without problem i tryed to figure out what is the problem but no luck i know samba v2 is not compatible with windows so i use only the v1 but without password is not ok for me i like to restrict access. Thanks for any info.
    Make sure you dont have any saved passwords in windows
    go to "Control Panel\All Control Panel Items\Credential Manager"
    then "windows credentials"
    look for ip of router and remove password

    and try again

    i am running smbv2 only with windows 10 and passwords and have no problems
    Thanks David1 i try that.
    Something interesting, looks like last week when I applied the following in ssh under v384.10_2:
    nvram unset ctf_fa_cap
    nvram commit

    It rebooted except it's like as if the entire configuration got wiped out as the modem went back to the default SSID on the bottom of the router and I had to reconfigure from scratch.

    I noticed my WiFi performance on a 1000Mbps/35Mbps went from 350Mbps/42Mbps to 200Mbps/42Mbps but it wasn't earlier today that I noticed that the MAC address changed to the one that people saw when going from the old cold to the ng when doing ifconfig in ssh:

    admin@NETGEAR-R7000:/tmp/home/root# nvram show | grep "serial_no"
    size: 53925 bytes (11611 left)
    admin@NETGEAR-R7000:/tmp/home/root# nvram show | grep "macaddr"
    size: 53925 bytes (11611 left)

    so basically I had to fix it by:

    nvram set et0macaddr=[from router's sticker]
    nvram set 0:macaddr=[et0macaddr + 1]
    nvram set 1:macaddr=[et0macaddr + 2]
    nvram set serial_no=[from router's sticker]
    nvram set board_id=U12H270T00_NETGEAR
    nvram commit

    and my Wifi speeds are restored.
    I'm not familiar with this command and what it does so did some more searching on this and saw a couple of your post on SNB also.

    So my setup now I cannot use it because i'm on 1 Gbps PPPOE connection with Vlans enabled so only CTF will be available. It would be nice if asus fixes(if possible)the code so FA is available on all modes DCHP,PPPOE and PPPOE+Vlans. At least in most major cities everyone is getting access to 1Gbps connections either via Cable or Fiber.

    This is what I see currently after running
    nvram show | grep ctf

    Question about this fix. There is another issue I believe with the Guest network slot 1 sharing the MAC address with the primary adapter. And the work around is to use Guest slot #2. Would it be possible to fix that using these commands?
    How can I go back to stock / KONG with stock FW and KONG I am getting this error

    Many Thanks
    In the OP is a link to the back to stock firmware. From there you can jump to whichever flavor of firmware you want.
    It is not recommended to jump directly to a 3rd party firmware from this.
    I tried that OFW what I found here coupla pages back, but still getting the same error
    Not sure if you read the OP but here is what it says for going away from this firmware.

    Link to the "back to stock" firmware (v1.0.3.80_1.1.38) is here.
    More recent version (v1.0.9.26_10.2.31) for NG build is here.
    Unbrick tutorial by @User0815 in case of stuck on the ofw is here.

    Important: If You want to go away from XWRT back to tomato or dd-wrt you MUST first flash the "back to stock" firmware image, or you will brick your router.
    @Makaveli, the command basically reverses the manual setting of that so the R7000 will set the FA mode automatically based on how the web interface is configured under LAN/Switch Control. If you wanted FA to be used, then all you would need to do is:
    nvram set ctf_fa_cap=2
    nvram commit

    As basically it's to set the FA mode. 0=CTF On/FA=Off, 1=CTF On/FA=Capable, 2=CTF On/FA=Enabled
    so 2 would force the FA to be on and 1 depends on if the router wants to turn on the FA or not.

    I didn't even realized that PPPoE was still used for anything other than DSL.

    As for those commands, it was actually someone else who posted the fix and I am just using it. It turns out that even the fix, you can't set all three MAC Addresses as 0:macaddr would use the same thing as et0macaddr while 1:macaddr appears to be et0macaddr + 1. I've never used Guest network's at all with this firmware. I still wonder what the default mac addresses are with the router shipped out of the box.
    Cool I will try it out when 384.11 get released.

