Can connect to wifi, obtain lan ip, sent arp packets, but cant neither ping router nor external servers

Hi, im new to the forum and I have a problem described in title. I can’t ping or connect to router or other devices on the same network or external servers. It started a while ago on kernel 5.10, switched recently to 6.1, but it didn’t help. I booted manjaro kde on usb on the same laptop, and with the same drivers everything works just fine. I have ip assigned by dhcp, and i can see my device in router admin panel. I checked it with wireshark, and i can see pings sent to me from another computer in the same wifi, but i don’t respond to them. I do respond to arp requests, and can send my own. Internet works through usb tethering (thats what i’ve been doing on this system for about a year…). I searched the forum, but didn’t find solution, any help would be very appreciated. Let me know if you need more information.

Some info:

$ inxi -v7azy

System:
  Kernel: 6.1.31-2-MANJARO arch: x86_64 bits: 64 compiler: gcc v: 13.1.1
    parameters: BOOT_IMAGE=/boot/vmlinuz-6.1-x86_64
    root=UUID=d34c8fb0-374c-4e97-8af1-537835c6b095 ro quiet apparmor=1
    security=apparmor udev.log_priority=3
  Desktop: Xfce v: 4.18.1 tk: Gtk v: 3.24.36 info: xfce4-panel wm: xfwm
    v: 4.18.0 vt: 7 dm: LightDM v: 1.32.0 Distro: Manjaro Linux base: Arch Linux
Machine:
  Type: Laptop System: LENOVO product: 81LB v: Lenovo Legion Y530-15ICH-1060
    serial: <superuser required> Chassis: type: 10 v: Lenovo Legion
    Y530-15ICH-1060 serial: <superuser required>
  Mobo: LENOVO model: LNVNB161216 v: NO DPK serial: <superuser required>
    UEFI: LENOVO v: 9VCN15WW date: 11/08/2018
Battery:
  ID-1: BAT0 charge: 5.7 Wh (16.1%) condition: 35.3/57.0 Wh (62.0%) volts: 11.9
    min: 11.5 model: SMP L17M3PG2 type: Li-poly serial: <filter> status: charging
Memory:
  System RAM: available: 15.5 GiB used: 5.7 GiB (36.8%)
  RAM Report: permissions: Unable to run dmidecode. Root privileges required.
CPU:
  Info: model: Intel Core i7-8750H bits: 64 type: MT MCP arch: Coffee Lake
    gen: core 8 level: v3 note: check built: 2018 process: Intel 14nm family: 6
    model-id: 0x9E (158) stepping: 0xA (10) microcode: 0xF2
  Topology: cpus: 1x cores: 6 tpc: 2 threads: 12 smt: enabled cache:
    L1: 384 KiB desc: d-6x32 KiB; i-6x32 KiB L2: 1.5 MiB desc: 6x256 KiB
    L3: 9 MiB desc: 1x9 MiB
  Speed (MHz): avg: 1150 high: 2200 min/max: 800/4100 scaling:
    driver: intel_pstate governor: powersave cores: 1: 800 2: 2200 3: 800 4: 2200
    5: 800 6: 800 7: 800 8: 800 9: 800 10: 800 11: 2200 12: 800 bogomips: 52815
  Flags: 3dnowprefetch abm acpi adx aes aperfmperf apic arat
    arch_capabilities arch_perfmon art avx avx2 bmi1 bmi2 bts clflush
