Comcast sometimes sets a WAN IP leasetime of 3600 seconds, sometimes of 7200 seconds.
Each time, I get the same exact IP addresses, but each time, the firewall and https-dns-proxy reload. They don’t have to. So we’re going to fix it so they don’t reload unless the WAN IP addresses actually change, or there is a configuration change.
Issue:
vi /etc/hotplug.d/iface/20-firewall
And paste the following code in, right above the last 2 lines of already-existing code:
# === SAME-IP BYPASS LOGIC START === # Reload the firewall only after WAN/WAN6 IP address updates if [ "$INTERFACE" = "wan" ] || [ "$INTERFACE" = "wan6" ]; then IP_CACHE="/tmp/last_${INTERFACE}_ip" # Handle IPv4 for wan, and IPv6-PD Prefix for wan6 if [ "$INTERFACE" = "wan" ]; then CURRENT_IP=$(ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address') [ -z "$CURRENT_IP" ] && CURRENT_IP=$(ifstatus "wan" | jsonfilter -e '@["ipv4-address"][0].address') else CURRENT_IP=$(ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address') [ -z "$CURRENT_IP" ] && CURRENT_IP=$(ifstatus "wan6" | jsonfilter -e '@["ipv6-prefix"][0].address') fi if [ -n "$CURRENT_IP" ] && [ -f "$IP_CACHE" ]; then OLD_IP=$(cat "$IP_CACHE") if [ "$CURRENT_IP" = "$OLD_IP" ] && [ "$ACTION" = "ifupdate" ]; then logger -t firewall "Bypassing firewall reload: $INTERFACE IP address has not changed: ($CURRENT_IP)." exit 0 fi fi # Update the cache for subsequent checks [ -n "$CURRENT_IP" ] && echo "$CURRENT_IP" > "$IP_CACHE" fi # === SAME-IP BYPASS LOGIC END ===
That’ll go right above this code:
logger -t firewall "Reloading firewall due to $ACTION of $INTERFACE ($DEVICE)" fw4 -q reload
That fixes the firewall. Now let’s fix https-dns-proxy:
Issue:
vi /etc/init.d/https-dns-proxy
… at the very bottom, paste this code in:
# Intercept standard procd reloads service_reload() { hdp_bypass_check } # Intercept legacy subsystem reloads reload_service() { hdp_bypass_check } # The bypass logic block hdp_bypass_check() { local wan_ip wan6_prefix old_wan_ip old_wan6_prefix # Fetch current IPs/Prefixes wan_ip=$(ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address') wan6_prefix=$(ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address') # Read cache files /tmp/last_wan_ip and /tmp/last_wan6_ip (created by the /etc/hotplug.d/iface/20-firewall and/or in /etc/rc.local) [ -f "/tmp/last_wan_ip" ] && old_wan_ip=$(cat /tmp/last_wan_ip) [ -f "/tmp/last_wan6_ip" ] && old_wan6_prefix=$(cat /tmp/last_wan6_ip) # If files exist and IPs are identical, exit without restarting https-dns-proxy if [ -n "$wan_ip" ] && [ "$wan_ip" = "$old_wan_ip" ] && [ "$wan6_prefix" = "$old_wan6_prefix" ]; then logger -t https-dns-proxy "Bypassing https-dns-proxy reload: WAN IPs have not changed." return 0 fi # If WAN IP changes, or a config file is updated, restart https-dns-proxy logger -t https-dns-proxy "https-dns-proxy reloading: WAN IP changed or config update." # Call the script's internal stop/start logic stop start }
And in /etc/rc.local (at System >> Startup >> Local Startup), enter the code below, above the ‘exit 0’ blurb:
# Seed firewall hotplug and https-dns-proxy IP address caches on boot # =========================================== ( ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address' > /tmp/last_wan_ip 2>/dev/null ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address' > /tmp/last_wan6_ip 2>/dev/null ) & # ===========================================
Now you can test it by forcing a DHCP lease renewal of your WAN IP addresses:
kill -SIGUSR1 $(cat /var/run/udhcpc-eth0.pid)
Which should return something like this in your logs if your ISP returns to you the same IP addresses:
[Sep 30, 2026, 22:27:23] daemon.notice: netifd: wan (22238): udhcpc: sending renew to server 96.113.84.149 [Sep 30, 2026, 22:27:23] daemon.notice: netifd: wan (22238): udhcpc: lease of 73.32.15.32 obtained from 96.113.84.149, lease time 7200 [Sep 30, 2026, 22:27:23] user.notice: firewall: Bypassing firewall reload: wan IP address has not changed: (73.32.15.32). [Sep 30, 2026, 22:27:24] user.notice: https-dns-proxy: Bypassing https-dns-proxy reload: WAN IPs have not changed.
And of course, we have to make sure the files survive firmware updates, so add:
/etc/hotplug.d/iface/20-firewall /etc/init.d/https-dns-proxy
… to the System >> Backup / Flash firmware >> Configuration tab.