My ASUSWRT 5.0 AiMesh extends coverage (same channels, all nodes); improves roaming (802.11k,v); maintains backhauls and a spare router; simplifies admin; and can be incrementally built/upgraded. No account, app, controller, subscription, or fee required.
cable ISP, 574/22Mbps
2.4/5.0 WiFi6 router RT-AX88U_Pro_3.0.0.6.102.33352
2.4/5.0 Smart Connect band steering/failover, same SSIDs
2.4 Fixed: 20MHz bw, ch 11; -100dBm noise, 31% ch utilize
5.0 Fixed1,3: 80MHz max bw, ch 36; -92dBm noise, 8% ch utilize
2.4/5.0 Roaming Assistant node steering, below -74/-74dBm RSSI
custom VLANs 2.4/5.0 Guest, 2.4 IoT
AdGuard Public DNS (DoT) blocking ads, trackers, malware/phishing sites
AiProtection Pro disabled
2.4/5.0 WiFi6 node at 77' RT-AX86U_Pro_3.0.0.6.102.34349
MoCA2.5 wired backhaul, 2.5GbE
5.0 wireless backhaul failover, -74dBm RSSI, ax, 4SS, 816Mbps
Install
*Security-related
o 2.4/5.0/6.0 = 2.4/5/6GHz bands
o AiMesh = router/AP root node + node(s) (4 max; 2 daisy-chain max)
Mixing models fw 3.0.0.6.102.*/topologies/backhauls is permitted
A root node in AP Mode is wired to LAN
EoL
o
FW Reset FAQ
Reset button/webUI Restore/node removal clears settings in NVRAM; reboot restores fw defaults from CFE
Hard Reset via WPS button/webUI Restore+Initialize also clears data logged in /jffs partition
o
Confirm ISP cable shield is bonded to Earth Ground at demarc*
o Use a UPS to protect hardware/data*
o
Power OFF router, modem, wait (cycle power)
o Wire router WAN to modem, LAN to admin PC
o Power ON modem, wait
o Power ON router, wait
Monitor LEDs; Power LED flashes ~3 times when ready
o
Hold Reset button until Power LED flashing to Reset fw, wait
o Browse to router LAN IP (default 192.168.50.1) to access webUI
o
Perform Quick Internet Setup (QIS) to check/upload fw, WAIT
See new fw link to review release notes
o Browse webUI sub page /ajax_coretmp.asp to confirm CPU temp <86C (85% Tj max)
o
Set Restore+Initialize to Hard Reset fw, wait
o Power OFF router/open WiFi*, modem
o Repeat for node
o Disconnect node WAN, LAN; place in range of router 5.0 WLAN
o Wire router WAN to modem, LAN to PC
o Power ON modem, wait; then router
o
Perform QIS and configuration
Wireless
- enable 2.4/5.0 Smart Connect; set 2.4/5.0 WLANs OE/OE (same SSIDs)
Or disable SC; set 2.4/5.0 WLANs OE/OE-50 (different SSIDs; user band steers/segregates clients)
- set 2.4/5.0 SSIDs (Aa-Zz 0-9 space,.'&()-); Hide SSID No; Wireless Mode Auto; enable 802.11ax/WiFi6 mode*
- set 2.4/5.0 Authentication Method to WPA2/WPA3-Personal*; same WPA Key (Aa-Zz 0-9); Protected Management Frames to Capable
Beware
compatibility
-
set 2.4/5.0 Channel Bandwidth, Control Channel
Wireless Log lists noise, 5.0 DFS status, wireless client/node connection detail
For Fixed bw and ch range given (US Region), determine ch with least noise <-84dBm and best connections >-75dBm RSSI
If radio interference persists, switch to Unfixed settings to let router vary bw/ch to coexist
Clients decide/connect with their best wireless mode, authentication method, bandwidth permitted
2.4 Fixed: 20MHz bw, ch 1-11 (1,6,11 do not overlap)
2.4 Unfixed: 20MHz bw, ch Auto
US FCC U-NII Device Regulations
5.0 Fixed1,2a: 160MHz max bw, ch 36-48,
52-64 (exclude DFS/2a)
5.0 Fixed2c: 160MHz max bw, ch 100-128 (exclude DFS/2c)
5.0 Unfixed1,2a,2c,3: 20/40/80/160MHz bw, ch Auto, exclude DFS/2a,2c (36-48,
52-64,100-144,149-165)
Start with
5.0 Fixed1,2a; if ALL clients/nodes support DFS bands, include DFS/2a,2c control channels (DFS delays WLAN startup; 160MHz bw can reduce range).
5.0 Fixed1,3: 80MHz max bw, disable 160MHz, ch 36-48,149-161
5.0 Unfixed1,3: 20/40/80MHz bw, disable 160MHz, ch Auto, exclude DFS/2a,2c (36-48,
52-64,100-144,149-165)
If RADAR/DFS prohibits using bands DFS/2a,2c, switch to
5.0 Fixed1,3 (no DFS, max Tx power/range, no LTE on ch 36-48)
6.0 (WiFi6e, more spectrum, no DFS, less range, not on Win10)
- disable WPS*
- confirm 2.4/5.0 Roaming Assistant enabled, -74/-74dBm
- confirm 2.4/5.0 Airtime Fairness disabled (compatibility)
- disable 2.4/5.0 Universal Beamforming (proprietary)
LAN
- set router LAN IP (192.168.1.1), DHCP server IP Pool of dynamic and manually-assigned/reserved IPs (pool .10-254 leaves .2-9 for static use on clients)
WAN
- disable UPnP*
- set DNS Server1,2, DNS-over-TLS (DoT), Strict, DoT Server1,2*
(94.140.14.14, 94.140.15.15, dns.adguard-dns.com)
Disable DoT for Wyze cam setup
Other DNSPs
1.1.1.2 1.0.0.2 security.cloudflare-dns.com
9.9.9.9 149.112.112.112 dns.quad9.net
DNS Check
- disable SIP Passthrough (VoIP)
Firewall
- confirm firewalls enabled*
Administration
- confirm Login Captcha enabled*
- set USB Mode to USB 2.0 (prevent USB 3.x EMI)
- set Time Zone, DST (Mar, 2nd Sun; Nov, 1st Sun)
- confirm Telnet, SSH, Web Access from WAN disabled*
- set WPS Button behavior to Toggle LED
- confirm Auto Firmware Upgrade disabled; Security Upgrade enabled*
- confirm Policy\Trend Micro Withdraw/hidden
AiMesh
o Power ON reset node, wait
o
Confirm all WLANs are broadcasting/stable
- if wireless backhaul only, confirm WPS enabled before and disabled after adding node*
- confirm Ethernet Backhaul Mode disabled to permit backhaul failover (wireless uplink is not in WLog until wired uplink fails... toggle EBM to clear it)
- Search/Add node, wait
- set node LEDs OFF
- confirm node Backhaul Connection Priority Auto/2.5G first
- disable node USB Application media servers, Network Place Share
- confirm node AiMesh Mode for existing GNP/SDN VLANs
Guest Network Pro
o Custom VLANs w/DHCP, 5 max
- set 2.4/5.0 VLAN52 OE Guest/OE Guest; WPA2/WPA3-Personal; Access Intranet disabled; DHCP Server enabled 192.168.52.*; VID 52; AP Isolated enabled; all nodes
- set 2.4 VLAN53 OE IoT; WPA2/WPA3-Personal; Access Intranet disabled; DHCP Server enabled 192.168.53.*; VID 53; AP Isolated enabled; all nodes
USB Application
- disable media servers, Network Place Share
SMB 2.0 support
o Logout, wait
o Power OFF-wait-ON router, wait
o
Shields UP! to test WAN ports*
o
Speed Test
o
Deploy node high, in the clear, in range of router 5.0 WLAN; not too far <-75dBm RSSI, too near >-55dBm RSSI, too many; not low/behind/obstructed
Do not co-locate with other 2.4/5/6GHz EMI
Disable unused WiFi Direct APs in printers, etc.
o Tilt/tighten antennas (~2dBi gain)
\ | | / for multi-orientation coverage
o Vary node location/orientation to adjust 5.0 WLAN coverage to affect roaming/node steering (a small change can matter)
o Connect wired backhaul from router LAN to node WAN
Other scenarios
Beware
managed switches
o Adjust
SC Rules to affect band steering
o Increment RA RSSI threshold from -74dBm until stationary clients reboot to near node
o Reboot AiMesh\System, wait; reboot unhealthy nodes, wait; then reboot/reconnect clients to affect change/clear lingering conditions
o Inspect cables/connectors (RG-59/Cat5e min; respect min bend radius of cable; clean dirty contacts)
o Wire stationary clients
o Upgrade client network adapter driver
o Adjust client WLAN adapter properties to affect band steering, roaming aggressiveness; forget connections to clear conditions and only make connection needed
o Let new network settle and use it before adding to it, one change at a time; make notes
o Avoid using app/voice admin and remote access/cloud features*
o Save configuration to .cfg file for recovery (Hard Reset same hw same fw; restore .cfg file)
Upgrade
o Browse notes
o Save configuration to .cfg file
o Download/extract fw to PC
Verify ASUSWRT file checksum value
Review release notes
o Eject/disconnect USB storage (free RAM; secure data)*
o Reboot AiMesh\System, wait (free RAM)
o Upload fw to node(s), WAIT; then root node, WAIT
o
Reconfigure before too much troubleshooting
Reconfigure
o Remove node(s) from AiMesh to auto Reset fw, wait
- set root node Restore+Initialize to Hard Reset fw, wait
o Configure AiMesh from scratch (do not restore .cfg file)
OE