Wireless Bridge

From DD-WRT Wiki

Revision as of 21:24, 20 March 2008 by Googleg (Talk | contribs)
Jump to: navigation, search
Wireless Bridging is used to connect two LAN segments via a wireless link. The two segments will be in the same subnet and look like two Ethernet switches connected by a cable to all computers on the subnet. Since the computers are on the same subnet, broadcasts will reach all machines, allowing DHCP clients in one segment to get their addresses from a DHCP server in a different segment. You could use a Wireless Bridge to transparently connect computer(s) in one room to computer(s) in a different room when you could not, or did not want to run an Ethernet cable between the rooms. Contrast this with Client Mode Wireless, where the local wireless device running DD-WRT connects to the remote router as a client, creating two separate subnets. Since the computers within the different subnets cannot see each other directly, this requires the enabling of NAT between the wireless and the wired ports, and setting up port forwarding for the computers behind the local wireless device. Segments connected via Client Mode Wireless cannot share a DHCP server.

In the case in which we are interested, a wireless device running DD-WRT such as a WRT54G is configured as a Wireless Bridge between a remote wireless router (of any make/brand) and the Ethernet ports on the WRT54G.



(Editorial Note: These instructions are incomplete and misleading. Please see A Practical Example further down this page for a better working, better documented procedure.)

A very simple step-by-step description to connect a WRT54G running DD-WRTV23:

To enable Brige-Mode between two WRT54G, one WRT54G has to be in AP-Mode in Wireless/Basic Setup. The other one is joining the first WRT54G as "Client-Bridged"

  1. Add WAN MAC-Address of WRT54G to your MAC filter list on your base station. (This ASSUMES you ARE using Wireless MAC Address Filtering on your base station! If you are NOT using, skip this step!)
  2. Connect to your non-base-station WRT54G (normally by wire which should act as client bridge.
  3. Enable Wireless Security (in Wireless/Wireless Security) as used, e.g. WEP and configure it as used in your local network.
  4. In Wireless/Basic Settings choose "Client-Bridged" as Wireless Mode and set SSID, Wireless channel and Network Mode can be set to same values as your Base Station, normally Auto / Mixed.

That's all. On next wired connect to your WRT54G you should get an IP address from your network.

If you want to configure your new WRT54G bridge again, set a static IP address of 192.168.1.x network to your client and you can reach the WRT54G as by wire.

Important: If you want to use WPA encryption on your client bridge, make sure your key is no longer than 63 characters, even if you are using a HEX key. Not all IEEE 802.11 devices support long keys; older ones, in particular, are limited to short keys. In order for all devices in your network to communicate, they must not use a key longer than the least capable device in the network supports.


I personally found all of these instructions confusing, so I've compiled an exact list of what I did to get the "Client Bridge" working with the "V23 SP1" version of the firmware.

My motivation: I wanted to get my XBox online (and on-LAN) from another room, without running Ethernet to it. WDS was out of the question unfortunately because one of my routers was a late-model WRT54G and as such wasn't (at the time) easily modified. I had an extra WRT54G lying around that could run DD-WRT. Alternatively I could have bought a proper Linksys or Microsoft solution to connect the XBox to the existing WiFi, but what's the fun in that?

My network is as such:

  • Primary Router (Internet Connection): WRT54G V5 — stock Linksys firmware —
  • Secondary Router (For the Bridge): WRT54G V3 — DD-WRT V23 SP1 Firmware — — which I changed to in my setup

(I'm guessing that the Primary Router could be any make and model of wireless router as we're not doing anything to it!)

Slambert71 adds: I set this up today using a Linksys WRT54G V.3 with DD-WRT V23 SP2 firmware as the secondary, and a D-Link DI-624 with factory firmware as the primary and it works great.

My Primary Router has 128bit WEP Encryption enabled. It does NOT have Wireless MAC Address Filtering enabled. We will assume you want your Secondary Router to become

Mailmanx adds: It worked successful for me with 2 WRT54GL Routers (Router with original firmware, Client Bridge with DD-WRT v23 SP2). WPA-PSK with AES enabled AND MAC Address Filtering (Be sure to set the the correct MAC address! The router provides a LAN, WAN and the needed Wireless MAC address of the Bridge). The MAC addresse can be found on the Status->Sysinfo tab of the DD-WRT webinterface.

I have my Secondary Router in another room, connected only to my laptop via an Ethernet cable to Port 1. The laptop has an IP from the Secondary Router's DHCP to begin with. Neither the laptop nor the Secondary Router are connected to anything but each other. I will be doing all of my setup from this laptop. If you have problems with DHCP or losing your IP address in the midst of these instructions, you may need to statically assign an IP to your Ethernet card. (I was running Knoppix Linux on the laptop and I didn't have to do that, but YMMV!)


  1. Log into the Secondary Router. (We will only be altering the Secondary Router!)
  2. Administration Tab — Factory Defaults Subtab
    1. Restore Factory Defaults: Yes
    2. Click "Save Settings" — triggers reboot. (DaveK - I'm using V24 with a Buffalo WHR-G125 router and had to click "Apply" after "Save" in order to trigger the reboot)
    3. Router's IP will now be if it wasn't already.
      This was a very important step. I have run this process 3 times now as a trial, and the instructions are written assuming you have a "clean" router.
  3. Setup Tab — Basic Setup Subtab
    1. Connection Type: Disable
    2. STP: Disable
    3. Local IP: (it was initially (Appears that it must/should be a valid IP in your Wireless Subnet)
    4. Assign WAN Port To Switch: Checked
    5. DHCP Server: Disable
    6. Click "Save Settings" — triggers reboot.
      I had an error along the lines of "Can't connect to" — This is because it's now — close and restart the browser to avoid authentification problems and connect to the new IP address and retype your username and password.
      (Aside from changing the local IP address, the above steps are unnecessary because putting the router in client-bridged mode takes care of these settings automatically) NOTE: If you change the IP and disable DHCP and then disconnect the network for some reason you will need to set a static IP in the same subnet on your windows TCP/IP settings in order to connect to the router again at the new IP
  4. Security Tab — Firewall Subtab
    1. SPI Firewall: Disable
    2. Click "Save Settings"
  5. Wireless Tab — Basic Settings Subtab
    1. Wireless Mode: Client Bridge
    2. Wireless Network Mode: Match your primary router.
    3. Wireless Network Name (SSID): Match your primary router. (case matters!)
    4. Wireless Channel is not relevant in Client Bridge mode.
    5. Wireless SSID Broadcast is not relevant in Client Bridge mode.
    6. Click "Save Settings". The router will now be in Client Bridge mode.
  6. Wireless Tab — Wireless Security Subtab
    1. Security Mode: Match your primary router, I used WEP (I have not tried anything but 128bit WEP!)
      note: WPA-PSK works as well -guyonphone;
      note: WPA-PSK even works if original router is WPA2 mixed -mcoope3;
      note: v2.3_sp2 in client bridge mode currently doesn't support WPA2-PSK, but only WPA2-PSK mixed mode, so the AP has to be set to mixed and not WPA2-only mode (it can be either AES or TKIP).-zevnik
      note: To put it simple, WPA2 doesn't work in Bridge Mode currently (dd-wrt v23 sp2)-teekay
      note: WPA Personal works great with an Apple Airport Extreme wireless router too. Select "WPA/WPA2 Personal" on the Extreme and "WPA Personal (TKIP)" on the bridge. Enter the same shared key on both of course. -gsosa70;
    2. Encryption: Match your primary router.
    3. Key 1: Match your primary router.
    4. Click "Save Settings"
  7. Wireless Tab — Advanced Settings Subtab
    1. Authentication Type: Shared Key
    2. Click "Save Settings"
      This seems like a VERY important step — it DID NOT work until I did this!
      note: worked for me on auto, when using WEP -cheesetoast.
      note: it worked for me as described when using WEP, but it didn't work using WPA-PSK - neither TKIP, AES, TKIP+AES. In any of these modes, after successful Join, the MAC of the primary router didn't appear on the Status screen and the "Transmitted (TX)" error counter in Status-->Wireless-->Wireless Packet Info was constantly incremented every few seconds. It finally connected and worked OK only when I changed "Shared Key" to "Auto" on both the primary and the secondary router. Just as a side note, it reported a successful join even if the connection was obviously broken (e.g. WEP on the primary router and WPA on the secondary). Using dd-wrt v23 sp2 vpn on the primary router and v23 sp2 voip on the secondary one. vbrindus, 2008-01-05
  8. Status Tab — Wireless Subtab
    1. Click Site Survey and join the appropriate wireless network. Access Point table should show the MAC address of your Primary Router, along with signal strength. (SSID Broadcast MUST be enabled on your primary router) At this point it was working 100% for me.
      If that worked, then:
  9. Administration Tab — Backup Subtab
    1. Click "Backup"
      (SAVE this config before doing anything else to your router, just in case!)

I've done this procedure three times to test it, and I've reset the router to Factory Defaults every time. It may not be the optimal way of accomplishing the task, but it did work for me and I was able to repeat it with the same results each time!

lrp note: I did setup the wireless security mode to "disabled" in the "Wireless Tab — Wireless Security Subtab", I had NOTHING to change in the "Wireless Tab — Advanced Settings Subtab" for this setup to work (DD-WRT v23 SP2 (09/15/06) std). lrp

I seconded these settings. Tried it on 2 WRT54G with v23SP2 and they work.

I third these settings. I succesfully linked a Dlink DI-524 (primary, not dd-wrt) and a Buffalo WHR-G125 (secondary, with dd-wrt). The secret here is that you need to change the firewall settings in the Dlink to allow all traffic from the source (ie to all destinations (in the Dlink webbased router setup under advanced-->firewall) -dapple

These settings verified working on a WRT54Gv8. I couldn't ping my gateway before (on the far end router). I'm curious if a factory reset is what did it. Setting the auth type between shared and auto seems to make no difference. --IamBren 07:40, 28 December 2007 (CET)

If you have an apostrophe in your SSID you will not be able to click the "Join" button on the "Site Survey" page. I also needed to switch from gateway to router in the Setup->Advanced Routing tab before it finally connected (DD-WRT v23 SP2 (09/15/06) std).

These instructions were perfect! I have a Linksys WRT54GL as the primary and a Motorola WR850G v3 as the secondary both with DD-WRT v24 Beta (05/02/07) std. I can now access both routers' configuration and files behind both routers. The only addition to the instructions is that you need to disconnect the cable for 10 seconds after the last step and reconnect to fully access all features. - PeterE 8 March 2008

This worked perfect for me with a Motorola/Netopia 3347W as primary router. However for some reason I had to force the wireless mode to G only on the WRT (I kept "mixed mode" on the Netopia). WPA is working fine but WPA2 support would be nice. Also DHCP messages do not reach the primary router. Using DD-WRT v24RC6.2 - Googleg 29/Mar/2008

Accessing Both Routers?

With this setup, I have full access to both routers — which runs contrary to a lot of the notes concerning Client Bridge mode. One router is, and the other is I can access both from either side of the bridge. There is no need to change any settings or IP addresses or the like with this setup in order to do so! Note: if you want to be able to access the Client Bridge router externally, you need to set its gateway address to point to the address of the router that has external access ( in this example).

Unmatched Routers?

If you don't have a matched pair of routers like I did, I would recommend changing step 3.3 from to an unused IP that matches your Primary Router. For example, if your primary router was set to, set this to (assuming is not already in use!). This way everything should be on the same subnet with unique IP addresses — and both routers should be accessible for configuration from anywhere on your network.


I was unaware at the time of writing this of any easy way of flashing a WRT54G V5 (and above) router with DD-WRT. This is not the case anymore, but there may still be lots of reasons to go with this setup rather than WDS. While WDS allows both ends of the connection to accept wireless clients, there is less bandwidth to go around, and there could be more latency. I'm guessing that this setup is still the best way to attach Ethernet devices to a wireless network with DD-WRT.

LRP note: I used this setup because I could not use WDS anymore (My initial setup was WAG54G-WDS-WRT54Gs ... I had to replace my broken WAG54G by a WAG200G, my setting became then: WAG200G-wirelessbridge-WRT54GS). At first, I attributed the speed increase to the ADSL2 capability ... I was really amazed when I could reduce a file transfer in between a wired machine behind the WRT54GS and a wired machine behind the WAG200G from about 55 minutes to 26 minutes (more than twice as fast). The only difference was the absence of WDS and the updated firmware. LRP

BrainSlayer Forum Answer [1] (edited to enhance): Client Bridge mode will only work well with just one connected computer on the far end, due a limitation in the 802.11 protocol. If you want to bridge a full LAN you must use WDS. The problem is that the 802.11 protocol just supports one MAC address, but in a LAN there is the possibility for more than one MAC address. It may cause ARP table problems, if you connect more than one computer on the far end of a Client Bridge mode setup. Use standard AP mode, if using WDS.

bobn: Multiple devices on the wireless bridge seem to work fine, including using DHCP to the 'server' AP. Although multiple devices on the client bridge (wireless bridge) appear to have the same MAC address in the arp tables of devices on the 'server' AP, something in the wireless bridge translates that MAC address on return traffic back to the correct one for a given device's IP address behind the bridge. (I suspect that there is enough of the routing function still turned on in the client bridge mode to maintain an arp table local to the client bridge and make the translations.) Most protocols (ICMP, UDP, TCP) seem to work fine for multiple devices on the bridge, based on some quick testing. I would not want to count on multiple devices using non-IP protocols, and would be suspicious of things using special MAC addresses such as multicast addresses (eg OSPF routers, multicast apps).

V23 Firmware

In the V23 firmware, you can set up the bridge from the Wireless->Wireless Mode menu. Just select "Client Bridged". This will automatically turn off DHCP. Note that only the Network Mode (b/g) and SSID settings are used in Client Bridged mode.

See notes on a 2.3 attempt at Client Bridged with a Belkin A/G AP in Bridge Install

I am also linking these in Client Bridged

New to Client Bridging?

Here's some extra information about client bridging and some, perhaps unexpected, side effects. (If you're a wireless networking wizard, you'll know this already.)

When you've switched to Client Bridge mode you won't be accessing the remote AP until your IP changes unless your box and the remote network are on the same subnet. For example, say you have:

Linksys box IP:
Your computer:
Remote network gateway:

Once you've made the configuration changes in your router, you'll need to get a new address to access the remote network. A simple way to do this with most computers is to unplug the network cable, count to 10, and plug it in again. When the cable is plugged in again, it will get a new lease, but this time from the remote computer. For example, it will get an address in the 10.0.0.x range, e.g., Now you'll be able to use the Internet over the wireless link as you expect.

However, you won't be able to access your Linksys to administer it. The solution is to turn off DHCP and use a static IP (e.g.,, or, alternatively, assign an address for your Linksys from the remote subnet (e.g., Be careful, however, not to pick an address already in use.

(Editorial Note: According to the introduction, "Wireless Bridging is used to connect two LAN segments via a wireless link. The two segments will be in the same subnet and looks like two Ethernet switches connected by a cable, to all computers on the subnet." From this info we can gather that you should be assigning an unused, unique IP address to your bridge router from your remote subnet, otherwise your bridging router will become inaccessible, and that's not optimal! Please see A Practical Example for a fully documented example of making this work.)


So I just bought a WRT54GL Ver 1.1 and I'm new. Anyhow, so I was trying and trying for two days straight to get Client-Bridge setup to work in V23sp2, followed the instructions as set out above in the practical example. However a lot of people have posted that WPA-Personal Security Protocol has not been able to work, not true, because I've done it by God's amazing grace! So here's the HOWTO
1. Follow the above practical example
2. Set Wireless Security > Security as WPA-Shared Key > TKIP
3. Enter the shared key ID
4. Go to Status > Wireless > Site Survey > Should probably find your 1st router and then click join, the next thing you should see is that its MAC address will appear on the Wireless AP at the bottom of the Wireless Status page.
5. Unplug your Ethernet connection from your PC and wait 20 seconds
6. Undo the TCP/IP setup to connect to the router (assuming you set the IP manually, you need to undo this)
7. Plug in the Ethernet connection and let it refresh! It should work!


Do not choose mixed mode (WPA+WPA2) on the Client-Bridge: the AP and the bridge would not be able to auto-negociate an encryption scheme, the bridge would not be able to connect to the AP.

Pick up one scheme (WPA or WPA2) on the bridge side: both schemes work nice - as long as the AP is configured for -, but you cannot let the bridge to make the decision.

MAC Filtering

For those of you who have enabled MAC filtering on your Primary router, you need to add the WLAN MAC address of your Secondary router to the permitted MAC filter list of the Primary router. This is different than the MAC address printed on the bottom of the case, you can find it by going to Status->Wireless and the top line will list the internal MAC address. Of course, you will want to add the MAC filter list to the Secondary router. This should be setup prior configuring your WPA, WPA2, etc. settings otherwise you will spend some time pondering why the bridge isn't working.


Wireless Bridging Forum Post by kkennedy070790