Two WAN connections to individual LANs

Hi there,

I have two ISPs (one VDSL and one fibre connection) and want to extend my current setup for the fibre connection.
The goal is to create a new LAN (new VLAN, new address ranges) and route the WAN traffic from the fibre connection to that newly created LAN.

At the moment I didn't want to use mwan3 as a solution, because the VDSL connection has different services than the fibre connection (mainly IPTV streaming services).
The new fibre connection should be routed to a new LAN.

What I already did:

  1. new interface with a new vlan (ID 100, address range 172.16.1.1, subnet 255.255.255.0)
  2. new wan interface for fibre connection (vlan ID 10 -> is going to an exclusive untagged port on the main switch in the house, dhcp client)
  3. new firewall zones for the new interfaces and new rules

What's working:
The client on the new LAN gets an IP from the new range. I can ping the router and also can reach the old LAN (192.168.1.1 and the clients in it).
What's not working on the new LAN: I can't access the internet. When I open a browser it says connection refused (so it has to be a firewall issue?).

Here are my config:
network:

BusyBox v1.36.1 (2024-06-16 12:03:03 UTC) built-in shell (ash)

  _______                     ________        __
 |       |.-----.-----.-----.|  |  |  |.----.|  |_
 |   -   ||  _  |  -__|     ||  |  |  ||   _||   _|
 |_______||   __|_____|__|__||________||__|  |____|
          |__| W I R E L E S S   F R E E D O M
 -----------------------------------------------------
 OpenWrt 23.05.3, r23809-234f1a2efa
 -----------------------------------------------------
root@OpenWrt-EG:~# cat /etc/config/network

config interface 'loopback'
        option device 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'
        option ula_prefix 'fdfd:6bc9:c800::/48'
        option packet_steering '1'

config device
        option name 'br-lan'
        option type 'bridge'
        list ports 'ethernet'
        list ports 'internet'

config device
        option name 'ethernet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'lan'
        option device 'br-lan.99'
        option proto 'static'
        option ipaddr '192.168.1.1'
        option netmask '255.255.255.0'
        option ip6assign '60'

config device
        option name 'internet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'wan'
        option device 'internet.7'
        option proto 'pppoe'
        option password 'pw'
        option username 'user'
        list dns '8.8.8.8'
        list dns '8.8.1.1'
        list dns '1.1.1.1'
        list dns '2001:4860:4860::8888'
        list dns '2001:4860:4860::8844'
        option peerdns '0'
        option ipv6 'auto'
        option type 'bridge'

config interface 'wan6'
        option device 'internet.7'
        option proto 'dhcpv6'

config device
        option type '8021q'
        option ifname 'internet'
        option vid '7'
        option name 'internet.7'

config interface 'wg0'
        option proto 'wireguard'
        option private_key 'private_key'
        option listen_port '1234'
        list addresses '10.14.0.1/24'

config wireguard_wg0
        option persistent_keepalive '25'
        option description 'Florian_Android'
        list allowed_ips '10.14.0.3/32'
        option public_key 'public_key0'

config wireguard_wg0
        option public_key 'public_key1'
        option persistent_keepalive '25'
        option description 'Michael_BZ'
        list allowed_ips '10.14.0.4/32'

config route
        option interface 'wg0'
        option target '10.14.0.0'
        option netmask '255.255.0.0'

config interface 'guest'
        option proto 'static'
        option ipaddr '10.20.30.1'
        option netmask '255.255.255.0'
        option device 'br-lan.20'

config bridge-vlan
        option device 'br-lan'
        option vlan '20'
        list ports 'internet:t'

config bridge-vlan
        option device 'br-lan'
        option vlan '99'
        list ports 'ethernet:u*'
        list ports 'internet:u*'

config interface 'wan_oi'
        option proto 'dhcp'
        option device 'internet.10'

config interface 'wan_oi6'
        option proto 'dhcpv6'
        option device 'internet.10'
        option reqaddress 'try'
        option reqprefix 'auto'

config interface 'lan_oi'
        option proto 'static'
        option device 'br-lan.100'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'

config bridge-vlan
        option device 'br-lan'
        option vlan '100'
        list ports 'ethernet:t'
        list ports 'internet:t'

config device
        option name 'internet.10'
        option type '8021q'
        option ifname 'internet'
        option vid '10'

firewall

root@OpenWrt-EG:~# cat /etc/config/firewall

config defaults
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option synflood_protect '1'
        option flow_offloading '1'
        option flow_offloading_hw '1'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan'
        list network 'wg0'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan'
        list network 'wan6'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option dest 'lan'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest 'lan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan_oi'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan_oi'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan_oi'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan_oi'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan_oi'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan_oi'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan_oi'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan_oi'
        option dest 'lan_oi'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan_oi'
        option dest 'lan_oi'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan_oi'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option src '*'
        option target 'ACCEPT'
        option proto 'udp'
        option dest_port '1234'
        option name 'Allow-Wireguard-Inbound'

config zone
        option name 'GuestZone'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        list network 'guest'

config forwarding
        option src 'GuestZone'
        option dest 'wan'

config rule
        option name 'Allow-Guest-DHCP-DNS'
        option src 'GuestZone'
        option dest_port '53 67 68'
        option target 'ACCEPT'

config zone
        option name 'lan_oi'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan_oi'

config zone
        option name 'wan_oi'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan_oi'
        list network 'wan_oi6'

config forwarding
        option src 'lan_oi'
        option dest 'lan'

config forwarding
        option src 'lan'
        option dest 'lan_oi'

config forwarding
        option src 'lan_oi'
        option dest 'wan_oi'

Hopefully it's an easy fix. Thanks in advance!

https://openwrt.org/docs/guide-user/network/routing/pbr_netifd#route_lan_to_vpn_and_dmz_to_wan

Thank you, I will check this.

Can I achieve the same behavior with mwan3? So strictly routing one WAN Port to a dedicated LAN? Than I would configure this... Although I thought it would be easier to simply route one WAN to their own LAN.

Yes, you can do it with mwan3 or pbr as well. It's a matter of configuration.

2 Likes

Somehow I managed to get both wan connections working with mwan3, but when both enabled my clients can't browse the internet.

I followed the guide on the official OpenWrt page and configured the metrics (wan = 10 and wanb = 20). I also installed the two packages for the nft-iptables translation.

I can also ping with both wan connections on IPv4 www.google.de.

I named my Interfaces same like in the mwan3 config (wan, wan6, wanb and wanb6). Although the status says it can't find Interfaces for IPv6.

So IPv6 is completely not working. I also have no clue why browsing with 2 connections isn't working.

MultiWAN Manager - Status
Interface status:
 interface wan is online 00h:00m:34s, uptime 00h:51m:23s and tracking is active
 interface wan6 is offline and tracking is paused
 interface wanb is online 00h:00m:34s, uptime 00h:51m:24s and tracking is active
 interface wanb6 is offline and tracking is paused

Current ipv4 policies:
balanced:
 wanb (50%)
 wan (50%)
wan_only:
 wan (100%)
wan_wanb:
 wan (100%)
wanb_only:
 wanb (100%)
wanb_wan:
 wanb (100%)

Current ipv6 policies:
balanced:
 unreachable
wan_only:
 unreachable
wan_wanb:
 unreachable
wanb_only:
 unreachable
wanb_wan:
 unreachable

Directly connected ipv4 networks:
192.168.1.0/24
127.0.0.1
172.16.1.1
10.14.0.0/16
10.14.0.0/24
127.0.0.0/8
192.168.1.1
62.155.240.37
91.1.49.51
127.255.255.255
224.0.0.0/3
100.67.2.231
192.168.1.255
100.67.3.255
10.20.30.1
172.16.1.255
10.14.0.1
10.14.0.255
10.20.30.0/24
172.16.1.0/24
100.67.0.0/22
10.20.30.255

Directly connected ipv6 networks:
fd46:b373:a44::/64
fdf8:373f:9a82::/64
fe80::86b5:9cff:fef9:5ab0
fdfd:6bc9:c800::/64
fe80::c531:3f3c:39f3:7e61
2003:cd:7fff:30a9::/64
fe80::/64
2003:cd:7f01:6c00::/64

Active ipv4 user rules:
  372 32303 S https  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            multiport dports 443 
   40  7536 - balanced  all  --  *      *       0.0.0.0/0            0.0.0.0/0            

Active ipv6 user rules:
   19  1480 S https  tcp      *      *       ::/0                 ::/0                 multiport dports 443 
    4   439 - balanced  all      *      *       ::/0                 ::/0                 

MultiWAN Manager - Troubleshooting
Software-Version
-------------------------------------------------
OpenWrt - 23.05.3

Output of "ip -4 a show"
-------------------------------------------------
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
26: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan.99
       valid_lft forever preferred_lft forever
27: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 10.20.30.1/24 brd 10.20.30.255 scope global br-lan.20
       valid_lft forever preferred_lft forever
28: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan.100
       valid_lft forever preferred_lft forever
29: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 100.67.2.231/22 brd 100.67.3.255 scope global internet.10
       valid_lft forever preferred_lft forever
31: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 10.14.0.1/24 brd 10.14.0.255 scope global wg0
       valid_lft forever preferred_lft forever
32: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    inet 91.1.49.51 peer 62.155.240.37/32 scope global pppoe-wan
       valid_lft forever preferred_lft forever

Output of "ip -4 route show"
-------------------------------------------------
default via 62.155.240.37 dev pppoe-wan proto static metric 10 
default via 100.67.0.1 dev internet.10 proto static src 100.67.2.231 metric 20 
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1 
10.14.0.0/16 dev wg0 proto static scope link 
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1 
62.155.240.37 dev pppoe-wan proto kernel scope link src 91.1.49.51 
100.67.0.0/22 dev internet.10 proto static scope link metric 20 
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1 
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1 

Output of "ip -4 rule show"
-------------------------------------------------
0:	from all lookup local
1001:	from all iif pppoe-wan lookup 1
1003:	from all iif internet.10 lookup 3
2001:	from all fwmark 0x100/0x3f00 lookup 1
2003:	from all fwmark 0x300/0x3f00 lookup 3
2061:	from all fwmark 0x3d00/0x3f00 blackhole
2062:	from all fwmark 0x3e00/0x3f00 unreachable
3001:	from all fwmark 0x100/0x3f00 unreachable
3003:	from all fwmark 0x300/0x3f00 unreachable
32766:	from all lookup main
32767:	from all lookup default

Output of "ip -4 route list table 1-250"
-------------------------------------------------
Routing table 1:
default via 62.155.240.37 dev pppoe-wan proto static metric 10 
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1 
10.14.0.0/16 dev wg0 proto static scope link 
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1 
62.155.240.37 dev pppoe-wan proto kernel scope link src 91.1.49.51 
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1 
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1 

Routing table 3:
default via 100.67.0.1 dev internet.10 proto static src 100.67.2.231 metric 20 
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1 
10.14.0.0/16 dev wg0 proto static scope link 
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1 
100.67.0.0/22 dev internet.10 proto static scope link metric 20 
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1 
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1 

Output of "iptables -t mangle -w -L -v -n"
-------------------------------------------------
Chain PREROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
37432   32M mwan3_hook  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain FORWARD (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain OUTPUT (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         
 2176  382K mwan3_hook  all  --  *      *       0.0.0.0/0            0.0.0.0/0           

Chain POSTROUTING (policy ACCEPT 0 packets, 0 bytes)
 pkts bytes target     prot opt in     out     source               destination         

Chain mwan3_connected_ipv4 (2 references)
 pkts bytes target     prot opt in     out     source               destination         
 2140  360K MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_connected_ipv4 dst MARK or 0x3f00

Chain mwan3_custom_ipv4 (2 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_custom_ipv4 dst MARK or 0x3f00

Chain mwan3_dynamic_ipv4 (2 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_dynamic_ipv4 dst MARK or 0x3f00

Chain mwan3_hook (2 references)
 pkts bytes target     prot opt in     out     source               destination         
39370   32M CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 CONNMARK restore mask 0x3f00
 4017  383K mwan3_ifaces_in  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 3094  228K mwan3_custom_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 3094  228K mwan3_connected_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 2304  162K mwan3_dynamic_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 2304  162K mwan3_rules  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
39608   32M CONNMARK   all  --  *      *       0.0.0.0/0            0.0.0.0/0            CONNMARK save mask 0x3f00
 4401  687K mwan3_custom_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match ! 0x3f00/0x3f00
 4401  687K mwan3_connected_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match ! 0x3f00/0x3f00
 3051  393K mwan3_dynamic_ipv4  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match ! 0x3f00/0x3f00

