Emergency Internet Connectivity Solutions for Certain Senerios
Recommended Reading
How to know if signal jamming is deployed?
Test with your mobile hotspot:
- Severe range reduction: Your hotspot cannot connect to the robot at a distance of more than one meter.
- Sudden drop in visible networks: While multiple Wi-Fi signals can be detected in normal areas, only a few carrier/provider signals remain visible once you are on the stage or inside the arena.
- Inability to broadcast: Your mobile device shows that the hotspot is turned on, but other nearby devices cannot discover its SSID (network name) at all.
Test with your Access Point (AP):
- Multi-device connection failure: Your AP is unable to transmit signals to or maintain connections with multiple robots simultaneously.
- Redundancy failure: Even after deploying multiple APs for redundancy, you still cannot establish a stable connection.
- Channel blindness: The AP auto-channel selection tool shows 100% utilization or maximum noise floor across all available 2.4GHz or 5GHz channels.
Diagnostics from the robot/client side:
- Abnormal ping and latency spikes: Ping times to the robot jump from 2–5ms to over 1000ms, or you experience severe packet loss (greater than 50%) within close range.
- De-authentication floods: The robot repeatedly connects and immediately disconnects from the AP, which often indicates a targeted de-auth jamming attack.
Use the provider’s network
WPA2-PSK (AES) / WPA3-SAE (personal)
The most common encryption type for home networks and mobile hotspots. It requires a single shared password (Pre-Shared Key / Passphrase). You can use Agibot Go to configure this security method directly.
WPA2/WPA3 enterprise (802.1X)
Commonly found in universities (e.g., eduroam) and corporate offices. It requires a username (Identity) and a password, often combined with specific authentication protocols (such as PEAP + MSCHAPv2) or CA certificates.
Enterprise networks cannot be connected to via Agibot Go or a single nmtui/nmcli device wifi connect command because they require identity protocols. You must create and modify a connection profile manually.
Below is the configuration for PEAP + MSCHAPv2 (the most widely used enterprise setup):
Let the carriers/providers know that you have deployed your robots on this network, and ping other devices on the same network to check whether the provider filters any TCP/UDP traffic locally or for outgoing Internet traffic. If filtering is applied, ask them to whitelist your robot’s IP and MAC address.
Connect to the robot using an Ethernet cable via ssh run@10.0.1.41 (for X2 Ultra).
Step 1: Remove connected networks (skip if none exist)
aima em stop-app housekeeper
Remove or edit the existing network configuration if needed.
# Remove
sudo rm -rf /agibot/data/var/housekeeper/info/connected_wifi.json
# Edit
sudo vim /agibot/data/var/housekeeper/info/connected_wifi.json
# press i to edit the connected ssid and passwords
# press ESC to exit writing.
# press :wq to write and quit vim
aima em start-app housekeeper
Step 2: Create and configure a new Wi-Fi connection profile
You can run the following commands directly in the terminal, or save them to a .sh file.
For example:
touch connect_wifi.sh
Save the file and set the execution permission:
chmod +x connect_wifi.sh
Then run the file with sudo:
sudo ./connect_wifi.sh
After rebooting, this connection will normally not be recorded in housekeeper. If you still need to connect to this network after a reboot, run the commands again.
#!/bin/bash
sudo nmcli connection add \
type wifi \
ifname wifi0 \
con-name DummyName \
ssid "TheProvidedWifi"
# Configure the 802.1X security parameters
sudo nmcli connection modify DummyName \
wifi-sec.key-mgmt wpa-eap \
802-1x.eap peap \
802-1x.identity "username" \
802-1x.password "password" \
802-1x.phase2-auth mschapv2
# Restart the network manager
sudo systemctl restart NetworkManager
# Check if connected
nmcli connection show
Wait a few seconds, then check the connection in nmtui or run ping google.com to verify Internet access.
You can also run ifconfig to check your IP address.
🚫 Don’t use open networks (captive portals)
Unencrypted public networks require no password at the Wi-Fi layer but intercept traffic via a web-based login page (captive portal). It is highly discouraged to deploy robots on these networks due to security risks, unpredictable lease times, and session timeouts.
However, if your arena or environment requires you to use one, you cannot complete the web authentication directly on a headless robot. The most reliable workaround is MAC address spoofing, which tricks the gateway into thinking your robot is a previously authenticated device.
🛠️ Step-by-step headless workaround (MAC spoofing)
Step 1: Authenticate using a primary device
Connect your smartphone or laptop to the captive Wi-Fi network and complete the web browser authentication normally (e.g., by entering a voucher, SMS code, or portal login). Verify that you have full Internet access.
Step 2: Note down the network details
Go to your device’s network settings (Settings → Wi-Fi → Connected Network Details) and record the following information:
- MAC Address: Usually formatted as
XX:XX:XX:XX:XX:XX. (Note: Ensure your phone or laptop is using its “Device/Hardware MAC” rather than a “Randomized MAC” for this network.) - IP Address and Subnet Mask: (e.g.,
192.168.1.55). - Gateway/Router Address: (e.g.,
192.168.1.1).
⚠️ CRITICAL: Immediately turn off Wi-Fi or enable Airplane Mode on the smartphone or laptop. If both devices remain active with the same MAC address on the same network, it will cause a severe IP/MAC conflict, routing loops, and knock both units offline.
Step 3: Clone the credentials on the robot
Access the robot via Ethernet, and ssh run@10.0.1.41 and use nmcli to spoof the authenticated device’s identity:
# 1. Clone the authenticated MAC address
nmcli connection modify "WiFi_Name" 802-11-wireless.cloned-mac-address "XX:XX:XX:XX:XX:XX"
# 2. Bind the exact same IP and gateway to prevent DHCP mismatches
nmcli connection modify "WiFi_Name" ipv4.addresses "Laptop_IP/24" ipv4.gateway "Gateway_IP"
nmcli connection modify "WiFi_Name" ipv4.method manual
# 3. Bring the connection up
nmcli connection up "WiFi_Name"
Step 4: Regain access on your laptop
On macOS:
# Generate and apply a random MAC address to your Wi-Fi interface (usually en0)
sudo ifconfig en0 ether $(openssl rand -hex 6 | sed 's/\(..\)/\1:/g; s/.$//')
On Linux (Ubuntu/Debian):
# Spoof a random MAC on your laptop's Wi-Fi using nmcli
nmcli connection modify "WiFi_Name" 802-11-wireless.cloned-mac-address "random"
nmcli connection up "WiFi_Name"
Taixin
Specific hardware is required; a tutorial will be provided.