WWAN (Wireless WAN)
WWAN (Wireless Wide-Area-Network) Interfaces
Overview
WWAN interfaces in VyOS provide network connectivity through wireless cellular modems. This technology lets you use carriers’ mobile networks (2G/3G/4G/LTE/5G) to access the internet and build resilient, fault-tolerant solutions.
Key Features
- Support for 2G/3G/4G/LTE/5G cellular modems
- Integration with the mobile networks of Russian and international operators
- Automatic IP address assignment via DHCP
- IPv4 and IPv6 support
- Integration with VRF (Virtual Routing and Forwarding)
- Signal strength and connection quality monitoring
- Support for modem firmware updates
- Use as a backup channel (failover)
Supported Hardware
VyOS supports a wide range of cellular modems connected via miniPCIe, M.2, and USB interfaces:
Sierra Wireless AirPrime Series
- MC7304 - LTE Cat 3 (up to 100 Mbps)
- MC7430 - LTE Cat 6 (up to 300 Mbps)
- MC7455 - LTE Cat 6 (up to 300 Mbps)
- MC7710 - LTE Cat 3 (up to 100 Mbps)
- EM7455 - LTE Cat 6 (up to 300 Mbps)
Huawei Modems
- ME909u-521 - LTE Cat 4 (up to 150 Mbps)
- ME909s-120 - LTE Cat 4 (up to 150 Mbps)
- ME906s - LTE Cat 4 (up to 150 Mbps)
HP/Intel Modems
- HP LT4120 - Snapdragon X5 LTE (up to 150 Mbps)
- Intel XMM 7160 - LTE Cat 4
Quectel Modems
- EC25 - LTE Cat 4 (up to 150 Mbps)
- EP06 - LTE Cat 6 (up to 300 Mbps)
- RM500Q - 5G (up to 2.5 Gbps)
USB Modems
- Huawei E3372
- ZTE MF823
- Yota LTE modems
Basic Configuration
APN Configuration
The APN (Access Point Name) is the operator’s access point name required to connect to the internet.
set interfaces wwan wwan0 apn 'internet.mts.ru'Obtaining an IP Address via DHCP
set interfaces wwan wwan0 address dhcpStatic IP Address
Some operators provide static IP addresses:
set interfaces wwan wwan0 address '10.123.45.67/32'Interface Description
set interfaces wwan wwan0 description 'MTS LTE Backup Connection'MTU
Configuring the Maximum Transmission Unit:
set interfaces wwan wwan0 mtu 1430Configuration for Russian Operators
MTS
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'MTS LTE Connection'Alternative APNs for MTS:
internet.mts.ru- standard internetinternet.mts- alternative optionmts- simplified option
Beeline
set interfaces wwan wwan0 apn 'internet.beeline.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'Beeline LTE Connection'Alternative APNs for Beeline:
internet.beeline.ru- standard internetbeeline- simplified option
MegaFon
set interfaces wwan wwan0 apn 'internet'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'MegaFon LTE Connection'Alternative APNs for MegaFon:
internet- standard internetinternet.mc- for modems
Tele2
set interfaces wwan wwan0 apn 'internet.tele2.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'Tele2 LTE Connection'Alternative APNs for Tele2:
internet.tele2.ru- standard internetinternet.tele2- alternative option
Yota
set interfaces wwan wwan0 apn 'internet.yota'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'Yota LTE Connection'IPv6 Configuration
DHCPv6
set interfaces wwan wwan0 address dhcpv6DHCPv6 Prefix Delegation
Obtaining an IPv6 prefix to delegate to local networks:
set interfaces wwan wwan0 dhcpv6-options prefix-delegation interface eth1 sla-id 0
set interfaces wwan wwan0 dhcpv6-options prefix-delegation length 56Integration with VRF
Assigning the WWAN interface to a specific VRF:
set interfaces wwan wwan0 vrf RED
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcpBackup Channel Configuration (Failover)
Using WWAN as a Backup Connection
Configuration with a primary wired link and a backup WWAN connection:
# Primary interface (Ethernet)
set interfaces ethernet eth0 address dhcp
set interfaces ethernet eth0 description 'Primary ISP'
# Backup interface (WWAN)
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'Backup LTE Connection'
# Routing using metric
set protocols static route 0.0.0.0/0 next-hop <primary-gateway> distance 10
set protocols static route 0.0.0.0/0 interface wwan0 distance 20
# Monitoring the availability of the primary channel
set service monitoring interface eth0 address <primary-gateway>
set service monitoring interface eth0 policy 'LTE-Failover'Policy-based Routing for Failover
# Creating a routing table for WWAN
set protocols static table 10 route 0.0.0.0/0 interface wwan0
# Policy-based routing
set policy route PBR rule 10 destination address 0.0.0.0/0
set policy route PBR rule 10 set table 10
# Applying the policy
set interfaces ethernet eth1 policy route PBRLoad Balancing
Load balancing between a wired and a WWAN connection:
# Load balancing configuration
set load-balancing wan interface-health eth0 nexthop <eth0-gateway>
set load-balancing wan interface-health eth0 test 10 type ping
set load-balancing wan interface-health eth0 test 10 target 8.8.8.8
set load-balancing wan interface-health wwan0 nexthop dhcp
set load-balancing wan interface-health wwan0 test 10 type ping
set load-balancing wan interface-health wwan0 test 10 target 8.8.4.4
# Balancing rules
set load-balancing wan rule 1 inbound-interface eth1
set load-balancing wan rule 1 interface eth0 weight 70
set load-balancing wan rule 1 interface wwan0 weight 30
set load-balancing wan rule 1 protocol allNAT for the WWAN Interface
Source NAT (Masquerade)
set nat source rule 100 outbound-interface name 'wwan0'
set nat source rule 100 source address '192.168.1.0/24'
set nat source rule 100 translation address masqueradeExcluding Local Traffic
set nat source rule 90 outbound-interface name 'wwan0'
set nat source rule 90 source address '192.168.1.0/24'
set nat source rule 90 destination address '192.168.0.0/16'
set nat source rule 90 translation address masquerade
set nat source rule 90 excludeFirewall Rules for WWAN
Basic WAN Interface Protection
# Creating a zone for WWAN
set firewall zone WWAN interface wwan0
set firewall zone WWAN default-action drop
# Allowing established connections
set firewall ipv4 name WWAN-LOCAL default-action drop
set firewall ipv4 name WWAN-LOCAL rule 10 action accept
set firewall ipv4 name WWAN-LOCAL rule 10 state established
set firewall ipv4 name WWAN-LOCAL rule 10 state related
# Blocking invalid packets
set firewall ipv4 name WWAN-LOCAL rule 20 action drop
set firewall ipv4 name WWAN-LOCAL rule 20 state invalid
# Allowing ICMP
set firewall ipv4 name WWAN-LOCAL rule 30 action accept
set firewall ipv4 name WWAN-LOCAL rule 30 protocol icmp
# Applying the rules
set firewall zone WWAN from LAN firewall name LAN-WWAN
set firewall zone WWAN to local firewall name WWAN-LOCALRestricting Access to Management
# Blocking SSH from the WWAN interface
set firewall ipv4 name WWAN-LOCAL rule 100 action drop
set firewall ipv4 name WWAN-LOCAL rule 100 destination port 22
set firewall ipv4 name WWAN-LOCAL rule 100 protocol tcpMonitoring and Diagnostics
Viewing Interface Status
show interfaces wwan wwan0Example output:
wwan0: <BROADCAST,MULTICAST,NOARP,UP,LOWER_UP> mtu 1500 state UP
link/ether 0e:3e:7d:98:a2:b4
inet 10.123.45.67/32 scope global wwan0
RX: bytes packets errors dropped overrun mcast
15467284 12456 0 0 0 0
TX: bytes packets errors dropped carrier collisions
3456789 8234 0 0 0 0Checking Signal Strength
show interfaces wwan wwan0 signalExample output:
Signal Quality: 85%
RSSI: -65 dBm
RSRQ: -9 dB
RSRP: -85 dBm
SNR: 15 dB
Technology: LTE
Band: B7 (2600 MHz)Modem Information
show interfaces wwan wwan0 capabilitiesExample output:
Manufacturer: Sierra Wireless
Model: MC7455
Firmware: SWI9X30C_02.24.05.06
IMEI: 123456789012345
Supported modes: 2G, 3G, LTE
Max bandwidth: Cat 6 (300 Mbps DL / 50 Mbps UL)Viewing Network Information
show interfaces wwan wwan0 networkExample output:
Operator: MTS RUS (25001)
Registration: Registered (home network)
Technology: LTE
Band: B7 (2600 MHz)
Channel: 2850
Cell ID: 12345678Firmware Information
show interfaces wwan wwan0 firmwareInterface Statistics
show interfaces wwan wwan0 statisticsViewing QMI Information
For modems that support QMI (Qualcomm MSM Interface):
sudo qmicli -d /dev/cdc-wdm0 --wds-get-packet-service-status
sudo qmicli -d /dev/cdc-wdm0 --nas-get-signal-strength
sudo qmicli -d /dev/cdc-wdm0 --nas-get-serving-systemAdvanced Configuration
Configuring Modem Parameters
Forcing a Network Mode
Some modems allow you to force a specific network mode (2G/3G/4G):
# LTE only
sudo qmicli -d /dev/cdc-wdm0 --nas-set-system-selection-preference=lte
# Automatic mode
sudo qmicli -d /dev/cdc-wdm0 --nas-set-system-selection-preference=autoLocking a Frequency Band
Forcing operation on a specific band:
# Operating only on band B7 (2600 MHz) - the primary LTE band in Russia
sudo qmicli -d /dev/cdc-wdm0 --nas-set-system-selection-preference=lte,band-7Configuring DHCP Timeouts
set interfaces wwan wwan0 dhcp-options default-route-distance 20
set interfaces wwan wwan0 dhcp-options no-default-routeDisabling the Interface
set interfaces wwan wwan0 disableUpdating Modem Firmware
Sierra Wireless Modems
# Download the firmware from the manufacturer's website
# Update via qmi-firmware-update
sudo qmi-firmware-update -d /dev/cdc-wdm0 -u <firmware-file.cwe>Checking the Firmware Version
sudo qmicli -d /dev/cdc-wdm0 --dms-get-software-versionPractical Scenarios
Scenario 1: Remote Office with an LTE Connection
A small office with a single communication channel over LTE:
# WWAN interface
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'MTS LTE - Primary Connection'
# Local network
set interfaces ethernet eth1 address '192.168.1.1/24'
set interfaces ethernet eth1 description 'LAN'
# DHCP server for the local network
set service dhcp-server shared-network-name LAN subnet 192.168.1.0/24 range 0 start 192.168.1.100
set service dhcp-server shared-network-name LAN subnet 192.168.1.0/24 range 0 stop 192.168.1.200
set service dhcp-server shared-network-name LAN subnet 192.168.1.0/24 default-router 192.168.1.1
set service dhcp-server shared-network-name LAN subnet 192.168.1.0/24 name-server 8.8.8.8
set service dhcp-server shared-network-name LAN subnet 192.168.1.0/24 domain-name 'office.local'
# NAT
set nat source rule 100 outbound-interface name 'wwan0'
set nat source rule 100 source address '192.168.1.0/24'
set nat source rule 100 translation address masquerade
# Firewall
set firewall zone LAN interface eth1
set firewall zone LAN default-action accept
set firewall zone WWAN interface wwan0
set firewall zone WWAN default-action drop
set firewall ipv4 name WWAN-LOCAL default-action drop
set firewall ipv4 name WWAN-LOCAL rule 10 action accept
set firewall ipv4 name WWAN-LOCAL rule 10 state established
set firewall ipv4 name WWAN-LOCAL rule 10 state related
set firewall zone WWAN from LAN firewall name LAN-WWAN
set firewall zone WWAN to local firewall name WWAN-LOCALScenario 2: Dual WAN with Priority for the Wired Connection
An office with a wired connection and an LTE backup:
# Primary wired channel
set interfaces ethernet eth0 address dhcp
set interfaces ethernet eth0 description 'Primary ISP - Fiber'
# Backup LTE channel
set interfaces wwan wwan0 apn 'internet.beeline.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'Backup ISP - Beeline LTE'
# Local network
set interfaces ethernet eth1 address '192.168.10.1/24'
set interfaces ethernet eth1 description 'Office LAN'
# Routing with priority
# eth0 - primary (distance 10)
# wwan0 - backup (distance 20)
set protocols static route 0.0.0.0/0 dhcp-interface eth0 distance 10
set protocols static route 0.0.0.0/0 interface wwan0 distance 20
# NAT for both interfaces
set nat source rule 100 outbound-interface name 'eth0'
set nat source rule 100 source address '192.168.10.0/24'
set nat source rule 100 translation address masquerade
set nat source rule 110 outbound-interface name 'wwan0'
set nat source rule 110 source address '192.168.10.0/24'
set nat source rule 110 translation address masquerade
