lluke
Occasional Visitor
Hi all,
on my 2 RT-AC86U whenever Iface a connectivity re-connect (also done from the scmerlin add-on Internet Connection restart action) or a VPN change (e.g., updating and saving the IPSec VPN Server config) restart the firewall then every service on the router is properly working (Unbound DNS, WireGuard tunnel, IPSec Server, YazFi Networks) but the internet connectivity is not working anymore for any client connected to the network
My first focus was on wireguard (last addition to my addons mix) but after some investigation by looking at the forward chain it seems the issue could be related to YazFi.
Indeed, the only difference before and after a connection issue (or even manual restart from scmerlin) are the following 2 rules missing:
pkts bytes target prot opt in out source destination
0 0 YazFiDNSFILTER_DOT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:853
105 190 YazFiFORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
Could the absence of these 2 rules be the root cause of the internet connectivity outage on clients?
See updates below (post #3 and #4), the issue on the iptables rules is slightly different.
My current setup on both routers is:
Asuswrt Merlin 386.9
YazFi v4.4.2
Unbound Manager v3.22
ntpMerlin v3.4.5
scMerlin v2.4.0
WireGuard Mgr v4.18
Any advice on how to better investigate (and hopefully solve) the issue would be more than welcome.
Edited after the additional discoveries (see post #3 and #4)
on my 2 RT-AC86U whenever I
My first focus was on wireguard (last addition to my addons mix) but after some investigation by looking at the forward chain it seems the issue could be related to YazFi.
pkts bytes target prot opt in out source destination
0 0 YazFiDNSFILTER_DOT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:853
105 190 YazFiFORWARD all -- * * 0.0.0.0/0 0.0.0.0/0
Could the absence of these 2 rules be the root cause of the internet connectivity outage on clients?
See updates below (post #3 and #4), the issue on the iptables rules is slightly different.
My current setup on both routers is:
Asuswrt Merlin 386.9
YazFi v4.4.2
Unbound Manager v3.22
ntpMerlin v3.4.5
scMerlin v2.4.0
WireGuard Mgr v4.18
Any advice on how to better investigate (and hopefully solve) the issue would be more than welcome.
Edited after the additional discoveries (see post #3 and #4)
Last edited: