Stop the frequent firewall and https-dns-proxy reloads on DHCP lease renewals

Comcast sometimes sets a WAN IP leasetime of 3600 seconds, sometimes of 7200 seconds.

Each time, I get the same exact IP addresses, but each time, the firewall and https-dns-proxy reload. They don’t have to. So we’re going to fix it so they don’t reload unless the WAN IP addresses actually change, or there is a configuration change.

Issue:

vi /etc/hotplug.d/iface/20-firewall

And paste the following code in, right above the last 2 lines of already-existing code:

# === SAME-IP BYPASS LOGIC START ===
# Reload the firewall only after WAN/WAN6 IP address updates
if [ "$INTERFACE" = "wan" ] || [ "$INTERFACE" = "wan6" ]; then
	IP_CACHE="/tmp/last_${INTERFACE}_ip"

	# Handle IPv4 for wan, and IPv6-PD Prefix for wan6
	if [ "$INTERFACE" = "wan" ]; then
		CURRENT_IP=$(ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address')
		[ -z "$CURRENT_IP" ] && CURRENT_IP=$(ifstatus "wan" | jsonfilter -e '@["ipv4-address"][0].address')
	else
		CURRENT_IP=$(ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address')
		[ -z "$CURRENT_IP" ] && CURRENT_IP=$(ifstatus "wan6" | jsonfilter -e '@["ipv6-prefix"][0].address')
	fi

	if [ -n "$CURRENT_IP" ] && [ -f "$IP_CACHE" ]; then
		OLD_IP=$(cat "$IP_CACHE")
		if [ "$CURRENT_IP" = "$OLD_IP" ] && [ "$ACTION" = "ifupdate" ]; then
			logger -t firewall "Bypassing firewall reload: $INTERFACE IP address has not changed: ($CURRENT_IP)."
			exit 0
		fi
	fi
	# Update the cache for subsequent checks
	[ -n "$CURRENT_IP" ] && echo "$CURRENT_IP" > "$IP_CACHE"
fi
# === SAME-IP BYPASS LOGIC END ===

That’ll go right above this code:

logger -t firewall "Reloading firewall due to $ACTION of $INTERFACE ($DEVICE)"
fw4 -q reload

That fixes the firewall. Now let’s fix https-dns-proxy:

Issue:

vi /etc/init.d/https-dns-proxy

… at the very bottom, paste this code in:

# Intercept standard procd reloads
service_reload() {
        hdp_bypass_check
}

# Intercept legacy subsystem reloads
reload_service() {
        hdp_bypass_check
}

# The bypass logic block
hdp_bypass_check() {
        local wan_ip wan6_prefix old_wan_ip old_wan6_prefix

        # Fetch current IPs/Prefixes
        wan_ip=$(ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address')
        wan6_prefix=$(ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address')

        # Read cache files /tmp/last_wan_ip and /tmp/last_wan6_ip (created by the /etc/hotplug.d/iface/20-firewall and/or in /etc/rc.local)
        [ -f "/tmp/last_wan_ip" ] && old_wan_ip=$(cat /tmp/last_wan_ip)
        [ -f "/tmp/last_wan6_ip" ] && old_wan6_prefix=$(cat /tmp/last_wan6_ip)

        # If files exist and IPs are identical, exit without restarting https-dns-proxy
        if [ -n "$wan_ip" ] && [ "$wan_ip" = "$old_wan_ip" ] && [ "$wan6_prefix" = "$old_wan6_prefix" ]; then
                logger -t https-dns-proxy "Bypassing https-dns-proxy reload: WAN IPs have not changed."
                return 0
        fi

        # If WAN IP changes, or a config file is updated, restart https-dns-proxy
        logger -t https-dns-proxy "https-dns-proxy reloading: WAN IP changed or config update."

        # Call the script's internal stop/start logic
        stop
        start
}

And in /etc/rc.local (at System >> Startup >> Local Startup), enter the code below, above the ‘exit 0’ blurb:

# Seed firewall hotplug and https-dns-proxy IP address caches on boot
# ===========================================
(
ubus call "network.interface.wan" status | jsonfilter -e '@["ipv4-address"][0].address' > /tmp/last_wan_ip 2>/dev/null
ubus call "network.interface.wan6" status | jsonfilter -e '@["ipv6-prefix"][0].address' > /tmp/last_wan6_ip 2>/dev/null
) &
# ===========================================

Now you can test it by forcing a DHCP lease renewal of your WAN IP addresses:

kill -SIGUSR1 $(cat /var/run/udhcpc-eth0.pid)

Which should return something like this in your logs if your ISP returns to you the same IP addresses:

[Sep 30, 2026, 22:27:23] daemon.notice: netifd: wan (22238): udhcpc: sending renew to server 96.113.84.149
[Sep 30, 2026, 22:27:23] daemon.notice: netifd: wan (22238): udhcpc: lease of 73.32.15.32 obtained from 96.113.84.149, lease time 7200
[Sep 30, 2026, 22:27:23] user.notice: firewall: Bypassing firewall reload: wan IP address has not changed: (73.32.15.32).
[Sep 30, 2026, 22:27:24] user.notice: https-dns-proxy: Bypassing https-dns-proxy reload: WAN IPs have not changed.

And of course, we have to make sure the files survive firmware updates, so add:

/etc/hotplug.d/iface/20-firewall
/etc/init.d/https-dns-proxy

… to the System >> Backup / Flash firmware >> Configuration tab.