LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux > Linux - Networking > Linux - Wireless Networking
User Name
Password
Linux - Wireless Networking This forum is for the discussion of wireless networking in Linux.

Notices

Tags used in this thread
Popular LQ Tags , , , , , , , , ,

Reply
 
Thread Tools
Old 07-23-2006, 12:21 PM   #1
jogress
LQ Newbie
 
Registered: Sep 2003
Posts: 8
Thanked: 0
Intercept 802.3 packets on egress and redirect until tagged


[Log in to get rid of this advertisement]
Hello,

I've moved into a giant mill building and wish to consider offering free internet to the unwashed masses. Yes, I know this sounds foolish and possibly even legally insane, but I absolve anyone from their advice.

However, the cynic in me knows that people are often bad, and so before allowing the optimist in me to offer forth this splendor of free internet (via 802.11something, of course), I wish to redirect any new MAC address first to a webpage on my linux NAT router, with the usual blurbs, "I promise I will not kill anyone". A checkbox and submit button later, and they're allowed to continue on.

The web part is obviously fairly easy. Assuming I know how to tag a MAC address as "good" or "bad" at the userlevel, how might I do the redirect at layer 2?

So people are going to be coming in through the wifi bridge. They spit out onto my lan with their own MAC (or maybe they aggregate through something before getting to me. Either way, it's granular to the apartment, and apartments have only a person or two, so I don't care). If the MAC address is not in a list, anything on the web needs to go to a local IP. Anything not on the web just doesn't work. Once they view the page and submit, their MAC gets into the system and all of a sudden they can browse the web (for a while). The other things still stay magically unavailable, though. Web only is fair.

A DNS approach won't work, because they could just use their own DNS, even if I assigned them the IP via DHCP (which I'll have to). Which makes it tricky, with the limited scope of how to tackle this I have.

So, the obvious foolishness aside, does anyone have any ideas how I could implement this?

Thanks!
jogress is offline  
Tag This Post , , , , , , , , ,
Reply With Quote
Old 07-27-2006, 06:32 PM   #2
jogress
LQ Newbie
 
Registered: Sep 2003
Posts: 8
Thanked: 0

Original Poster
yeah, i answered this one for myself too


http://www.ex-parrot.com/~pete/upside-down-ternet.html
jogress is offline     Reply With Quote

Reply

Bookmarks


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
iptables:redirect ports except for packets destined for fierwall(upto 256 ip) itself mmshekiba Linux - Security 1 02-02-2006 01:08 PM
OMfG TAGGED Lebanese Disease General 2 08-17-2005 04:41 PM
Egress filtering scorbett Linux - Security 2 11-03-2004 12:15 PM
RedHat 8.0 with 802.11a 802.11b and 802.11g Bryanx Linux - Hardware 2 05-23-2003 03:12 AM
aic7xxx tagged queue option. jgmarce Linux - Hardware 2 02-24-2003 10:58 AM


All times are GMT -5. The time now is 01:18 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
RSS2  LQ Podcast
RSS2  LQ Radio
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration