Kitz ADSL Broadband Information
adsl spacer  
Support this site
Home Broadband ISPs Tech Routers Wiki Forum
 
     
   Compare ISP   Rate your ISP
   Glossary   Glossary
 
Please login or register.

Login with username, password and session length
Advanced search  

News:

Author Topic: Huawei AX3 insecure mesh  (Read 1626 times)

denrok

  • Member
  • **
  • Posts: 15
Huawei AX3 insecure mesh
« on: December 27, 2021, 07:14:15 PM »

I have my broadband router with wifi disabled and connected a Huwaei AX3. I've configured the wifi on the AX3 in AP MODE and works as expected using my custom SSID i,e denrok_home and passphrase. After syncing a second AX3 to the main one using the H button the ssid of the second device doesn't change i.e it stays as huawei_xxxx and reports as OPEN/INSECURE i.e if i connect to that SSID with no password I can browse the internet via my broadband connection. 

On the second device if I connect my laptop via ethernet to it I can ping out to the internet and i'm given an ip via dhcp from my asus router so that's right the same as when connecting via wifi.

Huawei were completely useless at helping with this.

Someone mentioned on a different forum that mesh is disabled in AP mode but not sure if this is correct?
Logged

burakkucat

  • Respected
  • Senior Kitizen
  • *
  • Posts: 38300
  • Over the Rainbow Bridge
    • The ELRepo Project
Re: Huawei AX3 insecure mesh
« Reply #1 on: December 27, 2021, 08:17:00 PM »

Welcome to the kitz forum.  :)

I have my broadband router with wifi disabled and connected a Huwaei AX3.  . . .

<snip>

Someone mentioned on a different forum that mesh is disabled in AP mode but not sure if this is correct?

I do not know that particular Huawei device; nor have I seen any discussion about it.

Let's see if other members have had experience of it and are able to comment.
Logged
:cat:  100% Linux and, previously, Unix. Co-founder of the ELRepo Project.

Please consider making a donation to support the running of this site.

meritez

  • Content Team
  • Kitizen
  • *
  • Posts: 1626
Re: Huawei AX3 insecure mesh
« Reply #2 on: December 27, 2021, 10:16:03 PM »

I setup Huawei ax3 and honor 3 by connecting the second one's wan port to the Lan port of the first one.

This then downloads the configuration and I can disconnect it afterwards and put it where it needs to be.
Logged

denrok

  • Member
  • **
  • Posts: 15
Re: Huawei AX3 insecure mesh
« Reply #3 on: December 27, 2021, 11:22:25 PM »

I setup Huawei ax3 and honor 3 by connecting the second one's wan port to the Lan port of the first one.

This then downloads the configuration and I can disconnect it afterwards and put it where it needs to be.

Yes I have synced using this method also but the result is still the same, are you running the main AX3 node in Access Point mode?
Logged

meritez

  • Content Team
  • Kitizen
  • *
  • Posts: 1626
Re: Huawei AX3 insecure mesh
« Reply #4 on: December 28, 2021, 12:39:59 AM »

Main ax3 is in router mode, behind a virgin super hub in modem mode.
Logged

tubaman

  • Senior Kitizen
  • ******
  • Posts: 12632
Re: Huawei AX3 insecure mesh
« Reply #5 on: December 28, 2021, 08:53:17 AM »

Sounds like the second router has connected as a repeater with default open settings rather than as part of a mesh network (which I'd expect to have the same SSID) - not very clever as you say.   :no:
Logged
BT FTTC 55/10 Huawei Cab - Zyxel VMG8924-B10A

denrok

  • Member
  • **
  • Posts: 15
Re: Huawei AX3 insecure mesh
« Reply #6 on: December 28, 2021, 09:54:41 AM »

Main ax3 is in router mode, behind a virgin super hub in modem mode.

Yeah I think that's the difference i.e your using it in router mode which isn't suitable for me as it doesn't support openvpn server etc.

Sounds like the second router has connected as a repeater with default open settings rather than as part of a mesh network (which I'd expect to have the same SSID) - not very clever as you say.   :no:


Yeah utter madness when contacted Huawei support they said this "Unfortunately sir we don't offer such complex technical troubleshooting" I work in networking and if they thing this is complex they need a reality check.
Logged

tubaman

  • Senior Kitizen
  • ******
  • Posts: 12632
Re: Huawei AX3 insecure mesh
« Reply #7 on: December 28, 2021, 05:31:19 PM »

... when contacted Huawei support they said this "Unfortunately sir we don't offer such complex technical troubleshooting" I work in networking and if they thing this is complex they need a reality check.

You're not kidding, if they call that 'technical' they might as well close up shop and go home. Unbelievable!  :o
Logged
BT FTTC 55/10 Huawei Cab - Zyxel VMG8924-B10A

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Re: Huawei AX3 insecure mesh
« Reply #8 on: December 28, 2021, 07:24:42 PM »

I don't think Mesh is supposed to work in Access Point mode.  I know the Honor Router 3 claims the AI stuff is disabled in Access Point mode.

Access Point mode on the Honor Router 3 is rather broken in fact, it blocks broadcasts from the LAN side so none of my wired smart devices can be seen from the WiFi and the UI only works when connected to the Honor Router 3 itself.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

denrok

  • Member
  • **
  • Posts: 15
Re: Huawei AX3 insecure mesh
« Reply #9 on: December 28, 2021, 10:17:35 PM »

I don't think Mesh is supposed to work in Access Point mode.  I know the Honor Router 3 claims the AI stuff is disabled in Access Point mode.

Access Point mode on the Honor Router 3 is rather broken in fact, it blocks broadcasts from the LAN side so none of my wired smart devices can be seen from the WiFi and the UI only works when connected to the Honor Router 3 itself.

Right makes sense that it's not working for me then but it's a serious security hole because if someone non technically minded had set it up the same they would have been left with an open wifi ap on their network.
Logged

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Re: Huawei AX3 insecure mesh
« Reply #10 on: December 29, 2021, 11:38:56 AM »

Right makes sense that it's not working for me then but it's a serious security hole because if someone non technically minded had set it up the same they would have been left with an open wifi ap on their network.

Yeah not at all impressed with the Huawei software, theres no good reason it should block broadcasts or disable mesh, and even worse if its not disabling mesh correctly leaving security wide open like that.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors

denrok

  • Member
  • **
  • Posts: 15
Re: Huawei AX3 insecure mesh
« Reply #11 on: December 29, 2021, 05:42:09 PM »

I give up with it, utter junk, the last email from support said

Quote
please  contact your internet provider for further assistance as the connectivity  issues are usually from their side.

Not sure where they got that from as there is nothing wrong on the isp side ::)

I asked flat "Does the AX3 support mesh in access point mode yes or no?" and they couldn't even answer that.
Logged

Alex Atkin UK

  • Addicted Kitizen
  • *****
  • Posts: 5272
    • Thinkbroadband Quality Monitors
Re: Huawei AX3 insecure mesh
« Reply #12 on: December 29, 2021, 08:34:04 PM »

Its sad as Huawei use their own SoC so you can't even flash OpenWRT on them.
Logged
Broadband: Zen Full Fibre 900 + Three 5G Routers: pfSense (Intel N100) + Huawei CPE Pro 2 H122-373 WiFi: Zyxel NWA210AX
Switches: Netgear MS510TXUP, Netgear MS510TXPP, Netgear GS110EMX My Broadband History & Ping Monitors
 

anything