Skip to content

Cannot specify "-o" in AP mode #100

Description

@wujinjun-MC

If -o is used to specify Internet interface, ping is always Destination Port Unreachable.

Command log:

sudo lnxrouter -o enp5s0 --ap wlx************ wujinjun -p 12345678
WARN: Your adapter does not fully support AP virtual interface, enabling --no-virt
WARN: wlx************ has 15 characters which might be too long. If AP doesn't work, see --virt-name and https://github.com/garywill/linux-router/issues/44
linux-router 0.8.1 (https://github.com/garywill/linux-router)
Released under LGPL, with no warranty. Use on your own risk.

PID: 290341
Target interface is wlx************ (**:**:**:**:**:**)
lspci: -s: Invalid bus number
PCI: 1-1:1.0
System-already-loaded driver: rt2800usb

Use random LAN IPv4 address 192.168.41.1
Config dir: /dev/shm/lnxrouter_tmp/lnxrouter.wlx************.conf.DKEFBr
Channel not specified, use default
Freq band: 2.4 GHz   Channel: 1

iptables v1.8.11 (nf_tables)
Notice: Not showing all operations done to iptables rules

haveged_watchdog PID: 290484

Starting hostapd
hostapd PID: 290489
WARN: Low entropy detected. We recommend you to install `haveged'
wlx************: interface state UNINITIALIZED->ENABLED
wlx************: AP-ENABLED

WARN: You specified Internet interface but this host is providing local DNS. In some unexpected case (eg. mistaken configurations), queries may leak to other interfaces, which you should be aware of.


iptables: NAT
MASQUERADE  all opt -- in * out enp5s0  192.168.41.0/24 !-> 192.168.41.0/24   /* lrt290341wlx************ */
ACCEPT  all opt -- in wlx************ out enp5s0  192.168.41.0/24  -> 0.0.0.0/0   /* lrt290341wlx************ */
ACCEPT  all opt -- in enp5s0 out wlx************  0.0.0.0/0  -> 192.168.41.0/24   /* lrt290341wlx************ */
Loaded kernel module nf_nat_pptp

iptables: allow DNS
ACCEPT  tcp opt -- in wlx************ out *  192.168.41.0/24  -> 192.168.41.1   tcp dpt:53 /* lrt290341wlx************ */
ACCEPT  udp opt -- in wlx************ out *  192.168.41.0/24  -> 192.168.41.1   udp dpt:53 /* lrt290341wlx************ */

iptables: allow dhcp
ACCEPT  udp opt -- in wlx************ out *  0.0.0.0/0  -> 0.0.0.0/0   udp dpt:67 /* lrt290341wlx************ */

Starting dnsmasq
Apr 10 00:17:36 dnsmasq[290633]: started, version 2.91 cachesize 150
Apr 10 00:17:36 dnsmasq[290633]: compile time options: IPv6 GNU-getopt DBus no-UBus i18n IDN2 DHCP DHCPv6 no-Lua TFTP conntrack ipset nftset auth DNSSEC loop-detect inotify dumpfile
Apr 10 00:17:36 dnsmasq-dhcp[290633]: DHCP, IP range 192.168.41.10 -- 192.168.41.250, lease time 1h
Apr 10 00:17:36 dnsmasq-dhcp[290633]: DHCP, sockets bound exclusively to interface wlx************
Apr 10 00:17:36 dnsmasq[290633]: reading /etc/resolv.conf
Apr 10 00:17:36 dnsmasq[290633]: using nameserver 127.0.0.53#53
Apr 10 00:17:36 dnsmasq[290633]: cleared cache
dnsmasq PID: 290633


== Setting up completed, now linux-router should be working ==
wlx************: STA **:**:**:**:**:** IEEE 802.11: authenticated
wlx************: STA **:**:**:**:**:** IEEE 802.11: associated (aid 1)
wlx************: AP-STA-CONNECTED **:**:**:**:**:**
wlx************: STA **:**:**:**:**:** RADIUS: starting accounting session 4227BB82FBED6781
wlx************: STA **:**:**:**:**:** WPA: pairwise key handshake completed (RSN)
wlx************: EAPOL-4WAY-HS-COMPLETED **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPDISCOVER(wlx************) **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPOFFER(wlx************) 192.168.41.166 **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPDISCOVER(wlx************) **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPOFFER(wlx************) 192.168.41.166 **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPDISCOVER(wlx************) **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPOFFER(wlx************) 192.168.41.166 **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPREQUEST(wlx************) 192.168.41.166 **:**:**:**:**:**
Apr 10 00:18:12 dnsmasq-dhcp[290633]: DHCPACK(wlx************) 192.168.41.166 **:**:**:**:**:** OnePlus-12

