Quote from: bamf on September 30, 2026, 06:43:56 PMCan you give me some "real world" examples ?Quote from: nero355 on September 30, 2026, 06:05:55 PMSo far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...
It does resolve this issue in a more secure way than Static Port.
QuoteThere's a good explanation of the details in the Netgate documentation here: https://docs.netgate.com/pfsense/en/latest/nat/outbound.html#endpoint-independent-port-restricted-cone-natBut I am not yet sure what to do with it to be honest...
Quote from: BoerBart on September 30, 2026, 07:30:50 PMThe TP-link is running in bridge mode to have WiFi on the first floor.But that would mean each WiFi device has a WAN IP Address ?!
QuoteI'm not a 100% sure, so i'll go and check.I was thinking maybe you pick up the wrong DHCP Settings on your Client from time to time... Who knows... I have seen a lot of weird stuff throughout the years ;)
For my understanding, how would that cause random connections being dropped on the LAN interface?
QuoteThanks for the info - I'll have a look at that later.Wait...
It's one of the reasons I still have the modem, I'm very much it's not much, but it's something.
QuoteI'll go over the rules again to see if there's anything off.From the top down indeed and as they all seem to be so called 'Quick Rules' then it's basically the first rule that gets hit is the way to go IIRC :)
Though, as it's the main deny rule which is no. 13 in my case, it wouldn't matter what comes afterwards, as the rules are processed first match, correct?
QuoteOpenWRT isn't supported on the Archer AX50 sadly enough, i've looked into that a little ago.Too bad! :(
QuoteOf course, buying new hardware is always a good option, though I find it frustrating it 'suddenly' started acting up.Sometimes there is a simple reason such as simply a configuration that was wrong in the first place and after "Change X" to the software the issue rises to the surface so to speak...
Next to that, it seems to be somewhat specific.
QuoteMy PC and phone have issues, but when I check the Live view, no connections are dropped coming off the 2 Proxmox nodes.It could be something local to them but you will have to figure that out on your own.
QuoteI've got another TP-link switch laying around here, I'll take the Archer AX50 out, and replace it with the switch, see if that changes anything.Good idea anyway!
Quote**Added later**Bummer... :(
In the meantime, I've swapped out the TP-Link router for a TP-Link switch, no change to the issue.
I've stopped all (unnecessary) VMs and LXC containers in Proxmox, no change to the issue.
I've moved the Opnsense VM to the other node, also no change to the issue.
Quote from: nero355 on September 30, 2026, 06:24:33 PMWhat happens when you Enable all the Anti-Lock Out Rules for webGUI and SSH access ?
Or are they already Enabled ?!
Quote from: nero355 on September 30, 2026, 06:00:54 PMWhy have both a Modem and the TP-Link in Bridge Mode there ?!
Quote from: nero355 on September 30, 2026, 06:00:54 PMTo be sure :
Are you sure there is not a VM or LXC on any of these two connected to your LAN and running a DHCP Server without you knowing ?
Quote from: nero355 on September 30, 2026, 06:00:54 PMWatch out with this Switch : If connected like this a wrong configuration can expose the Switch's webGUI to the Internet !!
Quote from: nero355 on September 30, 2026, 06:05:55 PMSo far it seems you can't combine both so I am not sure if Endpoint-Independent NAT will solve that issue too...