Skip to content

Set up the HaLow mesh

Use this runbook to configure a new Morse Micro EKH19 evaluation kit and add it to the Bedrock HaLow network. It covers the multi-node deployment in which one stationary rack gate provides the Ethernet uplink and portable gates provide 2.4 GHz Wi-Fi access to phones.

The initial configuration follows the Morse Micro OpenWrt 2.9 802.11s Mesh Wizard. The portable-gate bridge correction is essential on the evaluated EKH19 build: selecting the same logical network on two wireless interfaces did not by itself create a Linux bridge.

Target topology

flowchart LR
    SW["Server-rack switch<br/>192.168.51.0/24"] ---|"Ethernet eth0"| RG
    RG["Rack gate<br/>HaLow gateway 192.168.12.1"]
    RG <-->|"802.11s HaLow"| M["Multi-node mesh<br/>BedrockDefence"]
    M <-->|"802.11s HaLow"| P["Portable gates 1...N<br/>2.4 GHz APs"]
    P --- PH["Phones"]

The rack gate and all portable gates participate in the 802.11s mesh and announce themselves as Mesh Gates. Only the rack gate routes and performs NAT towards Ethernet. Each portable gate bridges its phone-facing 2.4 GHz AP onto the HaLow mesh and does not run DHCP.

Deployment values

Setting Value
Mesh ID BedrockDefence
Mesh encryption WPA3-SAE (CCMP)
Mesh passphrase Deployment secret; use the same value on every gate
Portable 2.4 GHz SSID BedrockDefence
Portable AP encryption WPA2-PSK (CCMP)
Portable AP passphrase Deployment secret; use the same value on every portable gate
HaLow client subnet 192.168.12.0/24
Rack HaLow address/gateway 192.168.12.1
Rack upstream address 192.168.51.169/24
DNS supplied by DHCP 1.1.1.1, 8.8.8.8

Do not record either wireless passphrase in this repository. Set the regulatory region for the deployment location before configuring channels.

Before you start

  • Have local access to each gate and its OpenWrt web interface.
  • Connect and configure one new gate at a time. Give each gate a unique hostname before adding the next one.
  • Keep the rack gate's HaLow mesh radio enabled throughout. Disabling the whole radio removes the backhaul; disable only an unwanted 2.4 GHz AP interface.
  • Record the rack gate's current configuration or download an OpenWrt backup.
  • Factory-reset a gate whose prior role or network configuration is unknown.

The vendor procedure is in sections 3.9.2-3.9.4 of UG MM6108/MM8108 Eval Kit User Guide 2.9 - v25. Morse Micro also publishes an 802.11s configuration application note.

Configure the rack gate

Run the 802.11s wizard

  1. Connect to the factory-reset gate and complete the initial setup, including the correct regulatory region and HaLow channel.
  2. Open Wizards -> 802.11s Mesh Wizard.
  3. Select Mesh Gate.
  4. Set the Mesh ID to BedrockDefence, select WPA3-SAE, and enter the deployment mesh passphrase.
  5. Set Upstream Network to Ethernet and Traffic Mode to Router.
  6. Leave the optional co-located HaLow AP disabled unless the deployment also needs non-mesh 802.11ah clients. This wizard page does not configure the phone-facing 2.4 GHz AP.
  7. Apply the configuration, then connect eth0 to the server-rack switch.

Configure addressing, DHCP, and forwarding

The evaluated rack gate uses these logical networks:

  • The Ethernet/upstream network has 192.168.51.169/24.
  • ahwlan is static at 192.168.12.1/24 and is the mesh/client network.
  • The DHCP server is enabled only on ahwlan.

In Network -> DHCP and DNS, configure the ahwlan DHCP server to send:

3,192.168.12.1
6,1.1.1.1,8.8.8.8

Option 3 supplies the default gateway and option 6 supplies DNS. Save and apply the DHCP settings; a lease containing only an address is not sufficient.

In Network -> Firewall:

  1. Place ahwlan in its own firewall zone.
  2. Allow forwarding from the ahwlan zone to the Ethernet/upstream lan zone.
  3. Enable masquerading on the upstream lan zone.

Interface and zone names can differ after a firmware change. Verify them by device and address: the upstream side contains eth0 and 192.168.51.169/24; the downstream side contains the HaLow mesh interface and 192.168.12.1/24.

Confirm from Network -> Diagnostics that the rack gate can ping both its upstream gateway (for example 192.168.51.1) and 8.8.8.8.

Add a portable gate

Run the 802.11s wizard

  1. Factory-reset the portable gate and complete initial setup with the same regulatory region and compatible HaLow channel as the rack gate.
  2. Set a unique hostname using the deployment's naming scheme, such as Portable-Gate-03.
  3. Open Wizards -> 802.11s Mesh Wizard and select Mesh Gate.
  4. Configure Mesh ID BedrockDefence, WPA3-SAE, and the same mesh passphrase as the rack gate.
  5. Set Upstream Network to None.
  6. Leave the optional co-located HaLow AP disabled unless 802.11ah client access is explicitly required.
  7. Apply the configuration and confirm that at least one established mesh peer appears under Network -> Wireless -> Associated Stations. Depending on placement, this may be the rack gate or a neighbouring portable gate.

Use Network -> Wireless to enable the portable gate's 2.4 GHz radio as an Access Point:

  • Mode: Access Point
  • SSID: BedrockDefence
  • Encryption: WPA2-PSK (strong security)
  • Cipher: CCMP, or auto when the status resolves to CCMP
  • Key: the shared portable-AP passphrase
  • MAC filtering: disabled
  • Client isolation: disabled
  • 802.11w Management Frame Protection: disabled unless a deployment-specific policy requires it and all clients have been tested

Correct the portable-gate bridge

Do not stop after assigning both radios to ahwlan

On the evaluated OpenWrt 2.9 EKH19 image, ahwlan was a DHCP client bound directly to wlan0. Assigning the 2.4 GHz AP to the same logical network left phy1-ap0 and wlan0 as separate devices. The portable gate obtained its own lease, but client DHCP broadcasts could not cross the mesh.

Use the existing br-lan device. Do not create another bridge in Network -> Devices.

Stage the following changes and apply them together:

  1. Open Network -> Interfaces -> lan -> Edit.
  2. Set Protocol to DHCP client.
  3. Keep Device set to br-lan.
  4. Remove the old static 192.168.8.1/24 configuration if the UI does not remove it automatically.
  5. Under DHCP Server, enable Ignore interface.
  6. Open Network -> Wireless, edit the 2.4 GHz AP, and set Network to lan instead of ahwlan.
  7. Edit the HaLow Mesh Point and set Network to lan instead of ahwlan.
  8. Delete the now-redundant portable ahwlan interface. It must not remain bound directly to wlan0, because that prevents wlan0 from becoming a port of br-lan.
  9. Select Save & Apply. If OpenWrt warns about a connectivity change, choose Apply and keep settings.

The management address will usually change because br-lan has a different MAC address from wlan0. On the rack gate, open the DHCP leases and find the portable gate by hostname, then reconnect to its new 192.168.12.x address.

Repeat the complete portable-gate procedure for each additional gate. Portable gates use the same client SSID and passphrase for roaming, but retain unique hostnames. Plan channel reuse across non-overlapping 2.4 GHz channels (normally 1, 6, and 11), reusing a channel only where the portable gates are sufficiently separated.

Verify a portable gate

From Services -> Terminal on the portable gate, run:

bridge link
ubus call network.interface.lan status

The result must show both wlan0 and phy1-ap0 as ports with master br-lan. The lan interface must have:

  • a 192.168.12.x/24 address;
  • default route via 192.168.12.1;
  • DNS servers 1.1.1.1 and 8.8.8.8; and
  • DHCP server identifier 192.168.12.1.

Connect a phone to the portable 2.4 GHz AP and verify, in order:

  1. The phone remains in the AP's Associated Stations list.
  2. A phone lease appears on the rack gate.
  3. The phone receives a 192.168.12.x/24 address, gateway 192.168.12.1, and the configured DNS servers.
  4. The phone can reach 192.168.12.1.
  5. The phone can reach the rack gate's upstream address 192.168.51.169.
  6. The phone can reach the rack servers and the internet.

Troubleshooting

Phone reports "Failed to obtain IP address"

Check the portable gate while the phone attempts to connect:

iw dev phy1-ap0 station dump
logread | grep -E 'hostapd|DHCP|dnsmasq' | tail -n 80
bridge link

EAPOL-4WAY-HS-COMPLETED proves the WPA exchange completed. If the phone then disconnects after roughly 20 seconds and bridge link is empty, return to Correct the portable-gate bridge. The phone may disappear from the Associated Stations table after its DHCP timeout even though Wi-Fi authentication succeeded.

The phone may be choosing another same-SSID AP

During fault isolation, power off the other portable gates or temporarily give the test AP a unique SSID. Disable only the rack's 2.4 GHz AP interface; do not disable the rack HaLow mesh radio.

A lease has no gateway or DNS

Confirm that the rack gate's ahwlan DHCP server has options 3 and 6 configured and saved. Do not add a static route to the phone or laptop.

Avoid these changes

  • Do not enable a DHCP server on a portable gate.
  • Do not create another Linux bridge through Network -> Devices.
  • Do not add static routes to phones or laptops.
  • Do not change rack firewalling until association, bridge membership, and the complete DHCP lease have been verified.