Wi-Fi on Linux: iwd vs wpa_supplicant

Wi-Fi on Linux: iwd vs wpa_supplicant

Two programs handle Wi-Fi authentication on Linux: wpa_supplicant and iwd. Above them sits NetworkManager or systemd-networkd, which decides what to connect to and handles addressing.

The supplicant does the cryptographic handshake. It does not obtain an IP address, which is why a successful association with no connectivity is a DHCP problem rather than a Wi-Fi problem.

The difference

wpa_supplicant has been the default for two decades. It supports essentially every authentication method that exists, including obscure enterprise configurations, and that completeness comes with a large codebase that implements its own cryptography.

iwd is Intel’s replacement, written to be smaller and to use the kernel’s crypto subsystem rather than bundling its own. It connects and roams noticeably faster, and it needs no configuration file for ordinary networks.

The practical differences:

wpa_supplicantiwd
Connection speedSlowerNoticeably faster
Roaming between APsAdequateBetter
ConfigurationConfig file requiredNone needed
Enterprise coverageCompleteGood, occasional gaps
Default onMost distributionsChromeOS, some others

For a laptop moving between access points, iwd’s roaming is a real improvement. For an unusual corporate network, wpa_supplicant’s broader support is the safer bet.

Which are you running

systemctl status wpa_supplicant
systemctl status iwd

Never both. Two supplicants fighting over one interface produces connections that drop repeatedly for no visible reason, and it is a surprisingly common misconfiguration after someone follows a guide to switch.

Using iwd directly

sudo systemctl enable --now iwd
iwctl
[iwd]# device list
[iwd]# station wlan0 scan
[iwd]# station wlan0 get-networks
[iwd]# station wlan0 connect MyNetwork
Passphrase: ********
[iwd]# station wlan0 show
[iwd]# exit

Tab completion works throughout, including for network names.

One shot:

iwctl --passphrase 'secret' station wlan0 connect MyNetwork

Credentials are stored in /var/lib/iwd/MyNetwork.psk and reused automatically.

iwd has a built-in DHCP client, which wpa_supplicant does not:

# /etc/iwd/main.conf
[General]
EnableNetworkConfiguration=true

[Network]
NameResolvingService=systemd

With that, iwd handles the address as well and you need nothing else. Our systemd-resolved guide covers the DNS side.

Using wpa_supplicant directly

wpa_passphrase MyNetwork 'secret' | sudo tee /etc/wpa_supplicant/wpa_supplicant-wlan0.conf
network={
	ssid="MyNetwork"
	psk=a1b2c3d4e5f6...
}

wpa_passphrase hashes the passphrase so the plaintext is not in the file. Delete the commented plaintext line it also writes.

sudo systemctl enable --now wpa_supplicant@wlan0
sudo dhclient wlan0        # address, separately

That second command is the part people forget. wpa_supplicant authenticates and stops there.

Switching NetworkManager to iwd

# /etc/NetworkManager/conf.d/wifi-backend.conf
[device]
wifi.backend=iwd
sudo systemctl disable --now wpa_supplicant
sudo systemctl enable --now iwd
sudo systemctl restart NetworkManager

Disabling wpa_supplicant is mandatory, not optional.

Saved networks do not migrate. You will re-enter passphrases.

When the adapter does not appear

ip link                       # is there a wireless interface
lspci -k | grep -A3 -i network
lsusb                         # for USB adapters
sudo dmesg | grep -i -E 'firmware|iwlwifi|ath|rtw|brcm'

The usual culprit is missing firmware. Many wireless chipsets need a binary blob that is not always installed by default:

iwlwifi 0000:00:14.3: Direct firmware load for iwlwifi-so-a0-gf-a0-83.ucode failed
sudo apt install firmware-iwlwifi     # Debian, with non-free enabled
sudo apt install linux-firmware       # Ubuntu
sudo dnf install iwlwifi-dvm-firmware iwlwifi-mvm-firmware

Debian separates redistributable firmware from firmware-* packages in non-free, which is the single most common reason a fresh Debian install has no Wi-Fi. Our linux-firmware download page covers the package.

Broadcom chips are the perennial problem case and frequently need broadcom-sta-dkms, which builds an out-of-tree driver through DKMS and therefore needs rebuilding on every kernel update.

When 5GHz is missing

iw reg get
country 00: DFS-UNSET

country 00 is the world regulatory domain, a conservative default that excludes channels available in most countries.

sudo iw reg set GB

Persist it:

# /etc/conf.d/wireless-regdom or /etc/default/crda depending on distribution
WIRELESS_REGDOM="GB"

Some 5GHz channels require DFS, radar detection, which the driver must implement. If certain channels remain invisible after setting the domain correctly, that is usually why.

Diagnosing a connection

iw dev wlan0 link              # associated? which AP? what rate?
iw dev wlan0 scan | grep -E 'SSID|signal|freq'
watch -n1 'iw dev wlan0 link | grep signal'

Signal strength in dBm, and the numbers are negative:

  • -30 to -50: excellent
  • -50 to -60: good
  • -60 to -70: workable
  • below -70: expect problems
  • below -80: unusable

A connection that associates but has no connectivity is a DHCP or routing problem:

ip addr show wlan0
ip route
ping -c3 192.168.1.1

Our network troubleshooting guide covers working down the stack.

Watch the supplicant live:

journalctl -u iwd -f
journalctl -u wpa_supplicant -f
journalctl -u NetworkManager -f

Power saving

Aggressive Wi-Fi power management causes intermittent latency spikes and dropped connections, and it is enabled by default on many laptops.

iw dev wlan0 get power_save
sudo iw dev wlan0 set power_save off

Persist it through NetworkManager:

# /etc/NetworkManager/conf.d/wifi-powersave.conf
[connection]
wifi.powersave = 2

2 disables it, 3 enables it. The numbering is not intuitive.

The tradeoff is battery life, which our power management guide covers. If you have unexplained network stalls on a laptop, test with power saving off before investigating anything else.

Frequently Asked Questions

What is the difference between iwd and wpa_supplicant?

Both handle Wi-Fi authentication. wpa_supplicant is older, supports nearly every configuration including obscure enterprise setups, and has a large codebase. iwd is Intel’s newer replacement that uses kernel crypto instead of bundling its own, connects and roams noticeably faster, and needs no configuration file for normal use.

Which Wi-Fi supplicant is my system using?

Check which service is running with systemctl status iwd and systemctl status wpa_supplicant. NetworkManager uses wpa_supplicant by default on most distributions, and switching it to iwd requires a configuration change plus disabling the other service so they do not fight over the interface.

Why does my Wi-Fi adapter not appear at all?

Usually a missing driver or missing firmware. Check dmesg for firmware load failures, and confirm the device is visible with lspci or lsusb. Many wireless chipsets need a binary firmware blob from the linux-firmware package, which some distributions do not install by default.

Why can I not see or connect to 5GHz networks?

Frequently a regulatory domain problem. If the country code is unset the kernel applies a conservative default that excludes several channels. Check with iw reg get and set it correctly, and note that some channels require radar detection support the driver may not implement.

Can I connect to Wi-Fi without NetworkManager?

Yes. iwctl provides an interactive shell for iwd, and wpa_supplicant can be run with a configuration file generated by wpa_passphrase. You then need to obtain an address separately with a DHCP client, since the supplicant only handles authentication.

Does WPA3 work on Linux?

Yes, in both iwd and current wpa_supplicant, provided the driver and firmware support it. Some older chipsets do not, and some access points implement WPA3 transition mode in ways that cause problems. If a WPA3 network fails, testing whether WPA2-only works isolates it quickly.