    clflushopt cmov constant_tsc cpuid cpuid_fault cx16 cx8 de ds_cpl dtes64
    dtherm dts epb ept ept_ad erms est f16c flexpriority flush_l1d fma fpu
    fsgsbase fxsr ht hwp hwp_act_window hwp_epp hwp_notify ibpb ibrs ida
    intel_pt invpcid invpcid_single lahf_lm lm mca mce md_clear mmx monitor
    movbe mpx msr mtrr nonstop_tsc nopl nx pae pat pbe pcid pclmulqdq pdcm
    pdpe1gb pebs pge pln pni popcnt pse pse36 pti pts rdrand rdseed rdtscp
    rep_good sdbg sep smap smep ss ssbd sse sse2 sse4_1 sse4_2 ssse3 stibp
    syscall tm tm2 tpr_shadow tsc tsc_adjust tsc_deadline_timer vme vmx vnmi
    vpid x2apic xgetbv1 xsave xsavec xsaveopt xsaves xtopology xtpr
  Vulnerabilities:
  Type: itlb_multihit status: KVM: VMX disabled
  Type: l1tf mitigation: PTE Inversion; VMX: conditional cache flushes, SMT
    vulnerable
  Type: mds mitigation: Clear CPU buffers; SMT vulnerable
  Type: meltdown mitigation: PTI
  Type: mmio_stale_data mitigation: Clear CPU buffers; SMT vulnerable
  Type: retbleed mitigation: IBRS
  Type: spec_store_bypass mitigation: Speculative Store Bypass disabled via
    prctl
  Type: spectre_v1 mitigation: usercopy/swapgs barriers and __user pointer
    sanitization
  Type: spectre_v2 mitigation: IBRS, IBPB: conditional, STIBP: conditional,
    RSB filling, PBRSB-eIBRS: Not affected
  Type: srbds mitigation: Microcode
  Type: tsx_async_abort status: Not affected
Graphics:
  Device-1: Intel CoffeeLake-H GT2 [UHD Graphics 630] vendor: Lenovo
    driver: i915 v: kernel arch: Gen-9.5 process: Intel 14nm built: 2016-20
    ports: active: eDP-1 empty: none bus-ID: 00:02.0 chip-ID: 8086:3e9b
    class-ID: 0300
  Device-2: NVIDIA GP106M [GeForce GTX 1060 Mobile] vendor: Lenovo
    driver: nvidia v: 530.41.03 alternate: nouveau,nvidia_drm non-free: 530.xx+
    status: current (as of 2023-05) arch: Pascal code: GP10x process: TSMC 16nm
    built: 2016-21 pcie: gen: 1 speed: 2.5 GT/s lanes: 16 link-max: gen: 3
    speed: 8 GT/s bus-ID: 01:00.0 chip-ID: 10de:1c20 class-ID: 0300
  Device-3: Lite-On Integrated Camera driver: uvcvideo type: USB rev: 2.0
    speed: 480 Mb/s lanes: 1 mode: 2.0 bus-ID: 1-6:2 chip-ID: 04ca:7070
    class-ID: 0e02
  Display: x11 server: X.Org v: 21.1.8 compositor: xfwm v: 4.18.0 driver: X:
    loaded: modesetting,nvidia unloaded: nouveau alternate: fbdev,nv,vesa
    dri: iris gpu: i915 display-ID: :0.0 screens: 1
  Screen-1: 0 s-res: 1920x1080 s-dpi: 96 s-size: 508x285mm (20.00x11.22")
    s-diag: 582mm (22.93")
  Monitor-1: eDP-1 model: ChiMei InnoLux 0x15e8 built: 2016 res: 1920x1080
    hz: 60 dpi: 142 gamma: 1.2 size: 344x193mm (13.54x7.6") diag: 394mm (15.5")
    ratio: 16:9 modes: 1920x1080
