]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/blame - html/cgi-bin/wlanap.cgi
suricata: Change midstream policy to "pass-flow"
[people/pmueller/ipfire-2.x.git] / html / cgi-bin / wlanap.cgi
CommitLineData
27731caa
CS
1#!/usr/bin/perl
2###############################################################################
3# #
4# IPFire.org - A linux based firewall #
82134432 5# Copyright (C) 2007-2021 IPFire Team <info@ipfire.org> #
27731caa
CS
6# #
7# This program is free software: you can redistribute it and/or modify #
8# it under the terms of the GNU General Public License as published by #
9# the Free Software Foundation, either version 3 of the License, or #
10# (at your option) any later version. #
11# #
12# This program is distributed in the hope that it will be useful, #
13# but WITHOUT ANY WARRANTY; without even the implied warranty of #
14# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the #
15# GNU General Public License for more details. #
16# #
17# You should have received a copy of the GNU General Public License #
18# along with this program. If not, see <http://www.gnu.org/licenses/>. #
19# #
20###############################################################################
21#
22# WLAN AP cgi based on wlanap.cgi written by Markus Hoffmann & Olaf Westrik
23#
24
25use strict;
26
27# enable only the following on debugging purpose
8aa49c15
CS
28#use warnings;
29#use CGI::Carp 'fatalsToBrowser';
27731caa
CS
30
31require '/var/ipfire/general-functions.pl';
32require '/var/ipfire/lang.pl';
33require '/var/ipfire/header.pl';
34
35my $debug = 0;
8c2f203c 36my $status = '';
27731caa 37my $errormessage = '';
3827d1f6
AM
38my $status_started = "<td align='center' bgcolor='${Header::colourgreen}'><font color='white'><strong>$Lang::tr{'running'}</strong></font></td>";
39my $status_stopped = "<td align='center' bgcolor='${Header::colourred}'><font color='white'><strong>$Lang::tr{'stopped'}</strong></font></td>";
40my $count=0;
41my $col='';
27731caa
CS
42# get rid of used only once warnings
43my @onlyonce = ( $Header::colourgreen, $Header::colourred );
44undef @onlyonce;
45
46my %selected=();
47my %checked=();
48my %color = ();
49my %mainsettings = ();
54359730
CS
50my %netsettings=();
51my %wlanapsettings=();
27731caa 52my $channel = '';
c3d9a16d 53my $country = '';
27731caa
CS
54my $txpower = '';
55
56&General::readhash("${General::swroot}/main/settings", \%mainsettings);
8186b372 57&General::readhash("/srv/web/ipfire/html/themes/ipfire/include/colors.txt", \%color);
54359730 58&General::readhash("/var/ipfire/ethernet/settings", \%netsettings);
27731caa 59
27731caa 60$wlanapsettings{'APMODE'} = 'on';
23e368ab 61$wlanapsettings{'ACTION'} = '';
92f2665d
CS
62$wlanapsettings{'MACMODE'} = '0';
63$wlanapsettings{'INTERFACE'} = '';
27731caa
CS
64$wlanapsettings{'SSID'} = 'IPFire';
65$wlanapsettings{'HIDESSID'} = 'off';
91197a3f 66$wlanapsettings{'ENC'} = 'wpa2'; # none / wpa1 /wpa2
27731caa 67$wlanapsettings{'TXPOWER'} = 'auto';
2bb836df 68$wlanapsettings{'CHANNEL'} = '6';
c3d9a16d 69$wlanapsettings{'COUNTRY'} = '00';
7d30ef24 70$wlanapsettings{'HW_MODE'} = 'g';
27731caa 71$wlanapsettings{'PWD'} = 'IPFire-2.x';
27731caa
CS
72$wlanapsettings{'SYSLOGLEVEL'} = '0';
73$wlanapsettings{'DEBUG'} = '4';
c17883fd 74$wlanapsettings{'DRIVER'} = 'NL80211';
