Forgot to ask you, but what are the use cases for using the Brume 3 as a secondary/home auxiliary router? In which situations would anyone use the Brume 3 like that?
Thanks, but I don't know why you didn't address the second part of the post.
What's the point of the guest and IoT networks if there is no difference between them? Surely there has to be some difference.
Ok, I have v4.9.0-op24 beta2
-
automatic panel logout does not work, the same should be for ssh auto logout
-
when connecting pppoe I get google dns, why not ips?
Log
Sun Oct 19 18:53:34 2025 daemon.notice netifd: Network device 'eth1' link is up
Sun Oct 19 18:53:34 2025 daemon.notice netifd: Interface 'wan' has link connectivity
Sun Oct 19 18:53:34 2025 daemon.notice netifd: Interface 'wan' is setting up now
Sun Oct 19 18:53:34 2025 kern.info kernel: [ 961.090912] mtk_soc_eth 15100000.ethernet eth1: Link is Up - 1Gbps/Full - flow control off
Sun Oct 19 18:53:34 2025 daemon.info pppd[31969]: Plugin pppoe.so loaded.
Sun Oct 19 18:53:34 2025 daemon.info pppd[31969]: PPPoE plugin from pppd 2.5.1
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: pppd 2.5.1 started by root, uid 0
Sun Oct 19 18:53:34 2025 daemon.info pppd[31969]: PPP session is 22543
Sun Oct 19 18:53:34 2025 daemon.warn pppd[31969]: Connected to F4:XX:XX:XX:XX:XX via interface eth1
Sun Oct 19 18:53:34 2025 daemon.info pppd[31969]: Using interface pppoe-wan
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: Connect: pppoe-wan <--> eth1
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: CHAP authentication succeeded
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: peer from calling number F4:XX:XX:XX:XX:XX authorized
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: local IP address XXX.XXX.XXX.XXX
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: remote IP address XXX.XXX.XXX.X
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: primary DNS address 8.8.8.8
Sun Oct 19 18:53:34 2025 daemon.notice pppd[31969]: secondary DNS address 8.8.4.4
Sun Oct 19 18:53:34 2025 daemon.info avahi-daemon[7691]: Joining mDNS multicast group on interface pppoe-wan.IPv4 with address XXX.XXX.XXX.XXX.
Sun Oct 19 18:53:34 2025 daemon.info avahi-daemon[7691]: New relevant interface pppoe-wan.IPv4 for mDNS.
Sun Oct 19 18:53:34 2025 daemon.info avahi-daemon[7691]: Registering new address record for XXX.XXX.XXX.XXX on pppoe-wan.IPv4.
Sun Oct 19 18:53:34 2025 daemon.notice netifd: Network device 'pppoe-wan' link is up
Sun Oct 19 18:53:34 2025 daemon.notice netifd: Interface 'wan' is now up
Sun Oct 19 18:53:36 2025 user.notice kmwan: config json str={ "op": 2, "data": { "cells": [ { "interface": "wan", "netdev": "pppoe-wan", "track_mode": "force", "addr_type": 4, "force_ip": "XXX.XXX.XXX.XXX", "tracks": [ { "type": "ping", "ip": "1.1.1.1" }, { "type": "ping", "ip": "8.8.8.8" }, { "type": "ping", "ip": "208.67.222.222" }, { "type": "ping", "ip": "208.67.220.220" } ] } ] } }
Sun Oct 19 18:53:36 2025 kern.debug kernel: [ 962.585978] [add_dev_config 321]add node success. iface:wan, dev:pppoe-wan, ifindex:22
Sun Oct 19 18:53:36 2025 daemon.info gl-repeater[4625]: (repeater.lua:2175) interface wan offline
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: exiting on receipt of SIGTERM
Sun Oct 19 18:53:36 2025 user.notice firewall: Reloading firewall due to ifup of wan (pppoe-wan)
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: started, version 2.92 cachesize 1000
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: DNS service limited to local subnets
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: compile time options: IPv6 GNU-getopt no-DBus UBus no-i18n no-IDN DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC no-ID loop-detect inotify dumpfile
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: UBus support enabled: connected to system bus
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq-dhcp[1]: DHCP, IP range 192.168.9.100 -- 192.168.9.249, lease time 12h
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq-dhcp[1]: DHCP, IP range 192.168.8.100 -- 192.168.8.249, lease time 12h
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq-dhcp[1]: IPv6 router advertisement enabled
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using nameserver 127.0.0.1#5453
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for test
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for onion
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for localhost
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for local
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for invalid
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for bind
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: using only locally-known addresses for lan
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: read /etc/hosts - 12 names
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq[1]: read /tmp/hosts/dhcp.cfg01411c - 6 names
Sun Oct 19 18:53:36 2025 daemon.info dnsmasq-dhcp[1]: read /etc/ethers - 0 addresses
Sun Oct 19 18:53:39 2025 daemon.info gl-repeater[4625]: (repeater.lua:2175) interface wan online
Sun Oct 19 18:54:01 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:54:26 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:54:51 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:55:16 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:55:41 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:56:06 2025 user.notice timesync: Restarting chronyd due to repeated failures.
