@IBH I think this is the key firewall rule: config zone option name 'wan' list network 'wan' list network 'wwan' option output 'ACCEPT' option masq '1' option mtu_fix '1' option input 'ACCEPT' option forward 'ACCEPT' It causes masquerading of the sta through the ap.