I have the following issue with my Brume 3 fw v4.8.6, that my wireguard VPN to Mullvad randomly breaks down. Can be a few days, sometimes 1-2 days, sometimes 2-5 days, but eventually, it will stop working. VPN shows still green connected in the Webgui, but no traffic working anymore from any clients. Reconnecting or switching the server manually solves it, until it stopps working again eventually.
Currently using Beryl 7 not observing this issue connecting to the vpn server at home, but I do know some variation of mullvad servers are not that good.
The albanian ones often go down, or sometimes disappear like albania server 1 was gone for me, I also had recently a outage with them on I believe on NL-104.
It is weird because of the 104 one, the dns got numerous times reported as a german dns when mullvad site reported dutch, so clearly they had a configuration issue on their end on their 92.60.40.xx block.
I dont think that it is an issue with Mullvads servers. I opened up a post at Reddit and mostly was down voted by a lot of people claiming they have no issues at their side. I am also not using some “fishy” servers in weird countries, but just the German Mullvad servers, and I have issues with them ALL:
I tried over the last weeks literally ALL of these, all servers in Frankfurt, Düsseldorf, Berlin, 1 to 5, they all eventually wil stop working sooner or later on my Brume 3. Web interface shows no issue, green light, nothing in the logs. Reconnecting (stop, restart) to the same server fixes it, or to another German server, until the issue happens again.
From my perspective on my clients, it looks like suddenly the bandwith breaks totally down, I am watching twitch for example, the streams start to lag or buffer and then the entire bandwith goes to zero, nothing works anymore. I had the suspicion that maybe the server I am connected to is ddosed, I switch to anothr like #3 from #2 it works for a while, then it stops again, as if the ddos was cycling, but I doubt it would happen to all of these servers.
It sound unlikely it is just a outtage if it happens to all those servers.
Do you have a certain configuration with dns running? And what MTU do you have set?
Mullvad does hijack dns on their side, you may have to override dns for all clients, and ensure rebind protection is not enabled due to how Mullvad hijacks it.
It must not exceed 1500 mtu, wireguard takes around 80 bytes, gl's default value is 1384 I believe for clients, that is fine as value.
And the minimum mtu is 1280 lower will break ipv6 support on wireguard.
Does it also happen with ipv6 option off in gl ui? Maybe the RA is disappearing for some reason.