thanks, done.
do you mind having a look at my tplink router config to see if you find any inconsistencies or non recommended configs..thx
config interface 'loopback'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
option device 'lo'
config globals 'globals'
config device
option name 'br-lan'
option type 'bridge'
list ports 'eth1'
option ipv6 '0'
config interface 'LAN'
option proto 'static'
option ipaddr '192.168.4.1'
option netmask '255.255.255.0'
option device 'br-lan'
option delegate '0'
config switch
option name 'switch0'
option reset '1'
option enable_vlan '1'
config switch_vlan
option device 'switch0'
option vlan '1'
option vid '1'
option ports '0 4 3 2 1'
option description 'LAN'
config switch_vlan
option device 'switch0'
option vlan '2'
option vid '2'
option ports '6 5'
option description 'WAN'
config switch_vlan
option device 'switch0'
option vlan '3'
option ports '0t 4t 3t 2t 1t'
option vid '3'
option description 'NOVPN'
config switch_vlan
option device 'switch0'
option vlan '4'
option ports '0t 4t 3t 2t 1t'
option vid '4'
option description 'GUEST'
config interface 'LTE'
option device 'eth0'
option proto 'dhcp'
option classlessroute '0'
config interface 'NOVPN'
option proto 'static'
option netmask '255.255.255.0'
option delegate '0'
option ipaddr '192.168.5.1'
option device 'eth1.3'
option type 'bridge'
config interface 'GUEST'
option proto 'static'
option device 'eth1.4'
option ipaddr '192.168.6.1'
option netmask '255.255.255.0'
option delegate '0'
config interface 'VPN'
option proto 'wireguard'
option private_key 'xxxx'
list addresses '10.9.0.2/32'
option listen_port '51830'
option delegate '0'
option force_link '1'
option defaultroute '0'
option mtu '1420'
config wireguard_VPN 'wg0'
option public_key 'xxx'
option route_allowed_ips '1'
option persistent_keepalive '0'
option endpoint_port '51830'
list allowed_ips '10.9.0.1/32'
list allowed_ips '0.0.0.0/0'
list allowed_ips '10.9.0.3/32'
list allowed_ips '10.9.0.4/32'
option endpoint_host 'xxxx'
config device
option name 'eth0'
option ipv6 '0'
option acceptlocal '0'