Just noticed.
Disable updates-proxy-setup service for vpn-firewall. This service should be enabled for templates but not for UpdateVM:
qubes-updates-proxy (and its deprecated name: qubes-yum-proxy ) - a service providing a proxy for templates - by default enabled in NetVMs (especially: sys-net)
updates-proxy-setup (and its deprecated name: yum-proxy-setup ) - use a proxy provided by another VM (instead of downloading updates directly), enabled by default in all templates
OK, so I switched all my qubes back to fedora and was able to update the Fedora template without issues. The issue is with Debian 10 somewhere. I tried disabling updates-proxy-setup in vpn-firewall and enabling it in services on debian 10 template, no luck. I am trying to install a new template using
Thank you everyone for your help! You were all so responsive and helpful! Will do enmus. I think I figured it out, my solution was to install Debian 11 template and I was able to update this with update proxy through vpn. I think Debian 10 was just so old it lacked whatever was needed to update. I might make a guide at some point for first time users to set up with a VPN if they want, it was a bit rough (it only took a couple weeks) but everything is working now.