Chain mwan3_iface_in_wan (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  pppoe-wan *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_custom_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
    0     0 MARK       all  --  pppoe-wan *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_connected_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
    0     0 MARK       all  --  pppoe-wan *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_dynamic_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
   23  1004 MARK       all  --  pppoe-wan *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wan */ MARK xset 0x100/0x3f00

Chain mwan3_iface_in_wanb (1 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  internet.10 *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_custom_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
    0     0 MARK       all  --  internet.10 *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_connected_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
    0     0 MARK       all  --  internet.10 *       0.0.0.0/0            0.0.0.0/0            match-set mwan3_dynamic_ipv4 src mark match 0x0/0x3f00 /* default */ MARK or 0x3f00
  900  154K MARK       all  --  internet.10 *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wanb */ MARK xset 0x300/0x3f00

Chain mwan3_ifaces_in (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 3992  381K mwan3_iface_in_wan  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 3969  380K mwan3_iface_in_wanb  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00

Chain mwan3_policy_balanced (2 references)
 pkts bytes target     prot opt in     out     source               destination         
   60  7902 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 statistic mode random probability 0.50000000000 /* wanb 3 6 */ MARK xset 0x300/0x3f00
   61  6708 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wan 3 3 */ MARK xset 0x100/0x3f00

Chain mwan3_policy_wan_only (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wan 3 3 */ MARK xset 0x100/0x3f00

Chain mwan3_policy_wan_wanb (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wan 3 3 */ MARK xset 0x100/0x3f00

Chain mwan3_policy_wanb_only (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wanb 2 2 */ MARK xset 0x300/0x3f00

Chain mwan3_policy_wanb_wan (0 references)
 pkts bytes target     prot opt in     out     source               destination         
    0     0 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 /* wanb 2 2 */ MARK xset 0x300/0x3f00

Chain mwan3_rule_https (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 2135  140K MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 MARK xset 0x300/0x3f00
    7   420 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x300/0x3f00 ! match-set mwan3_rule_ipv4_https src,src MARK and 0xffffc0ff
    7   420 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00 MARK xset 0x100/0x3f00
    1    60 MARK       all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x100/0x3f00 ! match-set mwan3_rule_ipv4_https src,src MARK and 0xffffc0ff
    1    60 mwan3_policy_balanced  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
 2135  140K SET        all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match ! 0xfc00/0xfc00 del-set mwan3_rule_ipv4_https src,src
 2135  140K SET        all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match ! 0xfc00/0xfc00 add-set mwan3_rule_ipv4_https src,src

Chain mwan3_rules (1 references)
 pkts bytes target     prot opt in     out     source               destination         
 2135  140K mwan3_rule_https  tcp  --  *      *       0.0.0.0/0            0.0.0.0/0            multiport dports 443 mark match 0x0/0x3f00
  120 14550 mwan3_policy_balanced  all  --  *      *       0.0.0.0/0            0.0.0.0/0            mark match 0x0/0x3f00
Powered by LuCI openwrt-23.05 branch (git-24.086.45142-09d5a38) / OpenWrt 23.05.3 (r23809-234f1a2efa)

When I try to use only wanb (every other interface disabled), I can't browse the internet with my clients.

Please run the following commands (copy-paste the whole block) and paste the output here, using the "Preformatted text </> " button:
grafik
Remember to redact passwords, MAC addresses and any public IP addresses you may have

ubus call system board; \
uci export network; \
uci export dhcp; uci export firewall; \
uci export mwan3; \
ip -4 addr ; ip -4 ro li tab all ; ip -4 ru; \
ip -6 addr ; ip -6 ro li tab all ; ip -6 ru; \
ls -l  /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/* ; head -n -0 /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/*

Hi there and thank you for your support. I did run the commands and hopefully I blacked out all critical data.

root@OpenWrt-EG:~# ubus call system board; \
etwork;> uci export network; \
> uci export dhcp; uci export firewall; \
> uci export mwan3; \
> ip -4 addr ; ip -4 ro li tab all ; ip -4 ru; \
ip -6 ad> ip -6 addr ; ip -6 ro li tab all ; ip -6 ru; \
> ls -l  /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/* ; head -n -0 /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/*
{
        "kernel": "5.15.150",
        "hostname": "OpenWrt-EG",
        "system": "MediaTek MT7621 ver:1 eco:3",
        "model": "D-Link COVR-X1860 A1",
        "board_name": "dlink,covr-x1860-a1",
        "rootfs_type": "squashfs",
        "release": {
                "distribution": "OpenWrt",
                "version": "23.05.3",
                "revision": "r23809-234f1a2efa",
                "target": "ramips/mt7621",
                "description": "OpenWrt 23.05.3 r23809-234f1a2efa"
        }
}
package network

config interface 'loopback'
        option device 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'
        option ula_prefix 'fdfd:6bc9:c800::/48'
        option packet_steering '1'

config device
        option name 'br-lan'
        option type 'bridge'
        list ports 'ethernet'
        list ports 'internet'

config device
        option name 'ethernet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'lan'
        option device 'br-lan.99'
        option proto 'static'
        option ipaddr '192.168.1.1'
        option netmask '255.255.255.0'
        option ip6assign '60'

config device
        option name 'internet'
        option macaddr '0c:0e:76:cf:6b:19'

config interface 'wan'
        option device 'internet.7'
        option proto 'pppoe'
        option password 'pw'
        option username 'user'
        list dns '8.8.8.8'
        list dns '8.8.1.1'
        list dns '1.1.1.1'
        list dns '2001:4860:4860::8888'
        list dns '2001:4860:4860::8844'
        option peerdns '0'
        option ipv6 'auto'
        option type 'bridge'
        option metric '10'

config interface 'wan6'
        option device 'internet.7'
        option proto 'dhcpv6'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '10'

config device
        option type '8021q'
        option ifname 'internet'
        option vid '7'
        option name 'internet.7'

config interface 'wg0'
        option proto 'wireguard'
        option private_key 'key'
        option listen_port '1234'
        list addresses '10.14.0.1/24'

config wireguard_wg0
        option persistent_keepalive '25'
        option description 'Florian_Android'
        list allowed_ips '10.14.0.3/32'
        option public_key 'key'

config wireguard_wg0
        option public_key 'key'
        option persistent_keepalive '25'
        option description 'Michael_BZ'
        list allowed_ips '10.14.0.4/32'

config route
        option interface 'wg0'
        option target '10.14.0.0'
        option netmask '255.255.0.0'

config interface 'guest'
        option proto 'static'
        option ipaddr '10.20.30.1'
        option netmask '255.255.255.0'
        option device 'br-lan.20'

config bridge-vlan
        option device 'br-lan'
        option vlan '20'
        list ports 'internet:t'

config bridge-vlan
        option device 'br-lan'
        option vlan '99'
        list ports 'ethernet:u*'
        list ports 'internet:u*'

config interface 'wanb'
        option proto 'dhcp'
        option device 'internet.10'
        option metric '20'

config interface 'wanb6'
        option proto 'dhcpv6'
        option device 'internet.10'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '20'

config interface 'lan_oi'
        option proto 'static'
        option device 'br-lan.100'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'

config bridge-vlan
        option device 'br-lan'
        option vlan '100'
        list ports 'ethernet:t'
        list ports 'internet:t'

config device
        option name 'internet.10'
        option type '8021q'
        option ifname 'internet'
        option vid '10'
        option macaddr '0C:0E:76:CF:6B:20'

package dhcp

config dnsmasq
        option domainneeded '1'
        option localise_queries '1'
        option rebind_protection '1'
        option rebind_localhost '1'
        option local '/lan/'
        option domain 'lan'
        option expandhosts '1'
        option cachesize '1000'
        option readethers '1'
        option leasefile '/tmp/dhcp.leases'
        option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
        option localservice '1'
        option ednspacket_max '1232'

config dhcp 'lan'
        option interface 'lan'
        option start '100'
        option limit '150'
        option leasetime '12h'
        option dhcpv4 'server'
        option dhcpv6 'server'
        option ra 'server'
        list ra_flags 'managed-config'
        list ra_flags 'other-config'

config dhcp 'wan'
        option interface 'wan'
        option ignore '1'

config odhcpd 'odhcpd'
        option maindhcp '0'
        option leasefile '/tmp/hosts/odhcpd'
        option leasetrigger '/usr/sbin/odhcpd-update'
        option loglevel '4'

config host
        option name 'switch'
        option dns '1'
        option mac '50:C7:BF:82:72:69'
        option ip '192.168.1.10'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'nas540'
        option dns '1'
        option mac '5C:F4:AB:5B:A5:62'
        option ip '192.168.1.20'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'gigasetgo'
        option dns '1'
        option mac '7C:2F:80:AA:39:F5'
        option ip '192.168.1.15'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'KP105'
        option mac '00:5F:67:02:3F:88'
        option ip '192.168.1.40'

config host
        option name 'KNX-IPRT-803C06'
        option dns '1'
        option mac 'CC:1B:E0:80:3C:06'
        option ip '192.168.1.50'

config dhcp 'guest'
        option interface 'guest'
        option start '100'
        option limit '150'
        option leasetime '12h'

config dhcp 'lan_oi'
        option interface 'lan_oi'
        option start '100'
        option limit '150'
        option leasetime '12h'

package firewall

config defaults
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option synflood_protect '1'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan'
        list network 'wg0'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan'
        list network 'wan6'
        list network 'wan_oi'
        list network 'wan_oi6'
        list network 'wanb'
        list network 'wanb6'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option dest 'lan'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest 'lan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option src '*'
        option target 'ACCEPT'
        option proto 'udp'
        option dest_port '1234'
        option name 'Allow-Wireguard-Inbound'

config zone
        option name 'GuestZone'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        list network 'guest'

config forwarding
        option src 'GuestZone'
        option dest 'wan'

config rule
        option name 'Allow-Guest-DHCP-DNS'
        option src 'GuestZone'
        option dest_port '53 67 68'
        option target 'ACCEPT'

config zone
        option name 'lan_oi'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan_oi'

config zone
        option name 'wan_oi'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'

config forwarding
        option src 'lan_oi'
        option dest 'lan'

config forwarding
        option src 'lan'
        option dest 'lan_oi'

config forwarding
        option src 'lan_oi'
        option dest 'wan_oi'

package mwan3

config globals 'globals'
        option mmx_mask '0x3F00'

config interface 'wan'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wan6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config member 'wan_m1_w3'
        option interface 'wan'
        option metric '1'
        option weight '3'

config member 'wan_m2_w3'
        option interface 'wan'
        option metric '2'
        option weight '3'

config member 'wanb_m1_w2'
        option interface 'wanb'
        option metric '1'
        option weight '2'

config member 'wanb_m1_w3'
        option interface 'wanb'
        option metric '1'
        option weight '3'

config member 'wanb_m2_w2'
        option interface 'wanb'
        option metric '2'
        option weight '2'

config member 'wan6_m1_w3'
        option interface 'wan6'
        option metric '1'
        option weight '3'

config member 'wan6_m2_w3'
        option interface 'wan6'
        option metric '2'
        option weight '3'

config member 'wanb6_m1_w2'
        option interface 'wanb6'
        option metric '1'
        option weight '2'

config member 'wanb6_m1_w3'
        option interface 'wanb6'
        option metric '1'
        option weight '3'

config member 'wanb6_m2_w2'
        option interface 'wanb6'
        option metric '2'
        option weight '2'

config policy 'wan_only'
        list use_member 'wan_m1_w3'
        list use_member 'wan6_m1_w3'

config policy 'wanb_only'
        list use_member 'wanb_m1_w2'
        list use_member 'wanb6_m1_w2'

config policy 'balanced'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m1_w3'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m1_w3'

config policy 'wan_wanb'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m2_w2'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m2_w2'

config policy 'wanb_wan'
        list use_member 'wan_m2_w3'
        list use_member 'wanb_m1_w2'
        list use_member 'wan6_m2_w3'
        list use_member 'wanb6_m1_w2'

config rule 'https'
        option sticky '1'
        option dest_port '443'
        option proto 'tcp'
        option use_policy 'balanced'

config rule 'default_rule_v4'
        option dest_ip '0.0.0.0/0'
        option use_policy 'balanced'
        option family 'ipv4'

config rule 'default_rule_v6'
        option dest_ip '::/0'
        option use_policy 'balanced'
        option family 'ipv6'

