What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

group key rotation every hour on one router not the other?

lgkahn

Regular Contributor
i have two gt-axe16000 running in ap mode with the settings for system and 2.4 ghz wifi save differnt ssids)
i have legacy devices connecting to the 2.4ghz and dont understand why on one of the routers i have group key rotations every hour and none on the other?
 
Just set both the way you want and experiment if it works for your needs. If one of the routers had at some point IoT network with preset compatibility settings key rotation may be 0 for better stability.
 
Just set both the way you want
I can't find any relevant settings anywhere in the gui. I'm seeing the group key rotation on my router too, but the only ill effect is the occasional drop of streaming over WiFi. Just happened now as I'm typing.
 
It was in Wireless, General before. Gone now? The default was 3600, but on some equipment it’s 0.
 
Yes, it's gone now. So unless someone comes along with an nvram setting we're stuck with 1hr rotation.
I haven't time now - I'll look when I get back home later.
 
At least on the AX86U Pro it's still in the gui (set to 86400 in my environment), but these are the nvram variables:

Code:
wl0_wpa_gtk_rekey=86400
wl1.1_wpa_gtk_rekey=86400
wl1_wpa_gtk_rekey=86400
wl_wpa_gtk_rekey=86400

wl0 is 2.4 GHz, wl1 is 5 GHz and wl1.1 is the guest ssid on 5 GHz. But what purpose has the wl without the interface identifier behind? This exists for every wifi nvram parameter (wl, wl0, wl1) and I have no idea what wl is used for.

OT: If I test it with the dtim value, wl takes over the value from wl0 or wl1, depending on which one was changed last. Makes no sense to me, so maybe someone can clarify what wl is used for?

Code:
setting dtim on wl1 to 3 and wl0 to 2 (all changes done in gui, wl takes over the changed value few seconds after wl0/1 variable changed):
wl0_dtim=2
wl1_dtim=3
wl_dtim=2

changing wl1 to 1:
wl0_dtim=2
wl1_dtim=1
wl_dtim=1

changing wl1 to 4:
wl0_dtim=2
wl1_dtim=4
wl_dtim=4

changing wl0 to 1:
wl0_dtim=1
wl1_dtim=4
wl_dtim=1
 
Last edited:
ASUS may have decided to hardcode the value. In theory it's security related.
 
Yes of course it is security related. But why are there 3 different variables for nearly every wifi setting (wl, wl0, wl1) for only 2 wifi interfaces and the one without the interface identifier in the name (wl) changes its value more or less randomly between the value of wl0 and wl1?
 
Seems normal to me. I see individual settings per SSID on my UniFi equipment and in theory with 4x dual-band APs I can set 64x SSIDs with individual Group Rekey Interval. The default was 0, I have it set at 3600.
 
But why are there 3 different variables for nearly every wifi setting (wl, wl0, wl1) for only 2 wifi interfaces and the one without the interface identifier in the name (wl) changes its value more or less randomly between the value of wl0 and wl1?
The wl_ variables are usually containing whatever band was last displayed in the gui, when you had to always switch bands between 2.4 and 5.0, like on the Professional page.
 
The wl_ variables are usually containing whatever band was last displayed in the gui, when you had to always switch bands between 2.4 and 5.0, like on the Professional page.
Thank you very much dave!
 
figured it out . in my case one of the routers had wps enabled. once I disabled that it stopped doing hourly key rotations
 
Also figured it out for my own setup. WPS was already disabled (SOP). After searching for "rekey" in the nvram.txt file BACKUPMON saves I have this:
Code:
nvram set wl0.1_wpa_gtk_rekey=86400
nvram set wl0.2_wpa_gtk_rekey=86400
nvram set wl0_wpa_gtk_rekey=86400
nvram set wl1.1_wpa_gtk_rekey=86400
nvram set wl1.2_wpa_gtk_rekey=86400
nvram set wl1_wpa_gtk_rekey=86400
nvram set wl_wpa_gtk_rekey=86400
nvram commit
Survives a reboot. I'll know in a little under an hour if this is a fix. These are all that showed up in nvram with non-zero values (3600) so don't ask me why there seems to be a 2.4GHz on the main wifi and a 5GHz on the Guest even though I don't use them.
 
Last edited:
Similar threads
Thread starter Title Forum Replies Date
pedeb04 SSH with id_rsa.pub (public key) Asuswrt-Merlin 9

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top