Activity

  1. wujinjun-MC commented on Apr 10, 2026

    @wujinjun-MC
    Author

    Additional info: Policy based routing (/etc/NetworkManager/dispatcher.d/99-policy-routing-in-out-match.sh) is used because there are 2 ISP connections

    99-policy-routing-in-out-match.sh

  2. garywill commented on Apr 10, 2026

    @garywill
    Owner

    I haven't look through all you log. I saw in your setup_ipv6()

    ip route add default via "$gw6" dev "$IFACE" table "$TABLE_ID"

    Did you miss -6 ? Please make sure the enp5s0 works all around first.

    On your Linux

    ping -I enp5s0 <try-some-ips>

    does it work?

  3. wujinjun-MC commented on Apr 10, 2026

    @wujinjun-MC
    Author

    I don't have IPv6 on enp5s0 and setup_ipv6() doesn't add route/rule.

    ping is working.

    PING bing.com (150.171.28.10) from 10.1.*.* enp5s0: 56(84) bytes of data.
    64 bytes from 150.171.28.10: icmp_seq=1 ttl=113 time=77.2 ms
    64 bytes from 150.171.28.10: icmp_seq=2 ttl=113 time=76.3 ms
    64 bytes from 150.171.28.10: icmp_seq=3 ttl=113 time=74.2 ms
    64 bytes from 150.171.28.10: icmp_seq=4 ttl=113 time=77.0 ms
    64 bytes from 150.171.28.10: icmp_seq=5 ttl=113 time=74.2 ms
    64 bytes from 150.171.28.10: icmp_seq=6 ttl=113 time=77.1 ms
    64 bytes from 150.171.28.10: icmp_seq=7 ttl=113 time=74.2 ms
    64 bytes from 150.171.28.10: icmp_seq=8 ttl=113 time=77.0 ms
    64 bytes from 150.171.28.10: icmp_seq=9 ttl=113 time=74.2 ms
    64 bytes from 150.171.28.10: icmp_seq=10 ttl=113 time=77.1 ms
    ...
    
  4. garywill commented on Apr 10, 2026

    @garywill
    Owner
    1. Try lnxrouter --virt-name <name>. Use a short name like myap0.

    2. Run your lnxrouter command as you did. Use viddy to watch iptables hit counter.

      Open several terminals and run:

      sudo viddy -d -n 0.3 iptables -L -v -n 
      
      sudo viddy -d -n 0.3 iptables -L -v -n -t nat
      
      sudo viddy -d -n 0.3 iptables -L -v -n -t mangle

      to see if we can find out which rule is in the way.

      From your log, your system is using iptables-nft. So maybe there's something in nft list ruleset in the way too.

      Seeing nft counter is troublesome a little. Although there're some command we can use

      nft monitor trace
      
      xtables-monitor --trace

      but they requires explictly added trace/counter rule.

    3. Try replacing iptables-nft with legacy iptables.

      For example in my system , iptables command is

      /usr/sbin/iptables (symlink )
      -> /etc/alternatives/iptables 
      -> /usr/sbin/xtables-legacy-multi
      

      In your system it must be being linked to xtables-nft-multi. Replace it with xtables-legacy-multi (and reboot)

  5. wujinjun-MC commented on Apr 10, 2026

    @wujinjun-MC
    Author

    I asked AI. An ip rule must be added manually:

    ip rule add from "$HOTSPOT_GATEWAY"/24 table $TABLE_ID priority $((PRIO_V4 + 1))

    And specify host subnet. sudo lnxrouter -o enp5s0 --ap wlx************ wujinjun -p 12345678 -g "$HOTSPOT_GATEWAY", then clients can connect to Internet through enp5s0.

    Also -6 can work without adding ip -6 rule ....

  6. garywill commented on Apr 13, 2026

    @garywill
    Owner

    The script did not account for a scenario where, when multiple interfaces have internet , the -o interface is not used in the main routing table.

    We should add a note in the readme to remind users that in such cases, they will additionally need to add their routing rules

    I also considered enhancing our script, to let the script to handle this . But, this would involve selecting routing table IDs and priority numbers (unlike iptables rules, which do not require such numbering). Therefore, I think it's better to leave this to user, so they decide the number.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions