![]() |
ubuntu.com - launchpad.net - ubuntu help
|
|
|||||||
|
Tutorials & Tips The place to find Ubuntu related Tips & Tricks. |
| View Poll Results: Has this thread been helpful? | |||
| Yes |
|
498 | 68.50% |
| No |
|
92 | 12.65% |
| Somewhat |
|
137 | 18.84% |
| Voters: 727. You may not vote on this poll | |||
|
|
Thread Tools | Display Modes |
|
|
#1 | ||||||||||||||||||||
|
Himbeer Brombeer Macchiato
![]() Join Date: May 2006
Location: 100acrewood
Beans: 7,262
Kubuntu 9.10 Karmic Koala
|
HOWTO: Wireless Security - WPA1, WPA2, LEAP, etc.
This guide was tested with:
Gutsy Gibbon (7.10) Hardy Heron (8.04) Intrepid Ibex (8.10) Jaunty Jackalope (9.04) -- Since it appears that very few people take wireless security seriously, I'd like to come up with my first HOWTO and explain how I was able to configure a secure home network using WPA2, the latest encryption & authentication standard. There are also other types of configuration (WPA1, mixed mode, LEAP, PEAP, DHCP, etc.) shown in the appendix. Feedback is much appreciated. Common stumbling blocks - Make sure that: 1. Ethernet cable is unplugged. 2. No firewall & configuration tool is running (e.g. Firestarter). 3. MAC filtering is disabled. 4. NetworkManager, Wifi-Radar & similar wireless configuration tools are disabled/turned off and not in use. 5. Some cards/drivers (e.g. Madwifi) do not support WPA2 (AES). Try WPA1 (TKIP) if WPA2 secured connections fail. 6. Set router to BG-Only if using ndiswrapper (and perhaps Broadcom 43xx as I don't know about others). My Requirements: 1. WPA2 / RSN 2. AES / CCMP 3. Hidden ESSID (no broadcast) 4. Static IP (because I use port forwarding & firewall, etc.) 5. Pre-shared key (no EAP) If you want to know more about WPA / RSN & 802.11i security specification, I recommend this site. Now let's get started (wpa-suplicant is usually installed by default): 0. Install "wpa-supplicant": Quote:
Quote:
Quote:
2. Open "/etc/network/interfaces": Quote:
Quote:
Quote:
Now convert your WPA ASCII password using the following command: Quote:
Quote:
Quote:
*****************************Revoking read-permission from 'others'********************************* Quote:
*****************************Sample configuration WPA2 & DHCP, ESSID broadcast enabled*************** Quote:
*****************************Sample configuration WPA1 & DHCP, ESSID broadcast enabled*************** Quote:
****************************Sample configuration mixed mode (WPA1, WPA2) & DHCP, ESSID broadcast***** Quote:
****************************Sample conf. LEAP, WEP, DHCP, ESSID broadcast*************************** Quote:
****************************Sample conf. PEAP, AES, DHCP, ESSID broadcast*************************** Quote:
*****************************Sample conf. TTLS, WEP, DHCP, ESSID broadcast************************** Quote:
*****************************NOT TESTED: Sample conf. EAP-FAST, WPA1/WPA2, DHCP, ESSID broadcast**** Quote:
*****************************Tested adapters****************************************** ********* Quote:
*****************************Post this if you are stumped****************************************** Quote:
*****************************Other useful commands****************************************** *** Quote:
CHANGE LOG: 08/11/2006: Added section "Post this if you are stumped" (SquibT). 08/11/2006: Added sample configuration for WPA2 with DHCP & ESSID broadcast (Wieman01). 08/11/2006: Added sample configuration for WPA1 with DHCP & ESSID broadcast (Wieman01). 08/11/2006: Added section "Tested adapters" (Wieman01). 08/11/2006: Added section "Useful commands" (SquibT). 08/11/2006: Added section "Common stumbling blocks" (Wieman01). 08/11/2006: Changed section "wpa-driver" and added new drivers (Wieman01). 08/11/2006: Added section "Revoking read-permission from group 'others'" (Wieman01). 09/11/2006: Minor changes in layout (Wieman01). 09/11/2006: Added sample configuration for mixed mode (WPA1, WPA2) with DHCP & ESSID broadcast (Wieman01). 09/11/2006: Added experimental sample configuration for LEAP with WEP, DHCP & ESSID broadcast (Wieman01). 09/11/2006: Added section "Install wpa-supplicant" (Wieman01). 10/11/2006: Added experimental sample configuration for TTLS with WEP, DHCP & ESSID broadcast (Wieman01). 15/11/2006: Added experimental sample configuration for EAP-FAST with WPA1/WPA2, DHCP & ESSID broadcast (Wieman01). 04/12/2006: Changed "wpa_passphrase" section & added quotes ("") for encryption keys containing special characters (Wieman01). 04/01/2007: Added various security options (Wieman01). 15/01/2007: Added valid script for EAP-LEAP (Wieman01). 31/01/2007: Added valid script for EAP-PEAP (Wieman01). 21/04/2007: Removed "wpa-conf" for Edgy Eft (Wieman01). 22/04/2007: Simplified section concerning static network settings (Wieman01). 02/05/2007: Added note concerning WPA2 support for Atheros cards & drivers (Wieman01). 13/05/2007: Added note on Ralink drivers (Wieman01). 15/04/2008: Tested with HardyHeron (Wieman01). 04/09/2008: Added note on wireless B/G/N (Wieman01). 06/12/2008: Note for Intrepid Ibex users (Wieman01). 07/03/2009: Closed thread (Wieman01). 05/04/2009: Re-opened and enhanced thread (Wieman01). Last edited by wieman01; May 8th, 2009 at 01:29 PM.. |
||||||||||||||||||||
|
|
|
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|