Skip to content

Firewall: Significang packet loss on WAN when using default rule "wan Forward reject", solution: "wan Forward drop" #13340

@PixelOfDeath

Description

@PixelOfDeath

Describe the bug

I hat issues with significant WAN package loss on my setup. It ranged from 10% to 40% pings not getting a reply.

First of all I found the solution/workaround to this:
Switching the default wan forward rule from reject to drop solves all my issues!

wan forward drop

I also could stop the firewall under System > Startup and hat no more package loss when pinging.

So far I could exclude issues with
DCHP client v4 or v6 (Tested WAN on static IP)
my Cable Modem (Tested two different models)
the physical eth ports (Tested all 4 ports for wan)

My Setup:
Chinese Intel n5105 NUC with 4x I225-V (rev 03) as a Proxmox hypervisor

The OpenWrt VM network setup:
LAN = virtio bridge to the first I255-V
WAN = PCI pass-thru to a second I225-V

I also tested a setup with only PCI pass-thru, same issue.

I also tested OpenWrt 23.05.0-rc3/targets/x86/64/generic-squashfs-combined-efi.img.gz, same issue

OpenWrt version

r20134-5f15225c1e

OpenWrt target/subtarget

x86/64

Device

QEMU Standard PC (i440FX + PIIX, 1996)

Image kind

Official downloaded image

Steps to reproduce

Using the default image with default settings.

Actual behaviour

Significant package loss on WAN with the default firewall configuration

Expected behaviour

No package loss

Additional info

No response

Diffconfig

No response

Terms

  • I am reporting an issue for OpenWrt, not an unsupported fork.

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugissue report with a confirmed bug

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions