Software versions : OpenWrt - OpenWrt Barrier Breaker r41353 LuCI - svn-r10375 mwan3 - 1.4-20 luci-app-mwan3 - 1.2-19 Output of "cat /etc/config/mwan3" : config rule 'dns_via_gvt' option dest_port '53' option proto 'tcp' option dest_ip '0.0.0.0/0' option use_policy 'wan2_wan' config rule 'dns_via_gvt_udp' option dest_ip '0.0.0.0/0' option dest_port '53' option proto 'udp' option use_policy 'wan2_wan' config rule 'default_rule' option dest_ip '0.0.0.0/0' option use_policy 'balanced' config interface 'wan' option enabled '1' option count '1' option timeout '2' option interval '5' option down '3' option up '8' list track_ip '8.8.4.4' list track_ip '208.67.220.220' option reliability '1' config interface 'wan2' list track_ip '8.8.8.8' list track_ip '208.67.220.220' option reliability '1' option count '1' option timeout '2' option interval '5' option down '3' option up '8' option enabled '1' config member 'wan_m1_w3' option interface 'wan' option metric '1' option weight '3' config member 'wan_m2_w3' option interface 'wan' option metric '2' option weight '3' config member 'wan2_m1_w2' option interface 'wan2' option metric '1' option weight '2' config member 'wan2_m2_w2' option interface 'wan2' option metric '2' option weight '2' config policy 'wan_only' list use_member 'wan_m1_w3' config policy 'wan2_only' list use_member 'wan2_m1_w2' config policy 'balanced' list use_member 'wan_m1_w3' list use_member 'wan2_m1_w2' config policy 'wan_wan2' list use_member 'wan_m1_w3' list use_member 'wan2_m2_w2' config policy 'wan2_wan' list use_member 'wan_m2_w3' list use_member 'wan2_m1_w2' Output of "cat /etc/config/network" : config interface 'loopback' option ifname 'lo' option proto 'static' option ipaddr '127.0.0.1' option netmask '255.0.0.0' config globals 'globals' option ula_prefix 'fd65:f8be:e5d0::/48' config interface 'lan' option ifname 'eth0.1' option force_link '1' option type 'bridge' option proto 'static' option ipaddr '192.168.1.1' option netmask '255.255.255.0' option ip6assign '60' config interface 'wan' option ifname 'eth0.2' option _orig_ifname 'eth0.2' option _orig_bridge 'false' option proto 'static' option ipaddr '192.168.0.254' option netmask '255.255.255.0' option gateway '192.168.0.1' option broadcast '192.168.0.255' option dns '8.8.8.8' option metric '10' config interface 'wan6' option ifname '@wan' option proto 'dhcpv6' config switch option name 'switch0' option reset '1' option enable_vlan '1' option enable_vlan4k '1' config switch_vlan option device 'switch0' option vlan '1' option ports '2 3 4 5t' config switch_vlan option device 'switch0' option vlan '2' option ports '0 5t' config switch_vlan option device 'switch0' option vlan '3' option ports '1 5t' config interface 'wan2' option proto 'static' option ifname 'eth0.3' option ipaddr '192.168.2.254' option netmask '255.255.255.0' option gateway '192.168.2.1' option broadcast '192.168.2.255' option dns '8.8.8.8' option metric '20' Output of "ifconfig" : br-lan Link encap:Ethernet HWaddr F4:EC:38:E9:97:12 inet addr:192.168.1.1 Bcast:192.168.1.255 Mask:255.255.255.0 inet6 addr: fe80::f6ec:38ff:fee9:9712/64 Scope:Link inet6 addr: fd65:f8be:e5d0::1/60 Scope:Global UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:199 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:0 (0.0 B) TX bytes:37314 (36.4 KiB) eth0 Link encap:Ethernet HWaddr F4:EC:38:E9:97:12 inet6 addr: fe80::f6ec:38ff:fee9:9712/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:42496 errors:0 dropped:0 