> Fpor some reason each LAN can't communicate with the others (but that's another thread)Only first LAN interface has an allow all out rule. New interfaces and networks need it creating explicitly.
> Devices on WiFi AP are all Android or IoT, and all have full Internet access.> But I have 2 app that can't connect to Internet, but can't see/find any packet dropped, any blocked traffic (or I don't look in the right place)If all else works on the Android device except the app and no other services on the firewall enabled, then it suggests the problem not on OPN, no ?Zenarmor enabled ?
Ah!. Unlikely unless you hare doing something wacky with certificates and breaking TLS.Some of those use certificate pinning.
To me the next step in diagnostic is to do a packet capture and analysis.
You are using Unbound, right ?And do they (the apps) give some error or some indication of the problem?