Using 4G LTE wireless modems on a Raspberry Pi
jeffgeerling.com
jeffgeerling.com
> A mini PCI Express 4G LTE modem. I used a Quectel EC25-A, but there are some from Sierra Wireless I've heard recommended too.
This is actually just a mini-pci-e adapter board that exposes the USB pins to the USB type A connector seen in the photo. It's not an actual pci-e bus device LTE modem. As shown in the example, it appears to the kernel as a USB device.
Seems like there would be no reason to upgrade to PCIe, since (I assume) it would be a pretty expensive update for no meaningful change in theoretical max speed.
As an aside: You should pull out the SIM from your mobile phone anyway, and use a VPN hotspot instead (and connect your phone to that with Wi-Fi). The carriers are monitoring all of your unencrypted DNS traffic (and your unencrypted SNI traffic that starts all of your TLS/SSL connections that says to which hostname you're connecting) and selling it, alongside your phone number and name. Use a hotspot that supports a VPN so you're only sending VPN traffic across a mobile carrier network.
(This is why T-Mobile in the US is now blocking Apple's "Private Relay" encrypted service and are complaining loudly - it's costing them sniffing-data-resale revenue.)
Same goes for the Pi: make sure you run a VPN client so you're only sending encrypted traffic across the wwan0 interface. Verify with 'tcpdump -i wwan0'.
iOS is not a privacy-focused OS.
Having a discrete device means you can also connect multiple mobile devices via Wi-Fi on the same SIM, and do your own monitoring/filtering of traffic (such as blocking all unencrypted DNS, and installing DoH profiles on devices, or running an unencrypted-dns-to-DoH forwarding proxy).
But after rereading the parent comment, I think they could have a misconfiguration with their VPN. I just ran a few DNS leak tests with my WireGuard setup on iOS and they all go over the VPN to my personal resolver.
Or maybe only portions of the OS is leaking around the VPN (i.e not safari but system components).
No, the idea is that you use your phone without a SIM card at all: no mobile network, wi-fi to the VPN router only.
I'm fairly sure this was shown to be false. From memory, they were shown only to be blocking it on their "family monitoring" opt in plan - i.e where they sniff and intercept at the behest of the owner. As far as I know, no US mobile carriers are blocking it beyond this. Do you have evidence of this?
> The carriers are monitoring all of your unencrypted DNS traffic (and your unencrypted SNI traffic that starts all of your TLS/SSL connections that says to which hostname you're connecting) and selling it, alongside your phone number and name.
You're probably right they're collecting it, but adding PII and selling it doesn't pass the Litmus test for me. Do you have any evidence or sources of this?
Whilst the advice you provide is sound, it appears to be built on unfounded falsehoods.
I just plug them in my laptop first, use the browser based config site to set it up and then put it on the pi.
Didn't have any reconnects though but I had a script running checking the connection and if it failed it would re dial
I would like to figure it out though, because it seems they'd be the more plug-and-play solution if they can work with the modem out of the box.
But along the way I probably spent 40 hours (and counting) trying to figure out the ins-and-outs of 4G LTE modems and Linux networking when it comes to these oddball devices.
I hope some parts of this post help anyone else new to LTE networking in Linux, and maybe somebody can help clear up some of my open questions, like:
Why doesn't Quectel have any firmware downloads on their site? (And is there any way to get them besides downloading random files posted to forums?)
Is there any advantage to using QMI (`wwan0` / qmi_wwan) vs ECM (`usb0` / cdc_ether)?
Why does it seem there's no real documentation for LTE modems on Linux? What little _good_ information I found was in random presentation slides scattered around the Internet.
Other than that it's either extremely technical documentation pages that expect a very high level of familiarity already, or some very cookie-cutter blog posts that give a walkthrough to get Internet going, but don't really explain anything.
(Also in the course of my research I learned a lot from OSMOCOM's work reverse-engineering some of the LTE modems (including the QC25 I'm using): https://osmocom.org/projects/quectel-modems/wiki/EC25 ).