  API: OpenGL Message: Unable to show GL data. Required tool glxinfo missing.
Audio:
  Device-1: Intel Cannon Lake PCH cAVS vendor: Lenovo driver: snd_hda_intel
    v: kernel alternate: snd_soc_skl,snd_sof_pci_intel_cnl bus-ID: 00:1f.3
    chip-ID: 8086:a348 class-ID: 0403
  Device-2: NVIDIA GP106 High Definition Audio driver: snd_hda_intel
    v: kernel pcie: gen: 1 speed: 2.5 GT/s lanes: 16 link-max: gen: 3
    speed: 8 GT/s bus-ID: 01:00.1 chip-ID: 10de:10f1 class-ID: 0403
  API: ALSA v: k6.1.31-2-MANJARO status: kernel-api with: aoss
    type: oss-emulator tools: alsactl,alsamixer,amixer
  Server-1: JACK v: 1.9.22 status: off tools: N/A
  Server-2: PipeWire v: 0.3.70 status: off tools: pw-cli
  Server-3: PulseAudio v: 16.1 status: active with: 1: pulseaudio-alsa
    type: plugin 2: pulseaudio-jack type: module tools: pacat,pactl,pavucontrol
Network:
  Device-1: Intel Dual Band Wireless-AC 3165 Plus Bluetooth driver: iwlwifi
    v: kernel pcie: gen: 1 speed: 2.5 GT/s lanes: 1 bus-ID: 07:00.0
    chip-ID: 8086:3166 class-ID: 0280
  IF: wlp7s0 state: up mac: <filter>
  IP v4: <filter> type: dynamic noprefixroute scope: global
    broadcast: <filter>
  IP v6: <filter> type: noprefixroute scope: link
  Device-2: Realtek RTL8111/8168/8411 PCI Express Gigabit Ethernet
    vendor: Lenovo driver: r8169 v: kernel pcie: gen: 1 speed: 2.5 GT/s lanes: 1
    port: 3000 bus-ID: 08:00.0 chip-ID: 10ec:8168 class-ID: 0200
  IF: enp8s0 state: down mac: <filter>
  IF-ID-1: enp0s20f0u4 state: unknown speed: -1 duplex: half mac: <filter>
  IP v4: <filter> type: dynamic noprefixroute scope: global
    broadcast: <filter>
  IP v6: <filter> type: noprefixroute scope: link
  WAN IP: <filter>
Bluetooth:
  Device-1: Intel Bluetooth wireless interface driver: btusb v: 0.8 type: USB
    rev: 2.0 speed: 12 Mb/s lanes: 1 mode: 1.1 bus-ID: 1-14:3 chip-ID: 8087:0a2a
    class-ID: e001
  Report: rfkill ID: hci0 rfk-id: 3 state: up address: see --recommends
Logical:
  Message: No logical block device data found.
RAID:
  Message: No RAID data found.
Drives:
  Local Storage: total: 596.45 GiB used: 189.47 GiB (31.8%)
  SMART Message: Required tool smartctl not installed. Check --recommends
  ID-1: /dev/nvme0n1 maj-min: 259:0 vendor: Western Digital model: PC SN720
    SDAPNTW-512G-1101 size: 476.94 GiB block-size: physical: 512 B
    logical: 512 B speed: 31.6 Gb/s lanes: 4 tech: SSD serial: <filter>
    fw-rev: 10130001 temp: 44.9 C scheme: GPT
  ID-2: /dev/sda maj-min: 8:0 vendor: Samsung model: Flash Drive FIT
    size: 119.51 GiB block-size: physical: 512 B logical: 512 B type: USB
    rev: 3.1 spd: 5 Gb/s lanes: 1 mode: 3.2 gen-1x1 tech: SSD serial: <filter>
    fw-rev: 1100 scheme: GPT
  Message: No optical or floppy data found.
