Quote from: EricPerl on January 20, 2025, 09:39:49 PMIn a new thread, @dseven pointed out that "Firewall > Settings > Advanced > Disable reply-to" is the way to get the replies directly to the originating host (versus the GW). Details here.
It's policy-based routing related as well: Policy based routing
This does seem to work as well
If I unplug my wire into the vlan and have multiple hops into the wan interface it works.
If I disable that reply-to and source my traffic from the wan subnet it also works.
I experienced all kinds of bugginess this morning with the hardware/software. I had left the lan cable that was running to the device unplugged ( ran off with my laptop). Upon plugging the wire back in the link would not come up, Accessing LAN or overview in the gui just resulted in forever spins. I tried to reboot and after 5 mins the pings to it never dropped off. Had to run in there and hard power it off. IDK what it was doing or attempting to do but something was clearly in a dysfunctional state. After flipping these 2 options a couple of times :'Force gateway on WAN' and 'Disable reply-to on WAN GW' the firewall seemed to behave in all kinds of random ways until I went in and reloaded the packet filter and reset the state tables.
But this particular issue of 'why is nat from wan subnet broken unless pass', and the subissue of 'why isn't my routing behaving like a standard router should' seems solved