4.9.0-OP24 discussion for MT6000 and MT3000

Hello, i did that update and now both Adblock and Banip from Luci are not working. The Banip service can’t even start now. I did a factory reset but it remains the same. I can replace Adblock with Adguard Home but not Banip. Something changed with 4.9.0 OP24 that affects the Luci packages? Someone here with the same problem? Previous i was running 4.8.3 OP24.

Edit: I got Banip service working again after going to Luci System/Startup. It was enabled there but i pressed Start and Restart… and i worked. I did a reboot and it’s still working.

Now they works?

No worry — you can attach screenshots and the moderators will review them (this is to prevent those nasty ad bots, we had to tighten some post rules, but we won’t restrict images posted by legitimate users, once reviewed they will be displayed).

I checked the screenshots in PM, thanks for providing them, looks no problem.

This is not a bug nor an intentional miss it.

  • If the VPN tunnel is connected while ADG is disabled, the client (domain name resolution) will use the VPN tunnel’s DNS (via dnsmasq) — that’s expected.

  • If the VPN tunnel is connected and ADG is also running, dnsmasq will hand domain name resolution to ADG, so ADG will use the DNS server you have configured there to resolve names — that’s also expected.

Using a non-VPN tunnel DNS to resolve names does not mean a DNS leak.
What constitutes a DNS leak? For example, if you test with multiple DNS leak test websites and see your local DNS server appearing, that probably indicate a leak — but to be thorough we should capture packets on the WAN interface to confirm whether DNS requests are actually going out via the WAN.

Only DNS requests that go out via the WAN interface count as a DNS leak.

Could you share your router with us so we can take a look?

Stupid me. :grinning_face_with_smiling_eyes: The "Allow Custom DNS to Override VPN DNS" option was enabled. After unchecking it, the DNS leak disappeared and DNS requests are now correctly routed through the VPN.

1 Like

I’ve just noticed that my GL port forwardings don’t show up in LuCI interface and they don’t work at all.
Is there any workaround other than painstakingly adding manually on LuCI?

Is it MT6000 and is it v4.9.0-op24_beta2 firmware?

After GL GUI configured port forwarding, Luci will indeed not be displayed, but the port forwarding is actually working.

If you configured port forwarding in the GL GUI and it doesn't work, please try to check if there are ports conflict, if the configuration file is recorded or correct?

2 Likes

Yes, I have 4.9-op24 beta 2

I stand corrected: using SSH I can see that port forwarding is still there, but it doesn't do anything.

I have multiple services on my LAN that are published on WAN (such as WebDAV) that can't be discovered (especially WebDAV that even with IPv6 or using DDNS won't work on WAN)

If I can do anything to fix it or debug it, please let me know

Thanks

Hmm I have checked this on the 4.9.0 firmware on the brume 3.

I cannot replicate this, however because you also talk about ipv6 usually that does not need a port forward, only if you got a really small block of ipv6 you use nat6, normally only a firewall ACL rule for acceptance is fine.

My question though is masquarading still enabled on wan ?

MTU is set minimally to 1280?

It's a bit strange, and I did not reproduce this.

  1. Please confirm that the configuration file shows all port forwarding rules you configured?
  2. Please confirm if the firmware is downgraded to v4.8.3-op24 and the port forwarding rules are brand-new configured, will they work?

If it works in v4.8.3-op24, please upgrade to v4.9.0-op24 again (do not keep settings), configure port forwarding rules, and conduct the following tests:

opkg update
opkg install netcat
netns_client.sh -c br-lan 1
nc -zv [Flint2 WANI IP] [PORT]  
# Example: nc -zv 192.168.3.163 3001

NOTE: the IP address in nc is the Flint2 WAN port IP, not LAN client IP.

If Connection refused, it means there is a problem with Flint2's port forwarding or client's port listening / firewall issue.
Bruce_2026-06-03_15-47-12
If open, it means that Flint2 port forwarding works without issue. Probably the ISP blocks the port or other reasons on the upper-level network.
Bruce_2026-06-03_15-48-55

@xize11 MTU is set to 1500 and it is unchanged after the upgrade. Masquerade should be enabled too, I haven't changed it since I bought the router

@bruce I’ve upgraded from 4.8.2-op24 to 4.9-op24 beta1 then beta2 keeping the settings, maybe that could be the culprit.

I'll check ASAP the logs and I will attempt to discard previous settings (it might take a while)

Thanks for the quick support :+1:

In this case what does it mean? 6008 is my webdav port while 6009 is a bogus and closed one (second row is WAN IP port test)

Can the gli.net app be used with op24?

Yes it can be used.

Sorry, are you referring to the WebDAV from 'Network Storage' on the Flint2?

You only need to turn on the Allow Access WebDAV from WAN option, and there is no need to manually add rules in port forwarding.

If it does not work, please share your router with us via GoodCloud, I would like to remote check your router.

Please PM me your router MAC address and the Admin Panel password.

Ofc, it’s set on.

I'll share my router details shortly on DMs :+1:

Brilliant

Thanks for the reply

Heard the 2.4 is a bit janky with drop out and the like

Have you found that too be true?

3 days going strong with a "dirty" upgrade, no issues whatsoever :call_me_hand:


Good job guys :+1:

3 Likes

temperature is no longer displayed in this version?\

It was?
I never noticed :thinking:

1 Like

It was removed earlier saying that since there’s no active cooling, the temperature readout only brings anxiety..