In summary I find this is a confusing config that is either genius put together and above my limited knowledge or a hodge podge of internet searched rules cobbled together. ?????
It's neither. Most things aren't active/in use. I mean it's obviously a double NAT configuration. I can clean this up, though. I tested a lot of stuff in the beginning and was confused on how to delete some of the things or didn't bother.
The only things that are important is the bridge with 192.168.178.0/24 ip pool and the 2 wan interfaces.
And the question is why the connection between a server on 192.168.178.3 and the clients on 192.168.178.20-150 is getting interrupted every now and then.
(1) You should update to 7.4.1 firmware, less bugs and more stable.
Ok.
(2) Someone else can assist, I dont help those who configure vlan-id=1
I don't use any VLans
(3) Cannot understand your pool structure
Only DHCP pool #10 is in use.
(4) Do not understand why you need two bridge
There is one bridge for the 192.168.178.0/24 adresses and another one that was a default for configuring a connection to the router I think.
(5) Do not understand the lack of consistency in number of vlans, dhcp-server, dhcp-server-networkls, IP pools, and IP addresses
192.168.178.0/24 - Clients and Server
192.168.176.254 - Wan 1 goes to a Fritzbox
192.168.179.254 - Wan 2 goes to another Fritzbox
(6) I think your mixing up use of forward chain and NAT chain for port forwarding.
How would I port forward otherwise? Let's say from 192.168.176.254:8080 to 192.168.178.3:8080
(7) Total lack of default and expected firewall rules
It's a double NAT setup. Firewall rules are in place on the routers connected to the ISPs
(8) Not sure why you have a route rule for a public DNS server?
Recursive routing failover.
(9) Not clear why you are mangling as dont understand your wan situation.
I wanted load balancing between the 2 WAN ports but didn't manage to make sure that the gateway where the request came in was the same gateway the response was sent to. So I configured one line as failover instead of load balancing. All mangling rules are disabled, I thought its visible in the config. I don't want to delete them as I think they worked mostly and I may need them again.
best