# DHCP for the local network
set service dhcp-server shared-network-name LAN subnet 192.168.10.0/24 range 0 start 192.168.10.50
set service dhcp-server shared-network-name LAN subnet 192.168.10.0/24 range 0 stop 192.168.10.250
set service dhcp-server shared-network-name LAN subnet 192.168.10.0/24 default-router 192.168.10.1
set service dhcp-server shared-network-name LAN subnet 192.168.10.0/24 name-server 8.8.8.8
set service dhcp-server shared-network-name LAN subnet 192.168.10.0/24 name-server 8.8.4.4Scenario 3: IoT Devices over LTE with Restrictions
Connecting IoT devices with traffic restrictions:
# WWAN interface
set interfaces wwan wwan0 apn 'internet.tele2.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan0 description 'Tele2 LTE for IoT'
# Local network for IoT
set interfaces ethernet eth1 address '10.0.100.1/24'
set interfaces ethernet eth1 description 'IoT VLAN'
# Traffic shaping to limit the speed
set traffic-policy shaper IOT-LIMIT bandwidth '10mbit'
set traffic-policy shaper IOT-LIMIT default bandwidth '10mbit'
set traffic-policy shaper IOT-LIMIT default ceiling '10mbit'
set traffic-policy shaper IOT-LIMIT default queue-type fair-queue
set interfaces wwan wwan0 traffic-policy out IOT-LIMIT
# NAT
set nat source rule 200 outbound-interface name 'wwan0'
set nat source rule 200 source address '10.0.100.0/24'
set nat source rule 200 translation address masquerade
# Firewall - allow only HTTP/HTTPS and MQTT
set firewall ipv4 name IOT-WWAN default-action drop
set firewall ipv4 name IOT-WWAN rule 10 action accept
set firewall ipv4 name IOT-WWAN rule 10 state established
set firewall ipv4 name IOT-WWAN rule 10 state related
set firewall ipv4 name IOT-WWAN rule 20 action accept
set firewall ipv4 name IOT-WWAN rule 20 destination port 80,443
set firewall ipv4 name IOT-WWAN rule 20 protocol tcp
set firewall ipv4 name IOT-WWAN rule 30 action accept
set firewall ipv4 name IOT-WWAN rule 30 destination port 1883,8883
set firewall ipv4 name IOT-WWAN rule 30 protocol tcp
set firewall ipv4 name IOT-WWAN rule 30 description 'MQTT'
set firewall zone IOT interface eth1
set firewall zone WWAN interface wwan0
set firewall zone IOT from WWAN firewall name WWAN-IOT
set firewall zone WWAN from IOT firewall name IOT-WWANScenario 4: VPN over LTE
Connecting to a corporate network via VPN over LTE:
# WWAN interface
set interfaces wwan wwan0 apn 'internet.megafon.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'MegaFon LTE for VPN'
# WireGuard VPN interface
set interfaces wireguard wg0 address '10.10.10.2/24'
set interfaces wireguard wg0 description 'Corporate VPN'
set interfaces wireguard wg0 peer HQ address 'vpn.company.ru'
set interfaces wireguard wg0 peer HQ allowed-ips '0.0.0.0/0'
set interfaces wireguard wg0 peer HQ port 51820
set interfaces wireguard wg0 peer HQ public-key '<server-public-key>'
set interfaces wireguard wg0 port 51820
set interfaces wireguard wg0 private-key '<client-private-key>'
# Local network
set interfaces ethernet eth1 address '192.168.20.1/24'
set interfaces ethernet eth1 description 'Local LAN'
# Route all traffic through the VPN
set protocols static route 0.0.0.0/0 interface wg0
# NAT for internet access (if allowed by policy)
set nat source rule 300 outbound-interface name 'wg0'
set nat source rule 300 source address '192.168.20.0/24'
set nat source rule 300 translation address masquerade
# Firewall rules
set firewall zone LAN interface eth1
set firewall zone VPN interface wg0
set firewall zone WWAN interface wwan0
set firewall zone LAN default-action accept
set firewall zone VPN default-action accept
set firewall zone WWAN default-action dropScenario 5: Multi-WAN with Balancing Across Multiple Operators
Using two LTE modems from different operators:
# First modem (MTS)
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 description 'MTS LTE'
# Second modem (Beeline)
set interfaces wwan wwan1 apn 'internet.beeline.ru'
set interfaces wwan wwan1 address dhcp
set interfaces wwan wwan1 description 'Beeline LTE'
# Local network
set interfaces ethernet eth1 address '192.168.30.1/24'
# Load balancing
set load-balancing wan interface-health wwan0 nexthop dhcp
set load-balancing wan interface-health wwan0 test 10 type ping
set load-balancing wan interface-health wwan0 test 10 target 8.8.8.8
set load-balancing wan interface-health wwan1 nexthop dhcp
set load-balancing wan interface-health wwan1 test 10 type ping
set load-balancing wan interface-health wwan1 test 10 target 8.8.4.4
# Even load distribution
set load-balancing wan rule 1 inbound-interface eth1
set load-balancing wan rule 1 interface wwan0 weight 50
set load-balancing wan rule 1 interface wwan1 weight 50
set load-balancing wan rule 1 protocol all
# NAT for both interfaces
set nat source rule 400 outbound-interface name 'wwan0'
set nat source rule 400 source address '192.168.30.0/24'
set nat source rule 400 translation address masquerade
set nat source rule 410 outbound-interface name 'wwan1'
set nat source rule 410 source address '192.168.30.0/24'
set nat source rule 410 translation address masqueradeTroubleshooting
Problem: Modem Not Detected
Symptoms: The wwan0 interface does not appear in the system
Solution:
- Check the physical connection of the modem
- Check whether the modem is detected by the system:
lsusb
lspci | grep -i wireless- Check that the drivers are loaded:
lsmod | grep -i qmi
lsmod | grep -i cdc- Check the devices:
ls -la /dev/cdc-wdm*
ls -la /dev/ttyUSB*Problem: Modem Detected but Not Connecting
Symptoms: The interface is present but does not obtain an IP address
Solution:
- Verify that the APN is correct:
show interfaces wwan wwan0- Check the signal strength:
show interfaces wwan wwan0 signalIf the signal strength is below -100 dBm, try improving the antenna placement.
- Check network registration:
show interfaces wwan wwan0 network- Restart the interface:
sudo ip link set wwan0 down
sudo ip link set wwan0 up- Check the logs:
show log | match wwan
journalctl -u NetworkManager | grep wwanProblem: Low Connection Speed
Symptoms: The speed is significantly lower than expected
Solution:
- Check the signal strength and quality:
show interfaces wwan wwan0 signalOptimal values:
- RSSI: above -70 dBm
- RSRQ: above -10 dB
- RSRP: above -80 dBm
- SNR: above 10 dB
- Check the technology and band in use:
show interfaces wwan wwan0 network- Check the MTU:
set interfaces wwan wwan0 mtu 1430
commitUse an external antenna with a higher gain
Check the operator’s network load:
# Speed test
sudo apt install speedtest-cli
speedtest-cli --source wwan0Problem: Frequent Connection Drops
Symptoms: The connection periodically drops and reconnects
Solution:
- Check the signal stability:
# Real-time monitoring
watch -n 1 'sudo qmicli -d /dev/cdc-wdm0 --nas-get-signal-strength'- Check the modem temperature (overheating):
sensors | grep -i temp- Add monitoring and automatic restart:
# Monitoring script (/config/scripts/wwan-monitor.sh)
#!/bin/bash
if ! ping -I wwan0 -c 3 8.8.8.8 > /dev/null 2>&1; then
logger "WWAN connection lost, restarting interface"
ip link set wwan0 down
sleep 5
ip link set wwan0 up
fi- Add it to cron:
set system task-scheduler task wwan-monitor interval 5m
set system task-scheduler task wwan-monitor executable path /config/scripts/wwan-monitor.shProblem: DHCP Does Not Obtain an IP Address
Symptoms: The interface is up but has no IP address
Solution:
- Check the status of the DHCP client:
sudo journalctl -u dhclient | grep wwan0- Try renewing the DHCP lease:
sudo dhclient -r wwan0
sudo dhclient wwan0- Check the DHCP settings:
show interfaces wwan wwan0 dhcp-options- Use a static IP if the operator provides one:
delete interfaces wwan wwan0 address dhcp
set interfaces wwan wwan0 address '10.xxx.xxx.xxx/32'
commitProblem: DNS Does Not Work over WWAN
Symptoms: Ping by IP works, but domain names do not resolve
Solution:
- Check the DNS servers you received:
