Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Wi-Fi: laptop yes, phone no

    Scheduled Pinned Locked Moved Wireless
    46 Posts 6 Posters 7.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mrkaban @fireodo
      last edited by

      @fireodo said in Wi-Fi: laptop yes, phone no:

      @mrkaban said in Wi-Fi: laptop yes, phone no:

      There is nothing in the firewall log from the WLAN interface (wireless network).

      When my Android Smartphone connects I see this in wireless log:

      Apr 2 15:24:00	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 IEEE 802.1X: unauthorizing port
      Apr 2 15:24:00	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: event 2 notification
      Apr 2 15:24:00	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 IEEE 802.11: disassociated
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: pairwise key handshake completed (RSN)
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 RADIUS: starting accounting session 665BCC0E11586A5E
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 IEEE 802.1X: authorizing port
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: received EAPOL-Key frame (4/4 Pairwise)
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: sending 3/4 msg of 4-Way Handshake
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: received EAPOL-Key frame (2/4 Pairwise)
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: sending 1/4 msg of 4-Way Handshake
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 IEEE 802.1X: unauthorizing port
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: start authentication
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 WPA: event 1 notification
      Apr 2 15:23:46	hostapd	35016	ath0_wlan0: STA 00:27:15:3d:db:a7 IEEE 802.11: associated
      

      (MAC Adress is edited)

      and where exactly do you see these statistics? Status \ System Logs \ System \ Wireless connection

      fireodoF 1 Reply Last reply Reply Quote 0
      • fireodoF
        fireodo @mrkaban
        last edited by fireodo

        @mrkaban said in Wi-Fi: laptop yes, phone no:

        and where exactly do you see these statistics? Status \ System Logs \ System \ Wireless connection

        Exact there! (Highlighted)

        Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
        SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
        pfsense 2.8.0 CE
        Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

        1 Reply Last reply Reply Quote 0
        • stephenw10S
          stephenw10 Netgate Administrator
          last edited by

          Yes I see the same.
          You should also see it in Status > Wireless

          M 1 Reply Last reply Reply Quote 0
          • M
            mrkaban @stephenw10
            last edited by mrkaban

            @stephenw10 said in Wi-Fi: laptop yes, phone no:

            Yes I see the same.
            You should also see it in Status > Wireless

            It took me a moment to realize that the most recent ones were from below. Here's what appears after trying to connect from your phone:

            alt text

            not in the form of a picture, antispam does not allow you to write

            fireodoF 1 Reply Last reply Reply Quote 0
            • fireodoF
              fireodo @mrkaban
              last edited by

              @mrkaban said in Wi-Fi: laptop yes, phone no:

              Here's what appears after trying to connect from your phone:

              I see there:

              EAPOL-Key timeout
              

              and I interprete that like the Authentication is not coming from your device - is that smartphone logging in correctly in a other access point?

              Kettop Mi4300YL CPU: i5-4300Y @ 1.60GHz RAM: 8GB Ethernet Ports: 4
              SSD: SanDisk pSSD-S2 16GB (ZFS) WiFi: WLE200NX
              pfsense 2.8.0 CE
              Packages: Apcupsd, Cron, Iftop, Iperf, LCDproc, Nmap, pfBlockerNG, RRD_Summary, Shellcmd, Snort, Speedtest, System_Patches.

              1 Reply Last reply Reply Quote 0
              • stephenw10S
                stephenw10 Netgate Administrator
                last edited by

                Also I assume if you login from the laptop the logs look the same as we see?

                M 1 Reply Last reply Reply Quote 0
                • M
                  mrkaban @stephenw10
                  last edited by

                  @stephenw10 said in Wi-Fi: laptop yes, phone no:

                  Also I assume if you login from the laptop the logs look the same as we see?

                  It connects to all other Wi-fi points from the phone without problems.

                  This is what I see when I connect from my laptop:

                  alt text

                  1 Reply Last reply Reply Quote 0
                  • stephenw10S
                    stephenw10 Netgate Administrator
                    last edited by

                    Possible the phone is restricted to WPA3 only? Other APs you tested against are WPA2?

                    M 1 Reply Last reply Reply Quote 0
                    • M
                      mrkaban @stephenw10
                      last edited by

                      @stephenw10 said in Wi-Fi: laptop yes, phone no:

                      Possible the phone is restricted to WPA3 only? Other APs you tested against are WPA2?

                      Currently connected to a wireless network with WPA2-PSK

                      1 Reply Last reply Reply Quote 0
                      • stephenw10S
                        stephenw10 Netgate Administrator
                        last edited by

                        @fireodo said in Wi-Fi: laptop yes, phone no:

                        rtl8192ce

                        What driver is that using? rtwn(4)? Is that USB or PCI connected?

                        What does sysctl dev.rtwn.0.hwcrypto show?

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          mrkaban @stephenw10
                          last edited by

                          @stephenw10 said in Wi-Fi: laptop yes, phone no:

                          sysctl dev.rtwn.0.hwcrypto

                          If you run "Diagnostics \ Command Prompt" here, then the output:

                          dev.rtwn.0.hwcrypto: 1

                          1 Reply Last reply Reply Quote 0
                          • stephenw10S
                            stephenw10 Netgate Administrator
                            last edited by

                            Hmm, well I don't think that hardware crypto applies to WPA2 but try disabling that with:
                            sysctl dev.rtwn.0.hwcrypto=0

                            Unclear if that applies immediately.

                            M 1 Reply Last reply Reply Quote 0
                            • M
                              mrkaban @stephenw10
                              last edited by

                              @stephenw10 said in Wi-Fi: laptop yes, phone no:

                              Hmm, well I don't think that hardware crypto applies to WPA2 but try disabling that with:
                              sysctl dev.rtwn.0.hwcrypto=0

                              Unclear if that applies immediately.

                              Completed, the output was:

                              sysctl: oid 'dev.rtwn.0.hwcrypto' is a read only tunable
                              sysctl: Tunable values are set in /boot/loader.conf

                              Of course I rebooted and tried. And only after the failure did I read what exactly he was writing.

                              1 Reply Last reply Reply Quote 0
                              • stephenw10S
                                stephenw10 Netgate Administrator
                                last edited by

                                Yup run: echo dev.rtwn.0.hwcrypto=0 >> /boot/loader.conf.local

                                Then reboot.

                                M 1 Reply Last reply Reply Quote 0
                                • M
                                  mrkaban @stephenw10
                                  last edited by

                                  @stephenw10 said in Wi-Fi: laptop yes, phone no:

                                  Yup run: echo dev.rtwn.0.hwcrypto=0 >> /boot/loader.conf.local

                                  Then reboot.

                                  As before, it does not pass authentication. He says that the password is incorrect, but it is definitely correct.

                                  1 Reply Last reply Reply Quote 0
                                  • stephenw10S
                                    stephenw10 Netgate Administrator
                                    last edited by

                                    Running sysctl dev.rtwn.0.hwcrypto shows it's correctly disabled?

                                    Hmm, I didn't really expect that make any difference in WPA2 unless it had a broken AES/TKIP implementation perhaps.

                                    Do you have an older Android you could test with? I'm not aware of any particular issue with Android 14 but I don't have a device to test with right now.

                                    M 2 Replies Last reply Reply Quote 0
                                    • M
                                      mrkaban @stephenw10
                                      last edited by

                                      @stephenw10 said in Wi-Fi: laptop yes, phone no:

                                      Running sysctl dev.rtwn.0.hwcrypto shows it's correctly disabled?

                                      Hmm, I didn't really expect that make any difference in WPA2 unless it had a broken AES/TKIP implementation perhaps.

                                      Do you have an older Android you could test with? I'm not aware of any particular issue with Android 14 but I don't have a device to test with right now.

                                      I don't have it on my hands, but I'll try to find it and check it out.

                                      1 Reply Last reply Reply Quote 1
                                      • M
                                        mrkaban @stephenw10
                                        last edited by

                                        @stephenw10 said in Wi-Fi: laptop yes, phone no:

                                        Running sysctl dev.rtwn.0.hwcrypto shows it's correctly disabled?

                                        Hmm, I didn't really expect that make any difference in WPA2 unless it had a broken AES/TKIP implementation perhaps.

                                        Do you have an older Android you could test with? I'm not aware of any particular issue with Android 14 but I don't have a device to test with right now.

                                        You're right, it connects to android 4 phones without any problems. There are problems with Android 13 and 14 from different manufacturers. What can I try to do?

                                        1 Reply Last reply Reply Quote 0
                                        • stephenw10S
                                          stephenw10 Netgate Administrator
                                          last edited by

                                          Hmm, well that seem like a clue. Perhaps some deprecated cypher is preventing it? I'm not sure how you might change that though. Can you test with anything else? An iOS device perhaps?

                                          M 1 Reply Last reply Reply Quote 0
                                          • M
                                            mrkaban @stephenw10
                                            last edited by

                                            @stephenw10 said in Wi-Fi: laptop yes, phone no:

                                            Hmm, well that seem like a clue. Perhaps some deprecated cypher is preventing it? I'm not sure how you might change that though. Can you test with anything else? An iOS device perhaps?

                                            To be honest, it was difficult to get a phone with android 4. I can check on another laptop. iOS probably won't be available.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.