Warning: Unable to locate ipset utility, disabling ipset support
Warning: Section @zone[1] (wan) cannot resolve device of network 'ppp'
Warning: Section 'vpn_zone' cannot resolve device of network 'vpn'
Warning: Section 'l2tp_zone' cannot resolve device of network 'l2tp'
Warning: Section 'pptp_zone' cannot resolve device of network 'pptp'
Warning: Section 'gre_zone' cannot resolve device of network 'gre'
Warning: Section 'hotspot' cannot resolve device of network 'hotspot'
Warning: Section 'sstp' cannot resolve device of network 'sstp'
Warning: Option @rule[14]._name is unknown
Warning: Option @rule[15]._name is unknown
Warning: Option @rule[16]._name is unknown
Warning: Option @rule[17]._name is unknown
Warning: Option 'TR069'.source_port is unknown
Warning: Section @rule[25] has neither a source nor a destination zone assigned - assuming an output r
Warning: Section @rule[25] does not specify a protocol, assuming TCP+UDP
Warning: Section @rule[25] has no target specified, defaulting to REJECT
* Flushing IPv4 filter table
* Flushing IPv4 nat table
* Flushing IPv4 mangle table
* Flushing IPv4 raw table
* Flushing IPv6 filter table
* Flushing IPv6 nat table
* Flushing IPv6 mangle table
* Flushing IPv6 raw table
* Flushing conntrack table ...
* Populating IPv4 filter table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Rule 'Allow-DHCP-Renew'
* Rule 'Allow-Ping'
* Rule 'Allow-vpn-traffic'
* Rule 'Allow_TR069_server_request'
* Rule #7
* Forward 'vpn' -> 'lan'
* Forward 'l2tp' -> 'lan'
* Forward 'pptp' -> 'lan'
* Forward 'gre' -> 'lan'
* Forward 'hotspot' -> 'wan'
* Populating IPv4 nat table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Populating IPv4 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Populating IPv4 raw table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Populating IPv6 filter table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Rule 'Allow-DHCPv6'
* Rule 'Allow-ICMPv6-Input'
* Rule 'Allow-ICMPv6-Forward'
* Rule 'Allow_TR069_server_request'
! Skipping due to different family of ip address
* Rule #7
* Forward 'vpn' -> 'lan'
* Forward 'l2tp' -> 'lan'
* Forward 'pptp' -> 'lan'
* Forward 'gre' -> 'lan'
* Forward 'hotspot' -> 'wan'
* Populating IPv6 nat table
* Zone 'lan'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_lan_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_lan_rule'
* Zone 'wan'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_wan_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_wan_rule'
* Zone 'vpn'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_vpn_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_vpn_rule'
* Zone 'l2tp'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_l2tp_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_l2tp_rule'
* Zone 'pptp'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_pptp_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_pptp_rule'
* Zone 'gre'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_gre_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_gre_rule'
* Zone 'hotspot'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_hotspot_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_hotspot_rule'
* Zone 'sstp'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_sstp_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_sstp_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'prerouting_rule'
Warning: fw3_ipt_rule_append(): Can't find target 'postrouting_rule'
* Populating IPv6 mangle table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Populating IPv6 raw table
* Zone 'lan'
* Zone 'wan'
* Zone 'vpn'
* Zone 'l2tp'
* Zone 'pptp'
* Zone 'gre'
* Zone 'hotspot'
* Zone 'sstp'
* Set tcp_ecn to off
* Set tcp_syncookies to on
* Set tcp_window_scaling to on
* Running script '/etc/firewall.user'
* Running script '/tmp/privoxy/firewall'
! Skipping due to path error: No such file or directory
* Running script '/etc/logtrigger/fwblock_wrapper.sh'
80,443
* Running script '/etc/add-firewall-rule.sh'
* Running script '/etc/add-rs-rule.sh'
* Running script '/etc/add-port-rule.sh'
iptables: Bad rule (does a matching rule exist in that chain?).
iptables: Bad rule (does a matching rule exist in that chain?).
iptables: Bad rule (does a matching rule exist in that chain?).
iptables: Bad rule (does a matching rule exist in that chain?).
iptables: Bad rule (does a matching rule exist in that chain?).
! Failed with exit code 1
* Running script '/tmp/ipsec/firewall.sh'
! Skipping due to path error: No such file or directory
root@Teltonika-RUT955:~# uci show firewall | grep tun0
firewall.hotspot.device='tun0 tun1 tun2 tun3'
root@Teltonika-RUT955:~# uci show firewall | grep hotspot
firewall.hotspot=zone
firewall.hotspot.name='hotspot'
firewall.hotspot.input='REJECT'
firewall.hotspot.output='ACCEPT'
firewall.hotspot.forward='REJECT'
firewall.hotspot.device='tun0 tun1 tun2 tun3'
firewall.hotspot.network='hotspot'
firewall.@forwarding[4].src='hotspot'
firewall.Hotspot_input.src='hotspot'
firewall.TR069.src='hotspot'
root@Teltonika-RUT955:~# uci show firewall | grep 4
firewall.@rule[1].family='ipv4'
firewall.@rule[2].family='ipv4'
firewall.@rule[3].family='ipv4'
firewall.@rule[3].dest_port='1194'
firewall.@forwarding[4]=forwarding
firewall.@forwarding[4].dest='wan'
firewall.@forwarding[4].src='hotspot'
firewall.@include[4]=include
firewall.@include[4].path='/etc/add-rs-rule.sh'
firewall.@include[4].reload='1'
firewall.Hotspot_input.dest_port='53 67-68 444 81 1812 1813 3991 3990'
firewall.@rule[6].dest_port='4200-4220'
firewall.@rule[8].dest_port='443'
firewall.@rule[11].src_port='547'
firewall.@rule[11].dest_port='546'
firewall.@rule[14]=rule
firewall.@rule[14].name='Allow-l2tpd-on-1701'
firewall.@rule[14]._name='l2tpd'
firewall.@rule[14].target='ACCEPT'
firewall.@rule[14].proto='udp'
firewall.@rule[14].dest_port='1701'
firewall.@rule[14].family='ipv4'
firewall.@rule[14].src='wan'
firewall.@rule[14].enabled='0'
firewall.@rule[15].family='ipv4'
firewall.@rule[16].family='ipv4'
firewall.@rule[17].family='ipv4'
firewall.IPsecNAT.dest_port='4500'
firewall.E_HTTPS_W_P.src_dport='443'
firewall.E_CLI_W_P.src_dport='4200-4220'
firewall.ALLOW_GRE.proto='47'
root@Teltonika-RUT955:~# reboot
root@Teltonika-RUT955:~# client_loop: send disconnect: Broken pipe
And locks me out of the VPN tunnel. We couldn't find our VPN tunnel back.
Just a short note out of the result of uci firewall I assumed tun0 is defined as hotspot