Hey @JeffS,
Enjoy your vacation, no rush here at all. We’ll pick this right back up when you’re back after the 28th, and everything below will be waiting for you.
You actually found the culprit in step 4. Those three TP-Link security features, malicious content filter, intrusion prevention, and infected devices quarantine, are exactly what I’d want to test against, and the “defended against an attack from 192.168.0.211 and .210, classification DDoS” entries are the key clue. Those are internal (LAN) addresses, so they’re your own devices, and one of them is very likely the Mac mini. Roon Server holds many persistent, chatty connections open to our cloud, which is exactly the kind of traffic pattern these intrusion/DDoS systems tend to misread as an attack and start dropping. That lines up perfectly with what your logs showed: repeated timeouts to our servers from the mini specifically, while everything else on your network works fine.
So yes, when you’re back, those are the features to try turning off, and doing so is safe as a temporary diagnostic. A couple of notes so you’re comfortable:
First, before changing anything, jot down which IP the mini is using (System Settings → Network → Ethernet → Details will show it) so we can confirm whether .210 or .211 is in fact the mini. If it is, that essentially confirms the router is blocking Roon.
Second, the plan when you’re back would be, roughly in order: temporarily disable intrusion prevention first and restart Roon Server, then test artist overview and search. If that alone fixes it, we’ve found it and you can leave the other filters on. If not, also switch off the malicious content filter and the infected-devices quarantine, then test again. These are all reversible from the same TP-Link app screen, and turning them off briefly for a test doesn’t leave you exposed, your Macs each still have their own protections, and you can flip them back on the moment we confirm the cause.
If disabling all three restores things, the long-term fix is usually to add the Mac mini (or the Roon Server ports) to an allow-list / trusted-device exception in the TP-Link app so you can keep the security features enabled everywhere else.
One more reassurance: your DNS change looked correct. TP-Link/macOS replaced the single entry rather than appending to it, which is normal, 1.1.1.1 and 8.8.8.8 are both fine on their own.
Safe travels, and just reply here whenever you’re ready to continue. 