So after executing tcpdump for eth1 i got:
15:14:36.417740 IP (tos 0x0, ttl 64, id 0, offset 0, flags [none], proto UDP (17), length 328)
0.0.0.0.68 > 255.255.255.255.67: BOOTP/DHCP, Request from 00:c0:xx:xx:xx:cf (oui Unknown), length 300, xid 0x5d7ed745, Flags [none]
Client-Ethernet-Address 00:c0:xx:xx:xx:cf (oui Unknown)
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: Request
Requested-IP Option 50, length 4: xx.xxx.xx.xxx
Server-ID Option 54, length 4: xx.xxx.xxx.xxx
MSZ Option 57, length 2: 576
Parameter-Request Option 55, length 8:
Subnet-Mask, Default-Gateway, Domain-Name-Server, Hostname
Domain-Name, BR, NTP, Classless-Static-Route
Hostname Option 12, length 7: "OpenWrt"
Vendor-Class Option 60, length 12: "udhcp 1.35.0"
15:14:36.521855 IP (tos 0x0, ttl 64, id 0, offset 0, flags [none], proto UDP (17), length 328)
XX.XXX.80.1.67 > XX.XXX.84.238.68: BOOTP/DHCP, Reply, length 300, hops 2, xid 0x5d7ed745, Flags [none]
Your-IP XX.XXX.XX.XX
Server-IP 87.99.XX.XX
Gateway-IP XX.XXX.XX.X
Client-Ethernet-Address 00:xx:0x:xx:xx:xx (oui Unknown)
Vendor-rfc1048 Extensions
Magic Cookie 0x63825363
DHCP-Message Option 53, length 1: ACK
Server-ID Option 54, length 4: xx.xx.xxx.xx
Lease-Time Option 51, length 4: 43200
Subnet-Mask Option 1, length 4: 255.255.248.0
Default-Gateway Option 3, length 4: 83.xxx.xx.1
Domain-Name-Server Option 6, length 12: 192.168.198.250,192.168.200.250,192.168.197.250
Domain-Name Option 15, length 13: "telpol.net.pl"
15:14:36.713617 ARP, Ethernet (len 6), IPv4 (len 4), Request who-has xx.xx.80.1 tell xx.xx.84.238, lengt h 28
15:14:36.724895 ARP, Ethernet (len 6), IPv4 (len 4), Reply xx.xxx.80.1 is-at 00:01:5c:b7:fa:46 (oui Unknow n), length 46
15:14:36.724929 IP (tos 0x0, ttl 127, id 43906, offset 0, flags [DF], proto TCP (6), length 52)
xx.xxx.84.238.57419 > 4.28.136.54.80: Flags [S], cksum 0xcd1d (correct), seq 1579561741, win 64240, op tions [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:36.776302 IP6 (flowlabel 0xd37da, hlim 1, next-header UDP (17) payload length: 110) fe80::2c0:8ff:fe 94:2ecf.546 > ff02::1:2.547: [bad udp cksum 0x3729 -> 0x4b4d!] dhcp6 solicit (xid=f4bb11 (elapsed-time 0) (option-request SIP-servers-domain SIP-servers-address DNS-server DNS-search-list SNTP-servers NTP-server AFTR-Name opt_67 opt_94 opt_95 opt_96 opt_82) (client-ID hwaddr type 1 00c008942ecf) (reconfigure-accept) (Client-FQDN) (IA_NA IAID:1 T1:0 T2:0) (IA_PD IAID:1 T1:0 T2:0))
15:14:36.859601 IP (tos 0x0, ttl 55, id 0, offset 0, flags [DF], proto TCP (6), length 52)
4.28.136.54.80 > XX.XXX.84.238.57419: Flags [S.], cksum 0xc890 (correct), seq 883280842, ack 157956174 2, win 65535, options [mss 1460,nop,wscale 6,sackOK,eol], length 0
15:14:36.860838 IP (tos 0x0, ttl 127, id 43907, offset 0, flags [DF], proto TCP (6), length 40)
XX.XXX.84.238.57419 > 4.28.136.54.80: Flags [.], cksum 0x045f (correct), ack 1, win 1026, length 0
15:14:36.860863 IP (tos 0x0, ttl 127, id 43908, offset 0, flags [DF], proto TCP (6), length 40)
XX.XXX.84.238.57419 > 4.28.136.54.80: Flags [F.], cksum 0x045e (correct), seq 1, ack 1, win 1026, leng th 0
15:14:36.866359 IP (tos 0x0, ttl 64, id 2129, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.38432 > 192.168.198.250.53: 54495+ A? s07.upd.kaspersky.com. (39)
15:14:36.866416 IP (tos 0x0, ttl 64, id 31197, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.38432 > 192.168.200.250.53: 54495+ A? s07.upd.kaspersky.com. (39)
15:14:36.866445 IP (tos 0x0, ttl 64, id 12403, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.38432 > 192.168.197.250.53: 54495+ A? s07.upd.kaspersky.com. (39)
15:14:36.866576 IP (tos 0x0, ttl 64, id 2130, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.60988 > 192.168.198.250.53: 30422+ AAAA? s07.upd.kaspersky.com. (39)
15:14:36.866620 IP (tos 0x0, ttl 64, id 31198, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.60988 > 192.168.200.250.53: 30422+ AAAA? s07.upd.kaspersky.com. (39)
15:14:36.866661 IP (tos 0x0, ttl 64, id 12404, offset 0, flags [DF], proto UDP (17), length 67)
XX.XXX.84.238.60988 > 192.168.197.250.53: 30422+ AAAA? s07.upd.kaspersky.com. (39)
15:14:36.882087 IP (tos 0x0, ttl 59, id 54067, offset 0, flags [none], proto UDP (17), length 139)
192.168.198.250.53 > XX.XXX.84.238.60988: 30422 0/1/0 (111)
15:14:36.882848 IP (tos 0x0, ttl 60, id 8986, offset 0, flags [none], proto UDP (17), length 139)
