Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #181784 > unrolled thread

pointers to material for using netbook's wireless as access point

Started byJoel Rees <joel.rees@gmail.com>
First post2017-06-06 04:00 +0200
Last post2017-06-07 07:10 +0200
Articles 14 — 4 participants

Back to article view | Back to linux.debian.user


Contents

  pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-06 04:00 +0200
    Re: pointers to material for using netbook's wireless as access point didier gaumet <didier.gaumet@gmail.com> - 2017-06-06 09:20 +0200
      Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-07 07:10 +0200
        Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-08 02:30 +0200
          Re: pointers to material for using netbook's wireless as access point didier gaumet <didier.gaumet@gmail.com> - 2017-06-08 10:10 +0200
            Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-08 16:10 +0200
              Re: pointers to material for using netbook's wireless as access point rhkramer@gmail.com - 2017-06-08 16:50 +0200
                Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-10 06:10 +0200
                  Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-10 09:00 +0200
              Re: pointers to material for using netbook's wireless as access point didier gaumet <didier.gaumet@gmail.com> - 2017-06-08 20:40 +0200
                Re: pointers to material for using netbook's wireless as access point Dan Ritter <dsr@randomstring.org> - 2017-06-08 20:50 +0200
          Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-08 16:00 +0200
    Re: pointers to material for using netbook's wireless as access point Dan Ritter <dsr@randomstring.org> - 2017-06-06 12:40 +0200
      Re: pointers to material for using netbook's wireless as access point Joel Rees <joel.rees@gmail.com> - 2017-06-07 07:10 +0200

#181784 — pointers to material for using netbook's wireless as access point

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-06 04:00 +0200
Subjectpointers to material for using netbook's wireless as access point
Message-ID<tPbWN-2eo-1@gated-at.bofh.it>
I've seen a lot of answers that say "NOT POSSIBLE!!", as if the device
manufacturers really want us to believe that it can only be done on
MSWindows and MacOSX.

I've seen a bit of talk about what appears to me to be the reverse of what I
want to do -- allow other computers to connect via the netbook's ethernet
port and piggyback the netbook's wireless onto the web. That's not what
I want to do.

I've got brctl and hostapd installed and have tried some
configurations I've seen. I keep getting blocked, apparently by
RF-kill and/or something
else that tells me it's not allowed.

So, before I dump all my configuration files and error messages on the
list, can anyone point me to a good how-to? I want to make sure I'm not
missing something obvious before I start asking questions.

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [next] | [standalone]


#181791

Fromdidier gaumet <didier.gaumet@gmail.com>
Date2017-06-06 09:20 +0200
Message-ID<tPgWu-5BA-31@gated-at.bofh.it>
In reply to#181784
Le 06/06/2017 à 03:58, Joel Rees a écrit :
[...]
can anyone point me to a good how-to?
[...]

these should do the trick:
https://agentoss.wordpress.com/2011/10/31/creating-a-wireless-access-point-with-debian-linux/
https://wiki.archlinux.org/index.php/Software_access_point
http://oob.freeshell.org/nzwireless/LWAP-HOWTO.html

[toc] | [prev] | [next] | [standalone]


#181868

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-07 07:10 +0200
Message-ID<tPBoe-2ah-5@gated-at.bofh.it>
In reply to#181791
On Tue, Jun 6, 2017 at 4:10 PM, didier gaumet <didier.gaumet@gmail.com> wrote:
> Le 06/06/2017 à 03:58, Joel Rees a écrit :
> [...]
> can anyone point me to a good how-to?
> [...]
>
> these should do the trick:
> https://agentoss.wordpress.com/2011/10/31/creating-a-wireless-access-point-with-debian-linux/
> https://wiki.archlinux.org/index.php/Software_access_point
> http://oob.freeshell.org/nzwireless/LWAP-HOWTO.html
>

I'd thought I was recognized the URLs as some I had looked at before,
but I check now and see lots of useful information. Thanks.

I'll probably have more questions when I've had a chance to work through
them.

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [prev] | [next] | [standalone]


#181905

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-08 02:30 +0200
Message-ID<tPTuN-5p2-9@gated-at.bofh.it>
In reply to#181868
On Wed, Jun 7, 2017 at 2:08 PM, Joel Rees <joel.rees@gmail.com> wrote:
> On Tue, Jun 6, 2017 at 4:10 PM, didier gaumet <didier.gaumet@gmail.com> wrote:
>> Le 06/06/2017 à 03:58, Joel Rees a écrit :
>> [...]
>> can anyone point me to a good how-to?
>> [...]
>>
>> these should do the trick:
>> https://agentoss.wordpress.com/2011/10/31/creating-a-wireless-access-point-with-debian-linux/
>> https://wiki.archlinux.org/index.php/Software_access_point
>> http://oob.freeshell.org/nzwireless/LWAP-HOWTO.html
>>
>
> I'd thought I was recognized the URLs as some I had looked at before,
("had recognized" or maybe "was recognizing", erk)
> but I check now and see lots of useful information. Thanks.
>
> I'll probably have more questions when I've had a chance to work through
> them.

