Quote from: DEC740airp414user on December 28, 2025, 10:46:28 AMDo you mean wireguard groupEither work, the order is <interface group> first and then the <interface(s)>. If you have quick rules in the interface group that match, the interface rules are not evaluated.
Or the wireguard tunnel to external isp
Quote2nd part of weirdness.
Quote from: patient0 on December 28, 2025, 07:23:41 AMQuote from: DEC740airp414user on December 27, 2025, 10:34:59 PMany device going over the wireguard tunnel can't access the router gui.What firewall rules have you created on the Wireguard interface?
~ % ping6 ipv6.google.com
PING6(56=40+8+8 bytes) 2003:a:XXXX:XXXX:308f:4dc8:f9d9:d0e7 --> 2a00:1450:4016:801::200e
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=1 hlim=117 time=11.981 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=2 hlim=117 time=11.574 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=3 hlim=117 time=11.594 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=4 hlim=117 time=11.641 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=5 hlim=117 time=12.349 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=6 hlim=117 time=11.837 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=7 hlim=117 time=11.777 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=8 hlim=117 time=11.781 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=9 hlim=117 time=11.808 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=10 hlim=117 time=11.765 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=11 hlim=117 time=11.780 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=12 hlim=117 time=11.560 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=13 hlim=117 time=11.695 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=14 hlim=117 time=12.090 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=29 hlim=117 time=11.853 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=30 hlim=117 time=11.841 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=31 hlim=117 time=11.710 ms
16 bytes from 2a00:1450:4016:801::200e, icmp_seq=32 hlim=117 time=11.377 msQuote from: DEC740airp414user on December 27, 2025, 10:34:59 PMany device going over the wireguard tunnel can't access the router gui.What firewall rules have you created on the Wireguard interface?
Quote from: wewyweww on December 28, 2025, 06:53:00 AMI do not use the firewall for DNS or DHCP. However, when I do a DNS query from a client on the LAN, the originating IP address of the DNS request is the WAN IP on the WAN interface.If we are talking IPv4 then all traffic is NAT-ed to the WAN IP, including DNS queries.