OPNsense Forum

English Forums => 25.7, 25.10 Series => Topic started by: ToasterPC on January 17, 2026, 02:36:42 AM

Title: New site PPPoE PMTU woes
Post by: ToasterPC on January 17, 2026, 02:36:42 AM
Heya everyone!

So, it seems that this year is the year of PPPoE headaches for me. I'd like to illustrate for a bit in order to know what to do next.

I'm using OPNsense 25.7.11 through Proxmox 9.1.4 at two different sites, both of them operating with a Realtek RTL9601D-based SFP to APC Gigabit fiber module (DFP-34X-2C2) and being connected to an identical SKU of the Minisforum MS-01 (13th gen Core i9 and 32GB of RAM).

Both the LAN and WAN bridges are using the VirtIO driver and a multiqueue equal to the VM's number of cores (20 or 6, with 6 being the intended default but not changed in the older site in order to reduce variables while troubleshooting), with the LAN bridge having an MTU of 1500 and the WAN one having it set to 1512 on the hypervisor side.

Within OPNsense, the LAN and the WAN's MTU are explicitly set to 1500, and that's about where the similarities end (The first site was deployed as it is today around June of last year, and the site that has issues in the middle of December).

However, attempting to make the connection stable in the new site has proven challenging, as for the time being several websites that rely upon TLS 1.3 seem to time out during the handshake when tested from an end device, though not from the firewall itself:

From the OPNsense CLI over SSH:
curl -vv "https://kindleforpc.s3.us-east-1.amazonaws.com/70980/KindleForPC-installer-2.8.70980.exe"
19:26:35.099305 [0-0] * Host kindleforpc.s3.us-east-1.amazonaws.com:443 was resolved.
19:26:35.099350 [0-0] * IPv6: (none)
19:26:35.099356 [0-0] * IPv4: 54.231.167.26, 52.217.195.90, 52.217.126.146, 16.182.68.210, 54.231.163.122, 54.231.129.162, 16.15.223.27, 52.217.175.26
19:26:35.099363 [0-0] * [HTTPS-CONNECT] adding wanted h2
19:26:35.099369 [0-0] * [HTTPS-CONNECT] added
19:26:35.099376 [0-0] * [HTTPS-CONNECT] connect, init
19:26:35.099388 [0-0] *   Trying 54.231.167.26:443...
19:26:35.099420 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
19:26:35.099426 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
19:26:35.099433 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
19:26:35.149399 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
19:26:35.149411 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
19:26:35.149418 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
19:26:35.181027 [0-0] * ALPN: curl offers h2,http/1.1
19:26:35.181111 [0-0] * TLSv1.3 (OUT), TLS handshake, Client hello (1):
19:26:35.181138 [0-0] * SSL Trust Anchors:
19:26:35.181146 [0-0] *   CApath: /etc/ssl/certs
19:26:35.181163 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
19:26:35.181169 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
19:26:35.181177 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
19:26:35.261761 [0-0] * TLSv1.3 (IN), TLS handshake, Server hello (2):
19:26:35.261896 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
19:26:35.261905 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
19:26:35.261913 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
19:26:35.261932 [0-0] * TLSv1.3 (IN), TLS handshake, Encrypted Extensions (8):
19:26:35.261948 [0-0] * TLSv1.3 (IN), TLS handshake, Certificate (11):
19:26:35.262632 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
19:26:35.262643 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
19:26:35.262651 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
19:26:35.262665 [0-0] * TLSv1.3 (IN), TLS handshake, CERT verify (15):
19:26:35.262707 [0-0] * TLSv1.3 (IN), TLS handshake, Finished (20):
19:26:35.262729 [0-0] * TLSv1.3 (OUT), TLS change cipher, Change cipher spec (1):
19:26:35.262747 [0-0] * TLSv1.3 (OUT), TLS handshake, Finished (20):
19:26:35.262779 [0-0] * SSL connection using TLSv1.3 / TLS_AES_128_GCM_SHA256 / X25519 / RSASSA-PSS
19:26:35.262788 [0-0] * ALPN: server accepted http/1.1
19:26:35.262796 [0-0] * Server certificate:
19:26:35.262807 [0-0] *   subject: CN=s3.amazonaws.com
19:26:35.262815 [0-0] *   start date: Jul 20 00:00:00 2025 GMT
19:26:35.262822 [0-0] *   expire date: Jun 25 23:59:59 2026 GMT
19:26:35.262830 [0-0] *   issuer: C=US; O=Amazon; CN=Amazon RSA 2048 M01
19:26:35.262842 [0-0] *   Certificate level 0: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
19:26:35.262849 [0-0] *   Certificate level 1: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
19:26:35.262856 [0-0] *   Certificate level 2: Public key type RSA (2048/112 Bits/secBits), signed using sha256WithRSAEncryption
19:26:35.262868 [0-0] *   subjectAltName: "kindleforpc.s3.us-east-1.amazonaws.com" matches cert's "*.s3.us-east-1.amazonaws.com"
19:26:35.262875 [0-0] * SSL certificate verified via OpenSSL.
19:26:35.262883 [0-0] * [HTTPS-CONNECT] connect+handshake h2: 163ms, 1st data: 162ms
19:26:35.262889 [0-0] * [SETUP] query ALPN
19:26:35.262895 [0-0] * [HTTPS-CONNECT] connect -> 0, done=1
19:26:35.262902 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=1
19:26:35.262910 [0-0] * Established connection to kindleforpc.s3.us-east-1.amazonaws.com (54.231.167.26 port 443) from REDACTED port 32147
19:26:35.262917 [0-0] * [HTTPS-CONNECT] query ALPN
19:26:35.262923 [0-0] * using HTTP/1.x
19:26:35.262944 [0-0] > GET /70980/KindleForPC-installer-2.8.70980.exe HTTP/1.1
19:26:35.262944 [0-0] > Host: kindleforpc.s3.us-east-1.amazonaws.com
19:26:35.262944 [0-0] > User-Agent: curl/8.17.0
19:26:35.262944 [0-0] > Accept: */*
19:26:35.262944 [0-0] >
19:26:35.262986 [0-0] * Request completely sent off
19:26:35.370870 [0-0] < HTTP/1.1 200 OK
19:26:35.370883 [0-0] < x-amz-id-2: x7vjvAVKD4GJmkBItssh7dZPYxr2nGKHGcQZdEkdefrqA+4qn1qGxKfffbtz0TrlqlERwAQO+C4=
19:26:35.370890 [0-0] < x-amz-request-id: HBD9SQZDBSGBHD0Z
19:26:35.370896 [0-0] < Date: Sat, 17 Jan 2026 01:26:36 GMT
19:26:35.370902 [0-0] < Last-Modified: Thu, 21 Aug 2025 10:56:57 GMT
19:26:35.370907 [0-0] < ETag: "2b756dcc3905a9ff3aef6a0a57dd7c09-18"
19:26:35.370913 [0-0] < x-amz-server-side-encryption: AES256
19:26:35.370918 [0-0] < Accept-Ranges: bytes
19:26:35.370924 [0-0] < Content-Type: application/octet-stream
19:26:35.370934 [0-0] < Content-Length: 298242024
19:26:35.370940 [0-0] < Server: AmazonS3
19:26:35.370948 [0-0] <
Warning: Binary output can mess up your terminal. Use "--output -" to tell curl to output it to your
Warning: terminal anyway, or consider "--output <FILE>" to save to a file.
19:26:35.370973 [0-0] * client returned ERROR on write of 16384 bytes
19:26:35.370988 [0-0] * closing connection #0

From an end device (Dell laptop and Realtek NIC on Windows and WSL2):

curl -vv "https://kindleforpc.s3.us-east-1.amazonaws.com/70980/KindleForPC-installer-2.8.70980.exe"
18:52:27.097487 [0-0] * Host kindleforpc.s3.us-east-1.amazonaws.com:443 was resolved.
18:52:27.097634 [0-0] * IPv6: (none)
18:52:27.097689 [0-0] * IPv4: 52.217.139.154, 52.217.196.234, 52.217.93.120, 52.216.208.226, 52.217.226.210, 52.217.112.98, 16.15.217.226, 54.231.128.2
18:52:27.097748 [0-0] * [HTTPS-CONNECT] adding wanted h2
18:52:27.097894 [0-0] * [HTTPS-CONNECT] added
18:52:27.098019 [0-0] * [HTTPS-CONNECT] connect, init
18:52:27.098131 [0-0] *   Trying 52.217.139.154:443...
18:52:27.098331 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:27.098636 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:27.098725 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:27.100955 [0-0] * ALPN: curl offers h2,http/1.1
18:52:27.101507 [0-0] * TLSv1.3 (OUT), TLS handshake, Client hello (1):
18:52:27.101648 [0-0] * SSL Trust Anchors:
18:52:27.118431 [0-0] *   OpenSSL default paths (fallback)
18:52:27.118558 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:27.118661 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:27.118727 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:27.299109 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:27.299170 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:27.299213 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:28.300450 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:28.300538 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:28.300617 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:29.301858 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:29.301947 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:29.302014 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:30.303232 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:30.303327 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:30.303383 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:31.304561 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:31.304648 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:31.304720 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:32.305930 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:32.306021 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:32.306129 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:33.307289 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:33.307364 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:33.307425 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:34.308663 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:34.308752 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:34.308814 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:35.310021 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:35.310105 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:35.310177 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:36.311406 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:36.311510 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:36.311598 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:37.313018 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:37.313118 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:37.313204 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:38.314446 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:38.314535 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:38.314612 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:39.315853 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:39.315948 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:39.316018 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:40.317219 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:40.317305 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:40.317377 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:41.318575 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:41.318675 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:41.318706 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:42.319851 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:42.319933 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:42.320004 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:43.321172 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:43.321260 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:43.321331 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:44.322544 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:44.322631 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:44.322692 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:45.323905 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:45.323995 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:45.324071 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:46.325426 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:46.325520 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:46.325592 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:47.326809 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:47.326893 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:47.326980 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:48.328225 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:48.328315 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:48.328389 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:49.329580 [0-0] * [HTTPS-CONNECT] connect -> 0, done=0
18:52:49.329668 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 0, done=0
18:52:49.329741 [0-0] * [HTTPS-CONNECT] adjust_pollset -> 0, 1 socks
18:52:50.262208 [0-0] * TLSv1.3 (OUT), TLS alert, decode error (562):
18:52:50.262297 [0-0] * TLS connect error: error:0A000126:SSL routines::unexpected eof while reading
18:52:50.262365 [0-0] * [HTTPS-CONNECT] connect, all attempts failed
18:52:50.262431 [0-0] * [HTTPS-CONNECT] connect -> 35, done=0
18:52:50.262510 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(block=0) -> 35, done=0
18:52:50.262583 [0-0] * [HTTPS-CONNECT] Curl_conn_connect(), filter returned 35
18:52:50.262667 [0-0] * closing connection #0
curl: (35) TLS connect error: error:0A000126:SSL routines::unexpected eof while reading

As for interface configurations, this is the output of both ifconfig on the router and ip a on the laptop:

OPNsense:
vtnet0: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
        description: LAN (lan)
        options=880008<VLAN_MTU,LINKSTATE,HWSTATS>
        ether bc:24:11:71:71:2b
        inet 10.10.1.1 netmask 0xffffe000 broadcast 10.10.31.255
        inet6 fe80::be24:11ff:fe71:712b%vtnet0 prefixlen 64 scopeid 0x1
        inet6 REDACTED prefixlen 64
        media: Ethernet autoselect (10Gbase-T <full-duplex>)
        status: active
        nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
vtnet1: flags=1008843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1500
        options=880008<VLAN_MTU,LINKSTATE,HWSTATS>
        ether bc:24:11:e3:db:1e
        media: Ethernet autoselect (10Gbase-T <full-duplex>)
        status: active
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
lo0: flags=1008049<UP,LOOPBACK,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 16384
        options=680003<RXCSUM,TXCSUM,LINKSTATE,RXCSUM_IPV6,TXCSUM_IPV6>
        inet 127.0.0.1 netmask 0xff000000
        inet6 ::1 prefixlen 128
        inet6 fe80::1%lo0 prefixlen 64 scopeid 0x3
        groups: lo
        nd6 options=21<PERFORMNUD,AUTO_LINKLOCAL>
enc0: flags=0 metric 0 mtu 1536
        options=0
        groups: enc
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
pflog0: flags=0 metric 0 mtu 33152
        options=0
        groups: pflog
pfsync0: flags=0 metric 0 mtu 1500
        options=0
        maxupd: 128 defer: off version: 1400
        syncok: 1
        groups: pfsync
pppoe0: flags=10088d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST,LOWER_UP> metric 0 mtu 1492
        description: WAN_FTTH (wan)
        options=100000<NETMAP>
        inet REDACTED --> REDACTED netmask 0xffffffff
        inet6 fe80::1%pppoe0 prefixlen 64 scopeid 0x7
        inet6 fc00:1020:27:5359::1 prefixlen 64 autoconf pltime 604800 vltime 2592000
        nd6 options=23<PERFORMNUD,ACCEPT_RTADV,AUTO_LINKLOCAL>
zen0: flags=8010<POINTOPOINT,MULTICAST> metric 0 mtu 1500
        options=4080000<LINKSTATE,MEXTPG>
        groups: tun zenvpngroup
        nd6 options=29<PERFORMNUD,IFDISABLED,AUTO_LINKLOCAL>
tailscale0: flags=1008043<UP,BROADCAST,RUNNING,MULTICAST,LOWER_UP> metric 0 mtu 1280
        options=4080000<LINKSTATE,MEXTPG>
        inet REDACTED netmask 0xffffffff broadcast REDACTED
        inet6 REDACTED prefixlen 48
        groups: tun
        nd6 options=101<PERFORMNUD,NO_DAD>
        Opened by PID 66361

Laptop:

1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet 10.255.255.254/32 brd 10.255.255.254 scope global lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host
       valid_lft forever preferred_lft forever
2: bond0: <BROADCAST,MULTICAST,MASTER> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/ether 72:c6:10:61:e4:70 brd ff:ff:ff:ff:ff:ff
3: dummy0: <BROADCAST,NOARP> mtu 1500 qdisc noop state DOWN group default qlen 1000
    link/ether 66:28:03:c8:ef:bd brd ff:ff:ff:ff:ff:ff
4: tunl0@NONE: <NOARP> mtu 1480 qdisc noop state DOWN group default qlen 1000
    link/ipip 0.0.0.0 brd 0.0.0.0
5: sit0@NONE: <NOARP> mtu 1480 qdisc noop state DOWN group default qlen 1000
    link/sit 0.0.0.0 brd 0.0.0.0
    inet6 ::10.255.255.254/96 scope host
       valid_lft forever preferred_lft forever
    inet6 ::127.0.0.1/96 scope host
       valid_lft forever preferred_lft forever
6: loopback0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 00:15:5d:bc:b8:0e brd ff:ff:ff:ff:ff:ff
7: eth0: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 00:50:56:c0:00:01 brd ff:ff:ff:ff:ff:ff
8: eth1: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 00:15:5d:ef:f4:21 brd ff:ff:ff:ff:ff:ff
9: eth2: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 60:18:95:4b:d1:eb brd ff:ff:ff:ff:ff:ff
10: eth3: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 00:50:56:c0:00:08 brd ff:ff:ff:ff:ff:ff
11: eth4: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1280 qdisc mq state UP group default qlen 1000
    link/ether 00:15:5d:18:d5:39 brd ff:ff:ff:ff:ff:ff
    inet 169.254.254.112/16 brd 169.254.255.255 scope link noprefixroute eth4
       valid_lft forever preferred_lft forever
    inet6 fe80::a8c1:ef8b:51d7:e7cb/64 scope link nodad noprefixroute
       valid_lft forever preferred_lft forever
24: eth5: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc mq state UP group default qlen 1000
    link/ether 9c:b6:d0:3c:20:58 brd ff:ff:ff:ff:ff:ff
    inet 10.10.0.10/19 brd 10.10.31.255 scope global noprefixroute eth5
       valid_lft forever preferred_lft forever
    inet6 fd7a:cff:96ed:f11e:3d48:3842:3a2a:dd6b/128 scope global nodad noprefixroute
       valid_lft forever preferred_lft forever
    inet6 fd7a:cff:96ed:f11e:466a:8418:ee8f:7aaa/64 scope global nodad deprecated noprefixroute
       valid_lft forever preferred_lft 0sec
    inet6 fe80::ac9c:f777:9253:c052/64 scope link nodad noprefixroute
       valid_lft forever preferred_lft forever
40: eth6: <BROADCAST,MULTICAST> mtu 1500 qdisc mq state DOWN group default qlen 1000
    link/ether 5a:ee:39:8d:cf:14 brd ff:ff:ff:ff:ff:ff
41: eth7: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1420 qdisc mq state UP group default qlen 1000
    link/ether 00:15:5d:cd:ac:fb brd ff:ff:ff:ff:ff:ff
    inet 10.20.1.3/32 brd 10.20.1.3 scope global noprefixroute eth7
       valid_lft forever preferred_lft forever
    inet6 c0de:f00b:47aa:aaaa:201::3/128 scope global nodad noprefixroute
       valid_lft forever preferred_lft forever


Given that both network topologies are identical down to Layer 3, and that reinstalling the OS made no difference, I'm starting to think I'm at the end of my rope in regard to where to look next. Is there something else I could try to narrow down the root cause?


Thanks in advance!