Hi,
my goal is to have following setup and I have a really strange issue where I can only access some websites, but many not:
- Fritz!Box 7520 mainly used as modem (bridge mode) with OpenWrt 23.05.5
- GL.inet GL-MT6000 (Flint 2) as PPPoE endpoint and router running OpenWrt 23.05.5
Examples of accessible websites:
Not accessible:
Network file for Fritz!Box (bridge mode; it's a bit bloated due to my previous configuration):
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fddd:56ee:6c25::/48'
config atm-bridge 'atm'
option vpi '1'
option vci '32'
option encaps 'llc'
option payload 'bridged'
option nameprefix 'dsl'
config dsl 'dsl'
option annex 'j'
option tone 'b'
option ds_snr_offset '0'
config device
option name 'br-lan'
option type 'bridge'
option ipv6 '0'
option multicast '1'
option igmp_snooping '1'
list ports 'lan1'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.1.1'
option netmask '255.255.255.0'
option delegate '0'
config device
option name 'dsl0'
option macaddr 'REDACTED'
config interface 'tailscale'
option proto 'none'
option device 'tailscale0'
config interface 'guest'
option proto 'static'
option device 'br-guest'
option ipaddr '192.168.3.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-guest'
config interface 'server'
option proto 'static'
option device 'lan2'
option ipaddr '192.168.4.1'
option netmask '255.255.255.0'
config interface 'tv'
option proto 'static'
option device 'br-tv'
option ipaddr '192.168.5.1'
option netmask '255.255.255.0'
config device
option type 'bridge'
option name 'br-tv'
config device
option type 'bridge'
option name 'br-iot'
option bridge_empty '1'
config interface 'iot'
option proto 'static'
option device 'br-iot'
option ipaddr '192.168.6.1'
option netmask '255.255.255.0'
config interface 'wireguardvpn'
option proto 'wireguard'
option private_key 'REDACTED'
option listen_port '51820'
list addresses '192.168.9.1/24'
config wireguard_wireguardvpn
option description 'REDACTED'
option preshared_key 'REDACTED'
option public_key 'REDACTED'
option private_key 'REDACTED'
list allowed_ips '192.168.9.23/32'
option persistent_keepalive '25'
config interface 'wg_out'
option proto 'wireguard'
option private_key 'REDACTED'
list addresses '10.2.0.2/32'
list dns '10.2.0.1'
config wireguard_wg_out
option description 'Imported peer configuration'
option public_key 'REDACTED'
list allowed_ips '0.0.0.0/0'
option endpoint_host 'REDACTED'
option endpoint_port '51820'
config interface 'printer'
option proto 'static'
option device 'br-printer'
option ipaddr '192.168.8.1'
option netmask '255.255.255.0'
option delegate '0'
config device
option type 'bridge'
option name 'br-printer'
option multicast '1'
option igmp_snooping '1'
list ports 'lan3'
config interface 'wg_REDACTED'
option proto 'wireguard'
option private_key 'REDACTED'
list addresses '192.168.20.1/31'
option listen_port '51821'
config wireguard_wg_REDACTED
option description 'REDACTED'
option preshared_key 'REDACTED'
option public_key 'REDACTED'
option private_key 'REDACTED'
list allowed_ips '192.168.20.2/32'
option route_allowed_ips '1'
option endpoint_host 'REDACTED'
option persistent_keepalive '25'
option endpoint_port '51280'
config device
option type 'bridge'
option name 'br-dsl'
option bridge_empty '1'
list ports 'lan4'
list ports 'dsl0.7'
option vlan_filtering '1'
config interface 'MODEM'
option proto 'none'
option device 'br-dsl'
option defaultroute '0'
option delegate '0'
config device
option name 'lan4'
option ipv6 '1'
Network file for GL-MT6000 (router/PPPoE endpoint:)
config interface 'loopback'
option device 'lo'
option proto 'static'
option ipaddr '127.0.0.1'
option netmask '255.0.0.0'
config globals 'globals'
option ula_prefix 'fd20:1a05:a332::/48'
config device
option name 'br-lan'
option type 'bridge'
list ports 'lan1'
list ports 'lan2'
list ports 'lan3'
list ports 'lan4'
list ports 'lan5'
config device
option name 'lan1'
option macaddr 'REDACTED'
config device
option name 'lan2'
option macaddr 'REDACTED'
config device
option name 'lan3'
option macaddr 'REDACTED'
config device
option name 'lan4'
option macaddr 'REDACTED'
config device
option name 'lan5'
option macaddr 'REDACTED'
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.11.1'
option netmask '255.255.255.0'
option ip6assign '60'
config device
option name 'eth1'
option macaddr 'REDACTED'
config interface 'wan'
option device 'eth1'
option proto 'pppoe'
option username 'REDACTED'
option password 'REDACTED'
option ipv6 'auto'
option mtu '1492'
option peerdns '0'
list dns '1.1.1.1'
list dns '2606:4700:4700::1111'
Does anyone know why it does not work as expected?
Bonus question: I temporarily forgot to assign a firewall zone to the Fritz!Box's MODEM interface. It took about half a day, until I realized it. Were my devices and home network at risk during this time?