2 ###############################################################################
4 # IPFire.org - A linux based firewall #
5 # Copyright (C) 2012 IPFire Network Development Team #
7 # This program is free software: you can redistribute it and/or modify #
8 # it under the terms of the GNU General Public License as published by #
9 # the Free Software Foundation, either version 3 of the License, or #
10 # (at your option) any later version. #
12 # This program is distributed in the hope that it will be useful, #
13 # but WITHOUT ANY WARRANTY; without even the implied warranty of #
14 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15 # GNU General Public License for more details. #
17 # You should have received a copy of the GNU General Public License #
18 # along with this program. If not, see <http://www.gnu.org/licenses/>. #
20 ###############################################################################
22 HOSTAPD_CONTROL_INTERFACE_DIR
="/run/hostapd/ctrl"
24 HOSTAPD_SUPPORTED_MODES
="802.11a 802.11a/n 802.11ac 802.11g 802.11g/n"
26 hostapd_config_write
() {
33 # Shift the device and file argument.
38 local channel_bandwidth
39 local country_code
="$(wireless_get_reg_domain)"
42 local environment
="${WIRELESS_DEFAULT_ENVIRONMENT}"
49 while [ $# -gt 0 ]; do
52 broadcast_ssid
=$
(cli_get_val
"${1}")
55 channel
=$
(cli_get_val
"${1}")
57 --channel-bandwidth=*)
58 channel_bandwidth
="$(cli_get_val "${1}")"
61 dfs
="$(cli_get_val "${1}")"
64 encryption
=$
(cli_get_val
"${1}")
67 environment
="$(cli_get_val "${1}")"
70 key
=$
(cli_get_val
"${1}")
73 mfp
="$(cli_get_val "${1}")"
76 mode
=$
(cli_get_val
"${1}")
78 if ! isoneof mode
${HOSTAPD_SUPPORTED_MODES}; then
79 error
"Unsupported mode: ${mode}"
84 ssid
=$
(cli_get_val
"${1}")
87 local val
="$(cli_get_val "${1}")"
95 warning_log
"Ignoring unknown argument '${1}'."
101 # Check if mode is set
102 if ! isset mode
; then
103 error
"Mode is not set"
107 assert isset broadcast_ssid
108 assert isbool broadcast_ssid
111 assert isinteger channel
116 # Check if key is set when encryption is used.
117 if isset encryption
; then
118 assert isoneof encryption WPA WPA2 WPA
/WPA2
122 # Check wireless environment
123 if ! wireless_environment_is_valid
"${environment}"; then
124 error
"Invalid wireless environment: ${environment}"
128 # With channel 0, ACS must be supported
129 if [ ${channel} -eq 0 ] && ! wireless_supports_acs
"${device}"; then
130 error
"ACS requested, but not supported by ${device}"
134 # Check channel bandwidth for validity
135 if isset channel_bandwidth
&& ! wireless_channel_bandwidth_is_valid
"${mode}" "${channel_bandwidth}"; then
136 error
"Invalid channel bandwidth for ${mode}: ${channel_bandwidth}"
140 # Management Frame Proection
141 if ! isbool mfp
; then
142 error
"Invalid value for --mfp: ${mfp}"
150 local vht_oper_chwidth
="0"
164 ht_caps
="$(wireless_get_ht_caps "${device}")"
176 ht_caps
="$(wireless_get_ht_caps "${device}")"
185 vht_caps
="$(wireless_get_vht_caps "${device}")"
188 ht_caps
="$(wireless_get_ht_caps "${device}")"
190 case "${channel_bandwidth}" in
204 # Create configuration directory.
205 local config_dir
=$
(dirname ${file})
206 mkdir
-p ${HOSTAPD_CONTROL_INTERFACE_DIR} ${config_dir} 2>/dev
/null
208 config_header
"hostapd" > ${file}
210 # Interface configuration
212 print
"# Interface configuration"
213 print
"driver=nl80211"
214 print
"interface=${device}"
218 # Wireless configuration
219 local ignore_broadcast_ssid
220 if enabled broadcast_ssid
; then
221 ignore_broadcast_ssid
="0"
223 ignore_broadcast_ssid
="1"
227 # Advertise country code and maximum transmission power
229 print
"country_code=${country_code}"
231 # Wireless Environment
232 case "${environment}" in
234 print
"country3=0x49"
238 print
"country3=0x4f"
241 print
"country3=0x20"
245 # Always advertise TPC
246 print
"local_pwr_constraint=3"
247 print
"spectrum_mgmt_required=1"
249 # Enable Radar Detection
250 if enabled dfs
&& wireless_supports_dfs
"${device}"; then
258 print
"# Wireless configuration"
259 print
"hw_mode=${hw_mode}"
261 if isset ieee80211ac
; then
262 print
"ieee80211ac=${ieee80211ac}"
265 if isset ieee80211n
; then
266 print
"ieee80211n=${ieee80211n}"
269 print
"channel=${channel}"
270 print
"ignore_broadcast_ssid=${ignore_broadcast_ssid}"
272 print
"ssid2=\"${ssid}\""
275 # Kick stations that are too far away
276 print
"disassoc_low_ack=1"
278 # WMM & WMM-PS Unscheduled Automatic Power Save Delivery
279 print
"wmm_enabled=${wmm}"
280 print
"uapsd_advertisement_enabled=1"
282 # Low Priority / AC_BK = Background
283 print
"wmm_ac_bk_cwmin=4"
284 print
"wmm_ac_bk_cwmax=10"
285 print
"wmm_ac_bk_aifs=7"
286 print
"wmm_ac_bk_txop_limit=0"
287 print
"wmm_ac_bk_acm=0"
288 print
"tx_queue_data3_aifs=7"
289 print
"tx_queue_data3_cwmin=15"
290 print
"tx_queue_data3_cwmax=1023"
291 print
"tx_queue_data3_burst=0"
293 # Normal Priority / AC_BE = Best Effort
294 print
"wmm_ac_be_aifs=3"
295 print
"wmm_ac_be_cwmin=4"
296 print
"wmm_ac_be_cwmax=10"
297 print
"wmm_ac_be_txop_limit=0"
298 print
"wmm_ac_be_acm=0"
299 print
"tx_queue_data2_aifs=3"
300 print
"tx_queue_data2_cwmin=15"
301 print
"tx_queue_data2_cwmax=63"
302 print
"tx_queue_data2_burst=0"
304 # High Priority / AC_VI = Video
305 print
"wmm_ac_vi_aifs=2"
306 print
"wmm_ac_vi_cwmin=3"
307 print
"wmm_ac_vi_cwmax=4"
308 print
"wmm_ac_vi_txop_limit=94"
309 print
"wmm_ac_vi_acm=0"
310 print
"tx_queue_data1_aifs=1"
311 print
"tx_queue_data1_cwmin=7"
312 print
"tx_queue_data1_cwmax=15"
313 print
"tx_queue_data1_burst=3.0"
315 # Highest Priority / AC_VO = Voice
316 print
"wmm_ac_vo_aifs=2"
317 print
"wmm_ac_vo_cwmin=2"
318 print
"wmm_ac_vo_cwmax=3"
319 print
"wmm_ac_vo_txop_limit=47"
320 print
"wmm_ac_vo_acm=0"
321 print
"tx_queue_data0_aifs=1"
322 print
"tx_queue_data0_cwmin=3"
323 print
"tx_queue_data0_cwmax=7"
324 print
"tx_queue_data0_burst=1.5"
327 if isset vht_caps
; then
328 print
"vht_capab=${vht_caps}"
332 print
"ht_capab=${ht_caps}"
335 print
"vht_oper_chwidth=${vht_oper_chwidth}"
339 # 802.11w - Management Frame Protection (MFP)
341 print
"ieee80211w=2" # required
349 print
"# Control interface"
350 print
"ctrl_interface=${HOSTAPD_CONTROL_INTERFACE_DIR}"
351 print
"ctrl_interface_group=0"
355 # Encryption settings
356 if isset encryption
; then
357 local encryption_mode
=0
358 case "${encryption}" in
371 print
"# Encryption settings"
372 print
"wpa=${encryption_mode}"
373 print
"wpa_passphrase=${key}"
374 print
"wpa_key_mgmt=WPA-PSK"
375 print
"wpa_pairwise=TKIP"
376 print
"rsn_pairwise=CCMP"
388 service_start
"hostapd@${device}.service"
391 if [ ${ret} -eq ${EXIT_OK} ]; then
392 log DEBUG
"hostapd has been successfully started on '${device}'"
394 log ERROR
"Could not start hostapd on '${device}': ${ret}"
405 service_stop
"hostapd@${device}.service"