You should not change the firewall rules manually. I think it broken the rules causing IP leak.

ok

I’ve reverted the firmware to stock 3.025.

Didn’t mess with LUCI at all and only configured the port forwarding and the VPN client in the GL.iNet Admin Panel.

Now activated the said script on my Raspberry PI behind the MT300N again: will report tomorrow if there were any IP leaks over the night.

However I now again have the problem with not being able to access ( “Host is down” message) the SMB share which is on a device on the same side with the GL’s WAN from behind the GL’s LAN while the VPN client is connected. Not even able to ping any device from over the GL’s NAT; even though the Internet IPs - that’s over the double NAT (trippple NAT if you count the VPN) do get pinged.

If the last paragraph looks too complicated: I need to access the devices from my main LAN which is the GL’s WAN from the GL’s LAN however the GL seems to be blocking that as long as there is an established VPN connection.