=== STEP_031D IFUP VPN3 RUNTIME ONLY === timestamp=20260708-103621 intent: ifup vpn3 only expected: vpn3 runtime interface appears forbidden: firewall changes, table 203 routes, production policy switch, global network restart === BEFORE SAFE STATE === date=Wed Jul 8 10:36:21 UTC 2026 === vpn3 UCI safe fields before === proto=amneziawg auto=0 disabled=0 addresses=10.104.58.24/32 hmn_role=egress_pool_slot hmn_endpoint=95.211.68.119:45176 hmn_source_config=/root/hmn/configs/awg1/20260601-100614/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf hmn_loaded_at=2026-07-08T10:34:48+00:00 === ip -br addr before === lo UNKNOWN 127.0.0.1/8 ::1/128 eth0 UP 95.165.105.4/20 fe80::be24:11ff:fe42:83cf/64 eth1 UP 10.200.0.2/24 fe80::be24:11ff:fe09:4e2c/64 eth2 UP 10.71.100.2/24 fe80::be24:11ff:fe4d:7a71/64 eth3 UP 10.201.0.2/24 fe80::be24:11ff:fec8:2ee1/64 vpn1 UNKNOWN 10.91.233.132/32 === ip rule before === 0: from all lookup local 10019: from all iif eth1 lookup 200 10020: from 10.200.0.0/24 lookup 200 32766: from all lookup main 32767: from all lookup default === tables 200-205 before === TABLE 200 default dev vpn1 scope link 10.200.0.0/24 dev eth1 scope link src 10.200.0.2 10.201.0.0/24 dev eth3 scope link src 10.201.0.2 TABLE 201 TABLE 202 TABLE 203 TABLE 204 TABLE 205 === firewall vpn_out before === firewall.@zone[3].name='vpn_in' firewall.@zone[3].network='vpn_in' firewall.@zone[4].name='vpn_out' firewall.@zone[4].network='vpn1' 'vpn2' 'vpn_user' firewall.@rule[7].name='Allow-ICMP-from-vpn_in-to-router' firewall.@rule[7].src='vpn_in' firewall.@forwarding[0]=forwarding firewall.@forwarding[0].src='direct_in' firewall.@forwarding[0].dest='wan' firewall.@forwarding[1]=forwarding firewall.@forwarding[1].src='vpn_in' firewall.@forwarding[1].dest='vpn_out' firewall.@forwarding[2]=forwarding firewall.@forwarding[2].src='vpn_in' firewall.@forwarding[2].dest='wan' === uci pending before === === ACTION: ifup vpn3 only === IFUP_RC=0 === vpn3 runtime after ifup === vpn3 UNKNOWN 10.104.58.24/32 === wg show vpn3 after ifup === wg_vpn3_absent_or_down === OPTIONAL NON-BLOCKING PING PROBE VIA vpn3 === PING 1.1.1.1 (1.1.1.1): 56 data bytes 64 bytes from 1.1.1.1: seq=0 ttl=55 time=51.861 ms 64 bytes from 1.1.1.1: seq=1 ttl=55 time=51.711 ms 64 bytes from 1.1.1.1: seq=2 ttl=55 time=51.759 ms --- 1.1.1.1 ping statistics --- 3 packets transmitted, 3 packets received, 0% packet loss round-trip min/avg/max = 51.711/51.777/51.861 ms PING_I_VPN3_RC=0 === wg show vpn3 after optional probe === wg_vpn3_absent_or_down === AFTER SAFE STATE === date=Wed Jul 8 10:36:35 UTC 2026 === ip -br addr after === lo UNKNOWN 127.0.0.1/8 ::1/128 eth0 UP 95.165.105.4/20 fe80::be24:11ff:fe42:83cf/64 eth1 UP 10.200.0.2/24 fe80::be24:11ff:fe09:4e2c/64 eth2 UP 10.71.100.2/24 fe80::be24:11ff:fe4d:7a71/64 eth3 UP 10.201.0.2/24 fe80::be24:11ff:fec8:2ee1/64 vpn1 UNKNOWN 10.91.233.132/32 vpn3 UNKNOWN 10.104.58.24/32 === ip rule after === 0: from all lookup local 10019: from all iif eth1 lookup 200 10020: from 10.200.0.0/24 lookup 200 32766: from all lookup main 32767: from all lookup default === tables 200-205 after === TABLE 200 default dev vpn1 scope link 10.200.0.0/24 dev eth1 scope link src 10.200.0.2 10.201.0.0/24 dev eth3 scope link src 10.201.0.2 TABLE 201 TABLE 202 TABLE 203 TABLE 204 TABLE 205 === main route after === default via 95.165.96.1 dev eth0 proto static src 95.165.105.4 10.71.100.0/24 dev eth2 proto kernel scope link src 10.71.100.2 10.200.0.0/24 dev eth1 proto kernel scope link src 10.200.0.2 10.201.0.0/24 dev eth3 proto kernel scope link src 10.201.0.2 10.250.100.0/24 via 10.71.100.1 dev eth2 proto static 95.165.96.0/20 dev eth0 proto kernel scope link src 95.165.105.4 95.211.68.119 via 95.165.96.1 dev eth0 proto static 178.215.227.13 via 95.165.96.1 dev eth0 proto static 192.71.27.64 via 95.165.96.1 dev eth0 proto static 192.121.163.235 via 95.165.96.1 dev eth0 proto static === firewall vpn_out after === firewall.