![]() |
ubuntu.com - launchpad.net - ubuntu help
|
|
|||||||
|
Networking & Wireless Having problems getting connected to the internet or getting your wireless card to work? Ask here. |
|
|
Thread Tools | Display Modes |
|
|
#1 | |||||||||||||||||||||
|
Himbeer Brombeer Macchiato
![]() Join Date: May 2006
Location: 100acrewood
Beans: 7,262
Kubuntu 9.10 Karmic Koala
|
HOWTO: Wireless Security - WPA1, WPA2, LEAP, etc.
This guide was tested with Dapper Drake, Feisty Fawn, Gutsy Gibbon, and Hardy Heron.
-- Since it appears that very few people take wireless security seriously, I'd like to come up with my first HOWTO and explain how I was able to configure a secure home network using WPA2, the latest encryption & authentication standard. There are also other types of configuration (WPA1, mixed mode, LEAP, PEAP, DHCP, etc.) shown in the appendix. Feedback is much appreciated. Common stumbling blocks - Make sure that: 1. Ethernet cable is unplugged. 2. No firewall & configuration tool is running (e.g. Firestarter). 3. MAC filtering is disabled. 4. NetworkManager, Wifi-Radar & similar wireless configuration tools are disabled/turned off and not in use. 5. Some cards/drivers (e.g. Madwifi) do not support WPA2 (AES). Try WPA1 (TKIP) if WPA2 secured connections fail. 6. RTxxx (Ralink) drivers do not support this approach. Either install "ndiswrapper" replacing Serialmonkey's driver or visit this site. 7. Turn off "roaming" if you repeatedly fail to establish a connection. My Requirements: 1. WPA2 / RSN 2. AES / CCMP 3. Hidden ESSID (no broadcast) 4. Static IP (because I use port forwarding & firewall, etc.) 5. Pre-shared key (no EAP) If you want to know more about WPA / RSN & 802.11i security specification, I recommend this site. Now let's get started: 0. Install "wpa-supplicant": Quote:
Quote:
Quote:
2. Open "/etc/network/interfaces": Quote:
Quote:
Quote:
Now convert your WPA ASCII password using the following command: Quote:
Quote:
Quote:
*****************************Revoking read-permission from 'others'********************************* Quote:
*****************************Sample configuration WPA2 & DHCP, ESSID broadcast enabled*************** Quote:
*****************************Sample configuration WPA1 & DHCP, ESSID broadcast enabled*************** Quote:
****************************Sample configuration mixed mode (WPA1, WPA2) & DHCP, ESSID broadcast***** Quote:
****************************Sample conf. LEAP, WEP, DHCP, ESSID broadcast*************************** Quote:
****************************Sample conf. PEAP, AES, DHCP, ESSID broadcast*************************** Quote:
*****************************Sample conf. TTLS, WEP, DHCP, ESSID broadcast************************** Quote:
*****************************NOT TESTED: Sample conf. EAP-FAST, WPA1/WPA2, DHCP, ESSID broadcast**** Quote:
*****************************Tested adapters****************************************** ********* Quote:
*****************************Post this if you are stumped****************************************** Quote:
*****************************Other useful commands****************************************** *** Quote:
CHANGE LOG: 08/11/2006: Added section "Post this if you are stumped" (SquibT). 08/11/2006: Added sample configuration for WPA2 with DHCP & ESSID broadcast (Wieman01). 08/11/2006: Added sample configuration for WPA1 with DHCP & ESSID broadcast (Wieman01). 08/11/2006: Added section "Tested adapters" (Wieman01). 08/11/2006: Added section "Useful commands" (SquibT). 08/11/2006: Added section "Common stumbling blocks" (Wieman01). 08/11/2006: Changed section "wpa-driver" and added new drivers (Wieman01). 08/11/2006: Added section "Revoking read-permission from group 'others'" (Wieman01). 09/11/2006: Minor changes in layout (Wieman01). 09/11/2006: Added sample configuration for mixed mode (WPA1, WPA2) with DHCP & ESSID broadcast (Wieman01). 09/11/2006: Added experimental sample configuration for LEAP with WEP, DHCP & ESSID broadcast (Wieman01). 09/11/2006: Added section "Install wpa-supplicant" (Wieman01). 10/11/2006: Added experimental sample configuration for TTLS with WEP, DHCP & ESSID broadcast (Wieman01). 15/11/2006: Added experimental sample configuration for EAP-FAST with WPA1/WPA2, DHCP & ESSID broadcast (Wieman01). 04/12/2006: Changed "wpa_passphrase" section & added quotes ("") for encryption keys containing special characters (Wieman01). 04/01/2007: Added various security options (Wieman01). 15/01/2007: Added valid script for EAP-LEAP (Wieman01). 31/01/2007: Added valid script for EAP-PEAP (Wieman01). 21/04/2007: Removed "wpa-conf" for Edgy Eft (Wieman01). 22/04/2007: Simplified section concerning static network settings (Wieman01). 02/05/2007: Added note concerning WPA2 support for Atheros cards & drivers (Wieman01). 13/05/2007: Added note on Ralink drivers (Wieman01). 15/04/2008: Tested with Hardy Heron (Wieman01). Last edited by wieman01; June 1st, 2008 at 03:36 PM.. |
|||||||||||||||||||||
|
|
|
|
#2 |
|
Ubuntu French Roast
![]() Join Date: Jun 2005
Location: France
Beans: 6,385
Ubuntu 9.10 Karmic Koala
|
Re: HOWTO: Wireless Security - WPA1, WPA2, LEAP, etc.
PLease do not post here but in the thread linked below, no support will be given here
If you're looking for support about this tutorial here is the original thread : http://www.ubuntuforums.org/showthread.php?t=202834 Last edited by frodon; February 15th, 2007 at 04:01 AM.. |
|
|
| Bookmarks |
| Thread Tools | |
| Display Modes | |
|
|