Partition:
  ID-1: / raw-size: 274.36 GiB size: 269.75 GiB (98.32%)
    used: 189.47 GiB (70.2%) fs: ext4 dev: /dev/nvme0n1p5 maj-min: 259:5
    label: N/A uuid: d34c8fb0-374c-4e97-8af1-537835c6b095
  ID-2: /boot/efi raw-size: 100 MiB size: 96 MiB (96.00%)
    used: 450 KiB (0.5%) fs: vfat dev: /dev/nvme0n1p2 maj-min: 259:2 label: N/A
    uuid: 0A48-93C1
Swap:
  Alert: No swap data was found.
Unmounted:
  ID-1: /dev/nvme0n1p1 maj-min: 259:1 size: 529 MiB fs: ntfs label: N/A
    uuid: D2B4AC16B4ABFADD
  ID-2: /dev/nvme0n1p3 maj-min: 259:3 size: 500 MiB fs: vfat label: N/A
    uuid: 4CE7-B9E9
  ID-3: /dev/nvme0n1p4 maj-min: 259:4 size: 201.47 GiB fs: ext4 label: N/A
    uuid: 23bd7f80-421a-4c1f-b3bb-41b51796fa5e
  ID-4: /dev/sda1 maj-min: 8:1 size: 300 MiB fs: vfat label: NO_LABEL
    uuid: 2DB3-938D
  ID-5: /dev/sda2 maj-min: 8:2 size: 102.11 GiB fs: ext4 label: N/A
    uuid: 55c14b5e-fcd4-4c92-8847-6d73c08ca25d
  ID-6: /dev/sda3 maj-min: 8:3 size: 17.09 GiB fs: swap label: swap
    uuid: dae645e9-ac44-41d8-8a12-5c7dc02a56ca
USB:
  Hub-1: 1-0:1 info: hi-speed hub with single TT ports: 16 rev: 2.0
    speed: 480 Mb/s (57.2 MiB/s) lanes: 1 mode: 2.0 chip-ID: 1d6b:0002
    class-ID: 0900
  Device-1: 1-4:7 info: Motorola PCS moto g(30) type: CDC-data
    driver: rndis_host interfaces: 2 rev: 2.0 speed: 480 Mb/s (57.2 MiB/s)
    lanes: 1 mode: 2.0 power: 500mA chip-ID: 22b8:2e24 class-ID: 0a00
    serial: <filter>
  Device-2: 1-6:2 info: Lite-On Integrated Camera type: video
    driver: uvcvideo interfaces: 2 rev: 2.0 speed: 480 Mb/s (57.2 MiB/s) lanes: 1
    mode: 2.0 power: 500mA chip-ID: 04ca:7070 class-ID: 0e02
  Device-3: 1-14:3 info: Intel Bluetooth wireless interface type: bluetooth
    driver: btusb interfaces: 2 rev: 2.0 speed: 12 Mb/s (1.4 MiB/s) lanes: 1
    mode: 1.1 power: 100mA chip-ID: 8087:0a2a class-ID: e001
  Hub-2: 2-0:1 info: super-speed hub ports: 8 rev: 3.1
    speed: 10 Gb/s (1.16 GiB/s) lanes: 1 mode: 3.2 gen-2x1 chip-ID: 1d6b:0003
    class-ID: 0900
  Device-1: 2-3:2 info: Silicon Motion - Taiwan (formerly Feiya ) Flash Drive
    type: mass storage driver: usb-storage interfaces: 1 rev: 3.1
    speed: 5 Gb/s (596.0 MiB/s) lanes: 1 mode: 3.2 gen-1x1 power: 304mA
    chip-ID: 090c:1000 class-ID: 0806 serial: <filter>
Sensors:
  System Temperatures: cpu: 44.0 C pch: 59.0 C mobo: N/A
  Fan Speeds (RPM): N/A
Info:
  Processes: 299 Uptime: 3h 11m wakeups: 32424 Init: systemd v: 253
  default: graphical tool: systemctl Compilers: gcc: 13.1.1 alt: 11/12
  clang: 15.0.7 Packages: 1846 pm: pacman pkgs: 1831 libs: 444 tools: pamac,yay
  pm: flatpak pkgs: 0 pm: snap pkgs: 15 Shell: Bash v: 5.1.16
  running-in: xfce4-terminal inxi: 3.3.27
$ lspci -k

00:00.0 Host bridge: Intel Corporation 8th Gen Core Processor Host Bridge/DRAM Registers (rev 07)
	Subsystem: Lenovo 8th Gen Core Processor Host Bridge/DRAM Registers
	Kernel driver in use: skl_uncore
00:01.0 PCI bridge: Intel Corporation 6th-10th Gen Core Processor PCIe Controller (x16) (rev 07)
	Subsystem: Lenovo 6th-10th Gen Core Processor PCIe Controller (x16)
	Kernel driver in use: pcieport
00:02.0 VGA compatible controller: Intel Corporation CoffeeLake-H GT2 [UHD Graphics 630]
	Subsystem: Lenovo CoffeeLake-H GT2 [UHD Graphics 630]
	Kernel driver in use: i915
	Kernel modules: i915
00:04.0 Signal processing controller: Intel Corporation Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Thermal Subsystem (rev 07)
	Subsystem: Lenovo Xeon E3-1200 v5/E3-1500 v5/6th Gen Core Processor Thermal Subsystem
	Kernel driver in use: proc_thermal
	Kernel modules: processor_thermal_device_pci_legacy
00:08.0 System peripheral: Intel Corporation Xeon E3-1200 v5/v6 / E3-1500 v5 / 6th/7th/8th Gen Core Processor Gaussian Mixture Model
	Subsystem: Lenovo Xeon E3-1200 v5/v6 / E3-1500 v5 / 6th/7th/8th Gen Core Processor Gaussian Mixture Model
00:12.0 Signal processing controller: Intel Corporation Cannon Lake PCH Thermal Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH Thermal Controller
	Kernel driver in use: intel_pch_thermal
	Kernel modules: intel_pch_thermal
00:14.0 USB controller: Intel Corporation Cannon Lake PCH USB 3.1 xHCI Host Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH USB 3.1 xHCI Host Controller
	Kernel driver in use: xhci_hcd
	Kernel modules: xhci_pci
00:14.2 RAM memory: Intel Corporation Cannon Lake PCH Shared SRAM (rev 10)
	Subsystem: Lenovo Cannon Lake PCH Shared SRAM
00:15.0 Serial bus controller: Intel Corporation Cannon Lake PCH Serial IO I2C Controller #0 (rev 10)
	Subsystem: Lenovo Cannon Lake PCH Serial IO I2C Controller
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci
00:15.1 Serial bus controller: Intel Corporation Cannon Lake PCH Serial IO I2C Controller #1 (rev 10)
	Subsystem: Lenovo Cannon Lake PCH Serial IO I2C Controller
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci
00:16.0 Communication controller: Intel Corporation Cannon Lake PCH HECI Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH HECI Controller
	Kernel driver in use: mei_me
	Kernel modules: mei_me
00:17.0 SATA controller: Intel Corporation Cannon Lake Mobile PCH SATA AHCI Controller (rev 10)
	Subsystem: Lenovo Cannon Lake Mobile PCH SATA AHCI Controller
	Kernel driver in use: ahci
00:1d.0 PCI bridge: Intel Corporation Cannon Lake PCH PCI Express Root Port #9 (rev f0)
	Subsystem: Lenovo Cannon Lake PCH PCI Express Root Port
	Kernel driver in use: pcieport
00:1d.4 PCI bridge: Intel Corporation Cannon Lake PCH PCI Express Root Port #13 (rev f0)
	Subsystem: Lenovo Cannon Lake PCH PCI Express Root Port
	Kernel driver in use: pcieport
00:1d.5 PCI bridge: Intel Corporation Cannon Lake PCH PCI Express Root Port #14 (rev f0)
	Subsystem: Lenovo Cannon Lake PCH PCI Express Root Port
	Kernel driver in use: pcieport
00:1e.0 Communication controller: Intel Corporation Cannon Lake PCH Serial IO UART Host Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH Serial IO UART Host Controller
	Kernel driver in use: intel-lpss
	Kernel modules: intel_lpss_pci
00:1f.0 ISA bridge: Intel Corporation HM470 Chipset LPC/eSPI Controller (rev 10)
	Subsystem: Lenovo HM470 Chipset LPC/eSPI Controller
00:1f.3 Audio device: Intel Corporation Cannon Lake PCH cAVS (rev 10)
	Subsystem: Lenovo Cannon Lake PCH cAVS
	Kernel driver in use: snd_hda_intel
	Kernel modules: snd_hda_intel, snd_soc_skl, snd_sof_pci_intel_cnl
00:1f.4 SMBus: Intel Corporation Cannon Lake PCH SMBus Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH SMBus Controller
	Kernel driver in use: i801_smbus
	Kernel modules: i2c_i801
00:1f.5 Serial bus controller: Intel Corporation Cannon Lake PCH SPI Controller (rev 10)
	Subsystem: Lenovo Cannon Lake PCH SPI Controller
	Kernel driver in use: intel-spi
	Kernel modules: spi_intel_pci
01:00.0 VGA compatible controller: NVIDIA Corporation GP106M [GeForce GTX 1060 Mobile] (rev a1)
	Subsystem: Lenovo GP106M [GeForce GTX 1060 Mobile]
	Kernel driver in use: nvidia
	Kernel modules: nouveau, nvidia_drm, nvidia
01:00.1 Audio device: NVIDIA Corporation GP106 High Definition Audio Controller (rev a1)
	Kernel driver in use: snd_hda_intel
	Kernel modules: snd_hda_intel
06:00.0 Non-Volatile memory controller: Sandisk Corp WD Black 2018/SN750 / PC SN720 NVMe SSD
	Subsystem: Sandisk Corp WD Black 2018/SN750 / PC SN720 NVMe SSD
	Kernel driver in use: nvme
	Kernel modules: nvme
07:00.0 Network controller: Intel Corporation Dual Band Wireless-AC 3165 Plus Bluetooth (rev 99)
	Subsystem: Intel Corporation Dual Band Wireless-AC 3165
	Kernel driver in use: iwlwifi
	Kernel modules: iwlwifi
08:00.0 Ethernet controller: Realtek Semiconductor Co., Ltd. RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller (rev 15)
	Subsystem: Lenovo RTL8111/8168/8411 PCI Express Gigabit Ethernet Controller
	Kernel driver in use: r8169
	Kernel modules: r8169

