Strange WiFi issue

Started by suur13, December 25, 2025, 01:07:28 PM

Previous topic - Next topic
December 25, 2025, 01:07:28 PM Last Edit: December 25, 2025, 01:12:27 PM by suur13
Disclaimer: I'm aware that having Opnsense box acting like switch (bridge ports) and AP in the same time is not liked scenario, but I'm on home envoironment with light load. So here I am... using Topton box with 3 LAN/bridged ports and Atheros n-Wifi card. 25.7.10 with almost default settings (Dnsmasq + unbound, no ipv6 or any strange config or plugins).
In big picture everything works as normal. Due to my room layout I need to have Chromecast audio connected to my Opnsense box Wifi. It works well and I can stream audio into it from my computer, media server (both connected via cable and another switch to Opnsense) and iPhone, when iPhone is connecting to my other AP on the other side of the house - same 192.168.1.x network, same SSID, channel 6. But when I approach my living room where Opnsense and Chromecast locate and iPhone jumps to Opnsense box channel 1, I can not see Chromecast anymore - basically they can not share same AP). All other services work - Roon, web browsing, email etc. I can see other devices on my network - printer, Opnsense webui, BESIDES BubbleUPnP server installed in my media server. It starts asking password (not set), which acc. to Bubble help means, that "I try to accsess it from another network". But I'm not - all devices in 192.168.1.xxx
If I walk into other AP, all good.
I have done the Bridge and Wifi (part of bridge) following to the letter the Opnsense guide. Nothing I can see here which could create such issue.
I read somewhere that doing Bridge setup wrong, could cause issues with Multicast. Could that be it ? What shall I look for there ?

January 19, 2026, 07:48:00 PM #1 Last Edit: January 19, 2026, 07:50:05 PM by suur13
I was able to solve my main issue with Chromecast by enableing "Allow intra-BSS communication", but connecting to BubbleUPnP still gives error that I want to connect from WAN. Yes I could allow Wan settings from Bubble, but do not want (due security).
What OPNSense does block/filter that connecting via its internal Wifi makes one service in LAN to think that I'm trying to connect from WAN ?

Did you add proper firewall rules to the interfaces to permit UPnP?
In addition to the access to the other LAN devices, it's also required pass the UPnP multicasts to the other interface.

January 19, 2026, 09:36:07 PM #3 Last Edit: January 19, 2026, 10:22:58 PM by suur13
Thanks, looks like it helped. My WLAN connection is part of Bridge (together w/ OPT1, OPT2 and OPT3) and therefore also LAN. Firewall rules were applied only for LAN. Now I made similar Default rules also for WLAN. OPTx connections still are without rules and relay on LAN rules. Everything in other rooms work (via switch, via separate AP, via LAN, via OPT1). Strange that WLAN requires special approach, to me it was just like another port involved in bridge.

Did you add the mandatory tunables for the bridge?
Deciso DEC750
People who think they know everything are a great annoyance to those of us who do. (Isaac Asimov)

January 19, 2026, 10:21:40 PM #5 Last Edit: Today at 09:59:39 AM by suur13
You mean those 2 from Bridge guide:
net.link.bridge.pfil_member and set the value to 0
net.link.bridge.pfil_bridge and set the value to 1

Yes, those were done day 1.

EDIT: this morning BubbleUPnP still asked login. Not that it is very critical, but shows something is wrong in my configuration.