ER8411 SSL download errors
ER8411 SSL download errors

I am having an interesting issue with a new ER8411, I have searched around and can't find any information on how to resolve it for this Omada router (although there are solution for other routers)
I have a very simple setup, Telus ISP modem -> ER8411
The problem is, that file downloads will always fail if they are over HTTPS, testing over CURL gives this error
```
curl <any file url> -o arc.zip
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
0 378M 0 476k 0 0 865k 0 0:07:27 --:--:-- 0:07:27 864k
curl: (56) LibreSSL SSL_read: LibreSSL/3.3.6: error:06FFF064:digital envelope routines:CRYPTO_internal:bad decrypt, errno 0
```
The interesting thing is, I had the same problem with another router, and the solution was to disable GRO (generic receive upload) uaing the command `ethtool -K eth8 gro off`
I have tested with many routers
Modem -> Mikrotik router: Works fine
Modem -> Omada ER605: Works fine
Modem -> Omada ER8411: Errors
Modem -> Unifi router: Errors but fixed by disabling GRO
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Ok, it was a incompatability with the Telus modem
Original: Telus network access hub NH20a -> Issue is reproducable with ER8411 but not with ER707-M2
New: Telus hub Nokia XS-230Xa -> Fixed on all routers.
I had to ask my ISP to swap the modems, Still not sure why ER8411 is not compatible with NH20A given its the most common modem here.
- Copy Link
- Report Inappropriate Content

As you described that you have tested many routers, that is to say that ER8411 is reset to default status and without any possible config that might cause a problem in DNS resolution or HTTPS, you performed the downloads and it always fails?
What's the DNS resolution for the domain of the file you are trying to download?
BTW, what URL did you use?
Got an example?
- Copy Link
- Report Inappropriate Content
Hey, Yes I have tried it fully reset, and in both standalone + controller mode.
Some examples
- speedtest.net download tests on certain servers
- Most downloads result in the issue, but not all, for example, steam downloads are fine and download very fast, however, 90% of others fail (any device on network, and browser)
I am unable to post links on the forum, but downloading "Jetbrains intellij" or "arch linux" or "opnsense" or even downloading from dropbox files or tp-link firmware fails
The downloads do start (which I can see from curl) but very quickly fail
- Copy Link
- Report Inappropriate Content

antipesto wrote
Hey, Yes I have tried it fully reset, and in both standalone + controller mode.
Some examples
- speedtest.net download tests on certain servers
- Most downloads result in the issue, but not all, for example, steam downloads are fine and download very fast, however, 90% of others fail (any device on network, and browser)
I am unable to post links on the forum, but downloading "Jetbrains intellij" or "arch linux" or "opnsense" or even downloading from dropbox files or tp-link firmware fails
The downloads do start (which I can see from curl) but very quickly fail
From our static link, static.tp-link.com SSL would also fail? Will send this to the test team and see how they respond.
About the GRO, it is enabled by default. No option to disable it.
BTW, what's your curl version?
curl --version
The team replied that we got no reproduction of your reported issue on this version.
curl --version
curl 7.58.0 (x86_64-pc-linux-gnu) libcurl/7.58.0 OpenSSL/1.1.1 zlib/1.2.11 libidn2/2.0.4 libpsl/0.19.1 (+libidn2/2.0.4) nghttp2/1.30.0 librtmp/2.3
Release-Date: 2018-01-24
Protocols: dict file ftp ftps gopher http https imap imaps ldap ldaps pop3 pop3s rtmp rtsp smb smbs smtp smtps telnet tftp
Features: AsynchDNS IDN IPv6 Largefile GSS-API Kerberos SPNEGO NTLM NTLM_WB SSL libz TLS-SRP HTTP2 UnixSockets HTTPS-proxy PSL
- Copy Link
- Report Inappropriate Content
Thanks for your help!
I have tried curl on latest mac os (older) + windows (8.10.1)
Here is an example output when downloading formware from static.tp-link.
The setup here is simplyTelus NH20A modem in bridge mode -> RJ45 to WAN on ER8411
The results are the same when I reset the model fully and leave the configuration fully on default.
The issue is resolved if I switch to another router
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Download from tp-link, ER8411
download from tp-link unifi router
I do a test from a raspberry pi ER8411 router
- Copy Link
- Report Inappropriate Content
Thank you, I guess there is some incompatibility with my ISP... I tried to ask them but they only support if you use their own equipment only :(
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
I picked up an ER707-M2 out of curiosity, and it worked fine
Factory reset ER707 in standalone mode = fine
Factory reset ER8411 in standadlone fine = SSL errors
Clearly there is a difference between the routers, but specficically some feature of the ER8411 that is not compatible with my ISP (or ISP modem)
I don't have the skills to figure out what it might be so will find an alternative 10g router but happy to test anything you suggest!
- Copy Link
- Report Inappropriate Content
antipesto wrote
I picked up an ER707-M2 out of curiosity, and it worked fine
Factory reset ER707 in standalone mode = fine
Factory reset ER8411 in standadlone fine = SSL errors
Clearly there is a difference between the routers, but specficically some feature of the ER8411 that is not compatible with my ISP (or ISP modem)
I don't have the skills to figure out what it might be so will find an alternative 10g router but happy to test anything you suggest!
If you need to get to the reason, at least provide the curl version. That's important.
Many of us have not reproduced this issue. It could be a problem with the curl version.
- Copy Link
- Report Inappropriate Content

Information
Helpful: 0
Views: 847
Replies: 14
Voters 0
No one has voted for it yet.