Re: wifi public access

From: Jeff at NorrisTechs (jeff_at_norristechs.net)
Date: 09/27/05

  • Next message: LARRY C ISBELL: "Please reactivate your Yahoo! Groups account"
    Date: Tue, 27 Sep 2005 15:54:30 -0600
    To: Marcin Jessa <lists@yazzy.org>
    
    

    I believe you could use ipfilter or ipfirewall along with squid-cache
    (proxy) and Natd. All connections coming to the Internet would be
    picked up by the ipfilter rules and based on MAC, IP or other methods
    you would then forward to squid to proxy to the Internet, or redirect
    the connection to a sign up page. You then would need to have the web
    page update the ipfilter/ipfirewall rules and/or squid ruleset as well.

    I have seen several solutions from the users side, but not the from the
    admin site. Your access point would just need to be on with no WPA, WEP
    etc and sit between the WIFI zones and the proxy server allowing
    everything related to security to be setup on the BSD box(es).

    Just some ideas, hope the points you in the direction you wanted to.

    ------------------------------------------------------------------------

    */Jeff Norris/*
    /~ Web Hosting ~ VPN Solutions ~ Network Management ~
    Design, deploy, kick ass. /
    *N*orris*Techs* dot net
    http://www.norristechs.net
    *AOL IM or Yahoo IM: _ ntshelper _*

    Marcin Jessa wrote:

    >On Tue, 27 Sep 2005 13:24:21 -0700
    >Jim Pazarena <fisp@ccstores.com> wrote:
    >
    >
    >
    >>I distribute wifi internet to my customers via MAC
    >>authentication at the access point, and DHCP assignment
    >>from my server.
    >>
    >>I would like to offer "wide open" (no MAC authentication)
    >>at the access point, and have my server (somehow) permit
    >>the access, or re-direct non subscribers to a sign-up page.
    >>
    >>To provide service to the tourist traffic and non clients
    >>on a pay-per-go basis.
    >>
    >>What kind of software should I be looking for? It was suggested
    >>that non-clients get routed to a specific point. How would I
    >>accomplish this?
    >>
    >>
    >>
    >
    >You can use firewalling for that and redirect all unauthorized
    >clients to some site or local squid which can allow/disallow certain
    >domains with it's ACLs.
    >
    >The unauthorized users would get handed out their own network.
    >The access point would need to run some scripts to open firewall for
    >authorized MACs and the DHCP server would put authorized users to a
    >different DHCP class and give them a different IP range.
    >You could propably query your radius server and fetch all the MACs
    >there and open up your firewall for those MACs only.
    >
    >Cheers.
    >Marcin
    >
    >_______________________________________________
    >freebsd-isp@freebsd.org mailing list
    >http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    >To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"
    >
    >
    >
    >
    >
    _______________________________________________
    freebsd-isp@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-isp
    To unsubscribe, send any mail to "freebsd-isp-unsubscribe@freebsd.org"


  • Next message: LARRY C ISBELL: "Please reactivate your Yahoo! Groups account"

    Relevant Pages

    • Re: ISA Server Problems, please help
      ... Based on the rules you have listed, SecureNAT clients should only be allowed ... The All access rule for SBS Internet Users ... Web Proxy and/or Firewall Client ... > header to the publishing server instead of the actual one. ...
      (microsoft.public.windows.server.sbs)
    • [NT] Flaw in Winsock Proxy Service and ISA Firewall Service Can Cause Denial of Service
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Acceleration Server 2000 contain support for Windows Sockets ... proxy communications. ... communications requests for Internet applications in a Microsoft Windows ...
      (Securiteam)
    • Poor client web browsing performance
      ... I've switched all our users from an old proxy 2.0 server to ISA 2004, ... That DNS server is configured with the ISA server's internal NIC ... The first firewall policy rule is called "unrestricted internet ...
      (microsoft.public.isa.configuration)
    • Re: Need to Turn Off Proxy Server in SBS 4.5
      ... Issue is moving users from SBS 4.5 Domain to Active Directory Domain. ... Server is internal only...no outside web or ftp serving. ... proxy *would* work, ... internet access via integrated Proxy Server based on settings for each user ...
      (microsoft.public.backoffice.smallbiz)
    • Re: Need Help with OS X WormMalicious Code
      ... OSX Server or Apple Remote Desktop. ... Updates don't screw up Macs like they do PCs, ... can just hit "okay" once a month or so, then restart and you are done. ...
      (comp.sys.mac.advocacy)