Set up the HaLow mesh¶
Use this runbook to configure a new Morse Micro EKH19 evaluation kit and add it to the Bedrock HaLow network. It covers the multi-node deployment in which one stationary rack gate provides the Ethernet uplink and portable gates provide 2.4 GHz Wi-Fi access to phones.
The initial configuration follows the Morse Micro OpenWrt 2.9 802.11s Mesh Wizard. The portable-gate bridge correction is essential on the evaluated EKH19 build: selecting the same logical network on two wireless interfaces did not by itself create a Linux bridge.
Target topology¶
flowchart LR
SW["Server-rack switch<br/>192.168.51.0/24"] ---|"Ethernet eth0"| RG
RG["Rack gate<br/>HaLow gateway 192.168.12.1"]
RG <-->|"802.11s HaLow"| M["Multi-node mesh<br/>BedrockDefence"]
M <-->|"802.11s HaLow"| P["Portable gates 1...N<br/>2.4 GHz APs"]
P --- PH["Phones"]
The rack gate and all portable gates participate in the 802.11s mesh and announce themselves as Mesh Gates. Only the rack gate routes and performs NAT towards Ethernet. Each portable gate bridges its phone-facing 2.4 GHz AP onto the HaLow mesh and does not run DHCP.
Deployment values¶
| Setting | Value |
|---|---|
| Mesh ID | BedrockDefence |
| Mesh encryption | WPA3-SAE (CCMP) |
| Mesh passphrase | Deployment secret; use the same value on every gate |
| Portable 2.4 GHz SSID | BedrockDefence |
| Portable AP encryption | WPA2-PSK (CCMP) |
| Portable AP passphrase | Deployment secret; use the same value on every portable gate |
| HaLow client subnet | 192.168.12.0/24 |
| Rack HaLow address/gateway | 192.168.12.1 |
| Rack upstream address | 192.168.51.169/24 |
| DNS supplied by DHCP | 1.1.1.1, 8.8.8.8 |
Do not record either wireless passphrase in this repository. Set the regulatory region for the deployment location before configuring channels.
Before you start¶
- Have local access to each gate and its OpenWrt web interface.
- Connect and configure one new gate at a time. Give each gate a unique hostname before adding the next one.
- Keep the rack gate's HaLow mesh radio enabled throughout. Disabling the whole radio removes the backhaul; disable only an unwanted 2.4 GHz AP interface.
- Record the rack gate's current configuration or download an OpenWrt backup.
- Factory-reset a gate whose prior role or network configuration is unknown.
The vendor procedure is in sections 3.9.2-3.9.4 of UG MM6108/MM8108 Eval Kit User Guide 2.9 - v25. Morse Micro also publishes an 802.11s configuration application note.
Configure the rack gate¶
Run the 802.11s wizard¶
- Connect to the factory-reset gate and complete the initial setup, including the correct regulatory region and HaLow channel.
- Open Wizards -> 802.11s Mesh Wizard.
- Select Mesh Gate.
- Set the Mesh ID to
BedrockDefence, select WPA3-SAE, and enter the deployment mesh passphrase. - Set Upstream Network to Ethernet and Traffic Mode to Router.
- Leave the optional co-located HaLow AP disabled unless the deployment also needs non-mesh 802.11ah clients. This wizard page does not configure the phone-facing 2.4 GHz AP.
- Apply the configuration, then connect
eth0to the server-rack switch.
Configure addressing, DHCP, and forwarding¶
The evaluated rack gate uses these logical networks:
- The Ethernet/upstream network has
192.168.51.169/24. ahwlanis static at192.168.12.1/24and is the mesh/client network.- The DHCP server is enabled only on
ahwlan.
In Network -> DHCP and DNS, configure the ahwlan DHCP server to send:
Option 3 supplies the default gateway and option 6 supplies DNS. Save and apply the DHCP settings; a lease containing only an address is not sufficient.
In Network -> Firewall:
- Place
ahwlanin its own firewall zone. - Allow forwarding from the
ahwlanzone to the Ethernet/upstreamlanzone. - Enable masquerading on the upstream
lanzone.
Interface and zone names can differ after a firmware change. Verify them by
device and address: the upstream side contains eth0 and
192.168.51.169/24; the downstream side contains the HaLow mesh interface and
192.168.12.1/24.
Confirm from Network -> Diagnostics that the rack gate can ping both its
upstream gateway (for example 192.168.51.1) and 8.8.8.8.
Add a portable gate¶
Run the 802.11s wizard¶
- Factory-reset the portable gate and complete initial setup with the same regulatory region and compatible HaLow channel as the rack gate.
- Set a unique hostname using the deployment's naming scheme, such as
Portable-Gate-03. - Open Wizards -> 802.11s Mesh Wizard and select Mesh Gate.
- Configure Mesh ID
BedrockDefence, WPA3-SAE, and the same mesh passphrase as the rack gate. - Set Upstream Network to None.
- Leave the optional co-located HaLow AP disabled unless 802.11ah client access is explicitly required.
- Apply the configuration and confirm that at least one established mesh peer appears under Network -> Wireless -> Associated Stations. Depending on placement, this may be the rack gate or a neighbouring portable gate.
Use Network -> Wireless to enable the portable gate's 2.4 GHz radio as an Access Point:
- Mode: Access Point
- SSID:
BedrockDefence - Encryption: WPA2-PSK (strong security)
- Cipher: CCMP, or
autowhen the status resolves to CCMP - Key: the shared portable-AP passphrase
- MAC filtering: disabled
- Client isolation: disabled
- 802.11w Management Frame Protection: disabled unless a deployment-specific policy requires it and all clients have been tested
Correct the portable-gate bridge¶
Do not stop after assigning both radios to ahwlan
On the evaluated OpenWrt 2.9 EKH19 image, ahwlan was a DHCP client bound
directly to wlan0. Assigning the 2.4 GHz AP to the same logical network
left phy1-ap0 and wlan0 as separate devices. The portable gate obtained
its own lease, but client DHCP broadcasts could not cross the mesh.
Use the existing br-lan device. Do not create another bridge in
Network -> Devices.
Stage the following changes and apply them together:
- Open Network -> Interfaces -> lan -> Edit.
- Set Protocol to DHCP client.
- Keep Device set to br-lan.
- Remove the old static
192.168.8.1/24configuration if the UI does not remove it automatically. - Under DHCP Server, enable Ignore interface.
- Open Network -> Wireless, edit the 2.4 GHz AP, and set Network to
lan instead of
ahwlan. - Edit the HaLow Mesh Point and set Network to lan instead of
ahwlan. - Delete the now-redundant portable
ahwlaninterface. It must not remain bound directly towlan0, because that preventswlan0from becoming a port ofbr-lan. - Select Save & Apply. If OpenWrt warns about a connectivity change, choose Apply and keep settings.
The management address will usually change because br-lan has a different
MAC address from wlan0. On the rack gate, open the DHCP leases and find the
portable gate by hostname, then reconnect to its new 192.168.12.x address.
Repeat the complete portable-gate procedure for each additional gate. Portable gates use the same client SSID and passphrase for roaming, but retain unique hostnames. Plan channel reuse across non-overlapping 2.4 GHz channels (normally 1, 6, and 11), reusing a channel only where the portable gates are sufficiently separated.
Verify a portable gate¶
From Services -> Terminal on the portable gate, run:
The result must show both wlan0 and phy1-ap0 as ports with
master br-lan. The lan interface must have:
- a
192.168.12.x/24address; - default route via
192.168.12.1; - DNS servers
1.1.1.1and8.8.8.8; and - DHCP server identifier
192.168.12.1.
Connect a phone to the portable 2.4 GHz AP and verify, in order:
- The phone remains in the AP's Associated Stations list.
- A phone lease appears on the rack gate.
- The phone receives a
192.168.12.x/24address, gateway192.168.12.1, and the configured DNS servers. - The phone can reach
192.168.12.1. - The phone can reach the rack gate's upstream address
192.168.51.169. - The phone can reach the rack servers and the internet.
Troubleshooting¶
Phone reports "Failed to obtain IP address"¶
Check the portable gate while the phone attempts to connect:
EAPOL-4WAY-HS-COMPLETED proves the WPA exchange completed. If the phone then
disconnects after roughly 20 seconds and bridge link is empty, return to
Correct the portable-gate bridge. The phone
may disappear from the Associated Stations table after its DHCP timeout even
though Wi-Fi authentication succeeded.
The phone may be choosing another same-SSID AP¶
During fault isolation, power off the other portable gates or temporarily give the test AP a unique SSID. Disable only the rack's 2.4 GHz AP interface; do not disable the rack HaLow mesh radio.
A lease has no gateway or DNS¶
Confirm that the rack gate's ahwlan DHCP server has options 3 and 6 configured
and saved. Do not add a static route to the phone or laptop.
Avoid these changes¶
- Do not enable a DHCP server on a portable gate.
- Do not create another Linux bridge through Network -> Devices.
- Do not add static routes to phones or laptops.
- Do not change rack firewalling until association, bridge membership, and the complete DHCP lease have been verified.