I'm having an odd issue: I'm trying to set up my new Tenda BE12 Pro including some VLANs, and when I try to set up Wireless networks for each VLAN, the process works for VLAN 1 (lan) but doesn't seem to be functioning for VLAN 2 and 3 (IoT and Guest). The setups are identical. What could cause this? Thanks.
Please connect to your OpenWrt device using ssh and copy the output of the following commands and post it here using the "Preformatted text </> " button (red circle; this works best in the 'Markdown' composer view in the blue oval):
![]()
Remember to redact passwords, VPN keys, MAC addresses and any public IP addresses you may have:
ubus call system board
cat /etc/config/network
cat /etc/config/wireless
cat /etc/config/dhcp
cat /etc/config/firewall
type or paste code here
{
"kernel": "6.18.44",
"hostname": "OpenWrt",
"system": "ARMv8 Processor rev 4",
"model": "Tenda BE12 Pro",
"board_name": "tenda,be12-pro",
"rootfs_type": "squashfs",
"release": {
"distribution": "OpenWrt",
"version": "SNAPSHOT",
"firmware_url": "https://downloads.openwrt.org/",
"revision": "r36045-aa66786f38",
"target": "mediatek/filogic",
"description": "OpenWrt SNAPSHOT r36045-aa66786f38",
"builddate": "1788456292"
}
}
config interface 'loopback'
option device 'lo'
option proto 'static'
list ipaddr '127.0.0.1/8'
config globals 'globals'
option dhcp_default_duid '000416cedfbd5119574a9cdcf7e5a5b1dba7'
option ula_prefix 'REDACT::/48'
config device
option name 'br-lan'
option type 'bridge'
list ports 'eth2'
list ports 'lan3'
list ports 'lan4'
list ports 'lan5'
config interface 'lan'
option device 'br-lan.1'
option proto 'static'
option ip6assign '60'
list ipaddr '192.168.1.1/24'
config interface 'wan'
option device 'eth2'
option proto 'dhcp'
config interface 'wan6'
option device 'eth2'
option proto 'dhcpv6'
config device
option type '8021q'
option ifname 'br-lan'
option vid '1'
option name 'br-lan.1'
config device
option type '8021q'
option ifname 'br-lan'
option vid '2'
option name 'br-lan.2'
config device
option type '8021q'
option ifname 'br-lan'
option vid '3'
option name 'br-lan.3'
config bridge-vlan
option device 'br-lan'
option vlan '1'
list ports 'eth2'
list ports 'lan3'
list ports 'lan4'
config bridge-vlan
option device 'br-lan'
option vlan '2'
list ports 'lan5'
config bridge-vlan
option device 'br-lan'
option vlan '3'
config interface 'IoT'
option proto 'static'
option device 'br-lan.2'
option ipaddr '192.168.2.1'
option netmask '255.255.255.0'
config interface 'Guest'
option proto 'static'
option device 'br-lan.3'
option ipaddr '192.168.3.1'
option netmask '255.255.255.0'
config wifi-device 'radio0'
option type 'mac80211'
option path 'soc/11280000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0'
option radio '0'
option band '2g'
option channel '1'
option htmode 'EHT160'
option country 'US'
option cell_density '0'
config wifi-iface 'default_radio0'
option device 'radio0'
option network 'lan'
option mode 'ap'
option ssid 'Pizza'
option encryption 'sae'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
config wifi-device 'radio1'
option type 'mac80211'
option path 'soc/11280000.pcie/pci0000:00/0000:00:00.0/0000:01:00.0'
option radio '1'
option band '5g'
option channel '136'
option htmode 'EHT160'
option cell_density '0'
option country 'US'
config wifi-iface 'default_radio1'
option device 'radio1'
option network 'lan'
option mode 'ap'
option ssid 'Pizza'
option encryption 'sae'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
config wifi-iface 'wifinet2'
option device 'radio0'
option mode 'ap'
option ssid 'I0T'
option encryption 'sae-mixed'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
option network 'IoT'
config wifi-iface 'wifinet3'
option device 'radio1'
option mode 'ap'
option ssid 'I0T'
option encryption 'sae-mixed'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
option network 'IoT'
config wifi-iface 'wifinet4'
option device 'radio0'
option mode 'ap'
option ssid 'Gu3st'
option encryption 'sae-mixed'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
option network 'Guest'
config wifi-iface 'wifinet5'
option device 'radio1'
option mode 'ap'
option ssid 'Gu3st'
option encryption 'sae-mixed'
option key 'REDACT'
option ieee80211w '0'
option gcmp256 '1'
option sae_ext_key '1'
option network 'Guest'
config dnsmasq
option domainneeded '1'
option boguspriv '1'
option filterwin2k '0'
option localise_queries '1'
option rebind_protection '1'
option rebind_localhost '1'
option local '/lan/'
option domain 'lan'
option expandhosts '1'
option nonegcache '0'
option cachesize '1000'
option authoritative '1'
option readethers '1'
option leasefile '/tmp/dhcp.leases'
option resolvfile '/tmp/resolv.conf.d/resolv.conf.auto'
option nonwildcard '1'
option localservice '1'
option ednspacket_max '1232'
option filter_aaaa '0'
option filter_a '0'
config dhcp 'lan'
option interface 'lan'
option ra 'server'
option dhcpv4 'server'
option dhcpv6 'server'
list ra_flags 'managed-config'
list ra_flags 'other-config'
config dhcp 'wan'
option interface 'wan'
option ignore '1'
config odhcpd 'odhcpd'
option maindhcp '0'
option leasefile '/tmp/odhcpd.leases'
option leasetrigger '/usr/sbin/odhcpd-update'
option loglevel '4'
option piodir '/tmp/odhcpd-piodir'
option hostsdir '/tmp/hosts'
config dhcp 'IoT'
option interface 'IoT'
option dhcpv4 'server'
config dhcp 'Guest'
option interface 'Guest'
option dhcpv4 'server'
config defaults
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option synflood_protect '1'
option flow_offloading '1'
option flow_offloading_hw '1'
config zone
option name 'lan'
list network 'lan'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
config zone
option name 'wan'
list network 'wan'
list network 'wan6'
option input 'REJECT'
option output 'ACCEPT'
option forward 'DROP'
option masq '1'
option mtu_fix '1'
config forwarding
option src 'lan'
option dest 'wan'
config rule
option name 'Allow-DHCP-Renew'
option src 'wan'
option proto 'udp'
option dest_port '68'
option target 'ACCEPT'
option family 'ipv4'
config rule
option name 'Allow-Ping'
option src 'wan'
option proto 'icmp'
option icmp_type 'echo-request'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-IGMP'
option src 'wan'
option proto 'igmp'
option family 'ipv4'
option target 'ACCEPT'
config rule
option name 'Allow-DHCPv6'
option src 'wan'
option proto 'udp'
option dest_port '546'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-MLD'
option src 'wan'
option proto 'icmp'
option src_ip 'fe80::/10'
list icmp_type '130/0'
list icmp_type '131/0'
list icmp_type '132/0'
list icmp_type '143/0'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Input'
option src 'wan'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
list icmp_type 'router-solicitation'
list icmp_type 'neighbour-solicitation'
list icmp_type 'router-advertisement'
list icmp_type 'neighbour-advertisement'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-ICMPv6-Forward'
option src 'wan'
option dest '*'
option proto 'icmp'
list icmp_type 'echo-request'
list icmp_type 'echo-reply'
list icmp_type 'destination-unreachable'
list icmp_type 'packet-too-big'
list icmp_type 'time-exceeded'
list icmp_type 'bad-header'
list icmp_type 'unknown-header-type'
option limit '1000/sec'
option family 'ipv6'
option target 'ACCEPT'
config rule
option name 'Allow-IPSec-ESP'
option src 'wan'
option dest 'lan'
option proto 'esp'
option target 'ACCEPT'
config rule
option name 'Allow-ISAKMP'
option src 'wan'
option dest 'lan'
option dest_port '500'
option proto 'udp'
option target 'ACCEPT'
config zone
option name 'IoT'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
list network 'IoT'
config forwarding
option src 'IoT'
option dest 'wan'
config forwarding
option src 'lan'
option dest 'IoT'
config zone
option name 'Guest'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
list network 'Guest'
config forwarding
option src 'Guest'
option dest 'wan'
config forwarding
option src 'lan'
option dest 'Guest'
What is EHT160?
Additionally, this channel isn't 160 MHz capable (not in the US, at least).
Edit:
Also, have you tried WPA2 or WPA3 instead of mixed?
I'm using LuCI - why is the 160mhz option shown then? Also, why does this setup work for one VLAN and not the others?
Probably not related to your problem but there are some inconsistencies using the netmask, I know it is allowed in 25.12.5 but not sure about Main-snapshot
Modern way is the CIDR notation of the lan interface using list ipaddr
I'm not sure I understand the question.
The drop down boxes don't auto update or sanity check as you make changes, if that's what you mean.
Your others appear to be configured as mixed. Have you tried just WPA2 or WPA3?
OK, that setting is WiFI 7.
BTW, 802.11w is required for SAE.
It was a channel issue, thank you all.