As for the firmware. It seems to just be how these companies do things, unfortunately. At work, we use modems from both Quectel and Simcom and the experience described in OP is very similar. For Simcom we have gotten access to a "secret-but-public" Onedrive share with documentation, drivers and firmware where they put up stuff sporadically. Sometimes the firmware updates even works!
I have a theory that Qualcomm who makes the chipsets used by Quectel and Simcom (at least for the 5G modems) imposes some kind of heavy NDA which prevents free distribution of firmware and documentation. Everything seems very "hush, hush" at least.
While I can't help answer your remaining questions, I can point to wiki I have found really helpful: http://trac.gateworks.com/wiki/wireless/modem
Regarding FW updates, have you tried opening a support ticket with Quectel? For me they have been extremely responsive and helpful, providing extra documentation on special AT commands and stuff.
I would like to use modemmanager though, it _seems_ like it's the nicer path.
This is the config I'm using: https://github.com/commaai/agnos-builder/blob/master/userspa...
You can run modemmanager in debug mode, which allows you to send AT commands over dbus (or mmcli) in case you still want to configure some stuff manually or get debug info.
Users also are working on providing a mostly liberated firmware for the modem:
It makes life worth living.
Thank you kind, brave soul.
The telecoms industry in general is pretty shit and does a lot of anti-user nastiness like SIM locking or other arbitrary restrictions. It is not in the their best interests to let the user get too close to the inner workings of things. Security-wise it's also often terrible and security by obscurity is still very much the norm and would be threatened by more transparency. There's also only a handful of manufacturers of the underlying modem chips (Qualcomm is the main one) and they're all in bed with the industry and perpetuate the issue, and the barriers to entry to build your own module are huge both in terms of skill, factories/equipment needed to produce the chips and patents so there's little chance for a more open competitor to step up.
> And is there any way to get them besides downloading random files posted to forums?
If you can find a production-grade device that embeds the same modem that you have, search for firmware updates for that device - chances are it may embed the firmware for the modem too, which you can extract with a bit of reverse engineering. It's not great, but at least you're still getting the firmware from a more trusted source than random forum posts.
> Is there any advantage to using QMI (`wwan0` / qmi_wwan) vs ECM (`usb0` / cdc_ether)?
If you look carefully at the `ip addr` output of QMI vs ECM you would see that the IPs you got aren't the same.
In QMI mode, the LTE interface is directly connected to your system, the 10.... IP you got is the one assigned by your carrier (I am not sure where the initial 169.254.231.106 IP it had before you established the connection came from) and your machine is directly reachable from the Internet.
In ECM mode, you are given a fake Ethernet interface that's connected to a router and NAT gateway ran by the LTE module itself; this is also where that web interface comes from. In this mode, the module's router part is the one exposed to the internet and acts as a router/firewall/NAT gateway - your computer is not directly reachable unless you use that web interface to forward a port. Given the usual "quality" of these (as you witnessed by looking at the UI) I would not be surprised if there are exploits or bugs in there.
There should also be a third mode, where the modem exposes one or more serial ports that accept AT commands and you can establish a connection over it using wvdial/pppd just like good old dial-up. This is worse than QMI mode but preferable to ECM mode as you still get your system directly connected to the internet without relying on the modem's router/gateway part.
In general, I would recommend QMI mode - it is a breath of fresh air compared to the old school way of the modem exposing multiple serial ports and having to do dial-up on it. It does require some work but it's a solved problem - for desktop Linux look into ModemManager, or alternatively look into how OpenWRT deals with it for a potentially lighter alternative.
Maybe from the OS on the Raspberry Pi. I don't think it comes from the modem. Generelly I would recommend using MBIM if possible.
Some Huawei devices also had NCM, which is even better in terms of handling. You only have to send a command on the serial port to connect, then use a DHCP client on the ethernet interface and you'll get the external IP on that. Also bridge mode is way easier that way.