WiFi
About WiFi
WiFi on Wikipedia
Abbreviations
- AP
- Access Point
- BSS
- Basic Service Set (base station, AP)
- CSMA
- CSMA/CA
- CSMA/CD
- DFS
- DSSS
- FT
- OFDM
- MIMO
- MU-MIMO
- QAM
- SRD
- Short Range Devices (25 mW)
- STA
- Station
- SSID
- Service Set Identifier
- TDM
- TPC
- Transmitter Power Control, for IEEE 802.11h-2003 WLAN
- TKIP
- WM
- Wireless medium
- WME
- WMM
Wi-Fi Multimedia (=WME)
- WPS
WiFi Optimization
Here are some notes on configuring a secure and fast WiFi network. When changing options in the WiFi, it may be necessary to disconnect and reconnect to the SSID to make the changes work.
Use an open software
An open source firmware offers some huge benefits over proprietary firmwares:
- Control
- Rich feature set
- Standard compliance
You may loose some features of the original vendors firmware, but they probably wouldn't work either e.g.
- if you have a heterogenous Wi-Fi setup
- or are broken anyway.
I love OpenWRT.
Prior to buying a device you should check if it is already supported by OpenWRT. (Maybe only to have a plan B.)
Country code
Relevant options in OpenWRT are below
WiFi: Device Configuration: Advanced SettingsAlways set the right country code
to choose the correct frequency bands/channels and to comply with regulatory requirements.
WiFi channels
About WiFi channels
WiFi channels are just 5 MHz apart (in both bands.
- Channels may be bonded to increase bandwidth.
Relevant options in OpenWRT are below
WiFi: Device Configuration: General Setup- There are basically two types of interference
- Channel interference occurs on the same channel and is resolved using TDM sharing airtime. Sharing airtime is the better option in comparison to every STA shouting to the shared media and none of them can communicate efficiently.
- Co-Channel interference occurs between different channels that (partially) overlap, but is not targeted by TDM. Interference will just occur and disturb you network.
- Adjacent stations (no matter if your own or not) should not transmit on the same channel.
WiFi site survey
- Scan for other SSIDs, their channels and transmission power and create yourself a picture of the environment.
- Try to choose channels that are not overcrowded with other SSIDs.
- Please also see:
Channel width
- 2,4 GHz
In urban areas use 20 MHz wide channels to minimize interference.
- If you are on a farm in rural area use 40 MHz to gain bandwidth. Otherwise this is quite rude.
- 5 GHz
- 80 MHz wide wide channels are common, because 5 GHz is not as crowded as the 2.4 GHz band.
- If you don't need the bandwidth, (e.g. because the uplink is limited and shared across multiple nodes anyway) use narrower channels (40 MHz or 20MHz) to minimize interference and increase the number of distinct channels.
Non-overlapping Channels
Select only Non-overlapping Channels to minimize interference by using TDM and thus sharing airtime.
- 2,4 GHz (802.11b/g/n/ax/be/bn)
- 20 MHz channel width
- EU/Japan: 1,5,9,13
- USA: 1,6,11
- 40 MHz channel width
- Two non-overlapping channels
- 3 {1-6},11 {7-13}
- Only a single non-overlapping channel
- 4 {2-7}
- 5 {3-8}
- 6 {4-9}
- 7 {5-10}
- 8 {6-11}
- 8 {7-12}
- 10 {8-13}
- Two non-overlapping channels
- 20 MHz channel width
- 5 GHz (802.11a/h/n/ac/ax/be/bn)
- 20 MHz channel width
- EU/Japan:
- 36,40,44,48 Indoors/TPC
- 52,56,60,64 Indoors/DFS/TPC
- 68-96 Unused
- 100,104,108,112,116,120,124,128 DFS/TPC
- 132,136,140 DFS/SRD/TPC
- 144,149,153,157,161,165,169,173 SRD
- EU/Japan:
- 40 MHz channel width
- EU/Japan:
- 38 {36-40},46 {44-48} Indoors/TPC
- 54 {52,56},62 {60,64} Indoors/DFS/TPC
- 102 {100,104},110 {108,112},118 {116,120},126 {124,128} DFS/TPC
- EU/Japan:
- 80 MHz channel width
- EU/Japan:
- 42 {36,40,44,48} Indoors/TPC
- 58 {52,56,60,64} Indoors/DFS/TPC
- 106 {100,104,108,112},122 {116,120,124,128} DFS/TPC
- EU/Japan:
- 160 MHz channel width
- EU/Japan:
- 50 {36,40,44,48,52,56,60,64} Indoors/DFS/TPC
- 114 {100,104,108,112,116,120,124,128} DFS/TPC
- EU/Japan:
- 20 MHz channel width
- 6 GHz (802.11ax/be/bn) for Wi‑Fi 6E (IEEE 802.11ax), Wi-Fi 7 (IEEE 802.11be) and Wi-Fi 8 (IEEE 802.11bn).
On the same channel WiFi can use a time division multiplexing algorithm with other stations to increase performance for all. This is not possible if channels differ and interference will occur.
- The timeslots are usually shared equally/fair across the nodes participating on the same channel, given the fact that the firmware supports this feature.
These timeslots are called AIRTIME.