Sun Oct 19 18:56:07 2025 user.notice timesync: chrony sync failed after 30 attempts
- During the first start/new installation with the standard configuration and the first connection, DNS DOT/DOH is set, it will not work (in the sense of converting to numbers), it is better to leave DNS automatically to synchronize the time zone or with DOT/DOH set, force the time zone change.
- Is it possible to make the guest network so that there is no isolation on 2.4 GHz and isolation is active on 5GHz?
He did answer it already:
They’re intended to be used according to their names, but you’re in no way limited to this arrangement. You could use the Guests to serve your IoT devices and vice versa. The provided names are just to help guide you.
Functionally, they behave the same with respect to their associated subnets with the additional benefit of isolating those subnets from the LAN as well as from each other.
I was under the impression that other than the name, there are other differences. I guess I was wrong and that both networks are not just essentially the same, but it's the same.
No, they're distinctly different networks, associated with distinctly different devices. They just impose identical firewall rules.
Hi,
Please refer to our answers below:
-
We checked the Auto-Logout Time setting, and it appears to work normally in our environment.
Please note that the countdown only starts after the page is closed or the page enters a hibernating state. We suggest closing the page and performing further tests (for example, opening it again both within and after the configured timeout period to check whether login is still required).
Regarding SSH, this option does not apply to SSH sessions. If you would like SSH sessions to automatically log out after being idle for a certain period, you can adjust the Dropbear settings:
uci set dropbear.@dropbear[0].IdleTimeout='30' # unit: seconds uci commit /etc/init.d/dropbear restartPlease note that you may need to log out from the current SSH session and reconnect for the change to take effect.
-
The DNS addresses obtained through PPPoE are provided by your ISP, so it appears that your ISP is providing Google DNS instead of ISP-specific DNS servers like some other ISPs do.
-
This should be expected behavior. Since the new version uses NTS, switching to DoT/DoH before time synchronization is completed may cause a race condition.
Please make sure the system time has been successfully synchronized before switching to DoT/DoH.
-
You can manually adjust this under LuCI → Network → Wireless:
It is the average CPU load, the numbers tell how many CPU cores are in use averaged.
Thanks for the reply ![]()
- thanks for the ssh tip
and as for the panel, it actually works after closing the tab, but only when I open it after exceeding the set time, then I have to log in, but it doesn't seem to work when I have the entire panel open, after exceeding the time, I can still browse, it just doesn't log me out. I have Firefox 153.0.3~build1
I have this
after a minute of inactivity I change it to 5 minutes
a moment later this message is displayed
after that I have to log in and I see I have 5 minutes set
-
My mistake, I used the manual settings on my previous router for a long time using Cloudflare, and I didn't check if my ISP still had the same settings as before, but it turns out it changed to Google's. Oops.

-
Oh yeah, I didn't think to look at Luci... great
Just to be sure, I'll ask if disabling AP isolation in the guest network is still isolated from the primary network?
how about the internal test progress now, it has been another week.
It is still under testing.
Before the firmware is officially released, we will go through multiple rounds of testing. If any issues are discovered, additional time will be needed for fixes and further verification to ensure the firmware is stable and reliable before release.
Please give us some more time, and thank you for your patience.
I have 4.9.0-op24 and 1Gbps fiber optic, has anyone complained about low transfer speeds with acceleration disabled?
I have a Flint 2 and gigabit internet, and when I turn off hardware acceleration, my Wi-Fi speed drops to ~800 Mbit, which isn't good enough for me
We checked this, and it appears that there may indeed be some issues with detecting pages in a suspended/sleep state.
We will ask the development team to investigate how we can fix or optimize this behavior in future versions.
The isolation will still remain effective after this change.
The isolation between the Main LAN and Guest network is implemented at Layer 3 through the firewall, while Wi-Fi AP isolation works at Layer 2. In most cases, they do not affect each other.
I'm glad it's not just me
I think that the default session for Luci should also be changed to a shorter time, an hour is quite long.
After reading Luca's post I can see that it won't be easy, especially where there are active tabs ![]()
That's great. That's great. And ACL is also used to block the internet for specific devices?
And now a small suggestion. It would be great if you could add the current connection times for WAN PPPOE/IPOE and connected clients.
Yes, there is a drop, and after enabling QoS or SQM it is even worse.
I factory reset my Beryl AX with v4.9 beta 6 installed and noticed some differences compared to previously upgraded from v4.8 and carrying the old settings over.
Is it not possible to create a new tunnel without a VPN when running policy-based routing? I was able to do so when upgrading from v4.8 to v4.9. Now, after the factory reset, I only see the ability to add a VPN to the tunnel. I also used the Enhanced Kill Switch to ensure all devices used the tunnels. Now, I'm using allow non-VPN traffic to get my new setup going. What changed after the factory reset?
Also, under Admin Access, I have also enabled force HTTPS, but yet when trying to access the admin panel, I still get a warning from my browser that the connection isn't secured. What's going on?
Is it best to disable SSH and all options under Remote Access Control to maximize network security?
Then you shouldnt disable Hw acceleration; the raw cpu performance might not be good enough for 1Gbps+.
For some other features to work you have to disable hardware acceleration - DPI / content management needs to have HW accel of if you want to use those features.
It is still possible, but not as simply as before. The procedure is described there:





