Raspi 4 Wifi or Network Problem with adding Matter devices

Hi all

I’ve set up my home-assistant in a podman setup with docker images for home-assistant, openthread/border-router and matter-js-server.
I run them all with a bridge set up with eth0 and wlan0 from the Raspi 4. The containers connect to the bridge-network with there own ip addresses. The bridge and the containers are multicast enabled.
This so far works well.
To the wifi I also have connected a Xiaomi Air Purifyer and a iRobot vaccum cleaner.

The problem starts when I try to pair Matter devices. I have one light bulb using Thread and another one using Wifi.

Having the mobile (Poco F5Pro) with the companion app connected to the bridged network (its just a hotspot) I can start the adding of new devices for matter.

It then goes for the Wifi-Bulb:

  • Searching for device
  • Connecting to device
  • Generating Matter credentials
  • Uncertified device → I click ‘Set up anyway’
  • Connecting to device
  • Checking network connectivity to upc…
  • Cant connect device to upc …

Using the Thread-Bulb it is nearly the same

  • Bulb starts green
  • Searching for device
  • Connecting to device
  • Generating Matter credentials
  • Uncertified device → I click ‘Set up anyway’
  • Connecting to device
  • Checking connectivity to Thread network OpenThread..
  • Bulb instantly changes to blue (meaning connecting to Thread network) / App still says Checking connectivity …
  • Can’t reach device
    Make sure that your phone is connected to WiFi

In both cases to me it seems to be a problem with Wi-Fi. The phone is connected to the exact Wi-Fi network.

Can anyone help with setting up the Wi-Fi correctly so it can be used with Matter and for pairing?

  • Wi-Fi is Wi-Fi 4 with WPA/WPA2-Personal
  • This is the details:
pi@pi-iot0:~ $ sudo nmcli con show hotspot
connection.id:                          hotspot
connection.uuid:                        ab128352-34df-44a0-923f-e1bed877662b
connection.stable-id:                   --
connection.type:                        802-11-wireless
connection.interface-name:              wlan0
connection.autoconnect:                 yes
connection.autoconnect-priority:        0
connection.autoconnect-retries:         -1 (default)
connection.multi-connect:               0 (default)
connection.auth-retries:                -1
connection.timestamp:                   1783798144
connection.permissions:                 --
connection.zone:                        --
connection.controller:                  bridge0
connection.master:                      bridge0
connection.slave-type:                  bridge
connection.port-type:                   bridge
connection.autoconnect-slaves:          -1 (default)
connection.autoconnect-ports:           -1 (default)
connection.down-on-poweroff:            -1 (default)
connection.secondaries:                 --
connection.gateway-ping-timeout:        0
connection.ip-ping-timeout:             0
connection.ip-ping-addresses:           --
connection.ip-ping-addresses-require-all:-1 (default)
connection.metered:                     unknown
connection.lldp:                        default
connection.mdns:                        -1 (default)
connection.llmnr:                       -1 (default)
connection.dns-over-tls:                -1 (default)
connection.mptcp-flags:                 0x0 (default)
connection.wait-device-timeout:         -1
connection.wait-activation-delay:       -1
802-11-wireless.ssid:                   upcf3c9221
802-11-wireless.mode:                   ap
802-11-wireless.band:                   bg
802-11-wireless.channel:                6
802-11-wireless.bssid:                  --
802-11-wireless.mac-address:            --
802-11-wireless.cloned-mac-address:     --
802-11-wireless.generate-mac-address-mask:--
802-11-wireless.mac-address-denylist:   --
802-11-wireless.mac-address-randomization:default
802-11-wireless.mtu:                    auto
802-11-wireless.seen-bssids:            DC:A6:32:22:EB:B6
802-11-wireless.hidden:                 no
802-11-wireless.powersave:              0 (default)
802-11-wireless.wake-on-wlan:           0x1 (default)
802-11-wireless.ap-isolation:           -1 (default)
802-11-wireless.channel-width:          0 (auto)
802-11-wireless-security.key-mgmt:      wpa-psk
802-11-wireless-security.wep-tx-keyidx: 0
802-11-wireless-security.auth-alg:      open
802-11-wireless-security.proto:         --
802-11-wireless-security.pairwise:      --
802-11-wireless-security.group:         --
802-11-wireless-security.pmf:           1 (disable)
802-11-wireless-security.leap-username: --
802-11-wireless-security.wep-key0:      <hidden>
802-11-wireless-security.wep-key1:      <hidden>
802-11-wireless-security.wep-key2:      <hidden>
802-11-wireless-security.wep-key3:      <hidden>
802-11-wireless-security.wep-key-flags: 0 (none)
802-11-wireless-security.wep-key-type:  unknown
802-11-wireless-security.psk:           <hidden>
802-11-wireless-security.psk-flags:     0 (none)
802-11-wireless-security.leap-password: <hidden>
802-11-wireless-security.leap-password-flags:0 (none)
802-11-wireless-security.wps-method:    0x0 (default)
802-11-wireless-security.fils:          0 (default)
bridge-port.priority:                   32
bridge-port.path-cost:                  100
bridge-port.hairpin-mode:               no
bridge-port.vlans:                      --
GENERAL.NAME:                           hotspot
GENERAL.UUID:                           ab128352-34df-44a0-923f-e1bed877662b
GENERAL.DEVICES:                        wlan0
GENERAL.IP-IFACE:                       wlan0
GENERAL.STATE:                          activated
GENERAL.DEFAULT:                        no
GENERAL.DEFAULT6:                       no
GENERAL.SPEC-OBJECT:                    /org/freedesktop/NetworkManager/AccessPoint/11
GENERAL.VPN:                            no
GENERAL.DBUS-PATH:                      /org/freedesktop/NetworkManager/ActiveConnection/3
GENERAL.CON-PATH:                       /org/freedesktop/NetworkManager/Settings/4
GENERAL.ZONE:                           --
GENERAL.MASTER-PATH:                    /org/freedesktop/NetworkManager/Devices/4
IP4.GATEWAY:                            --
IP6.GATEWAY:                            --

Any help appreciated.

I got a step further for the WiFi Bulb.

I changed a few settings for the hotspot WLAN connection like enabling WPA3, disabling WPA and I now got one step further … after Checking network connectivity to upc… I now got a ‘Connecting device to Home Assistant..’. Then I again got a 'Something went wrong.
Another try with the Thread bulb gave the same outcome as described above.

Doing an avahi-browse on my Raspberry Pi I see additional entries. :slight_smile:

Before the pairing attempt:

pi@pi-iot0:~ $ avahi-browse -a
+ bridge0 IPv6 Home                                          _home-assistant._tcp local
+ bridge0 IPv4 Home                                          _home-assistant._tcp local
+ bridge0 IPv6 75D80F67D024A2F2-000000000001B669             _matter._tcp         local
+ bridge0 IPv4 75D80F67D024A2F2-000000000001B669             _matter._tcp         local
+ bridge0 IPv6 otTREL135232d590a96790                        _trel._udp           local
+ bridge0 IPv4 otTREL135232d590a96790                        _trel._udp           local
+ bridge0 IPv6 OpenThread BR (unspecified vendor) 135232d590a96790 _meshcop._udp        local
+ bridge0 IPv4 OpenThread BR (unspecified vendor) 135232d590a96790 _meshcop._udp        local
+ bridge0 IPv6 pi-iot0 [06:50:e4:54:b4:d9]                   Workstation          local
+ bridge0 IPv4 pi-iot0 [06:50:e4:54:b4:d9]                   Workstation          local

And after I see additional entries:

+ bridge0 IPv6 ACDF068E281FCA5D-00B157DAE7CA6F44             _matter._tcp         local
+ bridge0 IPv6 ACDF068E281FCA5D-987EA7E43B0E17C2             _matter._tcp         local
+ bridge0 IPv4 ACDF068E281FCA5D-00B157DAE7CA6F44             _matter._tcp         local
+ bridge0 IPv4 ACDF068E281FCA5D-987EA7E43B0E17C2             _matter._tcp         local

But still not successful after all.

I’ll admit to most of this being over my head, but what exactly are you trying to accomplish by creating a separate wifi network on HA & connecting your devices to that?

Devices connect to your wifi router (to which HA is presumably already connected via ethernet). You don’t need to create a separate wifi network inside HA to connect wifi or thread devices. All you need to do is to make sure that your router has Ipv6 enabled.

Thank you for the answer.

Actually the router’s WLANs are not an option. I have a zoned network. What I want to accomplich is the following:

  • use a Raspberry Pi4 for my new Smarthome Device
  • migrating the HomematicIP from the Ccu3 to an openCCU in a container
  • add Matter with WiFi and Thread for additional devices
  • add other home devices like a iRobot cleaner and Xiaomi Air Purifyier to the Raspberry Pi with their apps using the devices WLAN (hope to get them into HA later)

The Raspi is set up like most of my machines and I decided to go with containers. As I don’t like host network and priviledged containers this is what I did:

  • created a bridge on the Raspi with eth0 and wlan0: the iRobot and Air Purifier can connect and work
  • created an unmanged bridge network in Podman
  • have four containers connected to the bridge network, each with its own ip. HA, TBR, Matter and openCCU.
  • enabled Multicast on the bridge.

This is a setup as if each of the four containers would run on their own device, with own IP, etc, connected by betwork (bridge in this case). Works well so far.

The four ‘devices’ see each other, mDNS is working, Multicast groups appear on the bridge. Bridge and containers have the required sysctl values set.

At the moment, I just can’t get the pairing of the Matter devices ending successfully.

What I already figured out is:

  • I need WPA3 on the WLAN, so I added this.
  • The pairing has problems when the bridge has igmp-spoofing enabled (when I disable it I loose the mdb entries but that has already been checked so this is ok).

This is the brdge’s mdb:

pi@pi-iot0:~ $ bridge mdb
dev bridge0 port veth3 grp 239.255.255.250 temp
dev bridge0 port veth1 grp 239.255.255.250 temp
dev bridge0 port veth3 grp ff02::c temp
dev bridge0 port wlan0 grp ff02::1:ff01:3da5 temp
dev bridge0 port veth0 grp ff02::1:ff16:f667 temp
dev bridge0 port veth0 grp ff02::1:ff00:20 temp
dev bridge0 port veth3 grp ff02::1:ff16:f663 temp
dev bridge0 port veth1 grp ff02::1:ff16:f679 temp
dev bridge0 port veth2 grp ff02::1:ff16:f665 temp
dev bridge0 port wlan0 grp ff02::1:ff22:3680 temp
dev bridge0 port veth0 grp ff32:40:fd9d:68ef:4d73:c360:0:3 temp
dev bridge0 port veth2 grp ff02::1:ff00:23 temp
dev bridge0 port veth3 grp ff02::1:ff00:23 temp
dev bridge0 port veth2 grp ff02::1:ff00:22 temp
dev bridge0 port veth1 grp ff02::1:ff00:22 temp
dev bridge0 port eth0 grp ff02::1:ff00:1 temp
dev bridge0 port eth0 grp ff05::1:3 temp
dev bridge0 port eth0 grp ff02::1:ffe2:c064 temp
dev bridge0 port eth0 grp ff02::1:ffc1:162d temp
dev bridge0 port eth0 grp ff02::1:2 temp
dev bridge0 port veth0 grp ff02::1:ff00:24 temp
dev bridge0 port veth0 grp ff05::2 temp
dev bridge0 port veth2 grp ff05::2 temp
dev bridge0 port veth3 grp ff05::2 temp
dev bridge0 port veth1 grp ff05::2 temp
dev bridge0 port veth3 grp ff02::1:ff00:21 temp
dev bridge0 port veth1 grp ff02::1:ff00:21 temp
dev bridge0 port wlan0 grp ff02::1:ff04:28cc temp
dev bridge0 port bridge0 grp ff02::1:ff81:e320 temp
dev bridge0 port bridge0 grp ff02::1:ff72:3f13 temp
dev bridge0 port bridge0 grp ff02::1:ff00:0 temp
dev bridge0 port eth0 grp ff02::1:ff00:0 temp
dev bridge0 port veth0 grp ff02::1:ff00:0 temp
dev bridge0 port veth2 grp ff02::1:ff00:0 temp
dev bridge0 port veth3 grp ff02::1:ff00:0 temp
dev bridge0 port veth1 grp ff02::1:ff00:0 temp
dev bridge0 port bridge0 grp ff02::fb temp
dev bridge0 port wlan0 grp ff02::fb temp
dev bridge0 port veth0 grp ff02::fb temp
dev bridge0 port veth2 grp ff02::fb temp
dev bridge0 port veth3 grp ff02::fb temp
dev bridge0 port bridge0 grp ff02::1:ffdf:c8ff temp
dev bridge0 port bridge0 grp ff02::2 temp
dev bridge0 port wlan0 grp ff02::2 temp
dev bridge0 port eth0 grp ff02::2 temp
dev bridge0 port veth0 grp ff02::2 temp
dev bridge0 port veth2 grp ff02::2 temp
dev bridge0 port veth3 grp ff02::2 temp
dev bridge0 port veth1 grp ff02::2 temp
dev bridge0 port bridge0 grp ff02::6a temp

Matter use IPv6 and mDNS.
In your zoned network you need to make sure Matter use a routable IP network and that routing is set up too.
You also need to make sure that mDNS is handled correctly between the zones.
mDNS use Multicast, so normal IP routing will not solve it.

Hm
I think the mDNS is working, accoring to the avahi result as shown in first post.

And I do use a zoned network, but the iot stuff is on a single zone, even on a single device (Raspi with bridged Containers).

If the phone, HA, Matter server, Matter over Thread device and Thread Border Router are on the same network and HA and Matter server do not have multiple NICs, then you should be fine.