Page MenuHomeVyOS Platform

wireless: station mode cannot connect to open networks
Open, NormalPublic

Description

A wireless interface configured in station mode cannot connect to an open network.

The configuration commits without errors:

set interfaces wireless wlan0 address 'dhcp'
set interfaces wireless wlan0 dhcp-options no-default-route
set interfaces wireless wlan0 hw-id '9c:b1:50:xx:xx:xx'
set interfaces wireless wlan0 physical-device 'phy0'
set interfaces wireless wlan0 ssid 'OPEN-WIFI'
set interfaces wireless wlan0 type 'station'

OPEN-WIFI is an open network. Web authentication happens after association.

VyOS generates /run/wpa_supplicant/wlan0.conf without a key_mgmt option:

network={
    ssid="OPEN-WIFI"
    scan_ssid=1
}

After restarting wpa_supplicant@wlan0.service, the log only contains the initialization message and the interface remains disconnected:

vyos@vyos-edge:~$ sudo iw dev wlan0 link
Not connected.

wpa_supplicant defaults to WPA-PSK WPA-EAP when key_mgmt is omitted. Adding key_mgmt=NONE makes the interface associate immediately:

network={
    ssid="OPEN-WIFI"
    scan_ssid=1
    key_mgmt=NONE
}
vyos@vyos-edge:~$ sudo systemctl restart wpa_supplicant@wlan0.service
vyos@vyos-edge:~$ sudo iw dev wlan0 link
Connected to 32:b8:e6:xx:xx:xx (on wlan0)
        SSID: OPEN-WIFI
        freq: 5260
        signal: -58 dBm

DHCP also starts working after association.

This seems to be a regression introduced by commit fc4263021acb. Before that change, key_mgmt=NONE was generated by the else branch of the outer passphrase check. The WPA-Enterprise changes added a second condition for the username and moved the open-network branch inside it:

https://github.com/vyos/vyos-1x/commit/fc4263021acb72d2d8afb165922d9cb7e11b2bf1

The current template contains the following logic:

jinja2
{% if security.wpa.username is vyos_defined %}
    ...
{% elif security.wpa.username is not vyos_defined %}
    ...
{% else %}
    key_mgmt=NONE
{% endif %}

The final else cannot be reached because the first two branches cover both possible states. The whole block is also skipped when no WPA passphrase is configured.

Current template:

https://github.com/vyos/vyos-1x/blob/0712fac9dddb4dbfede4409867d2973ccbfb5aa2/data/templates/wifi/wpa_supplicant.conf.j2#L21-L91

For an open station network, the generated configuration should contain key_mgmt=NONE.

Tested with:

Version:          VyOS 1.5.0
Release train:    circinus
Built on:         Mon 30 Mar 2026 18:57 UTC
Build commit ID:  cb47cdb72c6d08
Architecture:     x86_64
System type:      bare metal

Wireless adapter: Intel AX200
Driver:           iwlwifi
Kernel:           6.6.128-vyos
Firmware:         77.f39cc7f9.0 cc-a0-77.ucode

Details

Version
1.5.0
Is it a breaking change?
Perfectly compatible
Issue type
Bug (incorrect behavior)

Event Timeline

bigant triaged this task as Normal priority.
bigant created this object in space S1 VyOS Public.