192.168.197.250.53 > XX.XXX.84.238.60988: 30422 0/1/0 (111)
15:14:36.883037 IP (tos 0xc0, ttl 64, id 58335, offset 0, flags [none], proto ICMP (1), length 167)
XX.XXX.84.238 > 192.168.197.250: ICMP XX.XXX.84.238 udp port 60988 unreachable, length 147
IP (tos 0x0, ttl 60, id 8986, offset 0, flags [none], proto UDP (17), length 139)
192.168.197.250.53 > XX.XXX.84.238.60988: 30422 0/1/0 (111)
15:14:36.883464 IP (tos 0x0, ttl 62, id 50430, offset 0, flags [none], proto UDP (17), length 139)
192.168.200.250.53 > XX.XXX.84.238.60988: 30422 0/1/0 (111)
15:14:36.883594 IP (tos 0xc0, ttl 64, id 39078, offset 0, flags [none], proto ICMP (1), length 167)
XX.XXX.84.238 > 192.168.200.250: ICMP XX.XXX.84.238 udp port 60988 unreachable, length 147
IP (tos 0x0, ttl 62, id 50430, offset 0, flags [none], proto UDP (17), length 139)
192.168.200.250.53 > XX.XXX.84.238.60988: 30422 0/1/0 (111)
15:14:36.901714 IP (tos 0x0, ttl 60, id 8991, offset 0, flags [none], proto UDP (17), length 83)
192.168.197.250.53 > XX.XXX.84.238.38432: 54495 1/0/0 s07.upd.kaspersky.com. A 80.239.170.187 (55)
15:14:36.909714 IP (tos 0x0, ttl 62, id 50435, offset 0, flags [none], proto UDP (17), length 83)
192.168.200.250.53 > XX.XXX.84.238.38432: 54495 1/0/0 s07.upd.kaspersky.com. A 80.239.174.62 (55)
15:14:36.909793 IP (tos 0xc0, ttl 64, id 39080, offset 0, flags [none], proto ICMP (1), length 111)
XX.XXX.84.238 > 192.168.200.250: ICMP XX.XXX.84.238 udp port 38432 unreachable, length 91
IP (tos 0x0, ttl 62, id 50435, offset 0, flags [none], proto UDP (17), length 83)
192.168.200.250.53 > XX.XXX.84.238.38432: 54495 1/0/0 s07.upd.kaspersky.com. A 80.239.174.62 (55)
15:14:40.866859 IP (tos 0x0, ttl 64, id 31460, offset 0, flags [DF], proto UDP (17), length 70)
XX.XXX.84.238.60200 > 192.168.200.250.53: 16046+ PTR? 54.136.28.4.in-addr.arpa. (42)
15:14:41.203199 IP (tos 0x0, ttl 127, id 11073, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57425 > 80.239.197.106.80: Flags [S], cksum 0x164e (correct), seq 339126719, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:41.264033 IP (tos 0x0, ttl 127, id 60066, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57430 > 40.115.3.253.443: Flags [S], cksum 0x0800 (correct), seq 3135568344, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:41.369794 IP (tos 0x0, ttl 127, id 53664, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57431 > 195.122.177.184.443: Flags [S], cksum 0xb6d5 (correct), seq 1978222394, win 6424 0, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:41.445690 IP (tos 0x0, ttl 127, id 9981, offset 0, flags [none], proto TCP (6), length 576)
XX.XXX.84.238.57423 > 185.136.68.153.443: Flags [P.], cksum 0xbb3d (correct), seq 3287765292:328776582 8, ack 1718621330, win 64400, length 536
15:14:41.600010 IP (tos 0x0, ttl 127, id 9982, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57432 > 185.136.68.153.443: Flags [S], cksum 0x6c4b (correct), seq 619796941, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:41.829373 IP (tos 0x0, ttl 127, id 41285, offset 0, flags [none], proto TCP (6), length 254)
XX.XXX.84.238.57424 > 20.42.73.24.443: Flags [P.], cksum 0x1a75 (correct), seq 1940800362:1940800576, ack 1420965381, win 1029, length 214
15:14:42.047699 58:60:d8:ed:db:1f (oui Unknown) > Broadcast, RRCP-0x23 query
15:14:42.366107 IP (tos 0x0, ttl 127, id 43326, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57427 > 130.117.190.213.443: Flags [S], cksum 0x0f6b (correct), seq 2106727144, win 6424 0, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:42.366445 IP (tos 0x0, ttl 127, id 26427, offset 0, flags [DF], proto TCP (6), length 52)
XX.XXX.84.238.57428 > 20.42.65.92.443: Flags [S], cksum 0x0ece (correct), seq 388786711, win 65160, op tions [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
15:14:42.531965 IP (tos 0x0, ttl 127, id 17531, offset 0, flags [DF], proto TCP (6), length 52)
^C XX.XXX.84.238.57418 > 94.75.236.122.80: Flags [S], cksum 0x17a9 (correct), seq 414281604, win 64240, options [mss 1460,nop,wscale 8,nop,nop,sackOK], length 0
206 packets captured
1284 packets received by filter
1047 packets dropped by kernel
root@OpenWrt:~#
I skip few minutes before my modem booted up and catch only moment when ITX gets WAN address, before that moment actually nothing changed