- The timeslots are usually shared equally/fair across the nodes participating on the same channel, given the fact that the firmware supports this feature.
Limit transmission power
If you drive a larger WiFi infrastructure you should limit the transmission power of each station to a value that offers full coverage of the area and simultaneously minimizes channel interference with your other stations utilizing the same channel. The signal should optimally decay before reaching the next station or they will share airtime (TDM).
This is involves additional #WiFi site surveys.
Disable 802.11b
- Uncheck "Allow legacy 802.11b rates"
Legacy or badly behaving devices may require legacy 802.11b rates to interoperate. Airtime efficiency may be significantly reduced where these are used. It is recommended to not allow 802.11b rates where possible.
Wi-Fi Multimedia (WMM)
Relevant options in OpenWRT are below
WiFi: Interface Configuration: General Setup- Where Wi-Fi Multimedia (WMM) Mode QoS is disabled, clients may be limited to 802.11a/802.11g rates.
- based on the IEEE 802.11e provides basic Quality of service (QoS) features to IEEE 802.11 networks.
Security
Relevant options in OpenWRT are below
WiFi: Interface Configuration: Security
WiFi Encryption
- "WPA2-PSK (strong security)" is usually a good option.
- "WPA3" and "WPA2/WPA3" mixed modes may cause interoperability issues and older client may not be able to connect.
This is not a good option for a "guest" WiFi.
WiFi Cipher
- Don't use cipher set to 'auto'.
- was deprecated by the IEEE in January 2009. TKIP is said to be limiting the data rates.
Key reinstallation (KRACK) countermeasures
- Check "Enable key reinstallation (KRACK) countermeasures"
- Complicates key reinstallation attacks on the client side by disabling retransmission of EAPOL-Key frames that are used to install keys. This workaround might cause interoperability issues and reduced robustness of key negotiation especially in environments with heavy traffic load.
802.11r Fast Transition
Relevant options in OpenWRT are below
WiFi: Interface Configuration: WLAN roamingEnable IEEE "802.11r Fast Transition"
to allow clients to move between BSS, 2.4 GHz and 5 GHz seamlessly.- Please make sure to use the identical mobility domain on all nodes (or leave the field empty to derive it from the SSID) with the same SSID.
Other tuning tips
WPS
WPS is widely understood to be insecure. It should not be used.
- vulnerable to brute-force and dictionary attacks (in few hours)
- Not very well supported
- Android removed WPS
- Linux desktop environments don't support it (gnome-shell seems to be an exception)
iw
iw - show / manipulate wireless devices and their configuration
man iw
List Wiki EN PHYs
List devices
Get currently registered country (to avoid radar interference)
iw wifi survey
Scan for other BSS on a device
1 iw dev wlp5s0 scan | less
List wifi survey info a bit more compact
python-wifi-survey-heatmap
A Python application for Linux machines to perform WiFi site surveys and present the results as a heatmap overlayed on a floorplan.
Installation
Install python-venv
1 apt install python3-venv python3-pybind11 python3-iperf3 wxpython-tools
Clone from github and build docker image
Use it
Connect to the wifi and get current associated BSSID
1 iw dev wlp5s0 link
2 Connected to 04:f0:21:31:ca:97 (on wlp5s0)
3 SSID: Arches
4 freq: 5580
5 RX: 185634 bytes (1280 packets)
6 TX: 56155 bytes (282 packets)
7 signal: -58 dBm
8 rx bitrate: 866.7 MBit/s VHT-MCS 9 80MHz short GI VHT-NSS 2
9 tx bitrate: 866.7 MBit/s VHT-MCS 9 80MHz short GI VHT-NSS 2
10
11 bss flags: short-slot-time
12 dtim period: 2
13 beacon int: 100
Start an iperf3 server somewhere.
Provide a PNG image of the area to be scanned floorplan.png
Create an environment file
.envrc
Run survey
1 source .envrc
2 docker run \
3 --net="host" \
4 --privileged \
5 --name survey \
6 -it \
7 --rm \
8 -v $(pwd):/pwd \
9 -w /pwd \
10 -e DISPLAY=$DISPLAY \
11 -v "$HOME/.Xauthority:/root/.Xauthority:ro" \
12 jantman/python-wifi-survey-heatmap \
13 wifi-survey -b "$BSSID" -i "$INTERFACE" \
14 -s "$IPERF_SERVER" -p "$FLOORPLAN_PNG" -t "$TITLE"
A file TITLE.json is created and you can later resume your measurements.
Create images
Some images are created.
1 channel_arches_heatmap.json.png
2 channel_bitrate_arches_heatmap.json.png
3 frequency_arches_heatmap.json.png
4 jitter_download_arches_heatmap.json.png
5 jitter_upload_arches_heatmap.json.png
6 signal_quality_arches_heatmap.json.png
7 tcp_download_Mbps_arches_heatmap.json.png
8 tcp_upload_Mbps_arches_heatmap.json.png
9 tx_power_arches_heatmap.json.png
10 udp_download_Mbps_arches_heatmap.json.png
11 udp_upload_Mbps_arches_heatmap.json.png
Some images
attachment:channel_arches_heatmap.json.png
signal_quality_arches_heatmap.json.png
tcp_upload_Mbps_arches_heatmap.json.png