Skip to content
DnsLister Forum

Where domain hunters compare notes

[BUG REPORT] Linksys Velop Pro 7 (LN14) false-positive FW.LANATTACK DROP on outbound IPv6 causes “No Internet” on Android (Pixel 10)

Model: Linksys Velop Pro 7 10G (LN14-EU)

Firmware: 1.0.14.216698 (Build: 2025-06-25)

Affected Client: Google Pixel 10 (Android) connected over 5GHz Wi-Fi (802.11be / Wi-Fi 7)

Issue Description

When connecting a modern Android client (Pixel 10) to the primary Wi-Fi network, the device connects successfully but reports "No Internet Access" after a short period and falls back to mobile data.

Inspection of the router logs via /var/log/messages reveals that the router's internal firewall heuristic flags legitimate outbound IPv6 probes from the client as a network attack and drops them with FW.LANATTACK DROP.

Log Evidence (/var/log/messages / dmesg)

The client (b0:d5:fb:ba:44:5f on interface ath0/ath10) issues standard IPv6 DNS queries (2001:4860:4860::8888:53) and HTTP captive portal checks (2a00:1450:4007:810::2003:80/443), which are systematically dropped by the router:

Plaintext

kern.notice kernel: FW.LANATTACK DROP IN=br0 OUT=eth4 PHYSIN=ath0 MAC=80:69:1a:c5:70:68:b0:d5:fb:ba:44:5f:86:dd SRC=2a02:a03f:8af9:e440:fea6:6264:b490:2acd DST=2001:4860:4860:0000:0000:0000:0000:8888 LEN=80 TC=0 HOPLIMIT=63 FLOWLBL=0 PROTO=ICMPv6 TYPE=128 CODE=0 ID=45614 SEQ=1 kern.notice kernel: FW.LANATTACK DROP IN=br0 OUT=eth4 PHYSIN=ath0 MAC=80:69:1a:c5:70:68:b0:d5:fb:ba:44:5f:86:dd SRC=2a02:a03f:8af9:e440:fea6:6264:b490:2acd DST=2a00:1450:4007:0810:0000:0000:0000:2003 LEN=80 TC=0 HOPLIMIT=63 FLOWLBL=0 PROTO=TCP SPT=49497 DPT=80 

Because outbound IPv6 validation requests to Google's connectivity endpoints are blocked, Android determines the network has no usable internet connection and disconnects.

Root Cause

The SPI firewall / Qualcomm NSS PPE flood heuristics in the current firmware incorrectly classify outbound client bursts (specifically IPv6 SLAAC privacy-addressed traffic resolving DNS/HTTP probes) as a local LAN attack (FW.LANATTACK) rather than routing them out through WAN (eth4).

Current Workarounds

  • Disabling IPv6 completely on the router WAN interface resolves the problem, forcing the client onto IPv4 where no packet drops occur.
  • Disabling "IPv6 SPI Firewall" stops the drops, but leaves internal LAN devices unprotected from unsolicited inbound WAN traffic.

Request

Please review and patch the rate-limiting / flood-detection rules for outbound IPv6 traffic in the next firmware release for the LN14 platform so that legitimate outbound bursts are not flagged as LAN attacks.

Source: r/Linksys · by /u/Puzzleheaded-Cry1192

Leave a Reply

Your email address will not be published. Required fields are marked *