First steps with the PortaPack H4M PRO
AI Disclosure
This article contains elements processed or created by AI.
- The screenshots were regenerated via AI from original device photographs.
They were run through several verification agents, and reviewed by a human before being approved.
For more information on how Lab401 uses AI, please see our AI Policy
If you've just purchased a H4M Pro and looking to get started - or looking to understand the new features of the device, Lab401 has performed a deep-dive into what you need to know before you start.
The following article covers: Flashing Firmware to your PortaPack H4M Pro, configuring the device, running local tests, and a CHANGELOG.
⚠️ Before you tune or transmit
The PortaPack H4M is a wide-band radio device, with transceiver capabilities.
The EU Radio Equipment Directive (2014/53/EU) Annex I places custom-built evaluation kits outside its scope for professional use in research and development contexts.
Restrictions for transmitting and receiving vary. You are responsible for ensuring that your possession and use of these devices complies with the law in your jurisdiction.
Receiving: Several countries restrict monitoring outside broadcast and amateur allocations, and a few restrict what you may do with what you hear. Check the rules where you are before you tune.
Transmitting: Transmit only on bands you are licensed for, at or below the power your licence and national regulations allow. The amateur allocations used later in this article need an amateur licence. Where you hold no licence for a band, work into a dummy load, a shielded enclosure, or a cabled and attenuated link so that nothing reaches the air.
Flashing Mayhem over DFU
Hold the DFU button and connect the unit to a computer over USB. All the indicator lights go out. The HackRF One behaves differently here, and on the HackRF Pro a dark board is the confirmation that DFU mode is active.
Open the firmware directory and run mayhem_flasher.bat. Enter 3 to select HackRF Pro / PortaPack, then 2 to select Flash DFU then Mayhem, which carries out the DFU unbrick and the Mayhem flash in one pass. The script needs no further input.
It loads the HackRF firmware through dfu-util, waits five seconds for the device to re-enumerate and writes the 4MB firmware_hpro.bin image to SPI flash. The line Firmware flashed successfully in the terminal indicates that the flash is complete. The MCU, FPGA and RF LEDs come on and Mayhem loads automatically.
Setting the battery capacity
For power, the Portapack H4M Pro now uses industry standard 18650 Li-Ion batteries. These batteries can be easily obtained, easily replaced, and allow you to carry multiple batteries for extended in-the-field operations.
Depending on the brand and configuration, 18650 batteries can have different capacities and power ratings. In order for your H4M Pro to give you an accurate Battery Remaining estimation, you need to configure the firmware to match your batteries settings.
If you purchased your H4M Pro from Lab401, the battery was included - and the instructions below correspond to the battery you have. If you're using a different battery, you'll need to configure the settings according to your specific battery.
Open the Mayhem home screen and tap the battery icon. The capacity field shows the default of 1500mAh.
The cell supplied with the device is a 3.7V 18650 rated at 9.25Wh. Capacity in mAh is energy divided by voltage and multiplied by 1,000, so 9.25 ÷ 3.7 × 1,000 gives 2500mAh. That matches the figure printed on the label.
Tap Settings on the battery page, turn the scroll wheel to change 1500 to 2500 and save.
Return to the battery page. The capacity now reads 2500mAh. The unit shown here is at 72% and 3.908V, drawing 352mA, with 4 hours 55 minutes remaining. Method reads IC, which means the fuel gauge is measuring rather than inferring the figure from voltage.
Transmit and receive tests
Mayhem transmits and receives WFM, NFM, APRS, ADS-B, POCSAG and BLE, with the mode, frequency and bandwidth set by the operator. Each test below used two H4M Pro units, one transmitting and one receiving.
⚠️ Before you tune or transmit
Transmitting: Transmit only on bands you are licensed for, at or below the power your licence and national regulations allow.
The following images are illustrative only. Do NOT transmit in restricted spectrum space. Use a dummy load, a shielded enclosure, or a cabled and attenuated link to prevent transmission.
WFM broadcast reception
Open Receive from the home screen, select Audio, then set the playback standard to WFM. The frequency is arbitrary. This test used 100.6MHz with the gains left at their default values.
NFM voice
On the receiving unit, open Receive, select the Audio channel and switch to NFM demodulation. On the transmitting unit, open Transmit and select Signal Generator. Set both units to 466.1750MHz. Point-to-point working requires the same frequency at each end, so set the receiver rather than assuming it has followed. The gains stay at their defaults, which puts transmit gain at 16.
Once transmission starts, audio reaches the receiver immediately. The generator defaults to CW, which applies no modulation. Switching it to FM before transmitting changes the timbre of the demodulated audio noticeably.
APRS messaging
Open APRS TX on the transmitting unit and APRS RX on the receiving unit, and set both to 144.3900MHz. The source and destination SSIDs can be set arbitrarily, and the gains stay at their defaults. Tap Set on the transmitting side, enter the message and confirm with OK. The text appears on the receiving list immediately.
In North America, APRS runs on 144.3900MHz. In Region 1 of the International Amateur Radio Union, which covers Europe, Africa and the Middle East, it operates on 144.8000MHz. Both frequencies fall within the two-metre amateur band and require an amateur licence.
ADS-B position reporting
Switch the receiving unit to ADS-B from the Receive menu and open the ADS-B TX page on the transmitting unit. The mode fixes both units on 1090MHz, and transmit gain is 16. That frequency carries live aviation traffic, so the link between the two units must be cabled and shielded. Tick Transmit position and enter simulated position data. This test used a simulated aircraft identified as TEST1234 at 36,000ft over the Niger delta, at 5°N and 6°E, on ICAO24 address 000001. The receiver plots that aircraft at those coordinates after a short delay.
Setting both the LNA and VGA gains on the receiver to 24 removes that delay. On restarting transmission the receiver captures immediately, the callsign and altitude populate, and the hit count passes a thousand.
POCSAG paging
Select POCSAG RX on the receiving unit and open POCSAG TX on the transmitting unit. The defaults are enough for the test. They are alphanumeric at 1200bps, address 0000000, function D and standard polarity, with PORTAPACK as the message. Both units share 466.1750MHz at default gain.
The receiver logs the message with its timestamp, bitrate and function code. POCSAG is sensitive to bitrate and polarity, so a clean decode indicates that the transmit chain is correctly timed.
BLE advertising
Open BLE TX on the transmitting unit and BLE RX on the receiving unit, setting the receiver to Auto with Sort set to Hits. Both operate on 2402MHz. On the transmitting side, load any file through Open file, enable BLE TX, set the gain to 16 and turn Loop on. On the receiving side, tap Clear to empty the existing records and refresh the list.
MAC address 01:02:03:04:05:06 then accumulates hits at the top of the list, matching the address the transmitter advertises. A receiver gain of 24 gives the fastest capture, and moving it in either direction slows the hit rate.
Changes in v2.4.0.1
Version 2.4.0.1 alters wideband FM reception and BLE. The operating procedure is unchanged in both cases.
Wideband FM
The route through the menus is the same as in v2.4.0: Receive, then Audio, then WFM, tuned to 100.6MHz with default gains. The waterfall is cleaner, with the carrier and its sidebands better separated, and speech is more intelligible.
BLE
The intermittent reception failures present in v2.4.0 have been corrected. Setup is otherwise unchanged, though the release notes now give transmit gain as 24 rather than 16. A receiver gain of 24 remains the fastest setting for capture.
Summary of settings
After flashing, calibration and testing, the unit receives and demodulates broadcast and narrowband voice, carries text over APRS, decodes ADS-B position reports, handles POCSAG paging, and tracks BLE advertisements by hit count. Runtime estimates match the cell. Two settings need raising from their defaults. ADS-B needs the LNA and VGA gains at 24, and BLE needs a receiver gain of 24.
The table below lists the settings used in each test.
| Test | Frequency | Mode | Gains |
|---|---|---|---|
| WFM broadcast | 100.6MHz | Audio RX, WFM | Default |
| NFM voice | 466.1750MHz | Audio RX / Signal Generator | TX 16, RX default |
| APRS | 144.3900MHz (144.8000MHz in Region 1) | APRS TX / APRS RX | Default |
| ADS-B | 1090MHz | ADS-B TX / ADS-B RX | TX 16, RX LNA 24 and VGA 24 |
| POCSAG | 466.1750MHz | POCSAG TX / POCSAG RX | Default |
| BLE | 2402MHz | BLE TX / BLE RX | TX 16 (24 in the v2.4.0.1 notes), RX 24 |
Tools Used:
Firmware and Further Reading:
Procedures and measured values in this article follow the OpenSourceSDRLab technical note "HackRF Pro and PortaPack H4M Pro: Parameter Settings and Firmware Operations".
Leave a comment