show dns forwarding
cat /etc/resolv.conf- Configure static DNS:
set system name-server 8.8.8.8
set system name-server 8.8.4.4
commit- Test DNS through a specific server:
nslookup google.com 8.8.8.8Problem: SIM Card Not Recognized
Symptoms: The modem works but does not detect the SIM card
Solution:
- Check the SIM card status:
sudo qmicli -d /dev/cdc-wdm0 --uim-get-card-status- Check the PIN code (if set):
sudo qmicli -d /dev/cdc-wdm0 --uim-verify-pin=PIN,<pin-code>Check the physical condition of the SIM card (contacts, size)
Try a different SIM card to rule out modem problems
Problem: Modem Works Only After a Reboot
Symptoms: After applying the configuration the modem does not work and a reboot is required
Solution:
- Add a delay during initialization:
# In /config/scripts/vyos-postconfig-bootup.script
sleep 30- Check the module load order:
lsmod | grep qmi
sudo modprobe -r qmi_wwan
sudo modprobe qmi_wwan- Update the modem firmware
Problem: High Ping over LTE
Symptoms: The latency is very high
Solution:
- Check the baseline ping to the operator’s gateway:
ping -I wwan0 <operator-gateway>LTE has an inherent latency of 20-50ms, which is normal
Check the channel load:
# Usage monitoring
watch -n 1 'ifstat -i wwan0'- Use QoS to prioritize traffic:
set traffic-policy shaper WWAN-QOS bandwidth '50mbit'
set traffic-policy shaper WWAN-QOS class 10 match VOIP ip protocol udp
set traffic-policy shaper WWAN-QOS class 10 match VOIP ip destination port 5060
set traffic-policy shaper WWAN-QOS class 10 bandwidth '10mbit'
set traffic-policy shaper WWAN-QOS class 10 priority 1
set interfaces wwan wwan0 traffic-policy out WWAN-QOSMonitoring and Logging
Configuring syslog for WWAN Events
set system syslog global facility local7 level debug
set system syslog file wwan facility local7 level debugMonitoring Traffic Usage
# Viewing interface statistics
show interfaces wwan wwan0 statistics
# Real-time monitoring
monitor interfaces wwan wwan0 trafficSNMP Monitoring
set service snmp community public authorization ro
set service snmp community public network 192.168.1.0/24
set service snmp listen-address 192.168.1.1Monitoring the WWAN interface via SNMP:
snmpwalk -v2c -c public 192.168.1.1 IF-MIB::ifDescr
snmpwalk -v2c -c public 192.168.1.1 IF-MIB::ifInOctetsPerformance Optimization
TCP Optimization for High Latency
set system sysctl parameter net.ipv4.tcp_congestion_control value 'bbr'
set system sysctl parameter net.core.rmem_max value '134217728'
set system sysctl parameter net.core.wmem_max value '134217728'
set system sysctl parameter net.ipv4.tcp_rmem value '4096 87380 67108864'
set system sysctl parameter net.ipv4.tcp_wmem value '4096 65536 67108864'Configuring the MTU for LTE
The optimal MTU for LTE is usually 1430 bytes:
set interfaces wwan wwan0 mtu 1430Traffic Shaping
Limiting outbound traffic to prevent congestion:
set traffic-policy shaper WWAN-OUT bandwidth '40mbit'
set traffic-policy shaper WWAN-OUT default bandwidth '40mbit'
set traffic-policy shaper WWAN-OUT default ceiling '40mbit'
set traffic-policy shaper WWAN-OUT default priority 7
set interfaces wwan wwan0 traffic-policy out WWAN-OUTSecurity
WWAN Security Recommendations
- Always use a firewall on the WWAN interface
- Disable unnecessary services on the WAN interface
- Use a VPN to encrypt traffic
- Monitor for suspicious activity
- Regularly update the modem firmware
- Use strong passwords for VyOS
- Restrict access to management from the WWAN interface
Disabling Management from WWAN
set firewall ipv4 name WWAN-LOCAL rule 100 action drop
set firewall ipv4 name WWAN-LOCAL rule 100 destination port 22,80,443
set firewall ipv4 name WWAN-LOCAL rule 100 protocol tcp
set firewall ipv4 name WWAN-LOCAL rule 100 description 'Block management from WWAN'Integration with Cloud Services
Yandex Cloud
WWAN interfaces can be used in Yandex Cloud for backup communication channels between the cloud and on-premise infrastructure.
# Configuration for a VPN tunnel to Yandex Cloud
set interfaces wwan wwan0 apn 'internet.mts.ru'
set interfaces wwan wwan0 address dhcp
# WireGuard VPN to Yandex Cloud
set interfaces wireguard wg0 address '10.128.0.2/24'
set interfaces wireguard wg0 peer YC address '<yandex-cloud-public-ip>'
set interfaces wireguard wg0 peer YC allowed-ips '10.128.0.0/24'
set interfaces wireguard wg0 peer YC port 51820
set interfaces wireguard wg0 peer YC public-key '<cloud-public-key>'
# Routing to the cloud over the VPN
set protocols static route 10.128.0.0/16 interface wg0Automation Scripts
Automatic SIM Card Switching
A script to switch between SIM cards when connection problems occur:
#!/bin/vbash
# /config/scripts/sim-switch.sh
source /opt/vyatta/etc/functions/script-template
# Connection check
if ! ping -I wwan0 -c 3 8.8.8.8 > /dev/null 2>&1; then
logger "WWAN: Primary SIM failed, switching to secondary"
# SIM switching (command depends on the modem)
sudo qmicli -d /dev/cdc-wdm0 --uim-switch-slot=2
sleep 10
# Restarting the interface
ip link set wwan0 down
sleep 5
ip link set wwan0 up
logger "WWAN: Switched to secondary SIM"
fiMonitoring Traffic Limits
#!/bin/vbash
# /config/scripts/data-limit-monitor.sh
source /opt/vyatta/etc/functions/script-template
LIMIT=10737418240 # 10 GB in bytes
CURRENT=$(cat /sys/class/net/wwan0/statistics/rx_bytes)
TX=$(cat /sys/class/net/wwan0/statistics/tx_bytes)
TOTAL=$((CURRENT + TX))
if [ $TOTAL -gt $LIMIT ]; then
logger "WWAN: Data limit exceeded ($TOTAL bytes), shutting down interface"
configure
set interfaces wwan wwan0 disable
commit
exit
fiAdditional Resources
Official Documentation
Useful Linux Commands for Debugging
# ModemManager
mmcli -L # List of modems
mmcli -m 0 # Modem information
mmcli -m 0 --simple-status # Simple status
# USB device information
lsusb -t # USB device tree
lsusb -v -d <vendor>:<product> # Detailed information
# Checking drivers
dmesg | grep -i usb
dmesg | grep -i qmi
dmesg | grep -i cdcSpeed Testing
# Installing speedtest-cli
sudo apt install speedtest-cli
# Speed test through the WWAN interface
speedtest-cli --source wwan0
# iPerf testing
iperf3 -c <server> -B <wwan0-ip>Conclusion
WWAN interfaces in VyOS provide flexible capabilities for building reliable network solutions using cellular networks. Proper configuration, monitoring, and maintenance ensure stable operation both as a primary and as a backup communication channel.
Key advantages of using WWAN in VyOS:
- Fast deployment without the need for wired links
- High reliability with support for automatic failover
- Flexible integration with existing network infrastructure
- The ability to use many Russian and international operators
- Full integration with firewall, VPN, NAT, and other VyOS features
When planning to use WWAN, consider:
- Coverage and signal quality at the installation site
- Operators’ pricing plans and traffic limits
- Speed and latency requirements for your applications
- The need for redundancy and failover mechanisms
- Data security and encryption considerations