Okay, I have partial success. My kids can connect via wireless, but I can't
connect on the netbook in question, at all.

First thing I did was install rfkill and use it to undo whatever had the thing
believing I'd shut the wireless down by hand or something:

---------------------------
$sudo rfkill list all
0: phy0: Wireless LAN
    Soft blocked: yes
    Hard blocked: no
1: ideapad_wlan: Wireless LAN
    Soft blocked: yes
    Hard blocked: yes

$sudo rfkill unblock wifi

$sudo rfkill unblock all

$sudo rfkill list all
0: phy0: Wireless LAN
    Soft blocked: no
    Hard blocked: no
1: ideapad_wlan: Wireless LAN
    Soft blocked: no
    Hard blocked: no
---------------------------

My /etc/hostapd/hostapd.conf is below, along with one of the
/etc/network/interfaces files I've tried. This combination allows my children
to access the internet from my netbook's wifi, through my netbook's ethernet,
to the provider's modem. I cannot access the internet on the same
netbook. (It only has one ethernet port.

DHCP from the modem is routed through the
wireless to the children's

Should I just remove networkmanager from the system, or should I try
to solve this by the NAT approach (which I still am working through).

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html





clients:

---------------------hostapd.conf----------------
### Wireless network name ###
interface=wlan0

### Driver Name ###
driver=nl80211

### Set your bridge name ###
bridge=br0

### Country name code in ISO/IEC 3166-1 format. ###
# This is used to set regulatory domain.
# Set as needed to indicate country in which device is operating.
# This can limit available channels and transmit power.
### (IN == INDIA, UK == United Kingdom, US == United Stats and so on ) ###
country_code=JP

### SSID: ###
ssid=StuporInducingNetwork

### channel number (some drivers will only accept 0) ###
channel=1

### operation mode (a = IEEE 802.11a, b = IEEE 802.11b, g = IEEE 802.11g) ###
hw_mode=g
ieee80211n=1
ht_capab=[HT40+][SHORT-GI-40][DSSS_CCK-40]

### WPA mode: ###
wpa=2

### passphrase (WiFi password): ###
wpa_passphrase=something!wouldn0t$#0wHER3

## Key management algorithms ##
wpa_key_mgmt=WPA-PSK

## Set cipher suites (encryption algorithms) ##
## TKIP = Temporal Key Integrity Protocol
## CCMP = AES in Counter mode with CBC-MAC
wpa_pairwise=TKIP
rsn_pairwise=CCMP
## Shared Key Authentication ##
auth_algs=1
## Accept all MAC address ###
macaddr_acl=0

-------------------------------------------------------

-------------------interfaces-v1------------------------
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo br0
#auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
#iface eth0 inet dhcp
# iface eth0 inet static
iface eth0:0 inet manual

iface eth0:1 inet static
     address 172.19.138.147
    netmask 255.255.255.128
    gateway 172.19.138.179
    broadcast 172.19.138.191
#
dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4



wireless wlan0
allow-hotplug wlan0
#iface wlan0 inet static
iface wlan0 inet manual

# Setup bridge
iface br0 inet manual
    bridge_ports wlan0 eth0:0
    address 172.19.138.177
    netmask 255.255.255.192
    network 172.19.138.160
    broadcast 172.19.138.191
## isp router 172.19.138.179 also runs DHCPD ##
    gateway 172.19.138.179
    dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4
-------------------------------------------------------------

This next interfaces file tries to make the default route explicit, but gives
similar results:

-------------------interfaces-v2------------------------
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo br0
#auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
#iface eth0 inet dhcp
# iface eth0 inet static

iface eth0 inet static
     address 172.19.138.147
    netmask 255.255.255.192
    gateway 172.19.138.179
    up route add -net default gw 172.19.138.179
    down route del -net default gw 172.19.138.179
    broadcast 172.19.138.191
iface eth0:1 inet manual
#
dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4

wireless wlan0
allow-hotplug wlan0
#iface wlan0 inet static
iface wlan0 inet manual

# Setup bridge
iface br0 inet manual
    bridge_ports wlan0 eth0:1
    address 172.19.138.177
    netmask 255.255.255.192
    network 172.19.138.160
    broadcast 172.19.138.191
## isp router 172.19.138.179 also runs DHCPD ##
    gateway 172.19.138.179
    dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4
-------------------------------------------------------------

Simply commenting out the bridge allows my netbook to access the
interent:

-------------------interfaces-holdoff-----------------
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).

# The loopback network interface
auto lo br0
#auto lo
iface lo inet loopback

# The primary network interface
allow-hotplug eth0
#iface eth0 inet dhcp
# iface eth0 inet static

iface eth0 inet static
     address 172.19.138.147
    netmask 255.255.255.192
    gateway 172.19.138.179
    up route add -net default gw 172.19.138.179
    down route del -net default gw 172.19.138.179
    broadcast 172.19.138.191
#iface eth0:1 inet manual
#
dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4


wireless wlan0
#allow-hotplug wlan0
#iface wlan0 inet static
iface wlan0 inet manual

# Setup bridge
#iface br0 inet manual
#    bridge_ports wlan0 eth0:1
#    address 172.19.138.177
#    netmask 255.255.255.192
#    network 172.19.138.160
#    broadcast 172.19.138.191
## isp router 172.19.138.179 also runs DHCPD ##
#    gateway 172.19.138.179
#    dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4
------------------------------------------------------------

Should I just remove networkmanager from the system, or should I try
to solve this by the NAT approach (which I still am working through
the reading on). Ultimately, I want to NAT the wireless anyway.

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [prev] | [next] | [standalone]


#181913

Fromdidier gaumet <didier.gaumet@gmail.com>
Date2017-06-08 10:10 +0200
Message-ID<tQ0FX-1HV-1@gated-at.bofh.it>
In reply to#181905
Le 08/06/2017 à 02:29, Joel Rees a écrit :

[...]
> # Setup bridge
> iface br0 inet manual
>     bridge_ports wlan0 eth0:0
[...]

I am sorry, network wise, I am a true dumb, so I cannot be of a great
help, but:

- the Archlinux wiki indicates that the wireless interface should not be
added to the bridge in the bridge configuration, being already attached
to it in the hostapd configuration.
- you could look at the ethernet-wireless bridge section of the Debian
wiki wich points at routing differences with ethernet bridges:
 https://wiki.debian.org/BridgeNetworkConnections#Bridging_with_a_wireless_NIC

[toc] | [prev] | [next] | [standalone]


#181931

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-08 16:10 +0200
Message-ID<tQ6in-5iV-57@gated-at.bofh.it>
In reply to#181913
On Thu, Jun 8, 2017 at 5:03 PM, didier gaumet <didier.gaumet@gmail.com> wrote:
> Le 08/06/2017 à 02:29, Joel Rees a écrit :
>
> [...]
>> # Setup bridge
>> iface br0 inet manual
>>     bridge_ports wlan0 eth0:0
> [...]
>
> I am sorry, network wise, I am a true dumb, so I cannot be of a great
> help, but:
>
> - the Archlinux wiki indicates that the wireless interface should not be
> added to the bridge in the bridge configuration, being already attached
> to it in the hostapd configuration.
> - you could look at the ethernet-wireless bridge section of the Debian
> wiki wich points at routing differences with ethernet bridges:
>  https://wiki.debian.org/BridgeNetworkConnections#Bridging_with_a_wireless_NIC
>

Maybe I'm misunderstanding that wiki, but it seems to be describing this
kind of setup:

   WAN <--> foreign AP <-wireless-> debian box <-> more devices

But what I'm wanting is

   WAN <-wired-> router/modem <-wired-> debian netbook AP <-> more devices

(But thanks for taking the time to mention that page.)

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [prev] | [next] | [standalone]


#181932

Fromrhkramer@gmail.com
Date2017-06-08 16:50 +0200
Message-ID<tQ6V4-5vT-17@gated-at.bofh.it>
In reply to#181931
On Thursday, June 08, 2017 10:00:17 AM Joel Rees wrote:
> Maybe I'm misunderstanding that wiki, but it seems to be describing this
> kind of setup:
> 
>    WAN <--> foreign AP <-wireless-> debian box <-> more devices
> 
> But what I'm wanting is
> 
>    WAN <-wired-> router/modem <-wired-> debian netbook AP <-> more devices

Thank you for including the above "sketch" which finally let me understand what 
you are looking for. 

 I doubt that I can help, but I'll think about it--my setup is somewhat 
similar to what you describe except that the "debian notebook AP" is replaced 
by a commericial wireless AP (but, as your sketch shows, wired to my router / 
modem).

Aside: I wouldn't think it should be very difficult, since it seems to be off-
the-shelf functionality you can buy, but ...

[toc] | [prev] | [next] | [standalone]


#181992

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-10 06:10 +0200
Message-ID<tQFSO-2gd-3@gated-at.bofh.it>
In reply to#181932
I posted the following to Randy, yesterday, intending it to go to the list.
I'll post it back to the list (with Randy's permission), with a bit of further
comment:

> On Friday, June 09, 2017 02:14:17 AM Joel Rees wrote:
>> (With aplogies for html mail)
>>
>> 2017/06/08 23:46 <rhkramer@gmail.com>:
>> > On Thursday, June 08, 2017 10:00:17 AM Joel Rees wrote:
>> > > Maybe I'm misunderstanding that wiki, but it seems to be describing
>> > > this
>> > >
>> > > kind of setup:
>> > >    WAN <--> foreign AP <-wireless-> debian box <-> more devices
>> > >
>> > > But what I'm wanting is
>> > >
>> > >    WAN <-wired-> router/modem <-wired-> debian netbook AP <-> more
>>
>> devices
>>
>> > Thank you for including the above "sketch" which finally let me
>>
>> understand what
>>
>> > you are looking for.
>> >
>> >  I doubt that I can help, but I'll think about it--my setup is somewhat
>> >
>> > similar to what you describe except that the "debian notebook AP" is
>>
>> replaced
>>
>> > by a commericial wireless AP (but, as your sketch shows, wired to my
>>
>> router /
>>
>> > modem).
>> >
>> > Aside: I wouldn't think it should be very difficult, since it seems to be
>>
>> off-
>>
>> > the-shelf functionality you can buy, but ...
>>
>> Thanks for looking at it.
>>
>> Just for the record, I am presently typing on my tablet, connected wireless
>> through the
>> software AP in the netbook (which is the reason for the html). It's
>> transparent, so the
>> modem at the wall sees it as if the wireless is an extension of the modem's
>> (wired)
>> network.

And this is kind of tricky, because it seems to be a bit dependent on the
weather, whether it works or no.

Or, rather, I have since installed dnsmasq and removed and re-installed
network-manager (stupid thing gets in the way), and I'm not connecting
any more.

>> What I'm trying to get is connection on the netbook itself. I can't even
>> ping the modem
>> from the netbook, because the bridge owns the netbook's only ethernet port.
>> So I can't
>> work on anything that requires the network while the kids are playing.
>>
>> I read hints here and there about how to do it, but I keep hitting walls.
>> (And learning
>> things. :)
>>
>> I had it serving dhcp and dns over the wireless a bit back, but I couldn't
>> get outside the
>> modem with either the wireless or the netbook. That was not, of course,
>> bridged. I think.

I was able to confirm that it was bridged.

>> 8-/
>>
>> It would be cheaper, time-wise, to buy a portable access point, of course,
>> and I will probably do so.
>> But I'm finally getting an idea of how a bridge really works, so it's also
>> worth the
>> education.
>>
>> Joel Rees

Randy replied,

On Fri, Jun 9, 2017 at 9:43 PM,  <rhkramer@gmail.com> wrote:
> This provides me with even more understanding of what you're looking for and
> the problems you're having--up until I read this, I didn't understand that (1)
> the netbook is already working "properly" as a wireless access point (in that
> your tablet wirelessly connects via it), but (2) the problem is that the
> netbook apparently can't be used simultaneously as a WAP and to provide its
> own connection to the Internet.
>
> I would suggest that you post this to the list--I think others may have the
> same misunderstanding as to your goal and the current problem, and once
> understanding this, may be able to help you.
>
> If you want, I can post it to the list as well.
>
> I would tend to say that your problem is not a common problem, so I suspect
> most documentation won't be helpful.  I also tend to doubt that you want the
> netbook to be in bridge mode, but I don't know that for sure.  IIRC (and I
> can't easily check at the moment), I believe my (commercial) WAP is working as
> a full fledged router, in the sense that it creates a new network (with a
> different IP address and provides DHCP functionality).  I'll have to turn my
> WAP on later and see what IP address my phone gets to see if it is on my "main
> LAN" (i.e., wired) or if it is an IP on a different network.
>
> Good luck,
> Randy Kramer
>

Indeed, that's what I want to do. But I'm not smart enough to set the wireless
up myself, so I was hoping hostapd would do that.

On Fri, Jun 9, 2017 at 10:30 PM,  <rhkramer@gmail.com> wrote:
> Update: I just turned on my WAP and my cell phone, and found that the cell
> phone gets an IP address in the 10. network (specifically, in this case
> 10.0.0.2), while my "main" (wired) LAN is on the 192.168.1 network (the server
> is 192.168.1.1), thus confirming my suspicion that the WAP is not in bridge
> mode, but is a "full" network server with services such as DHCP.

That is the usual case for portable access points in Japan. (And, unless you
ask, they don't tell you that you can log into the admin page and set the
number of devices that can connect wirelessly to the AP.)

> I guess if you're in bridge mode, the IP address of your tablet is coming from
> your modem / router.

That is correct. It was getting addresses in the range the wall modem was
providing. A couple of time it got addresses in the range that my netbook
was providing (dhcpd), but I wasn't serving dns through the port. Apparently,
it was not routing to the modem. (I don't have enough working computers to
check the connections any more, and the kids don't like me to take theirs
over to test things.)

> Digression: I actually usually have my DSL modem in bridge mode so that the
> next  device in my network string (a Ubiquity router) actually serves as the
> network server (with DHCP and such).  While in bridge mode, the DSL modem is
> pretty dumb--I can't connect to it or such.  When I have troubles with my
> Earthlink ISP, they typically want me to switch back out of bridge mode to
> (they think) help with diagnosis.  (Aside / rant: In no case have my troubles
> with Earthlink been inside my network, they have always been external, one way
> or another, but Earthlink likes to assume that the trouble is inside my
> network.  What a PITA.)

(Until we get Microsoft -- and now Google? -- to quit wanting to sell us the
privilege of helping ourselves, we won't have enough people in customer
service who really know what they are doing to avoid this kind of two-step
dance they want to do, I think.)

> Also, bridge mode in networking may have two slight different meanings
> depending on the context--I don't think I can articulate that very well.
> Putting my DSL modem in bridge mode makes it pretty much a dumb box, passing
> Internet traffic thru to my Ubiquity router (in both directions)--at that time,
> the Ubiquity router is the "brain" of my network.  Ubiquity also has a means
> to set some sort of bridge mode for devices or networks downstream of it, but
> I don't really know what that does, but it seems a little different than the
> bridge mode of the DSL modem.  (I've never experimented with it, or maybe only
> enough to realize it was not what I needed.)

There definitely seem to be both blind and intelligent bridges.

When I was reading about the split horizon yesterday, I was wondering
whether bridges could actually be used by the computer they are
connected to, but, if that were the case, hostapd could not really work
at all. I think.

It may be that I will have to go down to the coding level, or give it up.

And then I figured out, this morning, that something is preventing me
from configuring the NIC's network as precisely as I am trying to do.
Maybe that's the re-installed network-manager.

-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [prev] | [next] | [standalone]


#181997

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-10 09:00 +0200
Message-ID<tQIxj-3IT-7@gated-at.bofh.it>
In reply to#181992
I now have connection for both the wireless and the netbook that is acting
as the AP. I took out the bridge entirely, quit trying to play with
port forwarding,
just used dead simple setup. dnsmasq was the only missing piece, if I had
not been focusing on bridging.  Bridging is probably for the other direction.

But the wireless is pretty slow, so I'm not sure I'm finished.

I have to go take care of some family business, when I'm done I'll
post the details.

But it's really pretty simply. I was just working too hard.

--
Joel Rees

Randomly ranting:
http://reiisi.blogspot.com

[toc] | [prev] | [next] | [standalone]


#181948

Fromdidier gaumet <didier.gaumet@gmail.com>
Date2017-06-08 20:40 +0200
Message-ID<tQavE-7Na-3@gated-at.bofh.it>
In reply to#181931
Le 08/06/2017 à 16:00, Joel Rees a écrit :
> On Thu, Jun 8, 2017 at 5:03 PM, didier gaumet <didier.gaumet@gmail.com> wrote:
[...]
>>  https://wiki.debian.org/BridgeNetworkConnections#Bridging_with_a_wireless_NIC
> 
> Maybe I'm misunderstanding that wiki, but it seems to be describing this
> kind of setup:
> 
>    WAN <--> foreign AP <-wireless-> debian box <-> more devices
>
> But what I'm wanting is
> 
>    WAN <-wired-> router/modem <-wired-> debian netbook AP <-> more devices
> 
> (But thanks for taking the time to mention that page.)

I think it can be understood either way, so it seems to me it is
applicable the way you want it (the way I had already understood it)?
I suppose the one thing you probably do not have to bother with is
ebtables because you establish a bridge between an ethernet NIC and a
software AP NIC, not between an ethernet NIC and a wireless client NIC.

To summarize I would suggest to:
- not include wlan0 in /etc/interfaces because wlan0 is already declared
in hosapd.conf and that could interfere
- not include "pre-up iwconfig wlan0 essid $YOUR_ESSID" in the bridge
section of /etc/interfaces because it is probably relevant for  a
wireless client but irrelevant for an AP
- include "bridge_hw $MAC_ADDRESS_OF_YOUR_WIRELESS_CARD"  in the bridge
section of /etc/interfaces

(All of this being pure supposition of my part as I am almost ignorant
of the network things: do not assume what I am saying is correct without
verification)

[toc] | [prev] | [next] | [standalone]


#181951

FromDan Ritter <dsr@randomstring.org>
Date2017-06-08 20:50 +0200
Message-ID<tQaFk-7QA-13@gated-at.bofh.it>
In reply to#181948
On Thu, Jun 08, 2017 at 08:31:04PM +0200, didier gaumet wrote:
> Le 08/06/2017 à 16:00, Joel Rees a écrit :
> > On Thu, Jun 8, 2017 at 5:03 PM, didier gaumet <didier.gaumet@gmail.com> wrote:
> [...]
> >>  https://wiki.debian.org/BridgeNetworkConnections#Bridging_with_a_wireless_NIC
> > 
> > Maybe I'm misunderstanding that wiki, but it seems to be describing this
> > kind of setup:
> > 
> >    WAN <--> foreign AP <-wireless-> debian box <-> more devices
> >
> > But what I'm wanting is
> > 
> >    WAN <-wired-> router/modem <-wired-> debian netbook AP <-> more devices
> > 
> > (But thanks for taking the time to mention that page.)
> 
> I think it can be understood either way, so it seems to me it is
> applicable the way you want it (the way I had already understood it)?
> I suppose the one thing you probably do not have to bother with is
> ebtables because you establish a bridge between an ethernet NIC and a
> software AP NIC, not between an ethernet NIC and a wireless client NIC.
> 
> To summarize I would suggest to:
> - not include wlan0 in /etc/interfaces because wlan0 is already declared
> in hosapd.conf and that could interfere
> - not include "pre-up iwconfig wlan0 essid $YOUR_ESSID" in the bridge
> section of /etc/interfaces because it is probably relevant for  a
> wireless client but irrelevant for an AP
> - include "bridge_hw $MAC_ADDRESS_OF_YOUR_WIRELESS_CARD"  in the bridge
> section of /etc/interfaces
> 
> (All of this being pure supposition of my part as I am almost ignorant
> of the network things: do not assume what I am saying is correct without
> verification)

Once you have br0 controlling wlan0 and eth0, all routing
decisions need to be applied to br0.

-dsr-

[toc] | [prev] | [next] | [standalone]


#181928

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-08 16:00 +0200
Message-ID<tQ68I-50i-77@gated-at.bofh.it>
In reply to#181905
A little more detail, with the following pair of configurations, I get
on the boot console,

   Configuring network interfaces...can't add wlan0 to bridge br0:
Operation not supported
   SIOCSIFFLAGS: Cannot assign requested address
   SIOCSIFFLAGS: Cannot assign requested address

   Waiting for br0 to get ready (MAXWAIT is 32 seconds).

And another couple of messages I didn't get pictures of, including one
apparently from the driver, about the file already existing, and
another
probably from the kernel about not being able to set up the bridge. I think
it was the following, but I couldn't get a picture of it:

   RTNETLINK answers: File exists
   Failed to bring up [was it eth0 or br0?].

(And, yet, the bridge was set up and functional, even to routing the
DHCP handshake. It was only the netbook's inability to access the
internet through its own ethernet port that left me needing a better
solution.)

Those messages, by the way, were not recorded in any file under
/var/log. The only way to capture them was by taking a picture.

On Thu, Jun 8, 2017 at 9:29 AM, Joel Rees <joel.rees@gmail.com> wrote:
> [...]
>
> ---------------------hostapd.conf----------------
> ### Wireless network name ###
> interface=wlan0
>
> ### Driver Name ###
> driver=nl80211
>
> ### Set your bridge name ###
> bridge=br0
>
> ### Country name code in ISO/IEC 3166-1 format. ###
> # This is used to set regulatory domain.
> # Set as needed to indicate country in which device is operating.
> # This can limit available channels and transmit power.
> ### (IN == INDIA, UK == United Kingdom, US == United Stats and so on ) ###
> country_code=JP
>
> ### SSID: ###
> ssid=StuporInducingNetwork
>
> ### channel number (some drivers will only accept 0) ###
> channel=1
>
> ### operation mode (a = IEEE 802.11a, b = IEEE 802.11b, g = IEEE 802.11g) ###
> hw_mode=g
> ieee80211n=1
> ht_capab=[HT40+][SHORT-GI-40][DSSS_CCK-40]
>
> ### WPA mode: ###
> wpa=2
>
> ### passphrase (WiFi password): ###
> wpa_passphrase=something!wouldn0t$#0wHER3
>
> ## Key management algorithms ##
> wpa_key_mgmt=WPA-PSK
>
> ## Set cipher suites (encryption algorithms) ##
> ## TKIP = Temporal Key Integrity Protocol
> ## CCMP = AES in Counter mode with CBC-MAC
> wpa_pairwise=TKIP
> rsn_pairwise=CCMP
> ## Shared Key Authentication ##
> auth_algs=1
> ## Accept all MAC address ###
> macaddr_acl=0
>
> -------------------------------------------------------
>[...]
> -------------------interfaces-v2------------------------
> # This file describes the network interfaces available on your system
> # and how to activate them. For more information, see interfaces(5).
>
> # The loopback network interface
> auto lo br0
> #auto lo
> iface lo inet loopback
>
> # The primary network interface
> allow-hotplug eth0
> #iface eth0 inet dhcp
> # iface eth0 inet static
>
> iface eth0 inet static
>      address 172.19.138.147
>     netmask 255.255.255.192
>     gateway 172.19.138.179
>     up route add -net default gw 172.19.138.179
>     down route del -net default gw 172.19.138.179
>     broadcast 172.19.138.191
> iface eth0:1 inet manual
> #
> dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4
>
> wireless wlan0
> allow-hotplug wlan0
> #iface wlan0 inet static
> iface wlan0 inet manual
>
> # Setup bridge
> iface br0 inet manual
>     bridge_ports wlan0 eth0:1
>     address 172.19.138.177
>     netmask 255.255.255.192
>     network 172.19.138.160
>     broadcast 172.19.138.191
> ## isp router 172.19.138.179 also runs DHCPD ##
>     gateway 172.19.138.179
>     dns-nameservers 172.19.138.179 208.67.222.222 8.8.4.4
> -------------------------------------------------------------
>[...]



