Changes

From SME Server
Jump to navigationJump to search
651 bytes added ,  10:43, 7 March 2012
m
Line 3: Line 3:     
===Maintainer===
 
===Maintainer===
[[User:VIP-ire|Daniel B.]]<br/>
+
[mailto:daniel@firewall-services.com[[User:VIP-ire|Daniel B.]]] from [http://www.firewall-services.com Firewall Services]
[http://www.firewall-services.com Firewall Services]<br>
  −
mailto:daniel@firewall-services.com
      
=== Version ===
 
=== Version ===
Line 58: Line 56:  
*Attach an AP
 
*Attach an AP
   −
The final step is to connect an AP on the NIC. I'm talking about a AP and not a router. If you have a WiFi router, it is possible to work if these conditions are met:
+
The final step is to connect an AP on the NIC. I'm talking about a AP and not a router. If you have a WiFi router, it is possible to make it work if these conditions are met:
    
**Dhcp is disabled on the router
 
**Dhcp is disabled on the router
Line 67: Line 65:     
*Login
 
*Login
Connect a client, and try to open a web page, you should fall on a page like this:
+
Connect a client, and try to open a web page, you should be redirected on a page like this one:
    
[[Image:ChilliLogin-noguest.jpg]]
 
[[Image:ChilliLogin-noguest.jpg]]
Line 98: Line 96:  
*'''net''': the network range to use. The server uses the first IP available from the network (and thus default 10.1.0.1) and provide clients with addresses in this range.
 
*'''net''': the network range to use. The server uses the first IP available from the network (and thus default 10.1.0.1) and provide clients with addresses in this range.
   −
*'''status''': there's no trap that defined the state of service, and whether it should be started when the server boots up.
+
*'''status''': there's no trap, this key defines the state of service, and whether it should be started when the server boots up.
    
*'''tundev''': defines the tun interface to use (chilli mask the real interface eth2 and the system sees the traffic as comming from a tun interface).
 
*'''tundev''': defines the tun interface to use (chilli mask the real interface eth2 and the system sees the traffic as comming from a tun interface).
 
By default, tun0, you can change if tun0 is already used for a VPN for example.
 
By default, tun0, you can change if tun0 is already used for a VPN for example.
 +
 +
*'''uamhomepage''': URL of homepage to redirect unauthenticated users to. If not specified this defaults to the login page
    
*'''uamallowed''': A list of host that will be accessible before authentication. It can be a simple list of host, or a list of the form host:port, or protocol:host, or protocol:host:port
 
*'''uamallowed''': A list of host that will be accessible before authentication. It can be a simple list of host, or a list of the form host:port, or protocol:host, or protocol:host:port
Line 123: Line 123:     
*'''guestUpLink''': if guestAccess is enabled, this will limit the uplink bandwidth for guest user (in kbps)
 
*'''guestUpLink''': if guestAccess is enabled, this will limit the uplink bandwidth for guest user (in kbps)
 +
 +
*'''noc2c''': can be enabled or disabled (default is enabled). If enabled, clients will get a /32 netmask, and a special route will be added so they can contact the gateway. This prevent direct client to client communication. Note that it's a layer 3 isolation, a better way to prevent client to client is a layer 2 isolation, some AP and switch provides this.
 +
 +
*'''macallowed''': A comma separated list of MAC addresses which won't need to authenticate
    
After you've changed the configuration, just run the command  
 
After you've changed the configuration, just run the command  
Line 225: Line 229:     
*AllowedOutgoing will allow more outgoing traffic. It's a list of proto/host/port clients will be able to contact on the internet (These rules only apply to forwarded traffic, nothing will be allowed to the private network). Wildcard '*' (or keyword 'any') can replace host or port. Eg:
 
*AllowedOutgoing will allow more outgoing traffic. It's a list of proto/host/port clients will be able to contact on the internet (These rules only apply to forwarded traffic, nothing will be allowed to the private network). Wildcard '*' (or keyword 'any') can replace host or port. Eg:
  db configuration setprop AllowedOutgoing tcp:56.23.41.1:25,udp:*:1194,tcp:4.5.6.7:any,tcp:any:123
+
  db configuration setprop chilli AllowedOutgoing tcp:56.23.41.1:25,udp:*:1194,tcp:4.5.6.7:any,tcp:any:123
    
This will allow:
 
This will allow:
Line 265: Line 269:  
----
 
----
 
[[Category:Contrib]]
 
[[Category:Contrib]]
 +
[[Category:Administration:Remote Access]]

Navigation menu