Temat: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

Witam!
Mam 3 apeki dump (Asus ax4200) z openwrt 24.10 Cezarego i i ten sam asus jako router główny. Logowaniem do sieci wifi u mnie
zawiaduje radiius którego mam na raspberry pi, wszystko jakoś to śmiga, ale problem mam z routerem głównym, tj. jeżeli, chcę się zalogować loginem gościa do sieci wifi to nie otrzymuję ip (np telefon zatrzymuje się na pobieraniu ip). Natomiast jak łączę się do sieci obojętnie do którego apeka dump to dostaję ip sieci gościnnej bez problemu. Może ktoś spojrzeć  na moją konfiguracje, co tu jest nie tak?
tak mam na głównym:
network

config interface 'loopback'
    option device 'lo'
    option proto 'static'
    option ipaddr '127.0.0.1'
    option netmask '255.0.0.0'

config globals 'globals'
    option ula_prefix 'fdf4:2f9f:1a17::/48'
    option packet_steering '0'

config device
    option name 'br-lan'
    option type 'bridge'
    option vlan_filtering '1'
    list ports 'lan1'
    list ports 'lan2'
    list ports 'lan3'
    list ports 'lan4'

config bridge-vlan
    option device 'br-lan'
    option vlan '1'
    list ports 'lan1'
    list ports 'lan2'
    list ports 'lan3'
    list ports 'lan4'
    list ports 'eth0:t'

config bridge-vlan
    option device 'br-lan'
    option vlan '20'
    list ports 'lan1:t'
    list ports 'eth0:t'

config interface 'lan'
    option proto 'static'
    option device 'br-lan.1'
    option ipaddr '192.168.1.1'
    option netmask '255.255.255.0'
    list dns '8.8.8.8'
    list dns '8.8.4.4'

config interface 'guest'
    option proto 'static'
    option device 'br-lan.20'
    option ipaddr '192.168.2.1'
    option netmask '255.255.255.0'
    list dns '8.8.8.8'

config interface 'wan'
    option device 'eth1'
    option proto 'dhcp'

config interface 'wan6'
    option device 'eth1'
    option proto 'dhcpv6'

wireless:

config wifi-device 'radio0'
    option type 'mac80211'
    option path 'platform/soc/18000000.wifi'
    option band '2g'
    option channel '2'
    option htmode 'HE40'
    option country 'PL'
    option cell_density '0'
    option noscan '1'

config wifi-iface 'default_radio0'
    option device 'radio0'
    option network 'lan'
    option mode 'ap'
    option ssid 'Ap'\''dom'
    option encryption 'psk2'
    option macfilter 'deny'
    option key 'haslo'
    option ieee80211r '1'
    option ft_over_ds '0'
    option ft_psk_generate_local '1'
    option hidden '1'
    option mobility_domain '4f61'

config wifi-device 'radio1'
    option type 'mac80211'
    option path 'platform/soc/18000000.wifi+1'
    option band '5g'
    option channel '128'
    option htmode 'HE160'
    option country 'PL'
    option cell_density '0'
    option txpower '26'

config wifi-iface 'default_radio1'
    option device 'radio1'
    option network 'lan'
    option mode 'ap'
    option ssid 'Ap'\''dom-5G'
    option encryption 'psk2'
    option key 'haslo'
    option macfilter 'deny'
    option ieee80211r '1'
    option hidden '1'
    option ft_over_ds '0'
    option ft_psk_generate_local '1'
    option mobility_domain '4f63'

config wifi-iface 'wifinet2'
    option device 'radio0'
    option mode 'ap'
    option ssid 'Ap'\''dom-Mariusz'
    option encryption 'wpa2'
    option auth_server '192.168.1.43'
    option auth_port '1812'
    option auth_secret 'haslo'
    option acct_server '192.168.1.43'
    option acct_port '1813'
    option acct_secret 'haslo'
    option ieee80211r '1'
    option ft_over_ds '1'
    option network 'lan'
    option mobility_domain '4f62'
    option nasid 'glowny'
    option dynamic_vlan '1'
    option vlan_naming '1'
    option vlan_tagged_interface 'br-lan'
    option vlan_bridge 'br-vlan'
    option ieee80211k '1'

config wifi-iface 'wifinet3'
    option device 'radio1'
    option mode 'ap'
    option ssid 'Ap'\''dom-Mariusz-5G'
    option encryption 'wpa2'
    option auth_server '192.168.1.43'
    option auth_port '1812'
    option auth_secret 'haslo'
    option acct_server '192.168.1.43'
    option acct_port '1813'
    option acct_secret 'haslo'
    option ieee80211r '1'
    option ft_over_ds '1'
    option network 'lan'
    option mobility_domain '4f60'
    option nasid 'glowny-5g'
    option dynamic_vlan '1'
    option vlan_naming '1'
    option vlan_tagged_interface 'br-lan'
    option vlan_bridge 'br-vlan'
    option ieee80211k '1'

dhcp:

config dnsmasq
    option domainneeded '1'
    option localise_queries '1'
    option rebind_protection '1'
    option rebind_localhost '1'
    option local '/lan/'
    option domain 'lan'
    option expandhosts '1'
    option cachesize '1000'
    option authoritative '1'
    option readethers '1'
    option leasefile '/tmp/dhcp.leases'
    option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
    option localservice '1'
    option ednspacket_max '1232'
    option sequential_ip '1'

config dhcp 'lan'
    option interface 'lan'
    option start '2'
    option limit '150'
    option leasetime '12h'
    option dhcpv4 'server'
    option dhcpv6 'hybrid'
    option ra 'hybrid'
    option master '1'
    option dynamicdhcp '0'

config dhcp 'guest'
    option interface 'guest'
    option start '100'
    option limit '150'
    option leasetime '12h'
    option dhcpv4 'server'
    option ignore '0'
    option force '1'

config dhcp 'wan'
    option interface 'wan'
    option ignore '1'

config odhcpd 'odhcpd'
    option maindhcp '0'
    option leasefile '/tmp/hosts/odhcpd'
    option leasetrigger '/usr/sbin/odhcpd-update'
    option loglevel '4'

firewall:

 config defaults
    option input 'ACCEPT'
    option output 'ACCEPT'
    option forward 'ACCEPT'
    option synflood_protect '1'
    option flow_offloading '1'
    option flow_offloading_hw '1'

config zone
    option name 'lan'
    list network 'lan'
    option input 'ACCEPT'
    option output 'ACCEPT'
    option forward 'ACCEPT'

config zone
    option name 'wan'
    list network 'wan'
    list network 'wan6'
    option input 'REJECT'
    option output 'ACCEPT'
    option forward 'REJECT'
    option masq '1'
    option mtu_fix '1'

config forwarding
    option src 'lan'
    option dest 'wan'

config rule
    option name 'Allow-DHCP-Renew'
    option src 'wan'
    option proto 'udp'
    option dest_port '68'
    option target 'ACCEPT'
    option family 'ipv4'

config rule
    option name 'Allow-Ping'
    option src 'wan'
    option proto 'icmp'
    option icmp_type 'echo-request'
    option family 'ipv4'
    option target 'ACCEPT'

config rule
    option name 'Allow-IGMP'
    option src 'wan'
    option proto 'igmp'
    option family 'ipv4'
    option target 'ACCEPT'

config rule
    option name 'Allow-DHCPv6'
    option src 'wan'
    option proto 'udp'
    option dest_port '546'
    option family 'ipv6'
    option target 'ACCEPT'

config rule
    option name 'Allow-MLD'
    option src 'wan'
    option proto 'icmp'
    option src_ip 'fe80::/10'
    list icmp_type '130/0'
    list icmp_type '131/0'
    list icmp_type '132/0'
    list icmp_type '143/0'
    option family 'ipv6'
    option target 'ACCEPT'

config rule
    option name 'Allow-ICMPv6-Input'
    option src 'wan'
    option proto 'icmp'
    list icmp_type 'echo-request'
    list icmp_type 'echo-reply'
    list icmp_type 'destination-unreachable'
    list icmp_type 'packet-too-big'
    list icmp_type 'time-exceeded'
    list icmp_type 'bad-header'
    list icmp_type 'unknown-header-type'
    list icmp_type 'router-solicitation'
    list icmp_type 'neighbour-solicitation'
    list icmp_type 'router-advertisement'
    list icmp_type 'neighbour-advertisement'
    option limit '1000/sec'
    option family 'ipv6'
    option target 'ACCEPT'

config rule
    option name 'Allow-ICMPv6-Forward'
    option src 'wan'
    option dest '*'
    option proto 'icmp'
    list icmp_type 'echo-request'
    list icmp_type 'echo-reply'
    list icmp_type 'destination-unreachable'
    list icmp_type 'packet-too-big'
    list icmp_type 'time-exceeded'
    list icmp_type 'bad-header'
    list icmp_type 'unknown-header-type'
    option limit '1000/sec'
    option family 'ipv6'
    option target 'ACCEPT'

config rule
    option name 'Allow-IPSec-ESP'
    option src 'wan'
    option dest 'lan'
    option proto 'esp'
    option target 'ACCEPT'

config rule
    option name 'Allow-ISAKMP'
    option src 'wan'
    option dest 'lan'
    option dest_port '500'
    option proto 'udp'
    option target 'ACCEPT'

config rule
    option src 'guest'
    option name 'Allow-DHCP-Guest'
    list proto 'udp'
    option target 'ACCEPT'
    option dest_port '67-68'
    option family 'ipv4'

config rule
    option src 'guest'
    option name 'Allow-DNS-Guest'
    option dest_port '53'
    option target 'ACCEPT'
    option family 'ipv4'

config zone
    option name 'guest'
    option input 'ACCEPT'
    option output 'ACCEPT'
    option forward 'ACCEPT'
    option masq '1'
    list network 'guest'

config forwarding
    option src 'guest'
    option dest 'wan'

a tak mam na pierwszym lepszym apeku dump
network:

config interface 'loopback'
    option device 'lo'
    option proto 'static'
    option ipaddr '127.0.0.1'
    option netmask '255.0.0.0'

config globals 'globals'
    option ula_prefix 'fd95:bee7:583b::/48'
    option packet_steering '0'

config device
    option name 'br-lan'
    option type 'bridge'
    list ports 'eth1'
    list ports 'lan1'
    list ports 'lan2'
    list ports 'lan3'
    list ports 'lan4'

config bridge-vlan
    option device 'br-lan'
    option vlan '1'
    list ports 'eth1'
    list ports 'lan1'
    list ports 'lan2'
    list ports 'lan3'
    list ports 'lan4'

config bridge-vlan
    option device 'br-lan'
    option vlan '20'
    list ports 'lan1:t'

config interface 'lan'
    option device 'br-lan.1'
    option proto 'static'
    option ipaddr '192.168.1.201'
    option netmask '255.255.255.0'
    option gateway '192.168.1.1'
    list dns '192.168.1.1'

wireless:

config wifi-device 'radio0'
    option type 'mac80211'
    option path 'platform/soc/18000000.wifi'
    option band '2g'
    option channel '11'
    option htmode 'HE40'
    option country 'PL'
    option cell_density '0'
    option noscan '1'

config wifi-iface 'default_radio0'
    option device 'radio0'
    option network 'lan'
    option mode 'ap'
    option ssid 'Ap'\''dom'
    option encryption 'psk2'
    option key 'haslo'
    option ieee80211r '1'
    option hidden '1'
    option ft_over_ds '1'
    option ft_psk_generate_local '1'
    option mobility_domain '4f61'

config wifi-device 'radio1'
    option type 'mac80211'
    option path 'platform/soc/18000000.wifi+1'
    option band '5g'
    option channel '108'
    option htmode 'HE160'
    option country 'PL'
    option cell_density '0'

config wifi-iface 'default_radio1'
    option device 'radio1'
    option network 'lan'
    option mode 'ap'
    option ssid 'Ap'\''dom-5G'
    option encryption 'psk2'
    option key 'haslo'
    option ieee80211r '1'
    option hidden '1'
    option ft_over_ds '1'
    option ft_psk_generate_local '1'
    option mobility_domain '4f63'

config wifi-iface 'wifinet2'
    option device 'radio0'
    option mode 'ap'
    option ssid 'Ap'\''dom-Mariusz'
    option encryption 'wpa2'
    option auth_server '192.168.1.43'
    option auth_port '1812'
    option auth_secret 'haslo'
    option acct_port '1813'
    option acct_secret 'haslo'
    option acct_server '192.168.1.43'
    option ieee80211r '1'
    option ft_over_ds '1'
    option network 'lan'
    option mobility_domain '4f62'
    option nasid 'tv'
    option vlan_tagged_interface 'br-lan'
    option vlan_bridge 'br-vlan'
    option vlan_naming '1'
    option ieee80211k '1'
    option dynamic_vlan '1'

config wifi-iface 'wifinet3'
    option device 'radio1'
    option mode 'ap'
    option ssid 'Ap'\''dom-Mariusz-5G'
    option encryption 'wpa2'
    option auth_server '192.168.1.43'
    option auth_port '1812'
    option auth_secret 'haslo'
    option acct_server '192.168.1.43'
    option acct_port '1813'
    option acct_secret 'haslo'
    option ieee80211r '1'
    option ft_over_ds '1'
    option network 'lan'
    option mobility_domain '4f60'
    option nasid 'tv-5g'
    option dynamic_vlan '1'
    option vlan_naming '1'
    option vlan_tagged_interface 'br-lan'
    option vlan_bridge 'br-vlan'
    option ieee80211k '1'

2

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

option dynamicdhcp '0'

masz wyłączone przyznawanie adresów, tylko te wpisane w ether są uznawane. łączysz się czymś nowym?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

3 (edytowany przez mario026 2025-09-25 06:33:26)

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

mam wyłączone bo ip dostają klienci po mac łacze sie swoim telefonem ale z losowym mac. Dla testu załączę i zobaczę
edit.
Niestety załaczenie nic nie dało

4

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

No a masz ten adres (losowy) wpisany do ether czy nie? Jak nie to jak chcesz dostać adres skoro mu tego zabroniłeś?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

5 (edytowany przez mario026 2025-09-25 06:59:06)

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

Teraz próbowałem połączyć się z mac tym wpisanym ether, ta sama sytuacja nie dostał ip, jezeli łączę się loginem przypisanym w radius do sieci lokalnej to dostaje ip.
Oto fragment logu

Thu Sep 25 07:47:32 2025 daemon.notice hostapd: phy0-ap1: CTRL-EVENT-EAP-STARTED a4:a4:90:58:1e:aa
Thu Sep 25 07:47:32 2025 daemon.notice hostapd: phy0-ap1: CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=1
Thu Sep 25 07:47:33 2025 daemon.info hostapd: phy0-ap1: STA a4:a4:90:58:1e:aa RADIUS: VLAN ID 20
Thu Sep 25 07:47:33 2025 daemon.err hostapd: VLAN: vlan_add: ADD_VLAN_CMD failed for br-lan: File exists
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.123948] br-vlan20: port 1(br-lan.20) entered blocking state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.129878] br-vlan20: port 1(br-lan.20) entered disabled state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.135895] br-lan.20: entered allmulticast mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.140504] br-lan: entered allmulticast mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.145087] br-lan.20: entered promiscuous mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.149612] br-lan: entered promiscuous mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.154238] br-vlan20: port 1(br-lan.20) entered blocking state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.160150] br-vlan20: port 1(br-lan.20) entered forwarding state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.166612] br-vlan20: port 2(phy0-ap1.20) entered blocking state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.172732] br-vlan20: port 2(phy0-ap1.20) entered disabled state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.178841] mt798x-wmac 18000000.wifi phy0-ap1.20: entered allmulticast mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.186053] mt798x-wmac 18000000.wifi phy0-ap1.20: entered promiscuous mode
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.193124] br-vlan20: port 2(phy0-ap1.20) entered blocking state
Thu Sep 25 07:47:33 2025 kern.info kernel: [68582.199202] br-vlan20: port 2(phy0-ap1.20) entered forwarding state
Thu Sep 25 07:47:33 2025 daemon.notice hostapd: phy0-ap1: CTRL-EVENT-EAP-SUCCESS2 a4:a4:90:58:1e:aa
Thu Sep 25 07:47:33 2025 daemon.info hostapd: phy0-ap1: STA a4:a4:90:58:1e:aa WPA: pairwise key handshake completed (RSN)
Thu Sep 25 07:47:33 2025 daemon.notice hostapd: phy0-ap1: EAPOL-4WAY-HS-COMPLETED a4:a4:90:58:1e:aa
Thu Sep 25 07:47:33 2025 daemon.notice hostapd: phy0-ap1: AP-STA-CONNECTED a4:a4:90:58:1e:aa auth_alg=open
Thu Sep 25 07:47:33 2025 daemon.info hostapd: phy0-ap1: STA a4:a4:90:58:1e:aa RADIUS: starting accounting session 76C8977B650B6BCA
Thu Sep 25 07:47:33 2025 daemon.info hostapd: phy0-ap1: STA a4:a4:90:58:1e:aa IEEE 802.1X: authenticated - EAP type: 25 (PEAP)
Thu Sep 25 07:47:33 2025 daemon.warn dnsmasq-dhcp[1]: DHCP packet received on br-vlan20 which has no address
Thu Sep 25 07:47:34 2025 daemon.warn dnsmasq-dhcp[1]: DHCP packet received on br-vlan20 which has no address
Thu Sep 25 07:47:36 2025 daemon.warn dnsmasq-dhcp[1]: DHCP packet received on br-vlan20 which has no address
Thu Sep 25 07:47:39 2025 daemon.warn dnsmasq-dhcp[1]: DHCP packet received on br-vlan20 which has no address
Thu Sep 25 07:47:47 2025 daemon.warn dnsmasq-dhcp[1]: DHCP packet received on br-vlan20 which has no address
Thu Sep 25 07:47:51 2025 daemon.notice hostapd: phy0-ap1: AP-STA-DISCONNECTED a4:a4:90:58:1e:aa
Thu Sep 25 07:47:51 2025 daemon.info hostapd: phy0-ap1: STA a4:a4:90:58:1e:aa RADIUS: stopped accounting session 76C8977B650B6BCA
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.443277] br-vlan20: port 2(phy0-ap1.20) entered disabled state
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.503099] mt798x-wmac 18000000.wifi phy0-ap1.20 (unregistering): left allmulticast mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.511268] mt798x-wmac 18000000.wifi phy0-ap1.20 (unregistering): left promiscuous mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.519355] br-vlan20: port 2(phy0-ap1.20) entered disabled state
Thu Sep 25 07:47:51 2025 daemon.err hostapd: VLAN: br_delif: Failure determining interface index for 'phy0-ap1.20'
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.677520] br-lan.20: left allmulticast mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.681889] br-lan: left allmulticast mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.685986] br-lan.20: left promiscuous mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.690239] br-lan: left promiscuous mode
Thu Sep 25 07:47:51 2025 kern.info kernel: [68600.694469] br-vlan20: port 1(br-lan.20) entered disabled state
Thu Sep 25 07:47:55 2025 daemon.info hostapd: phy1-ap1: STA a4:a4:90:58:1e:aa IEEE 802.11: authenticated
Thu Sep 25 07:47:55 2025 daemon.info hostapd: phy1-ap1: STA a4:a4:90:58:1e:aa IEEE 802.11: associated (aid 2)
Thu Sep 25 07:47:55 2025 daemon.notice hostapd: phy1-ap1: CTRL-EVENT-EAP-STARTED a4:a4:90:58:1e:aa
Thu Sep 25 07:47:55 2025 daemon.notice hostapd: phy1-ap1: CTRL-EVENT-EAP-PROPOSED-METHOD vendor=0 method=1
Thu Sep 25 07:47:55 2025 daemon.notice hostapd: phy1-ap1: CTRL-EVENT-EAP-SUCCESS2 a4:a4:90:58:1e:aa
Thu Sep 25 07:47:55 2025 daemon.info hostapd: phy1-ap1: STA a4:a4:90:58:1e:aa WPA: pairwise key handshake completed (RSN)
Thu Sep 25 07:47:55 2025 daemon.notice hostapd: phy1-ap1: EAPOL-4WAY-HS-COMPLETED a4:a4:90:58:1e:aa
Thu Sep 25 07:47:55 2025 daemon.notice hostapd: phy1-ap1: AP-STA-CONNECTED a4:a4:90:58:1e:aa auth_alg=open
Thu Sep 25 07:47:55 2025 daemon.info hostapd: phy1-ap1: STA a4:a4:90:58:1e:aa RADIUS: starting accounting session FAADB1DD9762D6D6
Thu Sep 25 07:47:55 2025 daemon.info hostapd: phy1-ap1: STA a4:a4:90:58:1e:aa IEEE 802.1X: authenticated - EAP type: 25 (PEAP)
Thu Sep 25 07:47:55 2025 daemon.info dnsmasq-dhcp[1]: DHCPREQUEST(br-lan.1) 192.168.1.84 a4:a4:90:58:1e:aa
Thu Sep 25 07:47:55 2025 daemon.info dnsmasq-dhcp[1]: DHCPACK(br-lan.1) 192.168.1.84 a4:a4:90:58:1e:aa Telefon-Mariusz-XCover6-Pro

mac tego telefonu to: a4:a4:90:58:1e:aa

6

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

A teraz to user trafia ci do vlan20, robi bridge  br-vlan20 a dnsmasq twierdzi że tam nie ma adresu wiec nie nasłuchuje na żadania dhcp.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

7

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

tylko dlaczego robi bridge  br-vlan20 zamiast użyć który istnieje w network? jak go do tego zmusić aby nie tworzył nowego mostu?

8

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

Bo masz ustawiony dynamic_vlan  i resztę?

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

9

Odp: Pomoc radius na raspberry i openwrt 24.10 na asus AX4200

No chciałbym aby radius tym zawiadywał. na wszystkich routerach dump to fajnie działa tylko z tym głównym problem