overruns:0 frame:0 TX packets:64932 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:1000 RX bytes:5834387 (5.5 MiB) TX bytes:8424955 (8.0 MiB) Interrupt:4 eth0.1 Link encap:Ethernet HWaddr F4:EC:38:E9:97:12 UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:0 errors:0 dropped:0 overruns:0 frame:0 TX packets:199 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:0 (0.0 B) TX bytes:37314 (36.4 KiB) eth0.2 Link encap:Ethernet HWaddr F4:EC:38:E9:97:12 inet addr:192.168.0.254 Bcast:192.168.0.255 Mask:255.255.255.0 inet6 addr: fe80::f6ec:38ff:fee9:9712/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:40853 errors:0 dropped:0 overruns:0 frame:0 TX packets:39262 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:4124606 (3.9 MiB) TX bytes:6990191 (6.6 MiB) eth0.3 Link encap:Ethernet HWaddr F4:EC:38:E9:97:12 inet addr:192.168.2.254 Bcast:192.168.2.255 Mask:255.255.255.0 inet6 addr: fe80::f6ec:38ff:fee9:9712/64 Scope:Link UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1 RX packets:1643 errors:0 dropped:0 overruns:0 frame:0 TX packets:25466 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:944853 (922.7 KiB) TX bytes:1136251 (1.0 MiB) lo Link encap:Local Loopback inet addr:127.0.0.1 Mask:255.0.0.0 inet6 addr: ::1/128 Scope:Host UP LOOPBACK RUNNING MTU:65536 Metric:1 RX packets:43770 errors:0 dropped:0 overruns:0 frame:0 TX packets:43770 errors:0 dropped:0 overruns:0 carrier:0 collisions:0 txqueuelen:0 RX bytes:6849102 (6.5 MiB) TX bytes:6849102 (6.5 MiB) Output of "route -n" : Kernel IP routing table Destination Gateway Genmask Flags Metric Ref Use Iface 0.0.0.0 192.168.0.1 0.0.0.0 UG 10 0 0 eth0.2 0.0.0.0 192.168.2.1 0.0.0.0 UG 20 0 0 eth0.3 192.168.0.0 0.0.0.0 255.255.255.0 U 10 0 0 eth0.2 192.168.1.0 0.0.0.0 255.255.255.0 U 0 0 0 br-lan 192.168.2.0 0.0.0.0 255.255.255.0 U 20 0 0 eth0.3 Output of "ip rule show" : 0: from all lookup local 1001: from all iif eth0.2 lookup main 2001: from all fwmark 0x100/0xff00 lookup 1 2254: from all fwmark 0xfe00/0xff00 unreachable 32766: from all lookup main 32767: from all lookup default Output of "ip route list table 1-250" : 1 default via 192.168.0.1 dev eth0.2 Firewall default output policy (must be ACCEPT) : ACCEPT Output of "iptables -L -t mangle -v -n" : Chain PREROUTING (policy ACCEPT 1201 packets, 252K bytes) pkts bytes target prot opt in out source destination 28004 5684K mwan3_hook all -- * * 0.0.0.0/0 0.0.0.0/0 2323 421K fwmark all -- * * 0.0.0.0/0 0.0.0.0/0 Chain INPUT (policy ACCEPT 1201 packets, 252K bytes) pkts bytes target prot opt in out source destination Chain FORWARD (policy ACCEPT 0 packets, 0 bytes) pkts bytes target prot opt in out source destination 0 0 mssfix all -- * * 0.0.0.0/0 0.0.0.0/0 Chain OUTPUT (policy ACCEPT 1304 packets, 420K bytes) pkts bytes target prot opt in out source destination 27761 6384K mwan3_hook all -- * * 0.0.0.0/0 0.0.0.0/0 27761 6384K mwan3_track_hook all -- * * 0.0.0.0/0 0.0.0.0/0 Chain POSTROUTING (policy ACCEPT 1304 packets, 420K bytes) pkts bytes target prot opt in out source destination Chain fwmark (1 references) pkts bytes target prot opt in out source destination Chain mssfix (1 references) pkts bytes target prot opt in out source destination 0 0 TCPMSS tcp -- * eth0.2 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU 0 0 TCPMSS tcp -- * eth0.3 0.0.0.0/0 0.0.0.0/0 tcp flags:0x06/0x02 /* wan (mtu_fix) */ TCPMSS clamp to PMTU Chain mwan3_connected (1 references) pkts bytes target prot opt in out source destination 9 553 MARK all -- * * 0.0.0.0/0 127.0.0.0/8 mark match 0x0/0xff00 MARK or 0xff00 0 0 MARK all -- * * 0.0.0.0/0 224.0.0.0/3 mark match 0x0/0xff00 MARK or 0xff00 0 0 MARK all -- * * 0.0.0.0/0 192.168.0.0/24 mark match 0x0/0xff00 MARK or 0xff00 0 0 MARK all -- * * 0.0.0.0/0 192.168.1.0/24 mark match 0x0/0xff00 MARK or 0xff00 0 0 MARK all -- * * 0.0.0.0/0 192.168.2.0/24 mark match 0x0/0xff00 MARK or 0xff00 Chain mwan3_hook (2 references) pkts bytes target prot opt in out source destination 55765 12M CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0 CONNMARK restore mask 0xff00 2448 202K mwan3_ifaces all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 2410 200K mwan3_connected all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 2346 196K mwan3_rules all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 55765 12M CONNMARK all -- * * 0.0.0.0/0 0.0.0.0/0 CONNMARK save mask 0xff00 Chain mwan3_iface_wan (1 references) pkts bytes target prot opt in out source destination 29 1072 MARK all -- * * 192.168.0.0/24 0.0.0.0/0 mark match 0x0/0xff00 /* wan */ MARK or 0xff00 3 252 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* wan */ MARK xset 0x100/0xff00 Chain mwan3_ifaces (1 references) pkts bytes target prot opt in out source destination 32 1324 mwan3_iface_wan all -- eth0.2 * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 Chain mwan3_policy_balanced (1 references) pkts bytes target prot opt in out source destination 162 13584 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* wan 3 3 */ MARK xset 0x100/0xff00 Chain mwan3_policy_wan2_only (0 references) pkts bytes target prot opt in out source destination 0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* unreachable */ MARK xset 0xfe00/0xff00 Chain mwan3_policy_wan2_wan (2 references) pkts bytes target prot opt in out source destination 0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* wan 3 3 */ MARK xset 0x100/0xff00 Chain mwan3_policy_wan_only (0 references) pkts bytes target prot opt in out source destination 0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* wan 3 3 */ MARK xset 0x100/0xff00 Chain mwan3_policy_wan_wan2 (0 references) pkts bytes target prot opt in out source destination 0 0 MARK all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* wan 3 3 */ MARK xset 0x100/0xff00 Chain mwan3_rules (1 references) pkts bytes target prot opt in out source destination 0 0 mwan3_policy_wan2_wan tcp -- * * 0.0.0.0/0 0.0.0.0/0 multiport sports 0:65535 multiport dports 53 mark match 0x0/0xff00 /* dns_via_gvt */ 0 0 mwan3_policy_wan2_wan udp -- * * 0.0.0.0/0 0.0.0.0/0 multiport sports 0:65535 multiport dports 53 mark match 0x0/0xff00 /* dns_via_gvt_udp */ 162 13584 mwan3_policy_balanced all -- * * 0.0.0.0/0 0.0.0.0/0 mark match 0x0/0xff00 /* default_rule */ Chain mwan3_track_hook (1 references) pkts bytes target prot opt in out source destination 27739 6382K mwan3_track_wan all -- * * 0.0.0.0/0 0.0.0.0/0 27551 6365K mwan3_track_wan2 all -- * * 0.0.0.0/0 0.0.0.0/0 Chain mwan3_track_wan (1 references) pkts bytes target prot opt in out source destination 646 54264 MARK icmp -- * eth0.2 0.0.0.0/0 208.67.220.220 icmptype 8 MARK or 0xff00 646 54264 MARK icmp -- * eth0.2 0.0.0.0/0 8.8.4.4 icmptype 8 MARK or 0xff00 Chain mwan3_track_wan2 (1 references) pkts bytes target prot opt in out source destination 73 6132 MARK icmp -- * eth0.3 0.0.0.0/0 208.67.220.220 icmptype 8 MARK or 0xff00 72 6048 MARK icmp -- * eth0.3 0.0.0.0/0 8.8.8.8 icmptype 8 MARK or 0xff00