    And yes bell canada isp offers 1Gbps Fiber connections via PPPOE I switched from Cable which was DHCP.

    i'm hoping Bell does eventually migrate to DHCP because I also gave up IPV6 from the cable connection which new connection doesn't have.

    From what i've seen in the current firmware.

    Level 1 (CTF) (Software)
    Level 2 (CTF + FA) (Hardware)

    PPP0E+vlans only allows Level 1
    DHCP will allow level 2
    @Makaveli - hopefully 384.11 comes out soon. As I just upgraded to 1Gbps/42Mbps from 300Mbps/12Mbps on cable, I can't really tell if it's better with FA or or off. I'm just curious, what is the highest speed you or anyone else for that matter ever got out of the WiFi with the R7000? I'm seeing 350Mbps or so max but with the same Samsung Galaxy Note 8, it can do around 550Mbps with the XFinity XFi Advanced Gateway/XB6-T. The problem with PPPoE is that it has overhead as I believe the MTU is 1480 instead of 1500.
    I have CTF only enabled as I want Traffic analysis.
    On 5 Ghz WiFi I get a speed of 385 Mbits/s.
    With wired connection the speed is 875 Mbit/s.
    Actually I have 384.10_2
    I cant imaging an r7000 getting near gig speed on IPv4 with nat.
    Last I heard only IPv6 or no nat traffic gets near gig line speed.
    The dual core 1g cpu just isn't powerful enough for gig wan traffic that needs any nat.
    Congrats if your getting better than 400Mbps with nat IPv4.
    ~1gig is attainable on R7000 with ctf enabled, which bypasses the linux network stack (and many cpu cycles).
    My connection is 1Gbps down and 750 up on Fibre via PPPOE and IPv4 only now.

    CTF is on no FA


    Turn FA on and off and check cpu usage while running a speed test. Also my MTU is set to 1500 in router.

    I don't have a fast enough AC device to test for you until my girlfriend is over.

    My Blackberry Keyone only connects at 433Mbps while her S7 will do 867Mbps. So I can post a speed test from her phone when she is over.
    Yep, Ethernet in general maxes out at around 940Mbps or so due to overhead as Comcast/Xfinity actually delivers my internet provisioned at 1200MBps/42Mbps since they always overprovision by 20% compared to the advertised speeds. I was told that it takes 4x4 MIMO or something to get 800Mbps WiFi which was possible with a iPhone and the XFinity XB6-T Gateway so I think it's always in multiples of 433Mbps except there is overhead as well so my Intel 7260AC while at 867Mbps can only push under 400Mbps. I haven't tested the wired side yet.

    I do have a question, can the R7000 actually push the entire 1Gbps via WiFi from multiple devices or is it actually limited to the speed of what one device will test at?
    Max I got was 930 Mbps with my cable setup and I have CTF and FA enabled.
    Tell me, I'm new, how to upgrade the firmware from 380.70 to 384.10_2? First, at 384.8_2, then 384.9_0, then 384.10_2 or immediately at 384.10_2?
    Flash 380.70, do the factory reset, flash latest, factory reset again.

    However, do not import settings from builds that are so apart, reconfigure 384.10_2 from scratch. Think aboat flashing custom cfe also...

    Latest builds normally always contain all previous changes and fixes...
    I Finally got an R7000 AiMesh Router and R7000 Node working together..

    Both on XWRT 384.8.2
    The Router with custom CFE (nothing to do with this but it is..)

    First I enabled AiMesh on the router with SSH commands: nvram set amas_force=1 and nvram commit (without reboot)
    After I tried to connect to the node (after resetting the node) through wifi at first.
    It seemed to give an error message when trying to connecting to the node.
    After I waited a couple minutes I connected the Node by UTP from LAN (router) to WAN (node) and tried searching for a node and found one again. This time with UTP..
    After connecting the node again the node booted 1 time (by itself) and was added to the list! :)

    Not sure if this is gonna help anyone or if this is any news ;)
    Now some further testing for stability..