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
26: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan.99
       valid_lft forever preferred_lft forever
27: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 10.20.30.1/24 brd 10.20.30.255 scope global br-lan.20
       valid_lft forever preferred_lft forever
28: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan.100
       valid_lft forever preferred_lft forever
29: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet <wanb_IPv4>/22 brd 100.67.3.255 scope global internet.10
       valid_lft forever preferred_lft forever
31: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 10.14.0.1/24 brd 10.14.0.255 scope global wg0
       valid_lft forever preferred_lft forever
32: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    inet <wan_IPv4> peer 62.155.240.37/32 scope global pppoe-wan
       valid_lft forever preferred_lft forever
default via 62.155.240.37 dev pppoe-wan table 1 proto static metric 10
10.14.0.0/24 dev wg0 table 1 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 1 proto static scope link
10.20.30.0/24 dev br-lan.20 table 1 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan table 1 proto kernel scope link src <wan_IPv4>
172.16.1.0/24 dev br-lan.100 table 1 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 1 proto kernel scope link src 192.168.1.1
default via 100.67.0.1 dev internet.10 table 3 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 table 3 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 3 proto static scope link
10.20.30.0/24 dev br-lan.20 table 3 proto kernel scope link src 10.20.30.1
100.67.0.0/22 dev internet.10 table 3 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 table 3 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 3 proto kernel scope link src 192.168.1.1
default via 62.155.240.37 dev pppoe-wan proto static metric 10
default via 100.67.0.1 dev internet.10 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 proto static scope link
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan proto kernel scope link src <wan_IPv4>
100.67.0.0/22 dev internet.10 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1
local 10.14.0.1 dev wg0 table local proto kernel scope host src 10.14.0.1
broadcast 10.14.0.255 dev wg0 table local proto kernel scope link src 10.14.0.1
local 10.20.30.1 dev br-lan.20 table local proto kernel scope host src 10.20.30.1
broadcast 10.20.30.255 dev br-lan.20 table local proto kernel scope link src 10.20.30.1
local <wan_IPv4> dev pppoe-wan table local proto kernel scope host src <wan_IPv4>
local <wanb_IPv4> dev internet.10 table local proto kernel scope host src <wanb_IPv4>
broadcast 100.67.3.255 dev internet.10 table local proto kernel scope link src <wanb_IPv4>
local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
local 172.16.1.1 dev br-lan.100 table local proto kernel scope host src 172.16.1.1
broadcast 172.16.1.255 dev br-lan.100 table local proto kernel scope link src 172.16.1.1
local 192.168.1.1 dev br-lan.99 table local proto kernel scope host src 192.168.1.1
broadcast 192.168.1.255 dev br-lan.99 table local proto kernel scope link src 192.168.1.1
0:      from all lookup local
1001:   from all iif pppoe-wan lookup 1
1003:   from all iif internet.10 lookup 3
2001:   from all fwmark 0x100/0x3f00 lookup 1
2003:   from all fwmark 0x300/0x3f00 lookup 3
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
3001:   from all fwmark 0x100/0x3f00 unreachable
3003:   from all fwmark 0x300/0x3f00 unreachable
32766:  from all lookup main
32767:  from all lookup default
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1504 state UP qlen 1000
    inet6 fe80::bce4:b0ff:fe2f:83f/64 scope link
       valid_lft forever preferred_lft forever
25: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
26: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 2003:cd:7f01:6c00::1/60 scope global dynamic noprefixroute
       valid_lft 81542sec preferred_lft 81542sec
    inet6 fdf8:373f:9a82:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fd46:b373:a44:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fdfd:6bc9:c800::1/60 scope global noprefixroute
       valid_lft forever preferred_lft forever
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
27: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
28: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
29: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b20/64 scope link
       valid_lft forever preferred_lft forever
30: internet.7@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b19/64 scope link
       valid_lft forever preferred_lft forever
32: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 state UNKNOWN qlen 3
    inet6 2003:cd:7fff:30a9:c531:3f3c:39f3:7e61/64 scope global dynamic noprefixroute
       valid_lft 13955sec preferred_lft 1355sec
    inet6 <wan_IPv6> peer fe80::86b5:9cff:fef9:5ab0/128 scope link
       valid_lft forever preferred_lft forever
33: phy0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
34: phy1-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
35: phy1-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
36: phy0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
default from 2003:cd:7f01:6c00::/56 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
default from 2003:cd:7fff:30a9::/64 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
2003:cd:7f01:6c00::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable 2003:cd:7f01:6c00::/56 dev lo proto static metric 2147483647 pref medium
2003:cd:7fff:30a9::/64 dev pppoe-wan proto kernel metric 256 expires 13954sec pref medium
unreachable 2003:cd:7fff:30a9::/64 dev lo proto static metric 2147483647 pref medium
fd46:b373:a44::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdf8:373f:9a82::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdfd:6bc9:c800::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable fdfd:6bc9:c800::/48 dev lo proto static metric 2147483647 pref medium
fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto kernel metric 256 pref medium
<wan_IPv6> dev pppoe-wan proto kernel metric 256 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev internet.7 proto kernel metric 256 pref medium
fe80::/64 dev internet.10 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.20 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.99 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.100 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap1 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap1 proto kernel metric 256 pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto ra metric 1024 expires 1354sec hoplimit 64 pref medium
local ::1 dev lo table local proto kernel metric 0 pref medium
anycast 2003:cd:7f01:6c00:: dev br-lan.99 table local proto kernel metric 0 pref medium
local 2003:cd:7f01:6c00::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast 2003:cd:7fff:30a9:: dev pppoe-wan table local proto kernel metric 0 pref medium
local 2003:cd:7fff:30a9:c531:3f3c:39f3:7e61 dev pppoe-wan table local proto kernel metric 0 pref medium
anycast fd46:b373:a44:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fd46:b373:a44:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdf8:373f:9a82:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdf8:373f:9a82:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdfd:6bc9:c800:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdfd:6bc9:c800::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev eth0 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.20 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.100 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.7 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.10 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap0 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2e dev phy0-ap1 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2f dev phy1-ap1 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.20 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.100 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b19 dev internet.7 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b20 dev internet.10 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2e dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2f dev phy1-ap0 table local proto kernel metric 0 pref medium
local fe80::bce4:b0ff:fe2f:83f dev eth0 table local proto kernel metric 0 pref medium
local <wan_IPv6> dev pppoe-wan table local proto kernel metric 0 pref medium
multicast ff00::/8 dev eth0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.99 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev wg0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.7 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.10 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.20 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.100 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev pppoe-wan table local proto kernel metric 256 pref medium
0:      from all lookup local
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
32766:  from all lookup main
4200000000:     from 2003:cd:7f01:6c00::1/60 iif br-lan.99 unreachable
lrwxrwxrwx    1 root     root            16 Mar 22 23:09 /etc/resolv.conf -> /tmp/resolv.conf
-rw-r--r--    1 root     root            47 Jun 20 21:17 /tmp/resolv.conf
-rw-r--r--    1 root     root           245 Jun 21 09:17 /tmp/resolv.conf.d/resolv.conf.auto
-rw-r--r--    1 root     root            53 Jun 20 21:17 /tmp/resolv.conf.ppp

/tmp/resolv.conf.d:
-rw-r--r--    1 root     root           245 Jun 21 09:17 resolv.conf.auto
==> /etc/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf.d <==
head: /tmp/resolv.conf.d: I/O error

==> /tmp/resolv.conf.ppp <==
nameserver 217.237.151.51
nameserver 217.237.149.205

==> /tmp/resolv.conf.d/resolv.conf.auto <==
# Interface wan_6
# Interface wan
nameserver 8.8.8.8
nameserver 8.8.1.1
nameserver 1.1.1.1
nameserver 2001:4860:4860::8888
nameserver 2001:4860:4860::8844
# Interface wanb
nameserver 185.89.39.194
nameserver 185.89.38.162
search internetnord.de
root@OpenWrt-EG:~#

Today I can't ping over wanb the google server, yesterday it did work. In the meantime I changed nothing. I get an IPv4 address from my ISP on WANB, so normally it should be connected.

I can try with a dedicated router for wanb for troubleshooting, if you want.

<wan_IPv4> -> public IPv4 address on wan
<wan_IPv6> -> public IPv6 address on wan
<wanb_IPv4> -> public IPv4 address on wanb

I restarted the wanb interface and now I can ping again with wanb the google server. So here is a new log:

root@OpenWrt-EG:~# ubus call system board; \
> uci export network; \
> uci export dhcp; uci export firewall; \
> uci export mwan3; \
> ip -4 addr ; ip -4 ro li tab all ; ip -4 ru; \
> ip -6 addr ; ip -6 ro li tab all ; ip -6 ru; \
> ls -l  /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/* ; head -n -0 /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/*
{
        "kernel": "5.15.150",
        "hostname": "OpenWrt-EG",
        "system": "MediaTek MT7621 ver:1 eco:3",
        "model": "D-Link COVR-X1860 A1",
        "board_name": "dlink,covr-x1860-a1",
        "rootfs_type": "squashfs",
        "release": {
                "distribution": "OpenWrt",
                "version": "23.05.3",
                "revision": "r23809-234f1a2efa",
                "target": "ramips/mt7621",
                "description": "OpenWrt 23.05.3 r23809-234f1a2efa"
        }
}
package network

config interface 'loopback'
        option device 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'
        option ula_prefix 'fdfd:6bc9:c800::/48'
        option packet_steering '1'

config device
        option name 'br-lan'
        option type 'bridge'
        list ports 'ethernet'
        list ports 'internet'

config device
        option name 'ethernet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'lan'
        option device 'br-lan.99'
        option proto 'static'
        option ipaddr '192.168.1.1'
        option netmask '255.255.255.0'
        option ip6assign '60'

config device
        option name 'internet'
        option macaddr '0c:0e:76:cf:6b:19'

config interface 'wan'
        option device 'internet.7'
        option proto 'pppoe'
        option password 'pw'
        option username 'user'
        list dns '8.8.8.8'
        list dns '8.8.1.1'
        list dns '1.1.1.1'
        list dns '2001:4860:4860::8888'
        list dns '2001:4860:4860::8844'
        option peerdns '0'
        option ipv6 'auto'
        option type 'bridge'
        option metric '10'

config interface 'wan6'
        option device 'internet.7'
        option proto 'dhcpv6'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '10'

config device
        option type '8021q'
        option ifname 'internet'
        option vid '7'
        option name 'internet.7'

config interface 'wg0'
        option proto 'wireguard'
        option private_key 'key'
        option listen_port '1234'
        list addresses '10.14.0.1/24'

config wireguard_wg0
        option persistent_keepalive '25'
        option description 'Florian_Android'
        list allowed_ips '10.14.0.3/32'
        option public_key 'key'

config wireguard_wg0
        option public_key 'key'
        option persistent_keepalive '25'
        option description 'Michael_BZ'
        list allowed_ips '10.14.0.4/32'

config route
        option interface 'wg0'
        option target '10.14.0.0'
        option netmask '255.255.0.0'

config interface 'guest'
        option proto 'static'
        option ipaddr '10.20.30.1'
        option netmask '255.255.255.0'
        option device 'br-lan.20'

config bridge-vlan
        option device 'br-lan'
        option vlan '20'
        list ports 'internet:t'

config bridge-vlan
        option device 'br-lan'
        option vlan '99'
        list ports 'ethernet:u*'
        list ports 'internet:u*'

config interface 'wanb'
        option proto 'dhcp'
        option device 'internet.10'
        option metric '20'

config interface 'wanb6'
        option proto 'dhcpv6'
        option device 'internet.10'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '20'

config interface 'lan_oi'
        option proto 'static'
        option device 'br-lan.100'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'

config bridge-vlan
        option device 'br-lan'
        option vlan '100'
        list ports 'ethernet:t'
        list ports 'internet:t'

config device
        option name 'internet.10'
        option type '8021q'
        option ifname 'internet'
        option vid '10'
        option macaddr '0C:0E:76:CF:6B:20'

package dhcp

config dnsmasq
        option domainneeded '1'
        option localise_queries '1'
        option rebind_protection '1'
        option rebind_localhost '1'
        option local '/lan/'
        option domain 'lan'
        option expandhosts '1'
        option cachesize '1000'
        option readethers '1'
        option leasefile '/tmp/dhcp.leases'
        option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
        option localservice '1'
        option ednspacket_max '1232'

config dhcp 'lan'
        option interface 'lan'
        option start '100'
        option limit '150'
        option leasetime '12h'
        option dhcpv4 'server'
        option dhcpv6 'server'
        option ra 'server'
        list ra_flags 'managed-config'
        list ra_flags 'other-config'

