OK, I’ve got my new Omnia up. It has TOS 7.1.3 and almost everything works perfectly. But Ibhave a deep mystery I am struggling to solve and seek guidance to diagnose and ultimately fix.
The Omnia is a gateway between the WAN and my LAN. On that LAN are numerous WAPs besides the Omnia’s two WLAN interfaces. These WAPs include two OpenWRT WAPs, two Netgear WAPs, and the Omnia as a WAP too.
The symptoms are as follows:
- All wired LAN devices have access to the WAN
- I am serving numerous websites from the LAN using lighttpd as a reverse proxy.
- I have numerous IOT things on the WLAN that are seeing the WAN.
- I can connect to any WAP with Linux laptop and I can access the WAN.
- I have tested three phones, a Samsung, a Google Pixel and an Air Ultra all Android and have problems. One the Pixel works fine, the other two refuse to connect to any of the WAPS complaining that they can connect but not access the internet so cycle between WAPs trying again and again.
- I can even ssh to the WAPs (the openWRT ones), and see the WAN from there. But when some phones connect to that WAP they cannot. And on the previous Omnia (that this one replaces, they could).
In summary, a select few devices (with nothing much in common bar Android of different versions) cannot connect to the WAPs because they complain about lacking access to the Internet.
To add to the conundrum, I have two Omnias. The one I am commissioning is my spare. Which I am glad of because my other one has developed a serious fil3system problem (nothing can be saved anymore every reboot resets to the last snapshot and I can’t take any new snapshots and a btrfs scrub finds a load of unrecoverable errors, and more … so it’s pulled out of service for now for deeper diagnosis and rebuild, but available for comparison on configs, in fact had to manually transfer a lot of configs across. The old one is TOS4 and the one I’m working with now is TOS7.
The TOS4 one allowed both these errant phones to acccess the internet on any of these WAPs. The TOD7 Omnia does not.
it is not a WLAN configuration, as evidence by the fact that the same issue exists on all WAPS, the Turris ones and four other WAPs on the LAN. It is not a general firewall issue as laptops and some phones have no problem. But there is something at play, likely in the routing/firewall zone that is denying some phones access to the WAN when they connect to one of my WAPs.
When I look at the Firewall configs in Luci they are many and complicated. It is much more useful to work CLI (using ssh) and being able to dump configs into text format files for comparison.
What I am looking for here is pointers. What kind of issue could be at play here, how do we diagnose it and ultimately fix it.
WAN access issue for some phones all WAPs, for no laptops on any WAP, nor for any wired LAN device nor many IoT devices on the WLAN (connected to different WAPs for reasons of signal strength across a broad property).
There is something at play here with Android. Not least it’s annoying feature of refusing to connect to the WAP if it can’t get internet. If I knew how to turn that off! Any laptop connects fine to the WAP internet or not, and can navigate LAN devices. Why not these phones for crying out loud. And why did these phone shave no problem on my old flaky TOS4 Omnia and what files/configs can I dump from that and the new one to compare.
Could it be the new Omnia’s Threat Detection or Active Firewall?