-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

[toc] | [prev] | [next] | [standalone]


#181801

FromDan Ritter <dsr@randomstring.org>
Date2017-06-06 12:40 +0200
Message-ID<tPk42-7uB-11@gated-at.bofh.it>
In reply to#181784
On Tue, Jun 06, 2017 at 10:58:09AM +0900, Joel Rees wrote:
> I've seen a lot of answers that say "NOT POSSIBLE!!", as if the device
> manufacturers really want us to believe that it can only be done on
> MSWindows and MacOSX.
> 
> I've seen a bit of talk about what appears to me to be the reverse of what I
> want to do -- allow other computers to connect via the netbook's ethernet
> port and piggyback the netbook's wireless onto the web. That's not what
> I want to do.
> 
> I've got brctl and hostapd installed and have tried some
> configurations I've seen. I keep getting blocked, apparently by
> RF-kill and/or something
> else that tells me it's not allowed.
> 
> So, before I dump all my configuration files and error messages on the
> list, can anyone point me to a good how-to? I want to make sure I'm not
> missing something obvious before I start asking questions.

Depends on the wifi chipset. Some are deliberately disabled by
their manufacturer from acting in "infrastructure mode", which
is to say, as an access point.

Here's how to tell:

sudo iwconfig wlan1 mode master

will put it into infrastructure mode if it can *and you have an
older chip*

or

sudo iw list

will show "AP" as an available mode on newer chips.


brctl and hostapd are the right way to go. RF-kill
is sometimes in hardware (physical switch) and sometimes in
software (package rfkill is available starting in Wheezy).

-dsr-

[toc] | [prev] | [next] | [standalone]


#181867

FromJoel Rees <joel.rees@gmail.com>
Date2017-06-07 07:10 +0200
Message-ID<tPBod-2ah-1@gated-at.bofh.it>
In reply to#181801
On Tue, Jun 6, 2017 at 7:30 PM, Dan Ritter <dsr@randomstring.org> wrote:
> On Tue, Jun 06, 2017 at 10:58:09AM +0900, Joel Rees wrote:
>> I've seen a lot of answers that say "NOT POSSIBLE!!", as if the device
>> manufacturers really want us to believe that it can only be done on
>> MSWindows and MacOSX.
>>
>> I've seen a bit of talk about what appears to me to be the reverse of what I
>> want to do -- allow other computers to connect via the netbook's ethernet
>> port and piggyback the netbook's wireless onto the web. That's not what
>> I want to do.
>>
>> I've got brctl and hostapd installed and have tried some
>> configurations I've seen. I keep getting blocked, apparently by
>> RF-kill and/or something
>> else that tells me it's not allowed.
>>
>> So, before I dump all my configuration files and error messages on the
>> list, can anyone point me to a good how-to? I want to make sure I'm not
>> missing something obvious before I start asking questions.
>
> Depends on the wifi chipset. Some are deliberately disabled by
> their manufacturer from acting in "infrastructure mode", which
> is to say, as an access point.
>
> Here's how to tell:
>
> sudo iwconfig wlan1 mode master

Error for wireless request "Set Mode" (8B06) :
    SET failed on device wlan0 ; Invalid argument.

But, without "master",

wlan0     IEEE 802.11bgn  ESSID:off/any
          Mode:Managed  Access Point: Not-Associated   Tx-Power=off
          Retry  long limit:7   RTS thr=2347 B   Fragment thr:off
          Encryption key:off
          Power Management:on


> will put it into infrastructure mode if it can *and you have an
> older chip*
>
> or
>
> sudo iw list

    Supported interface modes:
         * IBSS
         * managed
         * AP
         * AP/VLAN
         * monitor
    software interface modes (can always be added):
         * AP/VLAN
         * monitor
    interface combinations are not supported

I'll paste in the rest below, just in case.

> will show "AP" as an available mode on newer chips.
>
>
> brctl and hostapd are the right way to go.

