Raspberry Pi as a 2.4 GHz Wi-Fi Access Point for Local Sensor Hubs
Use a Raspberry Pi with hostapd and dnsmasq to create a low-cost 2.4 GHz Wi-Fi access point for sensor hubs and labs, with DHCP, NAT and basic firewalling.
11 Jun 2026, 20:10 UTC

The problem is a small, isolated network without a router
Classroom labs, temporary event sites, and local sensor hubs often need a dedicated Wi-Fi network that only serves a handful of clients. A commercial router adds cost, power draw, and management overhead. A Raspberry Pi running Raspberry Pi OS can provide a fully functional 2.4 GHz access point with DHCP, NAT and basic firewalling using hostapd and dnsmasq.
hostapd is a user-space daemon that turns a wireless interface into an access point. dnsmasq provides lightweight DHCP and DNS forwarding. With iptables you can NAT traffic from the AP interface to an upstream Ethernet link.
The Pi uses wlan0 as the AP radio and eth0 as the upstream connection. Clients join the SSID, receive addresses from dnsmasq on a private subnet, and reach the internet through NAT on the Pi. The Pi itself stays reachable via SSH over eth0.
Key risks before you start: editing network services can drop your SSH session, the onboard radio is 2.4 GHz only and prone to interference from microwaves and crowded Wi-Fi, and open forwarding rules can expose services on the Pi to clients. Restrict firewall rules to necessary ports and keep a backup of changed files.
Worked configuration for wlan0 AP with NAT to eth0
Run all commands on the Pi console or over SSH with sudo privileges.
Install the required packages:
sudo apt update
sudo apt install hostapd dnsmasqPrepare hostapd. Create or edit /etc/hostapd/hostapd.conf with sudo. Replace placeholders with your values:
interface=wlan0
driver=nl80211
ssid=LabSensors
hw_mode=g
channel=6
wmm_enabled=0
macaddr_acl=0
auth_algs=1
ignore_broadcast_ssid=0
wpa=2
wpa_passphrase=REPLACE_WITH_STRONG_PASSPHRASE
wpa_key_mgmt=WPA-PSK
wpa_pairwise=TKIP CCMP
rsn_pairwise=CCMPEnable hostapd and prevent the system from managing wlan0 via dhcpcd. Edit /etc/default/hostapd to set DAEMON_CONF=\"/etc/hostapd/hostapd.conf\". Then:
sudo systemctl unmask hostapd
sudo systemctl enable hostapdConfigure dnsmasq for the AP subnet. Edit /etc/dnsmasq.conf with sudo and add:
interface=wlan0
dhcp-range=192.168.10.10,192.168.10.200,12h
dhcp-option=3,192.168.10.1
dhcp-option=6,192.168.10.1
no-resolv
server=1.1.1.1Set a static address for wlan0. Add to /etc/dhcpcd.conf:
interface wlan0
static ip_address=192.168.10.1/24
nohook wpa_supplicantAdd NAT and forwarding. Run with sudo. Replace eth0 if your upstream interface differs:
sudo iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE
sudo iptables -A FORWARD -i wlan0 -o eth0 -j ACCEPT
sudo iptables -A FORWARD -i eth0 -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
sudo sysctl -w net.ipv4.ip_forward=1To make the rules persist, add them to a startup script or use your distribution's iptables persistence tool.
Trade-offs and limits you will hit first
The onboard Wi-Fi chip on many Pi models, such as BCM43438, is single-band 2.4 GHz with a maximum data rate around 150 Mbps. That is adequate for light sensor traffic and web dashboards but not for HD streaming.
2.4 GHz is subject to interference from household Wi-Fi and microwave ovens, which degrades performance in dense environments. Client density also raises power consumption and CPU load on the Pi.
Dual-band operation requires a newer Pi model with 5 GHz support or an external USB dongle. Firewall hardening is essential; default forwarding rules expose the Pi to port scanning from clients.
How to check the result
Verify hostapd is running and the interface is in AP mode:
sudo systemctl status hostapd
iw dev wlan0 infoLook for active status and type AP for wlan0.
Connect a client to the SSID and confirm DHCP assignment by inspecting the Pi's lease information and the client's address.
Confirm NAT by attempting outbound connectivity from the client, for example ping to an external address. Success indicates forwarding and MASQUERADE are working.
Check logs for configuration errors:
journalctl -u hostapd
grep dnsmasq /var/log/syslogKeep backups of /etc/hostapd/hostapd.conf, /etc/dnsmasq.conf and /etc/dhcpcd.conf before changes so you can revert if the network becomes unreachable.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.