config dhcp 'wan'
        option interface 'wan'
        option ignore '1'

config odhcpd 'odhcpd'
        option maindhcp '0'
        option leasefile '/tmp/hosts/odhcpd'
        option leasetrigger '/usr/sbin/odhcpd-update'
        option loglevel '4'

config host
        option name 'switch'
        option dns '1'
        option mac '50:C7:BF:82:72:69'
        option ip '192.168.1.10'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'nas540'
        option dns '1'
        option mac '5C:F4:AB:5B:A5:62'
        option ip '192.168.1.20'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'gigasetgo'
        option dns '1'
        option mac '7C:2F:80:AA:39:F5'
        option ip '192.168.1.15'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'KP105'
        option mac '00:5F:67:02:3F:88'
        option ip '192.168.1.40'

config host
        option name 'KNX-IPRT-803C06'
        option dns '1'
        option mac 'CC:1B:E0:80:3C:06'
        option ip '192.168.1.50'

config dhcp 'guest'
        option interface 'guest'
        option start '100'
        option limit '150'
        option leasetime '12h'

config dhcp 'lan_oi'
        option interface 'lan_oi'
        option start '100'
        option limit '150'
        option leasetime '12h'

package firewall

config defaults
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option synflood_protect '1'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan'
        list network 'wg0'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan'
        list network 'wan6'
        list network 'wan_oi'
        list network 'wan_oi6'
        list network 'wanb'
        list network 'wanb6'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option dest 'lan'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest 'lan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option src '*'
        option target 'ACCEPT'
        option proto 'udp'
        option dest_port '1234'
        option name 'Allow-Wireguard-Inbound'

config zone
        option name 'GuestZone'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        list network 'guest'

config forwarding
        option src 'GuestZone'
        option dest 'wan'

config rule
        option name 'Allow-Guest-DHCP-DNS'
        option src 'GuestZone'
        option dest_port '53 67 68'
        option target 'ACCEPT'

config zone
        option name 'lan_oi'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan_oi'

config zone
        option name 'wan_oi'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'

config forwarding
        option src 'lan_oi'
        option dest 'lan'

config forwarding
        option src 'lan'
        option dest 'lan_oi'

config forwarding
        option src 'lan_oi'
        option dest 'wan_oi'

package mwan3

config globals 'globals'
        option mmx_mask '0x3F00'

config interface 'wan'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wan6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config member 'wan_m1_w3'
        option interface 'wan'
        option metric '1'
        option weight '3'

config member 'wan_m2_w3'
        option interface 'wan'
        option metric '2'
        option weight '3'

config member 'wanb_m1_w2'
        option interface 'wanb'
        option metric '1'
        option weight '2'

config member 'wanb_m1_w3'
        option interface 'wanb'
        option metric '1'
        option weight '3'

config member 'wanb_m2_w2'
        option interface 'wanb'
        option metric '2'
        option weight '2'

config member 'wan6_m1_w3'
        option interface 'wan6'
        option metric '1'
        option weight '3'

config member 'wan6_m2_w3'
        option interface 'wan6'
        option metric '2'
        option weight '3'

config member 'wanb6_m1_w2'
        option interface 'wanb6'
        option metric '1'
        option weight '2'

config member 'wanb6_m1_w3'
        option interface 'wanb6'
        option metric '1'
        option weight '3'

config member 'wanb6_m2_w2'
        option interface 'wanb6'
        option metric '2'
        option weight '2'

config policy 'wan_only'
        list use_member 'wan_m1_w3'
        list use_member 'wan6_m1_w3'

config policy 'wanb_only'
        list use_member 'wanb_m1_w2'
        list use_member 'wanb6_m1_w2'

config policy 'balanced'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m1_w3'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m1_w3'

config policy 'wan_wanb'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m2_w2'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m2_w2'

config policy 'wanb_wan'
        list use_member 'wan_m2_w3'
        list use_member 'wanb_m1_w2'
        list use_member 'wan6_m2_w3'
        list use_member 'wanb6_m1_w2'

config rule 'https'
        option sticky '1'
        option dest_port '443'
        option proto 'tcp'
        option use_policy 'balanced'

config rule 'default_rule_v4'
        option dest_ip '0.0.0.0/0'
        option use_policy 'balanced'
        option family 'ipv4'

config rule 'default_rule_v6'
        option dest_ip '::/0'
        option use_policy 'balanced'
        option family 'ipv6'

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
26: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan.99
       valid_lft forever preferred_lft forever
27: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 10.20.30.1/24 brd 10.20.30.255 scope global br-lan.20
       valid_lft forever preferred_lft forever
28: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan.100
       valid_lft forever preferred_lft forever
29: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet <wanb_IPv4>/22 brd 100.67.3.255 scope global internet.10
       valid_lft forever preferred_lft forever
31: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 10.14.0.1/24 brd 10.14.0.255 scope global wg0
       valid_lft forever preferred_lft forever
32: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    inet <wan_IPv4> peer 62.155.240.37/32 scope global pppoe-wan
       valid_lft forever preferred_lft forever
default via 62.155.240.37 dev pppoe-wan table 1 proto static metric 10
10.14.0.0/24 dev wg0 table 1 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 1 proto static scope link
10.20.30.0/24 dev br-lan.20 table 1 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan table 1 proto kernel scope link src <wan_IPv4>
172.16.1.0/24 dev br-lan.100 table 1 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 1 proto kernel scope link src 192.168.1.1
default via 100.67.0.1 dev internet.10 table 3 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 table 3 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 3 proto static scope link
10.20.30.0/24 dev br-lan.20 table 3 proto kernel scope link src 10.20.30.1
100.67.0.0/22 dev internet.10 table 3 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 table 3 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 3 proto kernel scope link src 192.168.1.1
default via 62.155.240.37 dev pppoe-wan proto static metric 10
default via 100.67.0.1 dev internet.10 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 proto static scope link
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan proto kernel scope link src <wan_IPv4>
100.67.0.0/22 dev internet.10 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1
local 10.14.0.1 dev wg0 table local proto kernel scope host src 10.14.0.1
broadcast 10.14.0.255 dev wg0 table local proto kernel scope link src 10.14.0.1
local 10.20.30.1 dev br-lan.20 table local proto kernel scope host src 10.20.30.1
broadcast 10.20.30.255 dev br-lan.20 table local proto kernel scope link src 10.20.30.1
local <wan_IPv4> dev pppoe-wan table local proto kernel scope host src <wan_IPv4>
local <wanb_IPv4> dev internet.10 table local proto kernel scope host src <wanb_IPv4>
broadcast 100.67.3.255 dev internet.10 table local proto kernel scope link src <wanb_IPv4>
local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
local 172.16.1.1 dev br-lan.100 table local proto kernel scope host src 172.16.1.1
broadcast 172.16.1.255 dev br-lan.100 table local proto kernel scope link src 172.16.1.1
local 192.168.1.1 dev br-lan.99 table local proto kernel scope host src 192.168.1.1
broadcast 192.168.1.255 dev br-lan.99 table local proto kernel scope link src 192.168.1.1
0:      from all lookup local
1001:   from all iif pppoe-wan lookup 1
1003:   from all iif internet.10 lookup 3
2001:   from all fwmark 0x100/0x3f00 lookup 1
2003:   from all fwmark 0x300/0x3f00 lookup 3
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
3001:   from all fwmark 0x100/0x3f00 unreachable
3003:   from all fwmark 0x300/0x3f00 unreachable
32766:  from all lookup main
32767:  from all lookup default
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1504 state UP qlen 1000
    inet6 fe80::bce4:b0ff:fe2f:83f/64 scope link
       valid_lft forever preferred_lft forever
25: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
26: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 2003:cd:7f01:6c00::1/60 scope global dynamic noprefixroute
       valid_lft 80153sec preferred_lft 80153sec
    inet6 fdf8:373f:9a82:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fd46:b373:a44:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fdfd:6bc9:c800::1/60 scope global noprefixroute
       valid_lft forever preferred_lft forever
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
27: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
28: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
29: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b20/64 scope link
       valid_lft forever preferred_lft forever
30: internet.7@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b19/64 scope link
       valid_lft forever preferred_lft forever
32: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 state UNKNOWN qlen 3
    inet6 2003:cd:7fff:30a9:c531:3f3c:39f3:7e61/64 scope global dynamic noprefixroute
       valid_lft 14374sec preferred_lft 1774sec
    inet6 <wan_IPv6> peer fe80::86b5:9cff:fef9:5ab0/128 scope link
       valid_lft forever preferred_lft forever
33: phy0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
34: phy1-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
35: phy1-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
36: phy0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
default from 2003:cd:7f01:6c00::/56 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
default from 2003:cd:7fff:30a9::/64 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
2003:cd:7f01:6c00::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable 2003:cd:7f01:6c00::/56 dev lo proto static metric 2147483647 pref medium
2003:cd:7fff:30a9::/64 dev pppoe-wan proto kernel metric 256 expires 14373sec pref medium
unreachable 2003:cd:7fff:30a9::/64 dev lo proto static metric 2147483647 pref medium
fd46:b373:a44::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdf8:373f:9a82::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdfd:6bc9:c800::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable fdfd:6bc9:c800::/48 dev lo proto static metric 2147483647 pref medium
fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto kernel metric 256 pref medium
<wan_IPv6> dev pppoe-wan proto kernel metric 256 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev internet.7 proto kernel metric 256 pref medium
fe80::/64 dev internet.10 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.20 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.99 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.100 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap1 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap1 proto kernel metric 256 pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto ra metric 1024 expires 1773sec hoplimit 64 pref medium
default via fe80::26a5:2cff:febb:b181 dev internet.10 proto ra metric 1024 expires 1747sec pref medium
local ::1 dev lo table local proto kernel metric 0 pref medium
anycast 2003:cd:7f01:6c00:: dev br-lan.99 table local proto kernel metric 0 pref medium
local 2003:cd:7f01:6c00::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast 2003:cd:7fff:30a9:: dev pppoe-wan table local proto kernel metric 0 pref medium
local 2003:cd:7fff:30a9:c531:3f3c:39f3:7e61 dev pppoe-wan table local proto kernel metric 0 pref medium
anycast fd46:b373:a44:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fd46:b373:a44:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdf8:373f:9a82:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdf8:373f:9a82:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdfd:6bc9:c800:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdfd:6bc9:c800::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev eth0 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.20 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.100 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.7 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.10 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap0 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2e dev phy0-ap1 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2f dev phy1-ap1 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.20 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.100 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b19 dev internet.7 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b20 dev internet.10 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2e dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2f dev phy1-ap0 table local proto kernel metric 0 pref medium
local fe80::bce4:b0ff:fe2f:83f dev eth0 table local proto kernel metric 0 pref medium
local <wan_IPv6> dev pppoe-wan table local proto kernel metric 0 pref medium
multicast ff00::/8 dev eth0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.99 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev wg0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.7 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.10 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.20 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.100 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev pppoe-wan table local proto kernel metric 256 pref medium
0:      from all lookup local
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
32766:  from all lookup main
4200000000:     from 2003:cd:7f01:6c00::1/60 iif br-lan.99 unreachable
lrwxrwxrwx    1 root     root            16 Mar 22 23:09 /etc/resolv.conf -> /tmp/resolv.conf
-rw-r--r--    1 root     root            47 Jun 20 21:17 /tmp/resolv.conf
-rw-r--r--    1 root     root           245 Jun 21 11:00 /tmp/resolv.conf.d/resolv.conf.auto
-rw-r--r--    1 root     root            53 Jun 20 21:17 /tmp/resolv.conf.ppp

/tmp/resolv.conf.d:
-rw-r--r--    1 root     root           245 Jun 21 11:00 resolv.conf.auto
==> /etc/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf.d <==
head: /tmp/resolv.conf.d: I/O error

==> /tmp/resolv.conf.ppp <==
nameserver 217.237.151.51
nameserver 217.237.149.205

==> /tmp/resolv.conf.d/resolv.conf.auto <==
# Interface wan_6
# Interface wan
nameserver 8.8.8.8
nameserver 8.8.1.1
nameserver 1.1.1.1
nameserver 2001:4860:4860::8888
nameserver 2001:4860:4860::8844
# Interface wanb
nameserver 185.89.39.194
nameserver 185.89.38.162
search internetnord.de
root@OpenWrt-EG:~#

If you are using auto, there will be a wan_6 interface created automatically.
Either leave it to auto, delete wan6, and adjust your configuration, or change it to 1.

