Mine is PPPoE cleint. There are 2 mangle rules “change MSS” at the top. Sometimes, for unknown reason, they were moved to the bottom.
Without them, some of the web pages can not be visited. When this happened, I have to move them to the top manually.
Is it a bug? Is there anyway to ALWAYS stick them at the top?
Those mangle rules that change position are automatically created ones for PPP interfaces.
Mine always stays at the bottom of my firewall table. I’m using an Intel x86 machine with ROS v5.2, and PPPoE & PPTP clients.
I haven’t tried moving those dynamic/automatically created ‘change MSS’ rules to the top though.
Perhaps you should try to create those ‘Change MSS’ rules manually?
If there are no other mangle rules in the froward chain, the position of those rules doesn’t matter and they will work no matter what.
That’s why they usually work.
One can do packet marking in the prerouting chain instead of forward, so they don’t interfere.