@zone[3].name='vpn_in' firewall.@zone[3].network='vpn_in' firewall.@zone[4].name='vpn_out' firewall.@zone[4].network='vpn1' 'vpn2' 'vpn_user' firewall.@rule[7].name='Allow-ICMP-from-vpn_in-to-router' firewall.@rule[7].src='vpn_in' firewall.@forwarding[0]=forwarding firewall.@forwarding[0].src='direct_in' firewall.@forwarding[0].dest='wan' firewall.@forwarding[1]=forwarding firewall.@forwarding[1].src='vpn_in' firewall.@forwarding[1].dest='vpn_out' firewall.@forwarding[2]=forwarding firewall.@forwarding[2].src='vpn_in' firewall.@forwarding[2].dest='wan' === vpn3 UCI safe fields after === proto=amneziawg auto=0 disabled=0 addresses=10.104.58.24/32 hmn_role=egress_pool_slot hmn_endpoint=95.211.68.119:45176 hmn_source_config=/root/hmn/configs/awg1/20260601-100614/075-NL-Netherlands-Amsterdam-H13-95.211.68.119-awg1.conf hmn_loaded_at=2026-07-08T10:34:48+00:00 === wg concise after === === uci pending after === === legacy processes after === === STEP_031D RESULT === ifup_rc=0 vpn3_runtime_lines=1 uci_pending_change_lines_after=0 table203_nonempty_lines=0 firewall_has_vpn3=0 ping_i_vpn3_rc=0 decision=PASS_VPN3_IFUP_RUNTIME_ONLY === SAFE CAPTURE === REPORT=/opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/REPORT.txt SAFE_ARCHIVE=/opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621.safe.tar.gz RAW_LOCAL_ONLY=/opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw -rw-r--r-- 1 ops ops 25K Jul 8 10:36 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621.safe.tar.gz -rw------- 1 ops ops 171K Jul 8 10:36 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/REPORT.txt === RC SUMMARY === /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/local_access_map.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/local_date.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/local_router_ops_tree.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_bridges.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_qm_list.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_snapshots_100.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_snapshots_101.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_vm100_config.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/pve_vm101_config.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm100_basic.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm100_relevant_files.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm100_uci_firewall.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm100_uci_network.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm100_wg_show.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_basic.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_hmn_tree.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_rt_nft.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_services_cron.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_uci_firewall.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_uci_network.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm101_wg_show.txt:rc=0 /opt/router-ops/captures/20260708-103635_step031d_ifup_vpn3_runtime_only_20260708-103621/raw/vm121_state.txt:rc=0