Not needed.

wanb6 doesn't have any IPv6 from ISP, you should remove it from the mwan3.

Finally the rules in mwan3 are only load balancing, while you need a rule to use wan for the lan and wanb for the guest.

1 Like

I did your suggestions. Thank you! I corrected the auto-option to 1 for wan. But then mwan3 thinks the wan6 is disabled although it's enabled in the config.

I speciefied explicit rules for my source networks to use dedicated wan ports. If I'm using both wan ports it breaks my internet for the IPv6 devices.

If I'm disabling the wan port and only use wanb without mwan3, it works (without IPv6 of course).

Very strange.

Can you post once again the configuration as above?

Again here are the logs.
Also my wireguard connection now doesn't work anymore. I commented out the route:

config route
        option interface 'wg0'
        option target '10.14.0.0'
        option netmask '255.255.0.0'

I tried it without the config route and then again with config route. Both options are now broken, so the problem is not here.

MWAN3 shows me no connection on the wan6 interface although I changed the auto option and now no new interface appears when connection via pppoe:


Is this looking correct? I expected an IPv6 address on the wan6 interface but it's not showing any address.

And in mwan3 I created following rules:

root@OpenWrt-EG:~# ubus call system board; \
> uci export network; \
> uci export dhcp; uci export firewall; \
> uci export mwan3; \
> ip -4 addr ; ip -4 ro li tab all ; ip -4 ru; \
> ip -6 addr ; ip -6 ro li tab all ; ip -6 ru; \
> ls -l  /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/* ; head -n -0 /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/*
{
        "kernel": "5.15.150",
        "hostname": "OpenWrt-EG",
        "system": "MediaTek MT7621 ver:1 eco:3",
        "model": "D-Link COVR-X1860 A1",
        "board_name": "dlink,covr-x1860-a1",
        "rootfs_type": "squashfs",
        "release": {
                "distribution": "OpenWrt",
                "version": "23.05.3",
                "revision": "r23809-234f1a2efa",
                "target": "ramips/mt7621",
                "description": "OpenWrt 23.05.3 r23809-234f1a2efa"
        }
}
package network

config interface 'loopback'
        option device 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'
        option ula_prefix 'fdfd:6bc9:c800::/48'
        option packet_steering '1'

config device
        option name 'br-lan'
        option type 'bridge'
        list ports 'ethernet'
        list ports 'internet'

config device
        option name 'ethernet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'lan'
        option device 'br-lan.99'
        option proto 'static'
        option ipaddr '192.168.1.1'
        option netmask '255.255.255.0'
        option ip6assign '60'

config device
        option name 'internet'
        option macaddr '0c:0e:76:cf:6b:19'

config interface 'wan'
        option device 'internet.7'
        option proto 'pppoe'
        option password 'pw'
        option username 'user'
        list dns '8.8.8.8'
        list dns '8.8.1.1'
        list dns '1.1.1.1'
        list dns '2001:4860:4860::8888'
        list dns '2001:4860:4860::8844'
        option peerdns '0'
        option ipv6 '1'
        option type 'bridge'
        option metric '10'

config interface 'wan6'
        option device 'internet.7'
        option proto 'dhcpv6'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '10'

config device
        option type '8021q'
        option ifname 'internet'
        option vid '7'
        option name 'internet.7'

config interface 'wg0'
        option proto 'wireguard'
        option private_key 'key'
        option listen_port '1234'
        list addresses '10.14.0.1/24'

config wireguard_wg0
        option persistent_keepalive '25'
        option description 'Florian_Android'
        list allowed_ips '10.14.0.3/32'
        option public_key 'key'

config wireguard_wg0
        option public_key 'key'
        option persistent_keepalive '25'
        option description 'Michael_BZ'
        list allowed_ips '10.14.0.4/32'

config route
        option interface 'wg0'
        option target '10.14.0.0'
        option netmask '255.255.0.0'

config interface 'guest'
        option proto 'static'
        option ipaddr '10.20.30.1'
        option netmask '255.255.255.0'
        option device 'br-lan.20'

config bridge-vlan
        option device 'br-lan'
        option vlan '20'
        list ports 'internet:t'

config bridge-vlan
        option device 'br-lan'
        option vlan '99'
        list ports 'ethernet:u*'
        list ports 'internet:u*'

config interface 'wanb'
        option proto 'dhcp'
        option device 'internet.10'
        option metric '20'

config interface 'wanb6'
        option proto 'dhcpv6'
        option device 'internet.10'
        option reqaddress 'try'
        option reqprefix 'auto'
        option metric '20'

config interface 'lan_oi'
        option proto 'static'
        option device 'br-lan.100'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'

config bridge-vlan
        option device 'br-lan'
        option vlan '100'
        list ports 'ethernet:t'
        list ports 'internet:t'

config device
        option name 'internet.10'
        option type '8021q'
        option ifname 'internet'
        option vid '10'
        option macaddr '0C:0E:76:CF:6B:20'

package dhcp

config dnsmasq
        option domainneeded '1'
        option localise_queries '1'
        option rebind_protection '1'
        option rebind_localhost '1'
        option local '/lan/'
        option domain 'lan'
        option expandhosts '1'
        option cachesize '1000'
        option readethers '1'
        option leasefile '/tmp/dhcp.leases'
        option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
        option localservice '1'
        option ednspacket_max '1232'

config dhcp 'lan'
        option interface 'lan'
        option start '100'
        option limit '150'
        option leasetime '12h'
        option dhcpv4 'server'
        option dhcpv6 'server'
        option ra 'server'
        list ra_flags 'managed-config'
        list ra_flags 'other-config'

config dhcp 'wan'
        option interface 'wan'
        option ignore '1'

config odhcpd 'odhcpd'
        option maindhcp '0'
        option leasefile '/tmp/hosts/odhcpd'
        option leasetrigger '/usr/sbin/odhcpd-update'
        option loglevel '4'

config host
        option name 'switch'
        option dns '1'
        option mac '50:C7:BF:82:72:69'
        option ip '192.168.1.10'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'nas540'
        option dns '1'
        option mac '5C:F4:AB:5B:A5:62'
        option ip '192.168.1.20'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'gigasetgo'
        option dns '1'
        option mac '7C:2F:80:AA:39:F5'
        option ip '192.168.1.15'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'KP105'
        option mac '00:5F:67:02:3F:88'
        option ip '192.168.1.40'

config host
        option name 'KNX-IPRT-803C06'
        option dns '1'
        option mac 'CC:1B:E0:80:3C:06'
        option ip '192.168.1.50'

config dhcp 'guest'
        option interface 'guest'
        option start '100'
        option limit '150'
        option leasetime '12h'

config dhcp 'lan_oi'
        option interface 'lan_oi'
        option start '100'
        option limit '150'
        option leasetime '12h'

package firewall

config defaults
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option synflood_protect '1'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan'
        list network 'wg0'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan'
        list network 'wan6'
        list network 'wan_oi'
        list network 'wan_oi6'
        list network 'wanb'
        list network 'wanb6'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option dest 'lan'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest 'lan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option src '*'
        option target 'ACCEPT'
        option proto 'udp'
        option dest_port '1234'
        option name 'Allow-Wireguard-Inbound'

config zone
        option name 'GuestZone'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        list network 'guest'

config forwarding
        option src 'GuestZone'
        option dest 'wan'

config rule
        option name 'Allow-Guest-DHCP-DNS'
        option src 'GuestZone'
        option dest_port '53 67 68'
        option target 'ACCEPT'

config zone
        option name 'lan_oi'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan_oi'

config zone
        option name 'wan_oi'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'

config forwarding
        option src 'lan_oi'
        option dest 'lan'

config forwarding
        option src 'lan'
        option dest 'lan_oi'

config forwarding
        option src 'lan_oi'
        option dest 'wan_oi'

package mwan3

config globals 'globals'
        option mmx_mask '0x3F00'

config interface 'wan'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wan6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config member 'wan_m1_w3'
        option interface 'wan'
        option metric '1'
        option weight '3'

config member 'wan_m2_w3'
        option interface 'wan'
        option metric '2'
        option weight '3'

config member 'wanb_m1_w2'
        option interface 'wanb'
        option metric '1'
        option weight '2'

config member 'wanb_m1_w3'
        option interface 'wanb'
        option metric '1'
        option weight '3'

config member 'wanb_m2_w2'
        option interface 'wanb'
        option metric '2'
        option weight '2'

config member 'wan6_m1_w3'
        option interface 'wan6'
        option metric '1'
        option weight '3'

config member 'wan6_m2_w3'
        option interface 'wan6'
        option metric '2'
        option weight '3'

config member 'wanb6_m1_w2'
        option interface 'wanb6'
        option metric '1'
        option weight '2'

config member 'wanb6_m1_w3'
        option interface 'wanb6'
        option metric '1'
        option weight '3'

config member 'wanb6_m2_w2'
        option interface 'wanb6'
        option metric '2'
        option weight '2'

config policy 'wan_only'
        list use_member 'wan_m1_w3'
        list use_member 'wan6_m1_w3'

config policy 'wanb_only'
        list use_member 'wanb_m1_w2'
        list use_member 'wanb6_m1_w2'

config policy 'balanced'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m1_w3'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m1_w3'

config policy 'wan_wanb'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m2_w2'
        list use_member 'wan6_m1_w3'
        list use_member 'wanb6_m2_w2'

config policy 'wanb_wan'
        list use_member 'wan_m2_w3'
        list use_member 'wanb_m1_w2'
        list use_member 'wan6_m2_w3'
        list use_member 'wanb6_m1_w2'

config rule 'guest'
        option family 'ipv4'
        option proto 'all'
        option src_ip '10.20.30.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan_oi'
        option family 'ipv4'
        option proto 'all'
        option src_ip '172.16.1.0/0'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan'
        option proto 'all'
        option src_ip '192.168.1.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wan_only'

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
52: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan.99
       valid_lft forever preferred_lft forever
53: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 10.20.30.1/24 brd 10.20.30.255 scope global br-lan.20
       valid_lft forever preferred_lft forever
54: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan.100
       valid_lft forever preferred_lft forever
55: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet <wanb_IPv4>/21 brd 100.67.47.255 scope global internet.10
       valid_lft forever preferred_lft forever
57: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 10.14.0.1/24 brd 10.14.0.255 scope global wg0
       valid_lft forever preferred_lft forever
59: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    inet <wan_IPv4> peer 62.155.240.37/32 scope global pppoe-wan
       valid_lft forever preferred_lft forever
default via 62.155.240.37 dev pppoe-wan table 1 proto static metric 10
10.14.0.0/24 dev wg0 table 1 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 1 proto static scope link
10.20.30.0/24 dev br-lan.20 table 1 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan table 1 proto kernel scope link src <wan_IPv4>
172.16.1.0/24 dev br-lan.100 table 1 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 1 proto kernel scope link src 192.168.1.1
default via 100.67.40.1 dev internet.10 table 3 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 table 3 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 table 3 proto static scope link
10.20.30.0/24 dev br-lan.20 table 3 proto kernel scope link src 10.20.30.1
100.67.40.0/21 dev internet.10 table 3 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 table 3 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 3 proto kernel scope link src 192.168.1.1
default via 62.155.240.37 dev pppoe-wan proto static metric 10
default via 100.67.40.1 dev internet.10 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1
10.14.0.0/16 dev wg0 proto static scope link
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan proto kernel scope link src <wan_IPv4>
100.67.40.0/21 dev internet.10 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1
local 10.14.0.1 dev wg0 table local proto kernel scope host src 10.14.0.1
broadcast 10.14.0.255 dev wg0 table local proto kernel scope link src 10.14.0.1
local 10.20.30.1 dev br-lan.20 table local proto kernel scope host src 10.20.30.1
broadcast 10.20.30.255 dev br-lan.20 table local proto kernel scope link src 10.20.30.1
local <wanb_IPv4> dev internet.10 table local proto kernel scope host src <wanb_IPv4>
broadcast 100.67.47.255 dev internet.10 table local proto kernel scope link src <wanb_IPv4>
local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
local 172.16.1.1 dev br-lan.100 table local proto kernel scope host src 172.16.1.1
broadcast 172.16.1.255 dev br-lan.100 table local proto kernel scope link src 172.16.1.1
local 192.168.1.1 dev br-lan.99 table local proto kernel scope host src 192.168.1.1
broadcast 192.168.1.255 dev br-lan.99 table local proto kernel scope link src 192.168.1.1
local <wan_IPv4> dev pppoe-wan table local proto kernel scope host src <wan_IPv4>
0:      from all lookup local
1001:   from all iif pppoe-wan lookup 1
1003:   from all iif internet.10 lookup 3
2001:   from all fwmark 0x100/0x3f00 lookup 1
2003:   from all fwmark 0x300/0x3f00 lookup 3
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
3001:   from all fwmark 0x100/0x3f00 unreachable
3003:   from all fwmark 0x300/0x3f00 unreachable
32766:  from all lookup main
32767:  from all lookup default
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1504 state UP qlen 1000
    inet6 fe80::bce4:b0ff:fe2f:83f/64 scope link
       valid_lft forever preferred_lft forever
51: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
52: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fda0:1017:eb8c:872a:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft 1745sec preferred_lft 1745sec
    inet6 fdf8:373f:9a82:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fd46:b373:a44:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fdfd:6bc9:c800::1/60 scope global noprefixroute
       valid_lft forever preferred_lft forever
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
53: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
54: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
55: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b20/64 scope link
       valid_lft forever preferred_lft forever
56: internet.7@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b19/64 scope link
       valid_lft forever preferred_lft forever
58: phy0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
59: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 state UNKNOWN qlen 3
    inet6 2003:cd:7fff:59:94a9:2e4f:5cf0:ec8b/64 scope global dynamic mngtmpaddr
       valid_lft 14063sec preferred_lft 1463sec
    inet6 <wan_IPv6> peer fe80::86b5:9cff:fef9:5ab0/128 scope link
       valid_lft forever preferred_lft forever
60: phy1-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
61: phy1-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
62: phy0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
2003:cd:7fff:59::/64 dev pppoe-wan proto kernel metric 256 expires 14062sec pref medium
fd46:b373:a44::/64 dev br-lan.99 proto kernel metric 256 pref medium
fda0:1017:eb8c:872a::/64 dev br-lan.99 proto kernel metric 256 expires 1744sec pref medium
fdf8:373f:9a82::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdfd:6bc9:c800::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable fdfd:6bc9:c800::/48 dev lo proto static metric 2147483647 pref medium
fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto kernel metric 256 pref medium
<wan_IPv6> dev pppoe-wan proto kernel metric 256 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev internet.7 proto kernel metric 256 pref medium
fe80::/64 dev internet.10 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.20 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.99 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.100 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap1 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap1 proto kernel metric 256 pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto ra metric 1024 expires 1462sec hoplimit 64 pref medium
default via fe80::26a5:2cff:febb:b181 dev internet.10 proto ra metric 1024 expires 1457sec pref medium
local ::1 dev lo table local proto kernel metric 0 pref medium
anycast 2003:cd:7fff:59:: dev pppoe-wan table local proto kernel metric 0 pref medium
local 2003:cd:7fff:59:94a9:2e4f:5cf0:ec8b dev pppoe-wan table local proto kernel metric 0 pref medium
anycast fd46:b373:a44:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fd46:b373:a44:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fda0:1017:eb8c:872a:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fda0:1017:eb8c:872a:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdf8:373f:9a82:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdf8:373f:9a82:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdfd:6bc9:c800:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdfd:6bc9:c800::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev eth0 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.100 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.7 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.20 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.10 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap0 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2e dev phy0-ap1 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2f dev phy1-ap1 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.100 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.20 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b19 dev internet.7 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b20 dev internet.10 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2e dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2f dev phy1-ap0 table local proto kernel metric 0 pref medium
local <wan_IPv6> dev pppoe-wan table local proto kernel metric 0 pref medium
local fe80::bce4:b0ff:fe2f:83f dev eth0 table local proto kernel metric 0 pref medium
multicast ff00::/8 dev eth0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.99 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev wg0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.7 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.10 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.20 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.100 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev pppoe-wan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap1 table local proto kernel metric 256 pref medium
0:      from all lookup local
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
32766:  from all lookup main
lrwxrwxrwx    1 root     root            16 Mar 22 23:09 /etc/resolv.conf -> /tmp/resolv.conf
-rw-r--r--    1 root     root            47 Jun 22 13:47 /tmp/resolv.conf
-rw-r--r--    1 root     root           227 Jun 22 13:47 /tmp/resolv.conf.d/resolv.conf.auto
-rw-r--r--    1 root     root            53 Jun 22 13:47 /tmp/resolv.conf.ppp

/tmp/resolv.conf.d:
-rw-r--r--    1 root     root           227 Jun 22 13:47 resolv.conf.auto
==> /etc/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf.d <==
head: /tmp/resolv.conf.d: I/O error

==> /tmp/resolv.conf.ppp <==
nameserver 217.237.151.51
nameserver 217.237.149.205

==> /tmp/resolv.conf.d/resolv.conf.auto <==
# Interface wan
nameserver 8.8.8.8
nameserver 8.8.1.1
nameserver 1.1.1.1
nameserver 2001:4860:4860::8888
nameserver 2001:4860:4860::8844
# Interface wanb
nameserver 185.89.39.194
nameserver 185.89.38.162
search internetnord.de
root@OpenWrt-EG:~#


Here is the speed test on my smartphone with mwan3 (no load balancing but every network get its wan)

Here with mwan3 disabled. I can browse without issues.

Looks like there is no delegated prefix from the wan6. All the addresses you have in lan are ULA.

Mask is wrong.

You keep using wanb6 in mwan3 configuration, although the interface is not defined in mwan3.

There are no rules for IPv6 in mwan3.

In firewall you allow lan_oi to wan_oi only, but wan_oi zone doesn't have any interfaces.

The route is anyway wrong, as you have a /24 on the interface but you set a static route for /16. And you don't need it because it is already in the routing table as directly connected.

Sorry, can you explain what ULA and the delegated prefix means? Is it something I have to configure in the mwan3 config or in the network config?

I corrected that to the right subnet mask (/24).

I just deleted the mwanb6 interface in the mwan3 config but kept it under the member section. So I should delete it there as well? I guess I need to delete also the policies of the wanb6 interfaces although I don't use them?

Yes, I configured first a complete new set of fw rules for the wanb interface (named wan_oi as fw zone). But then it didn't work as expected and I just removed all rules and put the wanb interfaces in the wan-fw-zone. So there are no client atm on the lan_oi so I don't care about the empty zone. I will clean up the rules when the most basic things are working.

OK, I just commented out the static route in the network config.

I forgot to mention that I created an IPv6 rule in mwan3 now:

I ran your logging commands again with the latest changes:

root@OpenWrt-EG:~# ubus call system board; \
> uci export network; \
> uci export dhcp; uci export firewall; \
> uci export mwan3; \
-4 addr > ip -4 addr ; ip -4 ro li tab all ; ip -4 ru; \
ip -6 ad> ip -6 addr ; ip -6 ro li tab all ; ip -6 ru; \
> ls -l  /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/* ; head -n -0 /etc/resolv.* /tmp/resolv.* /tmp/resolv.*/*
{
        "kernel": "5.15.150",
        "hostname": "OpenWrt-EG",
        "system": "MediaTek MT7621 ver:1 eco:3",
        "model": "D-Link COVR-X1860 A1",
        "board_name": "dlink,covr-x1860-a1",
        "rootfs_type": "squashfs",
        "release": {
                "distribution": "OpenWrt",
                "version": "23.05.3",
                "revision": "r23809-234f1a2efa",
                "target": "ramips/mt7621",
                "description": "OpenWrt 23.05.3 r23809-234f1a2efa"
        }
}
package network

config interface 'loopback'
        option device 'lo'
        option proto 'static'
        option ipaddr '127.0.0.1'
        option netmask '255.0.0.0'

config globals 'globals'
        option ula_prefix 'fdfd:6bc9:c800::/48'
        option packet_steering '1'

config device
        option name 'br-lan'
        option type 'bridge'
        list ports 'ethernet'
        list ports 'internet'

config device
        option name 'ethernet'
        option macaddr '0c:0e:76:cf:6b:18'

config interface 'lan'
        option device 'br-lan.99'
        option proto 'static'
        option ipaddr '192.168.1.1'
        option netmask '255.255.255.0'
        option ip6assign '60'

config device
        option name 'internet'
        option macaddr '0c:0e:76:cf:6b:19'

config interface 'wan'
        option device 'internet.7'
        option proto 'pppoe'
        option password 'user'
        option username 'pw'
        list dns '8.8.8.8'
        list dns '8.8.1.1'
        list dns '1.1.1.1'
        list dns '2001:4860:4860::8888'
        list dns '2001:4860:4860::8844'
        option peerdns '0'
        option ipv6 'auto'
        option type 'bridge'
        option metric '10'

config device
        option type '8021q'
        option ifname 'internet'
        option vid '7'
        option name 'internet.7'

config interface 'wg0'
        option proto 'wireguard'
        option private_key 'key'
        option listen_port '1234'
        list addresses '10.14.0.1/24'

config wireguard_wg0
        option persistent_keepalive '25'
        option description 'Florian_Android'
        list allowed_ips '10.14.0.3/32'
        option public_key 'key'

config wireguard_wg0
        option public_key 'key'
        option persistent_keepalive '25'
        option description 'Michael_BZ'
        list allowed_ips '10.14.0.4/32'

config interface 'guest'
        option proto 'static'
        option ipaddr '10.20.30.1'
        option netmask '255.255.255.0'
        option device 'br-lan.20'

config bridge-vlan
        option device 'br-lan'
        option vlan '20'
        list ports 'internet:t'

config bridge-vlan
        option device 'br-lan'
        option vlan '99'
        list ports 'ethernet:u*'
        list ports 'internet:u*'

config interface 'wanb'
        option proto 'dhcp'
        option device 'internet.10'
        option metric '20'
        option ipv6 'auto'

config interface 'lan_oi'
        option proto 'static'
        option device 'br-lan.100'
        option ipaddr '172.16.1.1'
        option netmask '255.255.255.0'

config bridge-vlan
        option device 'br-lan'
        option vlan '100'
        list ports 'ethernet:t'
        list ports 'internet:t'

config device
        option name 'internet.10'
        option type '8021q'
        option ifname 'internet'
        option vid '10'
        option macaddr '0C:0E:76:CF:6B:20'

package dhcp

config dnsmasq
        option domainneeded '1'
        option localise_queries '1'
        option rebind_protection '1'
        option rebind_localhost '1'
        option local '/lan/'
        option domain 'lan'
        option expandhosts '1'
        option cachesize '1000'
        option readethers '1'
        option leasefile '/tmp/dhcp.leases'
        option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
        option localservice '1'
        option ednspacket_max '1232'

config dhcp 'lan'
        option interface 'lan'
        option start '100'
        option limit '150'
        option leasetime '12h'
        option dhcpv4 'server'
        option dhcpv6 'server'
        option ra 'server'
        list ra_flags 'managed-config'
        list ra_flags 'other-config'

config dhcp 'wan'
        option interface 'wan'
        option ignore '1'

config odhcpd 'odhcpd'
        option maindhcp '0'
        option leasefile '/tmp/hosts/odhcpd'
        option leasetrigger '/usr/sbin/odhcpd-update'
        option loglevel '4'

config host
        option name 'switch'
        option dns '1'
        option mac '50:C7:BF:82:72:69'
        option ip '192.168.1.10'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'nas540'
        option dns '1'
        option mac '5C:F4:AB:5B:A5:62'
        option ip '192.168.1.20'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'gigasetgo'
        option dns '1'
        option mac '7C:2F:80:AA:39:F5'
        option ip '192.168.1.15'
        option leasetime '24h'
        option duid '0001000118072fd300235adb4560'

config host
        option name 'KP105'
        option mac '00:5F:67:02:3F:88'
        option ip '192.168.1.40'

config host
        option name 'KNX-IPRT-803C06'
        option dns '1'
        option mac 'CC:1B:E0:80:3C:06'
        option ip '192.168.1.50'

config dhcp 'guest'
        option interface 'guest'
        option start '100'
        option limit '150'
        option leasetime '12h'

config dhcp 'lan_oi'
        option interface 'lan_oi'
        option start '100'
        option limit '150'
        option leasetime '12h'

package firewall

config defaults
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option synflood_protect '1'

config zone
        option name 'lan'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan'
        list network 'wg0'

config zone
        option name 'wan'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'
        list network 'wan'
        list network 'wan6'
        list network 'wan_oi'
        list network 'wan_oi6'
        list network 'wanb'
        list network 'wanb6'

config forwarding
        option src 'lan'
        option dest 'wan'

config rule
        option name 'Allow-DHCP-Renew'
        option src 'wan'
        option proto 'udp'
        option dest_port '68'
        option target 'ACCEPT'
        option family 'ipv4'

config rule
        option name 'Allow-Ping'
        option src 'wan'
        option proto 'icmp'
        option icmp_type 'echo-request'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-IGMP'
        option src 'wan'
        option proto 'igmp'
        option family 'ipv4'
        option target 'ACCEPT'

config rule
        option name 'Allow-DHCPv6'
        option src 'wan'
        option proto 'udp'
        option dest_port '546'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-MLD'
        option src 'wan'
        option proto 'icmp'
        option src_ip 'fe80::/10'
        list icmp_type '130/0'
        list icmp_type '131/0'
        list icmp_type '132/0'
        list icmp_type '143/0'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Input'
        option src 'wan'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        list icmp_type 'router-solicitation'
        list icmp_type 'neighbour-solicitation'
        list icmp_type 'router-advertisement'
        list icmp_type 'neighbour-advertisement'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-ICMPv6-Forward'
        option src 'wan'
        option dest '*'
        option proto 'icmp'
        list icmp_type 'echo-request'
        list icmp_type 'echo-reply'
        list icmp_type 'destination-unreachable'
        list icmp_type 'packet-too-big'
        list icmp_type 'time-exceeded'
        list icmp_type 'bad-header'
        list icmp_type 'unknown-header-type'
        option limit '1000/sec'
        option family 'ipv6'
        option target 'ACCEPT'

config rule
        option name 'Allow-IPSec-ESP'
        option src 'wan'
        option dest 'lan'
        option proto 'esp'
        option target 'ACCEPT'

config rule
        option name 'Allow-ISAKMP'
        option src 'wan'
        option dest 'lan'
        option dest_port '500'
        option proto 'udp'
        option target 'ACCEPT'

config rule
        option target 'ACCEPT'
        option src 'wan'
        option name 'Allow-UPD-IPTV'
        option family 'ipv4'
        option proto 'udp'

config rule
        option src '*'
        option target 'ACCEPT'
        option proto 'udp'
        option dest_port '1234'
        option name 'Allow-Wireguard-Inbound'

config zone
        option name 'GuestZone'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        list network 'guest'

config forwarding
        option src 'GuestZone'
        option dest 'wan'

config rule
        option name 'Allow-Guest-DHCP-DNS'
        option src 'GuestZone'
        option dest_port '53 67 68'
        option target 'ACCEPT'

config zone
        option name 'lan_oi'
        option input 'ACCEPT'
        option output 'ACCEPT'
        option forward 'ACCEPT'
        list network 'lan_oi'

config zone
        option name 'wan_oi'
        option input 'REJECT'
        option output 'ACCEPT'
        option forward 'REJECT'
        option masq '1'
        option mtu_fix '1'

config forwarding
        option src 'lan_oi'
        option dest 'lan'

config forwarding
        option src 'lan'
        option dest 'lan_oi'

config forwarding
        option src 'lan_oi'
        option dest 'wan_oi'

package mwan3

config globals 'globals'
        option mmx_mask '0x3F00'

config interface 'wan'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wan_6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config member 'wan_m1_w3'
        option interface 'wan'
        option metric '1'
        option weight '3'

config member 'wan_m2_w3'
        option interface 'wan'
        option metric '2'
        option weight '3'

config member 'wanb_m1_w2'
        option interface 'wanb'
        option metric '1'
        option weight '2'

config member 'wanb_m1_w3'
        option interface 'wanb'
        option metric '1'
        option weight '3'

config member 'wanb_m2_w2'
        option interface 'wanb'
        option metric '2'
        option weight '2'

config member 'wan6_m1_w3'
        option interface 'wan6'
        option metric '1'
        option weight '3'

config member 'wan6_m2_w3'
        option interface 'wan6'
        option metric '2'
        option weight '3'

config policy 'wan_only'
        list use_member 'wan_m1_w3'
        list use_member 'wan6_m1_w3'

config policy 'wanb_only'
        list use_member 'wanb_m1_w2'
        option last_resort 'unreachable'

config policy 'balanced'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m1_w3'
        list use_member 'wan6_m1_w3'
        option last_resort 'unreachable'

config policy 'wan_wanb'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m2_w2'
        list use_member 'wan6_m1_w3'
        option last_resort 'unreachable'

config policy 'wanb_wan'
        list use_member 'wan_m2_w3'
        list use_member 'wanb_m1_w2'
        list use_member 'wan6_m2_w3'
        option last_resort 'unreachable'

config rule 'guest'
        option family 'ipv4'
        option proto 'all'
        option src_ip '10.20.30.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan_oi'
        option family 'ipv4'
        option proto 'all'
        option src_ip '172.16.1.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan'
        option proto 'all'
        option src_ip '192.168.1.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wan_only'

config rule 'IPv6'
        option family 'ipv6'
        option proto 'all'
        option dest_ip '::/0'
        option sticky '0'
        option use_policy 'wan_only'

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
76: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 192.168.1.1/24 brd 192.168.1.255 scope global br-lan.99
       valid_lft forever preferred_lft forever
77: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 10.20.30.1/24 brd 10.20.30.255 scope global br-lan.20
       valid_lft forever preferred_lft forever
78: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet 172.16.1.1/24 brd 172.16.1.255 scope global br-lan.100
       valid_lft forever preferred_lft forever
79: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    inet <wanb_IPv4>/22 brd 100.67.3.255 scope global internet.10
       valid_lft forever preferred_lft forever
81: wg0: <POINTOPOINT,NOARP,UP,LOWER_UP> mtu 1420 qdisc noqueue state UNKNOWN group default qlen 1000
    inet 10.14.0.1/24 brd 10.14.0.255 scope global wg0
       valid_lft forever preferred_lft forever
82: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 qdisc fq_codel state UNKNOWN group default qlen 3
    inet <wan_IPv4> peer 62.155.240.37/32 scope global pppoe-wan
       valid_lft forever preferred_lft forever
default via 62.155.240.37 dev pppoe-wan table 1 proto static metric 10
10.14.0.0/24 dev wg0 table 1 proto kernel scope link src 10.14.0.1
10.20.30.0/24 dev br-lan.20 table 1 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan table 1 proto kernel scope link src <wan_IPv4>
172.16.1.0/24 dev br-lan.100 table 1 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 1 proto kernel scope link src 192.168.1.1
default via 100.67.0.1 dev internet.10 table 3 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 table 3 proto kernel scope link src 10.14.0.1
10.20.30.0/24 dev br-lan.20 table 3 proto kernel scope link src 10.20.30.1
100.67.0.0/22 dev internet.10 table 3 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 table 3 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 table 3 proto kernel scope link src 192.168.1.1
default via 62.155.240.37 dev pppoe-wan proto static metric 10
default via 100.67.0.1 dev internet.10 proto static src <wanb_IPv4> metric 20
10.14.0.0/24 dev wg0 proto kernel scope link src 10.14.0.1
10.20.30.0/24 dev br-lan.20 proto kernel scope link src 10.20.30.1
62.155.240.37 dev pppoe-wan proto kernel scope link src <wan_IPv4>
100.67.0.0/22 dev internet.10 proto static scope link metric 20
172.16.1.0/24 dev br-lan.100 proto kernel scope link src 172.16.1.1
192.168.1.0/24 dev br-lan.99 proto kernel scope link src 192.168.1.1
local 10.14.0.1 dev wg0 table local proto kernel scope host src 10.14.0.1
broadcast 10.14.0.255 dev wg0 table local proto kernel scope link src 10.14.0.1
local 10.20.30.1 dev br-lan.20 table local proto kernel scope host src 10.20.30.1
broadcast 10.20.30.255 dev br-lan.20 table local proto kernel scope link src 10.20.30.1
local <wan_IPv4> dev pppoe-wan table local proto kernel scope host src <wan_IPv4>
local <wanb_IPv4> dev internet.10 table local proto kernel scope host src <wanb_IPv4>
broadcast 100.67.3.255 dev internet.10 table local proto kernel scope link src <wanb_IPv4>
local 127.0.0.0/8 dev lo table local proto kernel scope host src 127.0.0.1
local 127.0.0.1 dev lo table local proto kernel scope host src 127.0.0.1
broadcast 127.255.255.255 dev lo table local proto kernel scope link src 127.0.0.1
local 172.16.1.1 dev br-lan.100 table local proto kernel scope host src 172.16.1.1
broadcast 172.16.1.255 dev br-lan.100 table local proto kernel scope link src 172.16.1.1
local 192.168.1.1 dev br-lan.99 table local proto kernel scope host src 192.168.1.1
broadcast 192.168.1.255 dev br-lan.99 table local proto kernel scope link src 192.168.1.1
0:      from all lookup local
1001:   from all iif pppoe-wan lookup 1
1003:   from all iif internet.10 lookup 3
2001:   from all fwmark 0x100/0x3f00 lookup 1
2003:   from all fwmark 0x300/0x3f00 lookup 3
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
3001:   from all fwmark 0x100/0x3f00 unreachable
3003:   from all fwmark 0x300/0x3f00 unreachable
32766:  from all lookup main
32767:  from all lookup default
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 state UNKNOWN qlen 1000
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1504 state UP qlen 1000
    inet6 fe80::bce4:b0ff:fe2f:83f/64 scope link
       valid_lft forever preferred_lft forever
75: br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
76: br-lan.99@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 <wan_6_IPv6-PD>1/60 scope global dynamic noprefixroute
       valid_lft 86143sec preferred_lft 86143sec
    inet6 fda0:1017:eb8c:872a:e0e:76ff:fecf:6b18/64 scope global deprecated dynamic mngtmpaddr
       valid_lft 1534sec preferred_lft 0sec
    inet6 fdf8:373f:9a82:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fd46:b373:a44:0:e0e:76ff:fecf:6b18/64 scope global dynamic mngtmpaddr
       valid_lft forever preferred_lft forever
    inet6 fdfd:6bc9:c800::1/60 scope global noprefixroute
       valid_lft forever preferred_lft forever
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
77: br-lan.20@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
78: br-lan.100@br-lan: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b18/64 scope link
       valid_lft forever preferred_lft forever
79: internet.10@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b20/64 scope link
       valid_lft forever preferred_lft forever
80: internet.7@internet: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b19/64 scope link
       valid_lft forever preferred_lft forever
82: pppoe-wan: <POINTOPOINT,MULTICAST,NOARP,UP,LOWER_UP> mtu 1492 state UNKNOWN qlen 3
    inet6 <wan_6_IPv6>/64 scope global dynamic noprefixroute
       valid_lft 14140sec preferred_lft 1540sec
    inet6 <wan_IPv6> peer fe80::86b5:9cff:fef9:5ab0/128 scope link
       valid_lft forever preferred_lft forever
83: phy1-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
84: phy0-ap0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::e0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
85: phy1-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2f/64 scope link
       valid_lft forever preferred_lft forever
86: phy0-ap1: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 state UP qlen 1000
    inet6 fe80::c0e:76ff:fecf:6b2e/64 scope link
       valid_lft forever preferred_lft forever
<wan_6_IPv6-PD>/64 dev br-lan.99 table 2 proto static metric 1024 pref medium
unreachable <wan_6_IPv6-PD>/56 dev lo table 2 proto static metric 2147483647 pref medium
2003:cd:7fff:c6b::/64 dev pppoe-wan table 2 proto kernel metric 256 pref medium
unreachable 2003:cd:7fff:c6b::/64 dev lo table 2 proto static metric 2147483647 pref medium
fd46:b373:a44::/64 dev br-lan.99 table 2 proto kernel metric 256 pref medium
fda0:1017:eb8c:872a::/64 dev br-lan.99 table 2 proto kernel metric 256 pref medium
fdf8:373f:9a82::/64 dev br-lan.99 table 2 proto kernel metric 256 pref medium
fdfd:6bc9:c800::/64 dev br-lan.99 table 2 proto static metric 1024 pref medium
unreachable fdfd:6bc9:c800::/48 dev lo table 2 proto static metric 2147483647 pref medium
<wan_IPv6> dev pppoe-wan table 2 proto kernel metric 256 pref medium
fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan table 2 proto kernel metric 256 pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan table 2 proto static metric 512 pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan table 2 proto ra metric 1024 hoplimit 64 pref medium
default from <wan_6_IPv6-PD>/56 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
default from 2003:cd:7fff:c6b::/64 via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto static metric 512 pref medium
<wan_6_IPv6-PD>/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable <wan_6_IPv6-PD>/56 dev lo proto static metric 2147483647 pref medium
2003:cd:7fff:c6b::/64 dev pppoe-wan proto kernel metric 256 expires 14142sec pref medium
unreachable 2003:cd:7fff:c6b::/64 dev lo proto static metric 2147483647 pref medium
fd46:b373:a44::/64 dev br-lan.99 proto kernel metric 256 pref medium
fda0:1017:eb8c:872a::/64 dev br-lan.99 proto kernel metric 256 expires 1532sec pref medium
fdf8:373f:9a82::/64 dev br-lan.99 proto kernel metric 256 pref medium
fdfd:6bc9:c800::/64 dev br-lan.99 proto static metric 1024 pref medium
unreachable fdfd:6bc9:c800::/48 dev lo proto static metric 2147483647 pref medium
<wan_IPv6> dev pppoe-wan proto kernel metric 256 pref medium
fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto kernel metric 256 pref medium
fe80::/64 dev eth0 proto kernel metric 256 pref medium
fe80::/64 dev br-lan proto kernel metric 256 pref medium
fe80::/64 dev internet.7 proto kernel metric 256 pref medium
fe80::/64 dev internet.10 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.20 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.99 proto kernel metric 256 pref medium
fe80::/64 dev br-lan.100 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy1-ap1 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap0 proto kernel metric 256 pref medium
fe80::/64 dev phy0-ap1 proto kernel metric 256 pref medium
default via fe80::26a5:2cff:febb:b181 dev internet.10 proto ra metric 1024 expires 1533sec pref medium
default via fe80::86b5:9cff:fef9:5ab0 dev pppoe-wan proto ra metric 1024 expires 1542sec hoplimit 64 pref medium
local ::1 dev lo table local proto kernel metric 0 pref medium
anycast <wan_6_IPv6-PD> dev br-lan.99 table local proto kernel metric 0 pref medium
local <wan_6_IPv6-PD>1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast 2003:cd:7fff:c6b:: dev pppoe-wan table local proto kernel metric 0 pref medium
local <wan_6_IPv6> dev pppoe-wan table local proto kernel metric 0 pref medium
anycast fd46:b373:a44:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fd46:b373:a44:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fda0:1017:eb8c:872a:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fda0:1017:eb8c:872a:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdf8:373f:9a82:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdf8:373f:9a82:0:e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fdfd:6bc9:c800:: dev br-lan.99 table local proto kernel metric 0 pref medium
local fdfd:6bc9:c800::1 dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev eth0 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.99 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.20 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.7 table local proto kernel metric 0 pref medium
anycast fe80:: dev internet.10 table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan table local proto kernel metric 0 pref medium
anycast fe80:: dev br-lan.100 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap0 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy1-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap1 table local proto kernel metric 0 pref medium
anycast fe80:: dev phy0-ap0 table local proto kernel metric 0 pref medium
local <wan_IPv6> dev pppoe-wan table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2e dev phy0-ap1 table local proto kernel metric 0 pref medium
local fe80::c0e:76ff:fecf:6b2f dev phy1-ap1 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.99 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.20 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b18 dev br-lan.100 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b19 dev internet.7 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b20 dev internet.10 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2e dev phy0-ap0 table local proto kernel metric 0 pref medium
local fe80::e0e:76ff:fecf:6b2f dev phy1-ap0 table local proto kernel metric 0 pref medium
local fe80::bce4:b0ff:fe2f:83f dev eth0 table local proto kernel metric 0 pref medium
multicast ff00::/8 dev eth0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.99 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev wg0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.7 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev internet.10 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.20 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev br-lan.100 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev pppoe-wan table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy1-ap1 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap0 table local proto kernel metric 256 pref medium
multicast ff00::/8 dev phy0-ap1 table local proto kernel metric 256 pref medium
0:      from all lookup local
1002:   from all iif pppoe-wan lookup 2
2002:   from all fwmark 0x200/0x3f00 lookup 2
2061:   from all fwmark 0x3d00/0x3f00 blackhole
2062:   from all fwmark 0x3e00/0x3f00 unreachable
3002:   from all fwmark 0x200/0x3f00 unreachable
32766:  from all lookup main
4200000000:     from <wan_6_IPv6-PD>1/60 iif br-lan.99 unreachable
lrwxrwxrwx    1 root     root            16 Mar 22 23:09 /etc/resolv.conf -> /tmp/resolv.conf
-rw-r--r--    1 root     root            47 Jun 23 17:26 /tmp/resolv.conf
-rw-r--r--    1 root     root           245 Jun 23 17:26 /tmp/resolv.conf.d/resolv.conf.auto
-rw-r--r--    1 root     root            53 Jun 23 17:26 /tmp/resolv.conf.ppp

/tmp/resolv.conf.d:
-rw-r--r--    1 root     root           245 Jun 23 17:26 resolv.conf.auto
==> /etc/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf <==
search lan
nameserver 127.0.0.1
nameserver ::1

==> /tmp/resolv.conf.d <==
head: /tmp/resolv.conf.d: I/O error

==> /tmp/resolv.conf.ppp <==
nameserver 217.237.151.51
nameserver 217.237.149.205

==> /tmp/resolv.conf.d/resolv.conf.auto <==
# Interface wan_6
# Interface wan
nameserver 8.8.8.8
nameserver 8.8.1.1
nameserver 1.1.1.1
nameserver 2001:4860:4860::8888
nameserver 2001:4860:4860::8844
# Interface wanb
nameserver 185.89.39.194
nameserver 185.89.38.162
search internetnord.de
root@OpenWrt-EG:~#

In this state my phone is still unusable (in both lans: lan and guest).

Hmm, when I change my policy for the 192.168.1.0/24 network to wanb only it completly breaks my internet connection. No browsing is possible.

There is still a mix of config interface 'wan_6' and

config member 'wan6_m1_w3'
        option interface 'wan6'

Because wanb_only uses last resort unreachable.
Also lan rule is missing the IPv4 family.

Have you tested the connections as mentioned in the wiki? Something tells me that the wanb is not working.
Paste also the mwan3 status

I corrected all members and changed the wan6 to wan_6:

root@OpenWrt-EG:~# cat /etc/config/mwan3

config globals 'globals'
        option mmx_mask '0x3F00'

config interface 'wan'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wan_6'
        list track_ip '2606:4700:4700::1001'
        list track_ip '2606:4700:4700::1111'
        list track_ip '2620:0:ccd::2'
        list track_ip '2620:0:ccc::2'
        option family 'ipv6'
        option reliability '2'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config interface 'wanb'
        list track_ip '1.0.0.1'
        list track_ip '1.1.1.1'
        list track_ip '208.67.222.222'
        list track_ip '208.67.220.220'
        option family 'ipv4'
        option reliability '1'
        option initial_state 'online'
        option track_method 'ping'
        option count '1'
        option size '56'
        option max_ttl '60'
        option timeout '4'
        option interval '10'
        option failure_interval '5'
        option recovery_interval '5'
        option down '5'
        option up '5'
        option enabled '1'

config member 'wan_m1_w3'
        option interface 'wan'
        option metric '1'
        option weight '3'

config member 'wan_m2_w3'
        option interface 'wan'
        option metric '2'
        option weight '3'

config member 'wanb_m1_w2'
        option interface 'wanb'
        option metric '1'
        option weight '2'

config member 'wanb_m1_w3'
        option interface 'wanb'
        option metric '1'
        option weight '3'

config member 'wanb_m2_w2'
        option interface 'wanb'
        option metric '2'
        option weight '2'

config member 'wan6_m1_w3'
        option interface 'wan_6'
        option metric '1'
        option weight '3'

config member 'wan6_m2_w3'
        option interface 'wan_6'
        option metric '2'
        option weight '3'

config policy 'wan_only'
        list use_member 'wan_m1_w3'
        list use_member 'wan6_m1_w3'

config policy 'wanb_only'
        list use_member 'wanb_m1_w2'
        option last_resort 'unreachable'

config policy 'balanced'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m1_w3'
        list use_member 'wan6_m1_w3'
        option last_resort 'unreachable'

config policy 'wan_wanb'
        list use_member 'wan_m1_w3'
        list use_member 'wanb_m2_w2'
        list use_member 'wan6_m1_w3'
        option last_resort 'unreachable'

config policy 'wanb_wan'
        list use_member 'wan_m2_w3'
        list use_member 'wanb_m1_w2'
        list use_member 'wan6_m2_w3'
        option last_resort 'unreachable'

config rule 'guest'
        option family 'ipv4'
        option proto 'all'
        option src_ip '10.20.30.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan_oi'
        option family 'ipv4'
        option proto 'all'
        option src_ip '172.16.1.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wanb_only'

config rule 'lan'
        option proto 'all'
        option src_ip '192.168.1.0/24'
        option dest_ip '0.0.0.0/0'
        option sticky '0'
        option use_policy 'wan_only'

config rule 'IPv6'
        option family 'ipv6'
        option proto 'all'
        option dest_ip '::/0'
        option sticky '0'
        option use_policy 'wan_only'

root@OpenWrt-EG:~#

The problem I have due to the renaming of the wan_6 interface: It's created automatically so it's not in my fw zone for wan and I can't add a metric setting. The first attempt was to create manually an IPv6 interface but than the IPv6 address is not handed over.

Every policy uses unreachable for the last resort. Would it better to use default (use main routing table)?
I created 4 rules:


The rules that using wanb only are restricted to IPv4. Than I added a "default" rule for IPv6 requests which sould routed over wan. Because wanb doesn't provide an IPv6 address.

Yes sir:

root@OpenWrt-EG:~# ping -c 4 -4 -I internet.10 www.google.com
PING www.google.com (142.250.181.196): 56 data bytes
64 bytes from 142.250.181.196: seq=0 ttl=113 time=8.737 ms
64 bytes from 142.250.181.196: seq=1 ttl=113 time=8.626 ms
64 bytes from 142.250.181.196: seq=2 ttl=113 time=8.582 ms
64 bytes from 142.250.181.196: seq=3 ttl=113 time=8.498 ms

--- www.google.com ping statistics ---
4 packets transmitted, 4 packets received, 0% packet loss
round-trip min/avg/max = 8.498/8.610/8.737 ms
root@OpenWrt-EG:~#
root@OpenWrt-EG:~# mwan3 status
Interface status:
 interface wan is online 00h:00m:25s, uptime 65h:27m:56s and tracking is active
 interface wan_6 is online 00h:00m:25s, uptime 65h:27m:50s and tracking is active
 interface wanb is online 00h:00m:25s, uptime 02h:01m:17s and tracking is active

Current ipv4 policies:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
balanced:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wanb (50%)
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wan (50%)
wan_only:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wan (100%)
wan_wanb:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wan (100%)
wanb_only:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wanb (100%)
wanb_wan:
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
# Warning: iptables-legacy tables present, use iptables-legacy to see them
 wanb (100%)

Current ipv6 policies:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
balanced:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
 wan_6 (100%)
wan_only:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
 wan_6 (100%)
wan_wanb:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
 wan_6 (100%)
wanb_only:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
 unreachable
wanb_wan:
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
# Warning: ip6tables-legacy tables present, use ip6tables-legacy to see them
 wan_6 (100%)

Directly connected ipv4 networks:
192.168.1.0/24
127.0.0.1
172.16.1.1
185.89.39.64/26
10.14.0.0/24
127.0.0.0/8
192.168.1.1
<wan_IPv4>
62.155.240.37
127.255.255.255
224.0.0.0/3
185.89.39.127
192.168.1.255
10.20.30.1
172.16.1.255
10.14.0.1
10.14.0.255
10.20.30.0/24
172.16.1.0/24
10.20.30.255
<wanb_IPv4>

Directly connected ipv6 networks:
fd46:b373:a44::/64
<wan_IPv6>
2003:cd:7fff:1c64::/64
fdf8:373f:9a82::/64
fe80::86b5:9cff:fef9:5ab0
<wan_6_IPv6-PD>
fdfd:6bc9:c800::/64
fe80::/64

Active ipv4 user rules:
    0     0 - wanb_only  all  --  *      *       0.0.0.0/24           0.0.0.0/0
    0     0 - wanb_only  all  --  *      *       0.0.0.0/24           0.0.0.0/0
    6   352 - wan_only  all  --  *      *       0.0.0.0/24           0.0.0.0/0

Active ipv6 user rules:
    4   568 - wan_only  all      *      *       ::/0                 ::/0

root@OpenWrt-EG:~#