If I only knew what to do with them. ;-/

It seems like my goal would be to set up a brdge, or perhaps
(according to some of the things I read) routing with NAT, and to set
up the netbook as a DHCP server for the wireless network. Am I
thinking in the right direction, there?

> RF-kill
> is sometimes in hardware (physical switch) and sometimes in
> software (package rfkill is available starting in Wheezy).

Would the rfkill package be useful to install if the messages I get about rfkill
include "hard blocked"?

> -dsr-

And, something I keep wondering about, would ad hoc mode be a good
alternative to setting up an access point? I seem to remember using that,
perhaps in addition to sharing, on old Macs some fifteen our so years ago.


-- 
Joel Rees

One of these days I'll get someone to pay me
to design a language that combines the best of Forth and C.
Then I'll be able to leap wide instruction sets with a single #ifdef,
run faster than a speeding infinite loop with a #define,
and stop all integer size bugs with a bare cast.

More of my delusions:
http://reiisi.blogspot.com/2017/05/do-not-pay-modern-danegeld-ransomware.html
http://reiisi.blogspot.jp/p/novels-i-am-writing.html

-----------------------------
iw list output:

Wiphy phy0
    Band 1:
        Capabilities: 0x1862
            HT20/HT40
            Static SM Power Save
            RX HT20 SGI
            RX HT40 SGI
            No RX STBC
            Max AMSDU length: 7935 bytes
            DSSS/CCK HT40
        Maximum RX AMPDU length 65535 bytes (exponent: 0x003)
        Minimum RX AMPDU time spacing: 16 usec (0x07)
        HT TX/RX MCS rate indexes supported: 0-7, 32
        Frequencies:
            * 2412 MHz [1] (20.0 dBm)
            * 2417 MHz [2] (20.0 dBm)
            * 2422 MHz [3] (20.0 dBm)
            * 2427 MHz [4] (20.0 dBm)
            * 2432 MHz [5] (20.0 dBm)
            * 2437 MHz [6] (20.0 dBm)
            * 2442 MHz [7] (20.0 dBm)
            * 2447 MHz [8] (20.0 dBm)
            * 2452 MHz [9] (20.0 dBm)
            * 2457 MHz [10] (20.0 dBm)
            * 2462 MHz [11] (20.0 dBm)
            * 2467 MHz [12] (20.0 dBm)
            * 2472 MHz [13] (20.0 dBm)
            * 2484 MHz [14] (disabled)
        Bitrates (non-HT):
            * 1.0 Mbps
            * 2.0 Mbps
            * 5.5 Mbps
            * 11.0 Mbps
            * 6.0 Mbps
            * 9.0 Mbps
            * 12.0 Mbps
            * 18.0 Mbps
            * 24.0 Mbps
            * 36.0 Mbps
            * 48.0 Mbps
            * 54.0 Mbps
    max # scan SSIDs: 4
    max scan IEs length: 2257 bytes
    RTS threshold: 2347
    Coverage class: 0 (up to 0m)
    Supported Ciphers:
        * WEP40 (00-0f-ac:1)
        * WEP104 (00-0f-ac:5)
        * TKIP (00-0f-ac:2)
        * CCMP (00-0f-ac:4)
    Available Antennas: TX 0 RX 0
    Supported interface modes:
         * IBSS
         * managed
         * AP
         * AP/VLAN
         * monitor
    software interface modes (can always be added):
         * AP/VLAN
         * monitor
    interface combinations are not supported
    Supported commands:
         * new_interface
         * set_interface
         * new_key
         * new_beacon
         * new_station
         * new_mpath
         * set_mesh_params
         * set_bss
         * authenticate
         * associate
         * deauthenticate
         * disassociate
         * join_ibss
         * join_mesh
         * remain_on_channel
         * set_tx_bitrate_mask
         * action
         * frame_wait_cancel
         * set_wiphy_netns
         * set_channel
         * set_wds_peer
         * connect
         * disconnect
    Supported TX frame types:
         * IBSS: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90
0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
         * managed: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90
0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
         * AP: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90 0xa0
0xb0 0xc0 0xd0 0xe0 0xf0
         * AP/VLAN: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90
0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
         * mesh point: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80
0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
         * P2P-client: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80
0x90 0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
         * P2P-GO: 0x00 0x10 0x20 0x30 0x40 0x50 0x60 0x70 0x80 0x90
0xa0 0xb0 0xc0 0xd0 0xe0 0xf0
    Supported RX frame types:
         * IBSS: 0xd0
         * managed: 0x40 0xd0
         * AP: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
         * AP/VLAN: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0
         * mesh point: 0xb0 0xc0 0xd0
         * P2P-client: 0x40 0xd0
         * P2P-GO: 0x00 0x20 0x40 0xa0 0xb0 0xc0 0xd0

[toc] | [prev] | [standalone]


Back to top | Article view | linux.debian.user


csiph-web