wifi: Combining open non-encrypted AP and EAP-TLS in one



Hi:

I have got the idea that I want to set up a hostap on my FBSD box.

My idea is that I want to allow strangers to associate and get their network configuration via dhcp. Any attempt to access the Internet will then be redirected to a web page explaining that they have to register first.

Once registered, the AP should support (or rather require) EAP-TLS and allow access to the Internet.

I know, this sounds very much like VPN. Indeed it is, (and I might fall back on this). But the difference is that it is bound to a particular wireless network. Users may connect to other networks where all this is not required. So for usability I think it is easier if the wifi controller takes care of connecting with the correct certificate.

So, my first question: Is it possible to configure a Wireless NIC in hostap mode to support both non-encrypted open association as well as EAP-TLS (or some other type of encryption/authentication scheme)?

Secondly, is it possible to make the firewall (on the the hostap box) aware of whether a client uses security and only allow access if the wireless connection is encrypted? I use packet filter, and this is somewhat like authpf w. ssh that can invoke rules, or it could be solved with the traditional VPN. But I would like to use the EAP-TLS scheme.

Thanks, Erik
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: ath vap - second hostap _almost_ works
    ... I am able to create and configure the wlan1 interface and clients can see the SSID and associate to the network. ... The problem seems to follow the second hostap device configured. ... IEEE 802.11 Wireless Ethernet autoselect mode 11g ...
    (freebsd-current)
  • 2.6.x wireless update and status
    ... I also wanted to comment on the general status and direction of wireless. ... Use HostAP as the basis for a wireless stack that can drive "softMAC" ... fix Kconfig typos and missing select CRYPTO ... o Host AP: Updated to use Linux wireless extensions v17 ...
    (Linux-Kernel)
  • ath vap - second hostap _almost_ works
    ... I'm trying to set up a second access point for an "insecure" network. ... able to create and configure the wlan1 interface and clients can see the ... The problem seems to follow the second hostap device configured (e.g. ...
    (freebsd-current)
  • 54mbit 80211g atheros w/obsd
    ... Running linux w/latest madwifi and hostap for a ... wireless access-point and have tried old and new versions of madwifi, hostapd, ... Is obsd's atheros drivers and hostap known to work well, give strong signals, ...
    (comp.unix.bsd.openbsd.misc)
  • Re: uCLinux on Samsung S3C4510B (ARM7TDMI) based wireless router
    ... > but wlan-ng had already droped it for a while...only hostap still. ... > If those wireless chip companies don't release their AP firmware, ... The PCMCIA wireless card in this router is in fact a Prism 2, ... know if I can only get Linux into the router firmware, ...
    (comp.os.linux.embedded)