Différences
Ci-dessous, les différences entre deux révisions de la page.
| Les deux révisions précédentesRévision précédenteProchaine révision | Révision précédente | ||
| hostapd [Le 06/01/2011, 09:57] – 213.41.106.96 | hostapd [Le 04/08/2025, 19:15] (Version actuelle) – Message qui n'a rien à faire ici.. Nexus6 | ||
|---|---|---|---|
| Ligne 1: | Ligne 1: | ||
| + | {{tag> | ||
| + | ---- | ||
| ====== HostAP daemon ====== | ====== HostAP daemon ====== | ||
| Ligne 24: | Ligne 26: | ||
| [...] | [...] | ||
| </ | </ | ||
| + | |||
| ===== Installation, | ===== Installation, | ||
| + | Installation depuis dépots officiel | ||
| - | Installation du daemon : | + | < |
| - | < | + | |
| - | sudo apt-get install hostapd | + | |
| - | </ | + | |
| - | Le fichier de configuration / | + | Le fichier de configuration |
| La configuration minimale (Wi-Fi ouvert/ | La configuration minimale (Wi-Fi ouvert/ | ||
| Ligne 75: | Ligne 76: | ||
| Hostapd supporte les adaptateurs Wi-Fi utilisant les drivers madwifi, prism. | Hostapd supporte les adaptateurs Wi-Fi utilisant les drivers madwifi, prism. | ||
| + | === Authentification WPA/WPA2 === | ||
| + | |||
| + | Activez l' | ||
| + | |||
| + | Avec Wi-Fi WPA (WPA-PSK-TKIP) : | ||
| + | < | ||
| + | wpa=1 | ||
| + | # | ||
| + | wpa_passphrase=passphrase | ||
| + | wpa_key_mgmt=WPA-PSK | ||
| + | wpa_pairwise=TKIP | ||
| + | </ | ||
| + | |||
| + | Avec Wi-Fi WPA2 (WPA2-PSK-CCMP) : | ||
| + | < | ||
| + | wpa=2 | ||
| + | # | ||
| + | wpa_passphrase=passphrase | ||
| + | wpa_key_mgmt=WPA-PSK | ||
| + | wpa_pairwise=CCMP | ||
| + | rsn_pairwise=CCMP | ||
| + | </ | ||
| - | == Filtrage MAC == | + | === Filtrage MAC === |
| Activez le Filtrage des adresses MAC des clients sans fil : | Activez le Filtrage des adresses MAC des clients sans fil : | ||
| Ligne 99: | Ligne 122: | ||
| </ | </ | ||
| - | == Lancement de hostapd == | + | === Lancement de hostapd |
| Lancement de hostapd : | Lancement de hostapd : | ||
| < | < | ||
| - | hostapd / | + | hostapd / |
| </ | </ | ||
| + | ==== Configuration d'un point d' | ||
| - | == Exemple WPA/WPA2 == | + | L' |
| - | Exemple complet Wi-Fi WPA (WPA-PSK-TKIP) : | + | Tableau montrant l' |
| - | < | + | ^Bande passante ^ ^HT 20MHz ^HT 40MHz^ ^ |
| - | ##### WPA/IEEE 802.11i configuration ########################################## | + | |**Nombre de Flux** |800 ns Gi |400 ns Gi |800 ns Gi |400 ns Gi| |
| + | |1 flux |65 Mbps |75 Mbps |135 Mbps |150 Mbps| | ||
| + | |2 flux |130 Mbps |150 Mbps |270 Mbps |300 Mbps| | ||
| + | |3 flux |195 Mbps |225 Mbps |405 Mbps |450 Mbps| | ||
| + | |4 flux |260 Mbps |290 Mbps |540 Mbps |600 Mbps| | ||
| - | # Enable WPA. Setting this variable configures the AP to require WPA (either | + | Tableau des canaux dans le mode HT40 inférieur/ |
| - | # WPA-PSK or WPA-RADIUS/ | + | ^fréquences ^ HT40- ^ HT40+ ^ |
| - | # wpa_psk or wpa_passphrase must be set and wpa_key_mgmt must include WPA-PSK. | + | |2.4 GHz |5-13 |1-7 (1-9 en Europe/Japon)| |
| - | # For WPA-RADIUS/EAP, ieee8021x must be set (but without dynamic WEP keys), | + | |5 GHz |40,48, |
| - | # RADIUS authentication server must be configured, and WPA-EAP must be included | + | |
| - | # in wpa_key_mgmt. | + | |
| - | # This field is a bit field that can be used to enable WPA (IEEE 802.11i/ | + | |
| - | # and/or WPA2 (full IEEE 802.11i/ | + | |
| - | # bit0 = WPA | + | |
| - | # bit1 = IEEE 802.11i/RSN (WPA2) (dot11RSNAEnabled) | + | |
| - | wpa=1 | + | |
| - | # WPA pre-shared keys for WPA-PSK. This can be either entered as a 256-bit | + | Les règles sont les suivantes : vous ne devez pas paramètrer les canaux 1,2,3 ou 4 dans le mode HT40 inférieur, et vous ne devez pas paramétrer les canaux 10,11,12 ou 13 dans le mode HT 40 supérieur. Les canaux 5,6 ou 7 marcheront donc dans les deux modes HT40 -/+. |
| - | # secret in hex format (64 hex digits), wpa_psk, or as an ASCII passphrase | + | |
| - | # (8..63 characters) that will be converted to PSK. This conversion uses SSID | + | |
| - | # so the PSK changes when ASCII passphrase is used and the SSID is changed. | + | |
| - | # wpa_psk (dot11RSNAConfigPSKValue) | + | |
| - | # wpa_passphrase (dot11RSNAConfigPSKPassPhrase) | + | |
| - | # | + | |
| - | wpa_passphrase=passphrase | + | |
| - | # Optionally, WPA PSKs can be read from a separate text file (containing list | ||
| - | # of (PSK,MAC address) pairs. This allows more than one PSK to be configured. | ||
| - | # Use absolute path name to make sure that the files can be read on SIGHUP | ||
| - | # configuration reloads. | ||
| - | # | ||
| - | # Set of accepted key management algorithms (WPA-PSK, WPA-EAP, or both). The | + | Petit rappel du mode standard IEEE 802.11g, entre 2,4GHz et 2,5GHz il y a 100Mhz et il y a 14 canaux de 20MHz espacés de 5MHz seulement, et se chevauchant obligatoirement dans cette espace de la bande. En mode 802.11n la bande passant additionné de 2 canaux couvre 40MHz, chevauchant par conséquent beaucoup plus de canaux entre 2,4GHz et 2,5GHz. |
| - | # entries are separated with a space. WPA-PSK-SHA256 and WPA-EAP-SHA256 can be | + | |
| - | # added to enable SHA256-based stronger algorithms. | + | |
| - | # (dot11RSNAConfigAuthenticationSuitesTable) | + | |
| - | # | + | |
| - | wpa_key_mgmt=WPA-PSK | + | |
| - | # Set of accepted cipher suites (encryption algorithms) for pairwise keys | + | Paramètrage Wi-Fi N en mode IEEE 802.11g (2,4GHz) et channel : |
| - | # (unicast packets). This is a space separated list of algorithms: | + | < |
| - | # CCMP = AES in Counter | + | # mode Wi-Fi |
| - | # TKIP = Temporal Key Integrity Protocol [IEEE 802.11i/ | + | hw_mode=g |
| - | # Group cipher suite (encryption algorithm for broadcast and multicast frames) | + | channel=6 |
| - | # is automatically selected based on this configuration. If only CCMP is | + | </code> |
| - | # allowed as the pairwise cipher, group cipher will also be CCMP. Otherwise, | + | |
| - | # TKIP will be used as the group cipher. | + | |
| - | # (dot11RSNAConfigPairwiseCiphersTable) | + | |
| - | # Pairwise cipher for WPA (v1) (default: TKIP) | + | |
| - | wpa_pairwise=TKIP | + | |
| - | # Pairwise cipher for RSN/WPA2 (default: use wpa_pairwise value) | + | |
| - | # | + | |
| - | # Time interval for rekeying GTK (broadcast/ | + | Paramètrage Wi-Fi N en mode IEEE 802.11a (5GHz) et channel : |
| - | # seconds. (dot11RSNAConfigGroupRekeyTime) | + | < |
| - | #wpa_group_rekey=600 | + | # mode Wi-Fi |
| + | hw_mode=a | ||
| + | channel=36 | ||
| + | </ | ||
| - | # Rekey GTK when any STA that possesses the current GTK is leaving the BSS. | + | Hostapd implémente des règles très strictes en 802.11n en particulier IEEE_802.11n Draft 7.0 section 11.14.3.2. Au démarrage hostap scannera donc les APs HT20/40 actifs dans son environnement présent, et déterminera si votre fréquence primaire est en adéquation avec la fréquences secondaire conséquente du choix canal inférieur/ |
| - | # (dot11RSNAConfigGroupRekeyStrict) | + | |
| - | # | + | |
| - | # Time interval for rekeying GMK (master key used internally to generate GTKs | + | Ce patch est fonctionnel pour activer le mode 40MHz dans un environnement non contrôlé et perturbé, fichier IEEE_802.11n_D7.0_11.14.3.2.patch : |
| - | # (in seconds). | + | <code c> |
| - | # | + | hostapd-0.7.3/hostapd# diff -ur ../src.orign/ |
| - | + | --- ../src.orign/ | |
| - | # Maximum lifetime for PTK in seconds. This can be used to enforce rekeying of | + | +++ ../ |
| - | # PTK to mitigate some attacks against TKIP deficiencies. | + | @@ -378,8 +378,17 @@ |
| - | # | + | sec = pri + 20; |
| - | + | } | |
| - | # Enable IEEE 802.11i/RSN/WPA2 pre-authentication. This is used to speed up | + | |
| - | # roaming be pre-authenticating IEEE 802.1X/EAP part of the full RSN | + | - |
| - | # authentication and key handshake before actually associating with a new AP. | + | - (sec < affected_start || sec > affected_end)) |
| - | # (dot11RSNAPreauthenticationEnabled) | + | + |
| - | # | + | + " |
| - | # | + | + |
| - | # Space separated list of interfaces from which pre-authentication frames are | + | + pri, sec, pri_chan, |
| - | # accepted (e.g., ' | + | + sec > pri ? ' |
| - | # interface that are used for connections to other APs. This could include | + | + |
| - | # wired interfaces and WDS links. The normal wireless data interface towards | + | + |
| - | # associated stations (e.g., wlan0) should not be added, since | + | + |
| - | # pre-authentication is only used with APs other than the currently associated | + | + (sec < affected_start || sec > affected_end)) || |
| - | # one. | + | + ((pri > affected_start && sec > affected_end) || // |
| - | # | + | + (pri < affected_start && sec < affected_end)) ) // and reverse |
| - | + | | |
| - | # peerkey: Whether PeerKey negotiation for direct links (IEEE 802.11e) is | + | |
| - | # allowed. This is only used with RSN/WPA2. | + | wpa_printf(MSG_DEBUG, " |
| - | # 0 = disabled | + | @@ -451,7 +460,14 @@ |
| - | # 1 = enabled | + | iface-> |
| - | # | + | |
| - | + | } | |
| - | # ieee80211w: Whether management frame protection | + | - |
| - | # 0 = disabled | + | + else wpa_printf(MSG_INFO, "20/40 MHz permitted on " |
| - | # 1 = optional | + | + " |
| - | # 2 = required | + | + iface-> |
| - | # | + | + iface-> |
| - | + | + iface-> | |
| - | # Association SA Query maximum timeout | + | + iface-> |
| - | # (maximum time to wait for a SA Query response) | + | + iface-> |
| - | # dot11AssociationSAQueryMaximumTimeout, 1...4294967295 | + | + iface-> |
| - | # | + | |
| - | + | } | |
| - | # Association SA Query retry timeout | + | |
| - | # (time between two subsequent SA Query requests) | + | |
| - | # dot11AssociationSAQueryRetryTimeout, 1...4294967295 | + | |
| - | # | + | |
| - | + | ||
| - | + | ||
| - | # okc: Opportunistic Key Caching (aka Proactive Key Caching) | + | |
| - | # Allow PMK cache to be shared opportunistically among configured interfaces | + | |
| - | # and BSSes (i.e., all configurations within a single hostapd process). | + | |
| - | # 0 = disabled | + | |
| - | # 1 = enabled | + | |
| - | #okc=1 | + | |
| </ | </ | ||
| - | Exemple | + | Exemple |
| < | < | ||
| - | ##### WPA/IEEE 802.11i configuration ########################################## | + | ieee80211n=1 |
| + | ht_capab=[HT40+][SHORT-GI-40][RX-STBC1][DSSS_CCK-40][MAX-AMSDU-3839] | ||
| + | </code> | ||
| - | # Enable WPA. Setting this variable configures the AP to require WPA (either | + | Ici nous utilisons les modes HT20/HT40 supérieur, avec un intervalle de garde court en 40 MHz, avec 1 seul flux spatial, avec prise en charge du DSSS/CCK Mode en 40 MHz, avec un AMSDU de longueur maximum à 3839 bytes (par défaut). Canal 6 avec cryptage |
| - | # WPA-PSK or WPA-RADIUS/EAP based on other configuration). For WPA-PSK, either | + | |
| - | # wpa_psk or wpa_passphrase must be set and wpa_key_mgmt must include WPA-PSK. | + | |
| - | # For WPA-RADIUS/EAP, ieee8021x must be set (but without dynamic WEP keys), | + | |
| - | # RADIUS authentication server must be configured, and WPA-EAP must be included | + | |
| - | # in wpa_key_mgmt. | + | |
| - | # This field is a bit field that can be used to enable WPA (IEEE 802.11i/ | + | |
| - | # and/ | + | |
| - | # bit0 = WPA | + | |
| - | # bit1 = IEEE 802.11i/RSN (WPA2) (dot11RSNAEnabled) | + | |
| - | wpa=2 | + | |
| - | # WPA pre-shared keys for WPA-PSK. This can be either entered as a 256-bit | + | Utilisez la commande "iw list" pour déterminer les capacités de votre adaptateur en Wi-Fi 802.11n : |
| - | # secret in hex format (64 hex digits), wpa_psk, or as an ASCII passphrase | + | < |
| - | # (8..63 characters) that will be converted to PSK. This conversion uses SSID | + | # iw list |
| - | # so the PSK changes when ASCII passphrase is used and the SSID is changed. | + | Wiphy phy1 |
| - | # wpa_psk | + | Band 1: |
| - | # wpa_passphrase | + | Capabilities: |
| - | # | + | HT20/HT40 |
| - | wpa_passphrase=passphrase | + | SM Power Save disabled |
| + | RX HT40 SGI | ||
| + | RX STBC 1-stream | ||
| + | Max AMSDU length: 3839 bytes | ||
| + | DSSS/CCK HT40 | ||
| + | Maximum RX AMPDU length 65535 bytes (exponent: 0x003) | ||
| + | | ||
| + | HT TX/RX MCS rate indexes supported: 0-15 | ||
| + | [...] | ||
| + | </ | ||
| - | # Optionally, WPA PSKs can be read from a separate text file (containing list | + | Attention aux messages d' |
| - | # of (PSK,MAC address) pairs. This allows more than one PSK to be configured. | + | * Driver does not support |
| - | # Use absolute path name to make sure that the files can be read on SIGHUP | + | * Driver does not support configured HT capability [DSSS_CCK-40] |
| - | # configuration reloads. | + | * Driver does not support configured HT capability [RX-STBC*] |
| - | # | + | * HT (IEEE 802.11n) with WPA/WPA2 requires CCMP to be enabled |
| - | # Set of accepted key management algorithms (WPA-PSK, WPA-EAP, or both). The | ||
| - | # entries are separated with a space. WPA-PSK-SHA256 and WPA-EAP-SHA256 can be | ||
| - | # added to enable SHA256-based stronger algorithms. | ||
| - | # (dot11RSNAConfigAuthenticationSuitesTable) | ||
| - | # | ||
| - | wpa_key_mgmt=WPA-PSK | ||
| - | # Set of accepted cipher suites | + | N' |
| - | # (unicast packets). This is a space separated list of algorithms: | + | |
| - | # CCMP = AES in Counter mode with CBC-MAC [RFC 3610, IEEE 802.11i/D7.0] | + | |
| - | # TKIP = Temporal Key Integrity Protocol [IEEE 802.11i/D7.0] | + | |
| - | # Group cipher suite (encryption algorithm for broadcast and multicast frames) | + | |
| - | # is automatically selected based on this configuration. If only CCMP is | + | |
| - | # allowed as the pairwise cipher, group cipher will also be CCMP. Otherwise, | + | |
| - | # TKIP will be used as the group cipher. | + | |
| - | # (dot11RSNAConfigPairwiseCiphersTable) | + | |
| - | # Pairwise cipher for WPA (v1) (default: TKIP) | + | |
| - | wpa_pairwise=TKIP CCMP | + | |
| - | # Pairwise cipher for RSN/WPA2 (default: use wpa_pairwise value) | + | |
| - | rsn_pairwise=CCMP | + | |
| - | + | ||
| - | # Time interval for rekeying GTK (broadcast/ | + | |
| - | # seconds. (dot11RSNAConfigGroupRekeyTime) | + | |
| - | # | + | |
| - | + | ||
| - | # Rekey GTK when any STA that possesses the current GTK is leaving the BSS. | + | |
| - | # (dot11RSNAConfigGroupRekeyStrict) | + | |
| - | # | + | |
| - | # Time interval for rekeying GMK (master key used internally to generate GTKs | + | Lancement de hostapd en Wi-Fi N avec son fichier de configuration : |
| - | # (in seconds). | + | < |
| - | # | + | hostapd |
| - | + | ||
| - | # Maximum lifetime for PTK in seconds. This can be used to enforce rekeying of | + | |
| - | # PTK to mitigate some attacks against TKIP deficiencies. | + | |
| - | # | + | |
| - | + | ||
| - | # Enable IEEE 802.11i/RSN/WPA2 pre-authentication. This is used to speed up | + | |
| - | # roaming be pre-authenticating IEEE 802.1X/EAP part of the full RSN | + | |
| - | # authentication and key handshake before actually associating with a new AP. | + | |
| - | # (dot11RSNAPreauthenticationEnabled) | + | |
| - | # | + | |
| - | # | + | |
| - | # Space separated list of interfaces from which pre-authentication frames are | + | |
| - | # accepted (e.g., ' | + | |
| - | # interface that are used for connections to other APs. This could include | + | |
| - | # wired interfaces and WDS links. The normal wireless data interface towards | + | |
| - | # associated stations (e.g., wlan0) should not be added, since | + | |
| - | # pre-authentication is only used with APs other than the currently associated | + | |
| - | # one. | + | |
| - | # | + | |
| - | + | ||
| - | # peerkey: Whether PeerKey negotiation for direct links (IEEE 802.11e) is | + | |
| - | # allowed. This is only used with RSN/WPA2. | + | |
| - | # 0 = disabled (default) | + | |
| - | # 1 = enabled | + | |
| - | # | + | |
| - | + | ||
| - | # ieee80211w: Whether management frame protection (MFP) is enabled | + | |
| - | # 0 = disabled (default) | + | |
| - | # 1 = optional | + | |
| - | # 2 = required | + | |
| - | # | + | |
| - | + | ||
| - | # Association SA Query maximum timeout (in TU = 1.024 ms; for MFP) | + | |
| - | # (maximum time to wait for a SA Query response) | + | |
| - | # dot11AssociationSAQueryMaximumTimeout, | + | |
| - | # | + | |
| - | + | ||
| - | # Association SA Query retry timeout (in TU = 1.024 ms; for MFP) | + | |
| - | # (time between two subsequent SA Query requests) | + | |
| - | # dot11AssociationSAQueryRetryTimeout, | + | |
| - | # | + | |
| - | + | ||
| - | + | ||
| - | # okc: Opportunistic Key Caching (aka Proactive Key Caching) | + | |
| - | # Allow PMK cache to be shared opportunistically among configured interfaces | + | |
| - | # and BSSes (i.e., all configurations within a single | + | |
| - | # 0 = disabled (default) | + | |
| - | # 1 = enabled | + | |
| - | #okc=1 | + | |
| </ | </ | ||
| - | |||
| - | |||
| ===== Création d'un point d' | ===== Création d'un point d' | ||
| - | Cette exemple vous permettra de créer un point d' | + | Cet exemple vous permettra de créer un point d' |
| + | |||
| + | {{: | ||
| '' | '' | ||
| Ligne 349: | Ligne 261: | ||
| Ce type de configuration WI-Fi permet à des adaptateurs WI-Fi installés sur des périphériques, | Ce type de configuration WI-Fi permet à des adaptateurs WI-Fi installés sur des périphériques, | ||
| + | ==== Configuration de l' | ||
| + | |||
| + | Il nous faut activer l' | ||
| + | |||
| + | < | ||
| + | sudo ifconfig wlan0 down | ||
| + | sudo ifconfig wlan0 192.168.0.1 netmask 255.255.255.0 up | ||
| + | </ | ||
| + | |||
| + | ==== Configuration du daemon hostapd | ||
| + | |||
| + | Lancement du daemon hostapd avec son fichier de configuration pointant sur l' | ||
| + | < | ||
| + | sudo hostapd / | ||
| + | </ | ||
| ==== Configuration Dhcpd Serveur ==== | ==== Configuration Dhcpd Serveur ==== | ||
| Ligne 354: | Ligne 281: | ||
| La création d'un point d' | La création d'un point d' | ||
| - | Le fichier de configuration /etc/dhcpd3/dhcpd.conf | + | Le fichier de configuration /etc/dhcp/dhcpd.conf |
| < | < | ||
| Ligne 376: | Ligne 303: | ||
| </ | </ | ||
| - | Lancement de dhcpd-server : | + | Lancement de dhcpd-server : |
| < | < | ||
| - | dhcpd3 | + | sudo dhcpd -d -f -pf /var/run/dhcp-server/ |
| </ | </ | ||
| ==== Configuration Dnsmasq Serveur ==== | ==== Configuration Dnsmasq Serveur ==== | ||
| - | Notre sous-réseau étant créé, il ne reste plus qu'à configurer un serveur de cache DNS sur notre interface, qui transformera toute demande d'un domaine en adresse Ip. | + | Notre sous-réseau étant créé, il ne reste plus qu'à configurer un serveur de cache DNS sur notre interface, qui transformera toute demande d'un domaine en adresse Ip. |
| Attention notre DNS ne fait que lire le fichier '/ | Attention notre DNS ne fait que lire le fichier '/ | ||
| Ligne 400: | Ligne 327: | ||
| Bien que dnsmasq puisse distribuer des adresses IP d'un sous-réseau, | Bien que dnsmasq puisse distribuer des adresses IP d'un sous-réseau, | ||
| - | Lancement de dnsmasq : | + | Lancement de dnsmasq : |
| < | < | ||
| - | dnsmasq -x / | + | sudo dnsmasq -x / |
| </ | </ | ||
| ==== Configuration de IP forwarding ==== | ==== Configuration de IP forwarding ==== | ||
| - | Notre interface wlan nouvellement créée a besoin de communiquer avec notre seconde interface ayant Internet, nous devons configurer l'IP forwarding. | + | Notre interface wlan nouvellement créée a besoin de communiquer avec notre seconde interface ayant Internet, nous devons configurer l'IP forwarding. |
| Activez la prise en charge de l'IP forwarding, pour faire suivre les paquets d'une interface à l' | Activez la prise en charge de l'IP forwarding, pour faire suivre les paquets d'une interface à l' | ||
| Ligne 418: | Ligne 345: | ||
| Ou bien si vous voulez rendre cela permanent : | Ou bien si vous voulez rendre cela permanent : | ||
| - | Editez | + | Éditez |
| < | < | ||
| # Uncomment the next line to enable packet forwarding for IPv4 | # Uncomment the next line to enable packet forwarding for IPv4 | ||
| Ligne 426: | Ligne 353: | ||
| ==== Configuration de la Mascarade & du Firewall ==== | ==== Configuration de la Mascarade & du Firewall ==== | ||
| - | Notre sous-réseau 192.168.0.0/ | + | Notre sous-réseau 192.168.0.0/ |
| Pour traduire des adresses entre deux interfaces nous devons activer le masquerading (NAT/ | Pour traduire des adresses entre deux interfaces nous devons activer le masquerading (NAT/ | ||
| Ligne 433: | Ligne 360: | ||
| < | < | ||
| - | === Configuration du Firewall avec iptable | + | === Configuration du Firewall avec iptables |
| Activer la mascarade sur l' | Activer la mascarade sur l' | ||
| Ligne 447: | Ligne 374: | ||
| < | < | ||
| - | === Configuration du Firewall avec Ufw === | + | === Configuration du Firewall avec Ufw === |
| - | + | ||
| + | En premier lieux, il faut changer la règle par défaut du transfert de paquets d'une interface à l' | ||
| + | Editer le fichier / | ||
| + | < | ||
| Editer le fichier / | Editer le fichier / | ||
| < | < | ||
| Ligne 454: | Ligne 385: | ||
| </ | </ | ||
| - | Editer | + | Éditer |
| | | ||
| - | Juste après l' | + | Juste après l' |
| < | < | ||
| # nat Table rules | # nat Table rules | ||
| Ligne 469: | Ligne 400: | ||
| </ | </ | ||
| - | Dans la section *filter ajoutez : | + | Dans la section *filter ajoutez : |
| < | < | ||
| -A ufw-before-forward -m state --state RELATED, | -A ufw-before-forward -m state --state RELATED, | ||
| Ligne 489: | Ligne 420: | ||
| Fichier bash wifi_ap.sh | Fichier bash wifi_ap.sh | ||
| - | < | + | < |
| #!/bin/bash | #!/bin/bash | ||
| # | # | ||
| - | # | + | # |
| #Optionnel: paquet macchanger optionnel | #Optionnel: paquet macchanger optionnel | ||
| #Auteur: Nexus6[at]altern.org 01.12.2010 | #Auteur: Nexus6[at]altern.org 01.12.2010 | ||
| - | ### WARNING : kill hostapd dnsmasq & dhcpd3 | + | ### WARNING : kill hostapd dnsmasq & dhcpd à la fin... |
| # Configuration des interfaces | # Configuration des interfaces | ||
| Ligne 524: | Ligne 455: | ||
| #Mode Debug Dhcp ? | #Mode Debug Dhcp ? | ||
| DBG=" | DBG=" | ||
| - | #DBG="" | + | DBG="" |
| Ligne 556: | Ligne 487: | ||
| fi | fi | ||
| - | dhcpd3=$(which | + | dhcpd3=$(which |
| if [ $? != 0 ] | if [ $? != 0 ] | ||
| then | then | ||
| Ligne 577: | Ligne 508: | ||
| sudo $macchanger --random $INT_WIFI $NC | sudo $macchanger --random $INT_WIFI $NC | ||
| fi | fi | ||
| - | |||
| echo -e $blue" | echo -e $blue" | ||
| Ligne 594: | Ligne 524: | ||
| sleep 1 | sleep 1 | ||
| - | echo -e $blue" | + | echo -e $blue" |
| - | # start or resart | + | # start or resart |
| - | sudo touch /var/lib/dhcp3/ | + | sudo touch /var/lib/dhcp/ |
| - | #sudo mkdir -p /var/run/dhcp3-server | + | #sudo mkdir -p /var/run/dhcp-server |
| - | #sudo chown dhcpd:dhcpd /var/run/dhcp3-server | + | #sudo chown dhcpd:dhcpd /var/run/dhcp-server |
| - | sudo dhcpd3 | + | sudo dhcpd $DBG -f -pf /var/run/dhcp-server/ |
| - | #/ | + | #/ |
| sleep 2 | sleep 2 | ||
| Ligne 611: | Ligne 541: | ||
| sudo iptables -A POSTROUTING -t nat -o $INT_NET -j MASQUERADE | sudo iptables -A POSTROUTING -t nat -o $INT_NET -j MASQUERADE | ||
| - | echo -e $blue" | + | echo -e $blue" |
| sudo iptables -A FORWARD --match state --state RELATED, | sudo iptables -A FORWARD --match state --state RELATED, | ||
| sudo iptables -A FORWARD -i $INT_WIFI --destination $SUBNET --match state --state NEW --jump ACCEPT | sudo iptables -A FORWARD -i $INT_WIFI --destination $SUBNET --match state --state NEW --jump ACCEPT | ||
| Ligne 618: | Ligne 548: | ||
| # Wait user interaction !!! | # Wait user interaction !!! | ||
| echo -e $redhl" | echo -e $redhl" | ||
| - | echo -e $redhl" | + | echo -e $redhl" |
| echo -e $redhl" | echo -e $redhl" | ||
| echo -e $redhl" | echo -e $redhl" | ||
| Ligne 624: | Ligne 554: | ||
| - | echo -e $cyan" | + | echo -e $cyan" |
| - | # kill hostapd, dnsmasq & dhcpd3 | + | # kill hostapd, dnsmasq & dhcpd |
| - | sudo killall hostapd dnsmasq | + | sudo killall hostapd dnsmasq |
| echo -e $cyan" | echo -e $cyan" | ||
| sudo iptables -D POSTROUTING -t nat -o $INT_NET -j MASQUERADE 2>/ | sudo iptables -D POSTROUTING -t nat -o $INT_NET -j MASQUERADE 2>/ | ||
| Ligne 634: | Ligne 564: | ||
| echo -e $cyan" | echo -e $cyan" | ||
| - | # interface | + | # interface |
| sudo ifconfig $INT_WIFI down | sudo ifconfig $INT_WIFI down | ||
| + | sudo ifconfig $INT_WIFI up | ||
| # Turn off IP forwarding | # Turn off IP forwarding | ||
| Ligne 647: | Ligne 578: | ||
| ./ | ./ | ||
| </ | </ | ||
| + | |||
| + | Si pendant l’exécution du script précédent vous obtenez l' | ||
| + | ", exécuter ou rajouter la commande suivante en début de script : | ||
| + | < | ||
| == Monitoring AP == | == Monitoring AP == | ||
| - | L' | + | L' |
| < | < | ||
| watch -d -n 3 "iw dev wlan0 station dump; iwconfig wlan0; iwconfig mon.wlan0; iw dev wlan6 station dump; iwconfig wlan6;cat / | watch -d -n 3 "iw dev wlan0 station dump; iwconfig wlan0; iwconfig mon.wlan0; iw dev wlan6 station dump; iwconfig wlan6;cat / | ||
| Ligne 661: | Ligne 596: | ||
| * http:// | * http:// | ||
| * http:// | * http:// | ||
| - | * http:// | + | * https:// |
| - | + | * http:// | |
| - | Création par [[utilisateurs:Nexus6]] | + | |
| + | ---- | ||
| + | // | ||