patrial ip a:

3: wlp7s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether (mac) brd ff:ff:ff:ff:ff:ff
    inet 192.168.33.12/24 brd 192.168.33.255 scope global dynamic noprefixroute wlp7s0
       valid_lft 73031sec preferred_lft 73031sec
    inet6 fe80::70e0:2bcc:64b9:14b6/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever

sudo systemctl status NetworkManager (after restart)

● NetworkManager.service - Network Manager
     Loaded: loaded (/usr/lib/systemd/system/NetworkManager.service; enabled; preset: disabled)
     Active: active (running) since Sun 2023-06-11 20:45:00 CEST; 12s ago
       Docs: man:NetworkManager(8)
   Main PID: 19065 (NetworkManager)
      Tasks: 5 (limit: 19014)
     Memory: 8.8M
        CPU: 219ms
     CGroup: /system.slice/NetworkManager.service
             └─19065 /usr/bin/NetworkManager --no-daemon

cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.7572] dhcp4 (wlp7s0): activation: beginning transaction (timeout in 45 seconds)
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8139] dhcp4 (wlp7s0): state changed new lease, address=192.168.33.12
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8148] policy: set 'HALNy-2.4G' (wlp7s0) as default for IPv4 routing and DNS
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8247] device (wlp7s0): state change: ip-config -> ip-check (reason 'none', sys-iface-state: 'managed')
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8298] device (wlp7s0): state change: ip-check -> secondaries (reason 'none', sys-iface-state: 'managed')
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8304] device (wlp7s0): state change: secondaries -> activated (reason 'none', sys-iface-state: 'managed')
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8314] manager: NetworkManager state is now CONNECTED_SITE
cze 11 20:45:04 xory NetworkManager[19065]: <info>  [1686509104.8334] device (wlp7s0): Activation: successful, device activated.
cze 11 20:45:06 xory NetworkManager[19065]: <info>  [1686509106.4796] manager: startup complete
cze 11 20:45:06 xory NetworkManager[19065]: <warn>  [1686509106.7307] ndisc[0x56115e2977c0,"wlp7s0"]: solicit: failure sending router solicitation: Operation not permitted (1)

This has nothing to do with the xfce desktop environment. Please untag it as such.

Please provide the LAN IP of your router plus full output of:

ip a
ip r
ip -6 r

Partial output is not enough because we need to be able to check if there is something hindering the correct functionality…

Means you can only connect to your router if it has an address on the 192.168.33.x network unless you have a route setup properly to it…
:vulcan_salute:

Disable firewall.

Basic troubleshooting info

With firewalld (perhaps ufw as well) there is an option to block all network traffic - both in/out - sort of killswitch.

But there is also the shields up which blocks all incoming traffic.

https://man.archlinux.org/man/firewalld.1

@zbe @linux-aarhus i use ufw, turned it off - still the same problem

$ sudo ufw status
Status: inactive

@TriMoon here you go:

$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1000
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: enp8s0: <NO-CARRIER,BROADCAST,MULTICAST,UP> mtu 1500 qdisc fq_codel state DOWN group default qlen 1000
    link/ether [mac1] brd ff:ff:ff:ff:ff:ff
3: wlp7s0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
    link/ether [mac2] brd ff:ff:ff:ff:ff:ff
    inet 192.168.33.12/24 brd 192.168.33.255 scope global dynamic noprefixroute wlp7s0
       valid_lft 85791sec preferred_lft 85791sec
    inet6 fe80::70e0:2bcc:64b9:14b6/64 scope link noprefixroute 
       valid_lft forever preferred_lft forever
$ ip r
default via 192.168.33.1 dev wlp7s0 proto dhcp src 192.168.33.12 metric 20600 
192.168.33.0/24 dev wlp7s0 proto kernel scope link src 192.168.33.12 metric 600 
$ ip -6 r
::1 dev lo proto kernel metric 256 pref medium
fe80::/64 dev wlp7s0 proto kernel metric 1024 pref medium

So it is an old problem - you have had it for about a year according to your original post - and while I can sympathise - you have to know in what ways you have modded your system.

Even if ufw is not active iptables may still contain rules that block - if you get a response like below - that isn’t the cause.

 $ sudo iptables --list
Chain INPUT (policy ACCEPT)
target     prot opt source               destination         

Chain FORWARD (policy ACCEPT)
target     prot opt source               destination         

Chain OUTPUT (policy ACCEPT)
target     prot opt source               destination

It is clealy a configuration issue. You have faffed with something - impossible to know what.

You will have to work yourself backwards - it is impossible to deduct where and what you have changed.

Thanks a lot, turned out nordvpn-bin messed up with iptables. I reset them using this commands

https://wiki.archlinux.org/title/iptables#Resetting_rules

and everything works now. Appreciate your help :slight_smile:

So I reckon your iptables --list was not empty …