Present v2.3.3 has 2 defects in natpmp handling.
It creates wrong forward/accept rules in 2 ways:
if natpmp protocol is udp it creates tcp accept rule
if natpmp destination port != source port it creates rule regarding post-nat destination port
Both ways traversal does not happen at all.
Maintainer: none @stangri @stintel @jow-
Environment: x86_64 aarch64 ramips 23.05.0-3 snapshot
Description:
Present v2.3.3 has 2 defects in natpmp handling. It creates wrong forward/accept rules in 2 ways: if natpmp protocol is udp it creates tcp accept rule if natpmp destination port != source port it creates rule regarding post-nat destination port Both ways traversal does not happen at all.
Somewhat misguided maybe, but bypass attempt https://github.com/openwrt/firewall4/pull/28 Tried myself, https mirror still not avail https://forum.openwrt.org/t/how-to-proceed-updating-miniupnpd-233-236/194183 It works perfectly.