Skip to main content
markb
Associate III
July 1, 2015
Question

What does +WIND:54:Dot11 AuthIllegal 0/2 signify?

  • July 1, 2015
  • 27 replies
  • 2608 views
Posted on July 01, 2015 at 10:00

Hi, I am getting the above error indication when trying to access an AP, what does it mean?

Cheers,

Mark

    This topic has been closed for replies.

    27 replies

    Gerardo GALLUCCI
    ST Employee
    July 3, 2015
    Posted on July 03, 2015 at 11:27

    Please share AT&V dump

    markb
    markbAuthor
    Associate III
    July 3, 2015
    Posted on July 03, 2015 at 11:41

    # Dumping All Configuration Keys:
    # nv_manuf = ST
    # nv_model = SPWF01SA1
    # nv_serial = 2914D13607
    # nv_wifi_macaddr = 00:80:E1:FF:D2:0C
    # blink_led = 0
    # wind_off_low = 0x00000000
    # wind_off_medium = 0x00000000
    # wind_off_high = 0x00000000
    # user_desc = anonymous
    # escape_seq = at+s.
    # localecho1 = 0
    # console1_speed = 115200
    # console1_hwfc = 0
    # console1_enabled = 1
    # sleep_enabled = 0
    # standby_enabled = 0
    # standby_time = 10
    # wifi_tx_msdu_lifetime = 0
    # wifi_rx_msdu_lifetime = 0
    # wifi_operational_mode = 0x00000011
    # wifi_beacon_wakeup = 1
    # wifi_beacon_interval = 100
    # wifi_listen_interval = 0
    # wifi_rts_threshold = 3000
    # wifi_ssid = 43:4C:46:32:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
    # wifi_ssid_len = 4
    # wifi_txfail_thresh = 5
    # wifi_ht_mode = 0
    # wifi_channelnum = 6
    # wifi_opr_rate_mask = 0x00003FCF
    # wifi_bas_rate_mask = 0x0000000F
    # wifi_mode = 1
    # wifi_auth_type = 1
    # wifi_atim_window = 0
    # wifi_powersave = 0
    # wifi_tx_power = 18
    # wifi_rssi_thresh = 0
    # wifi_rssi_hyst = 0
    # wifi_ap_idle_timeout = 120
    # wifi_beacon_loss_thresh = 10
    # wifi_priv_mode = 2
    # wifi_wep_keys[0] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
    # wifi_wep_keys[1] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
    # wifi_wep_keys[2] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
    # wifi_wep_keys[3] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00
    # wifi_wep_key_lens = 00:00:00:00
    # wifi_wep_default_key = 0
    # wifi_wpa_psk_raw = 0A:C9:1E:70:69:21:CE:16:3D:D4:F9:AE:DE:96:95:05:6D:B6:30:06:53:CF:47:6C:9A:C7:F0:A8:F3:D1:FB:73
    # wifi_wpa_psk_text = plasmagun
    # ip_use_dhcp = 1
    # ip_use_httpd = 1
    # ip_mtu = 1500
    # ip_hostname = iwm-FF-D2-0C
    # ip_apdomainname = captiveportal.net
    # ip_apredirect = firstset.html
    # ip_ipaddr = 0.50
    # ip_netmask = 0
    # ip_gw = 0.1
    # ip_dns = 0.1
    # ip_http_get_recv_timeout = 3000
    # ip_wait_timeout = 12000
    # ip_dhcp_timeout = 20
    # ip_sockd_timeout = 250

    # Status & Statistics:
    # version = 150410-c2e37a3-SPWF01S
    # reset_reason = 2
    # conf_flag = 5
    # system_uptime = 799
    # system_sleeptime = 0
    # gpio_enable = 0
    # captiveportal = 0
    # wifi_state = 7
    # wifi_bssid = 74:EA:3A:BA:89:67
    # wifi_aid = 0
    # wifi_channelnum = 5
    # wifi_sup_rate_mask = 0x003FFFCF
    # wifi_bas_rate_mask = 0x0000000F
    # wifi_chan_activity2 = 0x00000000
    # wifi_max_tx_power = 18
    # wifi_gf_mode = 0
    # wifi_reg_country =
    # wifi_dtim_period = 1
    # wifi_sleeping = 0
    # wifi_num_assoc = 0
    # ip_ipaddr = 0.0.0.0
    # ip_netmask = 0.0.0.0
    # ip_gw = 0.0.0.0
    # ip_dns = 0.0.0.0
    # ip_sock_open = 0
    # ip_sockd_port = 0
    # free_heap = 20992
    # min_heap = 20848
    # current_time = 3615

    Gerardo GALLUCCI
    ST Employee
    July 3, 2015
    Posted on July 03, 2015 at 12:21

    I saw TL-WA701N is an N (B/G compatible) Access Point.

    Module, on the other hand, is configured as B/G only.

    I don't know where is the problem, and I have no that AP.

    Try this way:

    - at+s.scfg=

    wifi_ht_mode,1

    - at+s.scfg=wifi_opr_rate_mask,

    0x3FFCF

    - at&w

    - reboot (SW or HW)

    Helps?

    markb
    markbAuthor
    Associate III
    July 7, 2015
    Posted on July 07, 2015 at 09:06

    Hi, sorry for the slow reply, I have been busy chasing other problems. No, it didn't help. If I turn off the security for that AP, the module will connect to it happily so I think it must be a security related problem. Any other suggestions? Also, what does that error message actually say? What's the 0/2 mean?

    Thanks,

    Mark

    Gerardo GALLUCCI
    ST Employee
    July 7, 2015
    Posted on July 07, 2015 at 10:15

    Problem is that AP doesn't like authentication type requested by module.

    0 refers to authentication alghorithm received from AP.

    OPEN   is 0; SHARED is 1.

    Module receives 0, while configuration variable is set to 1.

    2 refers to ''challenge'' steps  received from AP.

    Big info is taken from next WIND:75. 0x0D, 13, Means: ''

    Responding station does not support the specified authentication algorithm

    ''

    Double check: are you sure your AP is configured in WPA? It seems that it's configured in WEP mode (open/shared mismatch means something only in WEP mode).

    Try to set wifi_auth_type = 0 on module. What does it happen?

    Can you share a sniff? Use wireshark, for example.

    Thanks

    jerry
    valentin
    Associate III
    January 26, 2017
    Posted on January 26, 2017 at 23:38

    Thanks from me for this info,

    . I had pretty much the same issue, trying to join my WPA2 network.

    Setting aut_type to 0 made it possible:

    +WIND:2:Reset+WIND:1:Poweron (150410-c2e37a3-SPWF02S)+WIND:13:ST SPWF01SA2 IWM: Copyright (c) 2012-2014 STMicroelectronics, Inc. All rights Reserved.+WIND:3:Watchdog Running+WIND:46:WPA: Crunching PSK...+WIND:0:Console active+WIND:32:WiFi Hardware Started+WIND:21:WiFi Scanning+WIND:35:WiFi Scan Complete (0x0)+WIND:19:WiFi Join:xx:xx:xx:43:02:94+WIND:25:WiFi Association with '***_wireless' successful+WIND:51:WPA Handshake Complete+WIND:24:WiFi Up:x.x.1 �?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?

    So my question now is: Your post below infers that setting auth_type to zero makes the module use WEP encryption? That cannot be the case because my wifi is definitely using WPA2 only - which seems to be confirmed by the WPA lines above.

    If I set auth_type to 1, though, I get his output:

    +WIND:2:Reset+WIND:1:Poweron (150410-c2e37a3-SPWF02S)+WIND:13:ST SPWF01SA2 IWM: Copyright (c) 2012-2014 STMicroelectronics, Inc. All rights Reserved.+WIND:3:Watchdog Running+WIND:0:Console active+WIND:32:WiFi Hardware Started+WIND:21:WiFi Scanning+WIND:35:WiFi Scan Complete (0x0)+WIND:19:WiFi Join:xx:xx:xx:xx:xx:xx+WIND:45:Dot11 AuthIllegal 1/2+WIND:75:Rejected Association (0xD) �?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?

    The config producing the error:

    # Dumping All Configuration Keys:# nv_manuf = ST# nv_model = SPWF01SA2# nv_serial = 2215P15051# nv_wifi_macaddr = 00:80:E1:B5:AF:25# blink_led = 0# wind_off_low = 0x00000000# wind_off_medium = 0x00000000# wind_off_high = 0x00000000# user_desc = anonymous# escape_seq = at+s.# localecho1 = 0# console1_speed = 115200# console1_hwfc = 1# console1_enabled = 1# sleep_enabled = 0# standby_enabled = 0# standby_time = 10# wifi_tx_msdu_lifetime = 0# wifi_rx_msdu_lifetime = 0# wifi_operational_mode = 0x00000011# wifi_beacon_wakeup = 1# wifi_beacon_interval = 100# wifi_listen_interval = 0# wifi_rts_threshold = 3000# wifi_ssid = xx:xx:xx:xx:5F:77:69:72:65:6C:65:73:73:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00# wifi_ssid_len = 13# wifi_txfail_thresh = 5# wifi_ht_mode = 0# wifi_channelnum = 6# wifi_opr_rate_mask = 0x00003FCF# wifi_bas_rate_mask = 0x0000000F# wifi_mode = 1# wifi_auth_type = 1# wifi_atim_window = 0# wifi_powersave = 0# wifi_tx_power = 18# wifi_rssi_thresh = 0# wifi_rssi_hyst = 0# wifi_ap_idle_timeout = 120# wifi_beacon_loss_thresh = 10# wifi_priv_mode = 2# wifi_wep_keys[0] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00# wifi_wep_keys[1] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00# wifi_wep_keys[2] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00# wifi_wep_keys[3] = 00:00:00:00:00:00:00:00:00:00:00:00:00:00:00:00# wifi_wep_key_lens = 00:00:00:00# wifi_wep_default_key = 0# wifi_wpa_psk_raw = xxxxxxxxxxx# wifi_wpa_psk_text = xxxxxxxx# ip_use_dhcp = 1# ip_use_httpd = 1# ip_mtu = 1500# ip_hostname = xx# ip_apdomainname = xx.com# ip_apredirect = firstset.html# ip_ipaddr = 0.50# ip_netmask = 0# ip_gw = 0.1# ip_dns = 0.1# ip_http_get_recv_timeout = 3000# ip_wait_timeout = 12000# ip_dhcp_timeout = 20# ip_sockd_timeout = 250�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?�?

    Can you explain, please? And is there a reference sheet available somewhere, detailing the error codes?

    Thanks a lot!

    Gerardo GALLUCCI
    ST Employee
    January 28, 2017
    Posted on January 28, 2017 at 12:11

    Hi,

    using WPA/WPA2, wifi_auth_type must be set to 0. WPA does not support shared authentication.

    From Google:

    Open System and Shared Key

    The Open System and Shared Key authentication methods use WEP encryption. WEP is not as secure as WPA2 and WPA (Wi-Fi Protected Access). We recommend you do not use these less secure methods unless your wireless clients do not support WPA or WPA2.

    • Open System — Open System authentication allows any user to authenticate to the access point. This method can be used with no encryption or with WEP encryption.
    • Shared Key — In Shared Key authentication, only those wireless clients that have the shared key can connect. Shared Key authentication can be used only with WEP encryption.

    Ciao

    jerry

    markb
    markbAuthor
    Associate III
    July 7, 2015
    Posted on July 07, 2015 at 10:47

    Yes, setting wifi_auth_type to 0 makes it work. It can now associate and data flows. I have tried with two access points (one a Netgear and the other a TP-LINK) and with wifi_auth_type set to 0 it can talk to either when the AP security is WPA/WPA2 but if wifi_auth_type is set to 1 it fails for both APs - the TP-LINK fails as we have previously discussed and the Netgear fails because it gets no further than WIND:19 and just keeps retrying.

    So, what magic does setting wifi_auth_type to 0 do and will that work with other APs?

    Mark

    Gerardo GALLUCCI
    ST Employee
    July 7, 2015
    Posted on July 07, 2015 at 11:21

    Hi Mark,

    From Google:

    Open System and Shared Key

    The Open System and Shared Key authentication methods use WEP encryption. WEP is not as secure as WPA2 and WPA (Wi-Fi Protected Access). We recommend you do not use these less secure methods unless your wireless clients do not support WPA or WPA2.

    • Open System â€�? Open System authentication allows any user to authenticate to the access point. This method can be used with no encryption or with WEP encryption.
    • Shared Key â€�? In Shared Key authentication, only those wireless clients that have the shared key can connect. Shared Key authentication can be used only with WEP encryption.

    The last sentence is clear: ''

    Shared Key authentication can be used only with WEP encryption

    ''.

    AP gives a status error (0x0D), and module aborts the authentication process at the beginning.

    I'll give this feedback to the right people for updating User Manuals, and highlight that WPA+SharedAuth=Rejection!

    Thanks for your feedback.

    Ciao

    jerry

    markb
    markbAuthor
    Associate III
    July 7, 2015
    Posted on July 07, 2015 at 14:18

    Hi Jerry,

    Thanks for all your help, it's working pretty well now. One other question (there's always another question!) How do you specify the IP address to be used when you force AP mode via the GPIO signal? At the moment, it is 172.31.12.1 but I would like to change that if possible.

    Cheers,

    Mark

    Gerardo GALLUCCI
    ST Employee
    July 7, 2015
    Posted on July 07, 2015 at 14:32

    Use variable ip_use_dhcp.

    Default, 172.31.12.1 when ip_use_dhcp is 1, is self-generated, based on MAC address.

    Set ip_use_dhcp to 2, for custom address, based on ip_ipaddr & Co. variables.

    0=off (in STA mode: the variables ip_ipaddr, ip_netmask and ip_gw must be properly set to connect to the AP),

    1=on (in STA mode: the ipaddr, netmask and gw will be provided by the AP),

    2=on&customize (in MiniAP mode: user can customize the ip_ipaddr of the MiniAP, the ip_address of the client is automatically assigned by the MiniAP)

    markb
    markbAuthor
    Associate III
    July 7, 2015
    Posted on July 07, 2015 at 15:45

    Hi Jerry, thanks again for your swift reply. I am exploring changing the MiniAP ip address because I am trying to get UDP broadcast working when in MiniAP mode. If the module is in STA mode with an ip address of, say, 192.168.1.138 as handed out by the local DHCP server, I can broadcast UDP packets from the module to address 192.168.1.255 OK. But when the module is in MiniAP mode and it has the IP address of 172.31.12.1 then broadcasting to 172.31.12.255 does not give an error but the packets don't get delivered either.

    So, the question is, what is the correct broadcast address to use when the IP address is 172.31.12.1 ? Or is there some other reason why UDP broadcasts fail when in MiniAP mode?

    Cheers,

    Mark