6e346fe0 75$wlanapsettings{'HTCAPS'} = '';
f887bf5f 76$wlanapsettings{'VHTCAPS'} = '';
d823d5f0 77$wlanapsettings{'NOSCAN'} = 'off';
5b4464a9 78$wlanapsettings{'CLIENTISOLATION'} = 'off';
37a83c83 79$wlanapsettings{'IEEE80211W'} = 'off';
27731caa 80
27731caa 81&General::readhash("/var/ipfire/wlanap/settings", \%wlanapsettings);
23e368ab 82&Header::getcgihash(\%wlanapsettings);
27731caa 83
45b1fc5c
MT
84# Find the selected interface
85my $INTF = &Network::get_intf_by_address($wlanapsettings{'INTERFACE'});
86
23e368ab 87my @macs = $wlanapsettings{'MACS'};
27731caa 88
23e368ab
CS
89delete $wlanapsettings{'__CGI__'};
90delete $wlanapsettings{'x'};
91delete $wlanapsettings{'y'};
92delete $wlanapsettings{'MACS'};
93delete $wlanapsettings{'ACCEPT_MACS'};
94delete $wlanapsettings{'DENY_MACS'};
27731caa
CS
95
96&Header::showhttpheaders();
97
182a817a
JPT
98my $string=();
99my $status=();
100my $errormessage = '';
101my $memory = 0;
102my @memory=();
103my @pid=();
104my @hostapd=();
105sub pid
106{
107# for pid and memory
108 open(FILE, '/usr/local/bin/addonctrl hostapd status | ');
109 @hostapd = <FILE>;
110 close(FILE);
111 $string = join("", @hostapd);
112 $string =~ s/[a-z_]//gi;
113 $string =~ s/\[[0-1]\;[0-9]+//gi;
114 $string =~ s/[\(\)\.]//gi;
115 $string =~ s/ //gi;
116 $string =~ s/\e//gi;
117 @pid = split(/\s/,$string);
118 if (open(FILE, "/proc/$pid[0]/statm")){
119 my $temp = <FILE>;
120 @memory = split(/ /,$temp);
121 close(FILE);
122 }
123 $memory+=$memory[0];
124}
125pid();
126
127
128
129if ( $wlanapsettings{'ACTION'} eq "$Lang::tr{'wlanap del interface'}" ){
130 delete $wlanapsettings{'INTERFACE'};
131 &General::writehash("/var/ipfire/wlanap/settings", \%wlanapsettings);
132}
133
23e368ab 134if ( $wlanapsettings{'ACTION'} eq "$Lang::tr{'save'}" ){
3af89eb5 135 # verify WPA Passphrase - only with enabled enc
f832c758 136 if ($wlanapsettings{'ENC'} ne "none") {
3af89eb5 137 # must be 8 .. 63 characters
182a817a
JPT
138 if ( (length($wlanapsettings{'PWD'}) < 8) || (length($wlanapsettings{'PWD'}) > 63)){
139 $errormessage .= "$Lang::tr{'wlanap invalid wpa'}<br />";
140 }
3af89eb5 141 # only ASCII alowed
cdbeabe2 142 if ( !($wlanapsettings{'PWD'} !~ /[^\x00-\x7f]/) ){
3af89eb5
AF
143 $errormessage .= "$Lang::tr{'wlanap invalid wpa'}<br />";
144 }
27731caa
CS
145 }
146
147 if ( $errormessage eq '' ){
92f2665d 148 &General::writehash("/var/ipfire/wlanap/settings", \%wlanapsettings);
27731caa
CS
149 &WriteConfig_hostapd();
150
90d81a4b 151 &General::system("/usr/local/bin/wlanapctrl", "restart");
182a817a 152 pid();
27731caa 153 }
182a817a 154}elsif ( $wlanapsettings{'ACTION'} eq "$Lang::tr{'wlanap interface'}" ){
92f2665d 155 &General::writehash("/var/ipfire/wlanap/settings", \%wlanapsettings);
182a817a 156}elsif ( ($wlanapsettings{'ACTION'} eq "$Lang::tr{'start'}") && ($memory == 0) ){
90d81a4b 157 &General::system("/usr/local/bin/wlanapctrl", "start");
182a817a
JPT
158 pid();
159}elsif ( $wlanapsettings{'ACTION'} eq "$Lang::tr{'stop'}" ){
90d81a4b 160 &General::system("/usr/local/bin/wlanapctrl", "stop");
182a817a 161 $memory=0;
27731caa
CS
162}
163
d3790c6a 164&Header::openpage($Lang::tr{'wlanap configuration'}, 1, '', '');
27731caa 165&Header::openbigbox('100%', 'left', '', $errormessage);
27731caa
CS
166
167if ( $errormessage ){
54359730 168 &Header::openbox('100%', 'center', $Lang::tr{'error messages'});
27731caa
CS
169 print "<class name='base'>$errormessage\n";
170 print "&nbsp;</class>\n";
171 &Header::closebox();
172}
173
174
175# Found this usefull piece of code in BlockOutTraffic AddOn 8-)
176# fwrules.cgi
177###############
178# DEBUG DEBUG
179if ( $debug ){
54359730 180 &Header::openbox('100%', 'center', 'DEBUG');
27731caa 181 my $debugCount = 0;
23e368ab
CS
182 foreach my $line (sort keys %wlanapsettings) {
183 print "$line = '$wlanapsettings{$line}'<br />\n";
27731caa
CS
184 $debugCount++;
185 }
186 print "&nbsp;Count: $debugCount\n";
187 &Header::closebox();
188}
189# DEBUG DEBUG
190###############
191
192#
193# Driver and status detection
194#
195my $wlan_card_status = 'dummy';
196my $wlan_ap_status = '';
92f2665d
CS
197my $message = "";
198
45b1fc5c
MT
199my %INTERFACES = &Network::list_wireless_interfaces();
200
201foreach my $intf (keys %INTERFACES) {
202 $selected{'INTERFACE'}{$intf} = '';
203}
92f2665d 204$selected{'ENC'}{$wlanapsettings{'INTERFACE'}} = "selected='selected'";
27731caa 205
92f2665d 206if ( ($wlanapsettings{'INTERFACE'} eq '') ){
182a817a 207 $message = $Lang::tr{'wlanap select interface'};
92f2665d
CS
208 &Header::openbox('100%', 'center', "WLAN AP");
209print <<END
210$message<br />
211<form method='post' action='$ENV{'SCRIPT_NAME'}'>
212<select name='INTERFACE'>
92f2665d
CS
213END
214;
45b1fc5c
MT
215
216 foreach my $intf (sort keys %INTERFACES) {
217 print "<option value='${intf}' $selected{'INTERFACE'}{$intf}>$INTERFACES{$intf}</option>";
92f2665d 218 }
45b1fc5c 219
92f2665d
CS
220print <<END
221</select>
182a817a
JPT
222<br /><br />
223<hr size='1'>
224 <input type='submit' name='ACTION' value='$Lang::tr{'wlanap interface'}' /></form>
92f2665d
CS
225END
226;
227 &Header::closebox();
228 &Header::closebigbox();
229 &Header::closepage();
230 exit;
27731caa 231}else{
45b1fc5c 232 my $cmd_out = `/usr/sbin/iwconfig $INTF 2>/dev/null`;
27731caa
CS
233
234 if ( $cmd_out eq '' ){
182a817a 235 $message = "$Lang::tr{'wlanap no interface'}";
92f2665d 236 $wlan_card_status = '';
27731caa 237 }else{
45b1fc5c 238 $cmd_out = `/sbin/ifconfig $INTF`;
27731caa
CS
239 if ( $cmd_out eq '' ){
240 $wlan_card_status = 'down';
241 }else{
242 $wlan_card_status = 'up';
45b1fc5c 243 $cmd_out = `/usr/sbin/iwconfig $INTF | /bin/grep "Mode:Master"`;
27731caa
CS
244 if ( $cmd_out ne '' ){
245 $wlan_ap_status = 'up';
27731caa
CS
246 }
247 }
248 }
249}
250
e62efbb7
AF
251# Change old "n" to "gn"
252if ( $wlanapsettings{'HW_MODE'} eq 'n' ) {
253 $wlanapsettings{'HW_MODE'}='gn';
254}
255
b8990355
CS
256$checked{'HIDESSID'}{'off'} = '';
257$checked{'HIDESSID'}{'on'} = '';
258$checked{'HIDESSID'}{$wlanapsettings{'HIDESSID'}} = "checked='checked'";
27731caa 259
d823d5f0
AF
260$checked{'NOSCAN'}{'off'} = '';
261$checked{'NOSCAN'}{'on'} = '';
262$checked{'NOSCAN'}{$wlanapsettings{'NOSCAN'}} = "checked='checked'";
263
5b4464a9
PM
264$checked{'CLIENTISOLATION'}{'off'} = '';
265$checked{'CLIENTISOLATION'}{'on'} = '';
266$checked{'CLIENTISOLATION'}{$wlanapsettings{'CLIENTISOLATION'}} = "checked='checked'";
267
13cbb92a
MT
268$selected{'IEEE80211W'}{'off'} = '';
269$selected{'IEEE80211W'}{'optional'} = '';
270$selected{'IEEE80211W'}{'on'} = '';
271$selected{'IEEE80211W'}{$wlanapsettings{'IEEE80211W'}} = "selected";
37a83c83 272
27731caa 273$selected{'ENC'}{$wlanapsettings{'ENC'}} = "selected='selected'";
30313f28 274$selected{'CHANNEL'}{$wlanapsettings{'CHANNEL'}} = "selected='selected'";
c3d9a16d 275$selected{'COUNTRY'}{$wlanapsettings{'COUNTRY'}} = "selected='selected'";
54359730 276$selected{'TXPOWER'}{$wlanapsettings{'TXPOWER'}} = "selected='selected'";
7d30ef24 277$selected{'HW_MODE'}{$wlanapsettings{'HW_MODE'}} = "selected='selected'";
92f2665d 278$selected{'MACMODE'}{$wlanapsettings{'MACMODE'}} = "selected='selected'";
27731caa 279
45b1fc5c
MT
280my $monwlaninterface = $INTF;
281if ( -d '/sys/class/net/mon.' . $INTF) {
282 $monwlaninterface = 'mon.' . $INTF;
c3d9a16d
AF
283}
284
0f0d6a5a 285my @channellist_cmd;
ea10f1a0 286my @channellist = (0);
0f0d6a5a
AF
287
288if ( $wlanapsettings{'DRIVER'} eq 'NL80211' ){
45b1fc5c 289my $wiphy = `iw dev $INTF info | grep wiphy | cut -d" " -f2`;
0f0d6a5a
AF
290chomp $wiphy;
291
05583186 292@channellist_cmd = `iw phy phy$wiphy info | grep " MHz \\\[" | grep -v "(disabled)" | grep -v "no IBSS" | grep -v "no IR" | grep -v "passive scanning" 2>/dev/null`;
0f0d6a5a
AF
293# get available channels
294
295my @temp;
296foreach (@channellist_cmd){
297$_ =~ /(.*) \[(\d+)(.*)\]/;
298$channel = $2;chomp $channel;
12f74b8f 299if ( $channel =~ /\d+/ ){push(@temp,$channel + 0);}
0f0d6a5a 300}
ea10f1a0 301push(@channellist, @temp);
0f0d6a5a
AF
302} else {
303@channellist_cmd = `iwlist $monwlaninterface channel|tail -n +2 2>/dev/null`;
27731caa 304# get available channels
27731caa 305
54359730 306my @temp;
8c2f203c 307foreach (@channellist_cmd){
54359730 308$_ =~ /(.*)Channel (\d+)(.*):/;
8c2f203c 309$channel = $2;chomp $channel;
12f74b8f 310if ( $channel =~ /\d+/ ){push(@temp,$channel + 0);}
27731caa 311}
ea10f1a0 312push(@channellist, @temp);
0f0d6a5a 313}
54359730 314
c3d9a16d 315# get available country codes
82134432 316open(FILE, "</lib/firmware/regulatorydb.txt");
15db8226
AB
317my @countrylist_cmd = <FILE>;
318close(FILE);
319
c3d9a16d 320
8e23b351 321my @temp = "00";
c3d9a16d
AF
322foreach (@countrylist_cmd){
323$_ =~ /country (.*):/;
324$country = $1;chomp $country;
325if ( $country =~ /[0,A-Z][0,A-Z]/ ) {push(@temp,$country);}
326}
327my @countrylist = @temp;
328
329my @txpower_cmd = `iwlist $monwlaninterface txpower 2>/dev/null`;
330if ( $wlanapsettings{'DRIVER'} eq 'NL80211' ){
45b1fc5c 331 # There is a bug with NL80211 only all devices can displaye
c3d9a16d
AF
332 @txpower_cmd = `iwlist txpower 2>/dev/null | sed -e "s|unknown transmit-power information.||g"`;
333}
334# get available power
27731caa 335
27731caa 336$selected{'SYSLOGLEVEL'}{$wlanapsettings{'SYSLOGLEVEL'}} = "selected='selected'";
27731caa
CS
337$selected{'DEBUG'}{$wlanapsettings{'DEBUG'}} = "selected='selected'";
338
339#
340# Status box
341#
54359730 342&Header::openbox('100%', 'center', "WLAN AP");
27731caa 343print <<END
3827d1f6 344<table width='80%' cellspacing='1' class='tbl'>
27731caa
CS
345END
346;
182a817a 347
27731caa 348if ( $wlan_card_status ne '' ){
3827d1f6
AM
349 print "<tr><th align='left' width='50%'><strong>$Lang::tr{'service'}</strong></th><th width='22%'>Status</th><th width='10%'>PID</th><th width='15%'>$Lang::tr{'memory'}</th><th colspan='2'width='5%'>$Lang::tr{'action'}</th></tr>";
350 print "<tr><td class='base'>$Lang::tr{'wlanap wlan card'} ($wlanapsettings{'DRIVER'})</td>";
27731caa 351 print $wlan_card_status eq 'up' ? $status_started : $status_stopped;
3827d1f6 352 print"<td colspan='4'></td></tr>";
d3790c6a 353 print "<tr><td class='base' bgcolor='$color{'color22'}'>$Lang::tr{'wlanap'}</td>";
27731caa 354 print $wlan_ap_status eq 'up' ? $status_started : $status_stopped;
3827d1f6
AM
355 if ( ($memory != 0) && (@pid[0] ne "///") ){
356 print "<td bgcolor='$color{'color22'}' align='center'>@pid[0]</td>";
357 print "<td bgcolor='$color{'color22'}' align='center'>$memory KB</td>";
358 print "<td bgcolor='$color{'color22'}'><form method='post' action='$ENV{'SCRIPT_NAME'}'><input type='hidden' name='ACTION' value='$Lang::tr{'start'}' /><input type='image' alt='$Lang::tr{'start'}' title='$Lang::tr{'start'}' src='/images/go-up.png' /></form></td>";
359 print "<td bgcolor='$color{'color22'}'><form method='post' action='$ENV{'SCRIPT_NAME'}'><input type='hidden' name='ACTION' value='$Lang::tr{'stop'}' /><input type='image' alt='$Lang::tr{'stop'}' title='$Lang::tr{'stop'}' src='/images/go-down.png' /></form></td>";
360 }else{
361 print"<td colspan='2' bgcolor='$color{'color22'}'></td>";
362 print "<td bgcolor='$color{'color22'}'><form method='post' action='$ENV{'SCRIPT_NAME'}'><input type='hidden' name='ACTION' value='$Lang::tr{'start'}' /><input type='image' alt='$Lang::tr{'start'}' title='$Lang::tr{'start'}' src='/images/go-up.png' /></form></td>";
363 print "<td bgcolor='$color{'color22'}'><form method='post' action='$ENV{'SCRIPT_NAME'}'><input type='hidden' name='ACTION' value='$Lang::tr{'stop'}' /><input type='image' alt='$Lang::tr{'stop'}' title='$Lang::tr{'stop'}' src='/images/go-down.png' /></form></td>";
364 }
182a817a 365
27731caa 366}else{
3827d1f6 367 print "<tr><td class='base'>$message";
182a817a
JPT
368}
369 print "</table>";
370
3827d1f6
AM
371if ( $wlan_card_status eq '' ){
372 print "<br />";
373 print "<table width='80%' cellspacing='0' border='0'>";
374 print "<tr align='center'>";
375 print "<td colspan='4'></td>";
182a817a 376 print "</tr>";
3827d1f6
AM
377 print "<tr align='center'>";
378 print "<td width='40%'>&nbsp;</td>";
379 print "<td width='20%'><form method='post' action='/cgi-bin/wlanap.cgi'><input type='submit' name='ACTION' value='$Lang::tr{'wlanap del interface'}' /></form></td>";
380 print "<td width='20%'></td>";
381 print "<td width='20%'></td>";
182a817a
JPT
382 print "</tr>";
383 print "</table>";
27731caa 384}
27731caa
CS
385
386if ( $wlan_card_status eq '' ){
92f2665d 387 &Header::closebox();
27731caa
CS
388 &Header::closebigbox();
389 &Header::closepage();
390 exit 0;
391}
27731caa 392print <<END
3827d1f6 393<br><br>
23e368ab 394<form method='post' action='$ENV{'SCRIPT_NAME'}'>
3827d1f6
AM
395<table width='80%' cellspacing='0' class='tbl' border='0'>
396<tr><th bgcolor='$color{'color20'}' colspan='4' align='left'><strong>$Lang::tr{'wlanap wlan settings'}</strong></th></tr>
397<tr><td colspan='4'><br></td></tr>
c7217140 398<tr><td width='25%' class='base'>$Lang::tr{'wlanap ssid'}:&nbsp;</td><td class='base' colspan='3'><input type='text' name='SSID' size='30' value='$wlanapsettings{'SSID'}' /></td></tr>
0d4e628e 399<!--SSID Broadcast: on => HIDESSID: off -->
c7217140
MT
400<tr><td width='25%' class='base'>$Lang::tr{'wlanap broadcast ssid'}:&nbsp;</td><td class='base' colspan='3'>$Lang::tr{'on'} <input type='radio' name='HIDESSID' value='off' $checked{'HIDESSID'}{'off'} /> | <input type='radio' name='HIDESSID' value='on' $checked{'HIDESSID'}{'on'} /> $Lang::tr{'off'}</td></tr>
401<tr><td width='25%' class='base'>$Lang::tr{'wlanap client isolation'}:&nbsp;</td><td class='base' colspan='3'>$Lang::tr{'on'} <input type='radio' name='CLIENTISOLATION' value='on' $checked{'CLIENTISOLATION'}{'on'} /> | <input type='radio' name='CLIENTISOLATION' value='off' $checked{'CLIENTISOLATION'}{'off'} /> $Lang::tr{'off'}</td></tr>
3827d1f6
AM
402<tr><td width='25%' class='base'>$Lang::tr{'wlanap country'}:&nbsp;</td><td class='base' colspan='3'>
403 <select name='COUNTRY'>
404END
405;
406foreach $country (@countrylist){
407 print "<option $selected{'COUNTRY'}{$country}>$country</option>";
408}
409print<<END
410</select></td></tr>
7d30ef24
AF
411<tr><td width='25%' class='base'>HW Mode:&nbsp;</td><td class='base' colspan='3'>
412 <select name='HW_MODE'>
182a817a
JPT
413 <option value='a' $selected{'HW_MODE'}{'a'}>802.11a</option>
414 <option value='b' $selected{'HW_MODE'}{'b'}>802.11b</option>
415 <option value='g' $selected{'HW_MODE'}{'g'}>802.11g</option>
e62efbb7
AF
416 <option value='an' $selected{'HW_MODE'}{'an'}>802.11an</option>
417 <option value='gn' $selected{'HW_MODE'}{'gn'}>802.11gn</option>
f887bf5f 418 <option value='ac' $selected{'HW_MODE'}{'ac'}>802.11ac</option>
7d30ef24
AF
419 </select>
420</td></tr>
fe3f3050
AF
421END
422;
423
fe3f3050
AF
424if ( scalar @channellist > 0 ){
425 print <<END
182a817a 426<tr><td width='25%' class='base'>$Lang::tr{'wlanap channel'}:&nbsp;</td><td class='base' colspan='3'>
30313f28 427 <select name='CHANNEL'>
27731caa
CS
428END
429;
fe3f3050 430 foreach $channel (@channellist){
ea10f1a0
MT
431 print "<option $selected{'CHANNEL'}{$channel}>";
432 if ($channel eq 0) {
433 print "- $Lang::tr{'wlanap auto'} -";
434 } else {
435 print $channel;
436 }
437 print "</option>";
fe3f3050
AF
438 }
439 print "</select></td></tr>"
440} else {
441 print <<END
442<tr><td width='25%' class='base'>$Lang::tr{'wlanap channel'}:&nbsp;</td><td class='base' colspan='3'>
443<input type='text' name='CHANNEL' size='10' value='$wlanapsettings{'CHANNEL'}' />
444</td></tr>
445END
446;
27731caa 447}
3827d1f6 448print<<END
fd1b46f1 449<tr><td width='25%' class='base'>$Lang::tr{'wlanap neighbor scan'}:&nbsp;</td><td class='base' >$Lang::tr{'on'} <input type='radio' name='NOSCAN' value='off' $checked{'NOSCAN'}{'off'} /> | <input type='radio' name='NOSCAN' value='on' $checked{'NOSCAN'}{'on'} /> $Lang::tr{'off'}</td><td class='base' colspan='2'>$Lang::tr{'wlanap neighbor scan warning'}</td></tr>
3827d1f6
AM
450<tr><td colspan='4'><br></td></tr>
451<tr><td width='25%' class='base'>$Lang::tr{'wlanap encryption'}:&nbsp;</td><td class='base' colspan='3'>
452 <select name='ENC'>
453 <option value='none' $selected{'ENC'}{'none'}>$Lang::tr{'wlanap none'}</option>
454 <option value='wpa1' $selected{'ENC'}{'wpa1'}>WPA1</option>
455 <option value='wpa2' $selected{'ENC'}{'wpa2'}>WPA2</option>
f832c758 456 <option value='wpa3' $selected{'ENC'}{'wpa3'}>WPA3</option>
3827d1f6 457 <option value='wpa1+2' $selected{'ENC'}{'wpa1+2'}>WPA1+2</option>
f832c758 458 <option value='wpa2+3' $selected{'ENC'}{'wpa2+3'}>WPA2+3</option>
3827d1f6
AM
459 </select>
460</td></tr>
461<tr><td width='25%' class='base'>Passphrase:&nbsp;</td><td class='base' colspan='3'><input type='text' name='PWD' size='30' value='$wlanapsettings{'PWD'}' /></td></tr>
37a83c83
MT
462<tr>
463 <td width='25%' class='base'>$Lang::tr{'wlanap management frame protection'}:&nbsp;</td>
464 <td class='base' colspan="3">
13cbb92a
MT
465 <select name="IEEE80211W">
466 <option value="off" $selected{'IEEE80211W'}{'off'}>$Lang::tr{'wlanap 802.11w disabled'}</option>
467 <option value="optional" $selected{'IEEE80211W'}{'optional'}>$Lang::tr{'wlanap 802.11w optional'}</option>
468 <option value="on" $selected{'IEEE80211W'}{'on'}>$Lang::tr{'wlanap 802.11w enforced'}</option>
469 </select>
37a83c83
MT
470 </td>
471</tr>
3827d1f6 472<tr><td colspan='4'><br></td></tr>
c3d9a16d
AF
473END
474;
27731caa 475print <<END
3827d1f6 476<tr><td width='25%' class='base'>HT Caps:&nbsp;</td><td class='base' colspan='3'><input type='text' name='HTCAPS' size='30' value='$wlanapsettings{'HTCAPS'}' /></td></tr>
f887bf5f 477<tr><td width='25%' class='base'>VHT Caps:&nbsp;</td><td class='base' colspan='3'><input type='text' name='VHTCAPS' size='30' value='$wlanapsettings{'VHTCAPS'}' /></td></tr>
c17883fd 478<tr><td width='25%' class='base'>Tx Power:&nbsp;</td><td class='base' colspan='3'><input type='text' name='TXPOWER' size='10' value='$wlanapsettings{'TXPOWER'}' /></td></tr>
27731caa
CS
479<tr><td width='25%' class='base'>Loglevel (hostapd):&nbsp;</td><td class='base' width='25%'>
480 <select name='SYSLOGLEVEL'>
182a817a
JPT
481 <option value='0' $selected{'SYSLOGLEVEL'}{'0'}>0 ($Lang::tr{'wlanap verbose'})</option>
482 <option value='1' $selected{'SYSLOGLEVEL'}{'1'}>1 ($Lang::tr{'wlanap debugging'})</option>
483 <option value='2' $selected{'SYSLOGLEVEL'}{'2'}>2 ($Lang::tr{'wlanap informations'})</option>
484 <option value='3' $selected{'SYSLOGLEVEL'}{'3'}>3 ($Lang::tr{'wlanap notifications'})</option>
485 <option value='4' $selected{'SYSLOGLEVEL'}{'4'}>4 ($Lang::tr{'wlanap warnings'})</option>
27731caa
CS
486 </select>
487</td>
488<td width='25%' class='base'>Debuglevel (hostapd):&nbsp;</td><td class='base' width='25%'>
489 <select name='DEBUG'>
182a817a
JPT
490 <option value='0' $selected{'DEBUG'}{'0'}>0 ($Lang::tr{'wlanap verbose'})</option>
491 <option value='1' $selected{'DEBUG'}{'1'}>1 ($Lang::tr{'wlanap debugging'})</option>
492 <option value='2' $selected{'DEBUG'}{'2'}>2 ($Lang::tr{'wlanap informations'})</option>
493 <option value='3' $selected{'DEBUG'}{'3'}>3 ($Lang::tr{'wlanap notifications'})</option>
494 <option value='4' $selected{'DEBUG'}{'4'}>4 ($Lang::tr{'wlanap warnings'})</option>
27731caa
CS
495 </select>
496</td></tr>
3827d1f6 497<tr><td colspan='4'><br></td></tr>
27731caa 498</table>
92f2665d
CS
499END
500;
45b1fc5c 501if ( $INTF =~ /green0/ ){
92f2665d
CS
502 print <<END
503<br />
3827d1f6
AM
504<table width='80%' cellspacing='0' class='tbl' border='1'>
505<tr>
506 <th colspan='3' align='left'>$Lang::tr{'mac filter'}</th>
507</tr>
92f2665d
CS
508<td width='25%' class='base'>Mac Filter:&nbsp;</td><td class='base' width='25%'>
509 <select name='MACMODE'>
510 <option value='0' $selected{'MACMODE'}{'0'}>0 (off)</option>
8aa49c15
CS
511 <option value='1' $selected{'MACMODE'}{'1'}>1 (Accept MACs)</option>
512 <option value='2' $selected{'MACMODE'}{'2'}>2 (Deny MACs)</option>
92f2665d 513 </select>
8aa49c15 514</td><td colspan='2'>Mac Adress List (one per line)<br /><textarea name='MACS' cols='20' rows='5' wrap='off'>
92f2665d
CS
515END
516;
8aa49c15 517 print `cat /var/ipfire/wlanap/macfile`;
92f2665d
CS
518print <<END
519</textarea></td>
92f2665d
CS
520</table>
521END
522;
523}
524print <<END
54359730 525<br />
3827d1f6 526<table width='80%' cellspacing='0'>
735fce60 527<tr><td align='center'>
182a817a 528<form method='post' action='$ENV{'SCRIPT_NAME'}'>
ed7f8152 529 <input type='submit' name='ACTION' value='$Lang::tr{'save'}' /></form></td>
27731caa
CS
530</tr>
531</table>
532END
533;
0f0d6a5a 534my @status;
7d30ef24 535if ( $wlanapsettings{'DRIVER'} eq 'NL80211' ){
45b1fc5c 536 @status = `iw dev $INTF info && iw dev $INTF station dump && echo ""`;
7d30ef24 537}
54359730
CS
538print <<END
539<br />
3827d1f6
AM
540<table width='80%' cellspacing='0' class='tbl'>
541<tr><th colspan='3' bgcolor='$color{'color20'}' align='left'><strong>$Lang::tr{'wlanap wlan status'}</strong></th></tr>
542END
543;
0f0d6a5a
AF
544
545for (my $i=0;$i<$#status;$i++){
546
547if (@status[$i]=~"^Station ") { $count++; }
548if ($count % 2){
3827d1f6
AM
549 $col="bgcolor='$color{'color20'}'";
550 }else{
551 $col="bgcolor='$color{'color22'}'";
552 }
0f0d6a5a
AF
553 print"<tr><td colspan='3' $col><pre>@status[$i]</pre></td></tr>";
554 if (! @status[$i]=~"^/t" ) { $count++; }
3827d1f6 555}
0f0d6a5a
AF
556 $count++;
557
558foreach my $nr (@channellist_cmd){
559 if ($count % 2){
3827d1f6
AM
560 $col="bgcolor='$color{'color20'}'";
561 }else{
562 $col="bgcolor='$color{'color22'}'";
563 }
0f0d6a5a 564 print"<tr><td colspan='3' $col>$nr</td></tr>";
3827d1f6
AM
565 $count++;
566}
0f0d6a5a
AF
567
568for (my $i=0;$i<$#txpower_cmd;$i=$i+2){
3827d1f6
AM
569 if ($count % 2){
570 $col="bgcolor='$color{'color20'}'";
571 }else{
572 $col="bgcolor='$color{'color22'}'";
573 }
0f0d6a5a 574 print "<tr><td $col>@txpower_cmd[$i]</td></tr>";
3827d1f6
AM
575 $count++;
576}
84624b2a 577print "</table>";
54359730 578&Header::closebox();
27731caa
CS
579print "</form>";
580&Header::closebigbox();
581&Header::closepage();
582
27731caa
CS
583sub WriteConfig_hostapd{
584 $wlanapsettings{'DRIVER_HOSTAPD'} = lc($wlanapsettings{'DRIVER'});
585
586 open (CONFIGFILE, ">/var/ipfire/wlanap/hostapd.conf");
587 print CONFIGFILE <<END
cdbeabe2 588driver=$wlanapsettings{'DRIVER_HOSTAPD'}
54359730 589######################### basic hostapd configuration ##########################
891b6138 590#
cdbeabe2
AF
591country_code=$wlanapsettings{'COUNTRY'}
592ieee80211d=1
f89678de 593ieee80211h=1
7d30ef24 594channel=$wlanapsettings{'CHANNEL'}
b8012afd
CS
595END
596;
e62efbb7
AF
597 if ( $wlanapsettings{'HW_MODE'} eq 'an' ){
598 print CONFIGFILE <<END
599hw_mode=a
600ieee80211n=1
601wmm_enabled=1
602ht_capab=$wlanapsettings{'HTCAPS'}
603END
604;
605
606 }elsif ( $wlanapsettings{'HW_MODE'} eq 'gn' ){
b8012afd
CS
607 print CONFIGFILE <<END
608hw_mode=g
609ieee80211n=1
6e346fe0
CS
610wmm_enabled=1
611ht_capab=$wlanapsettings{'HTCAPS'}
b8012afd 612END
f887bf5f
MT
613;
614
615 }elsif ( $wlanapsettings{'HW_MODE'} eq 'ac' ){
616 print CONFIGFILE <<END
617hw_mode=a
618ieee80211ac=1
619ieee80211n=1
620wmm_enabled=1
621ht_capab=$wlanapsettings{'HTCAPS'}
622vht_capab=$wlanapsettings{'VHTCAPS'}
dc850cb3 623vht_oper_chwidth=1
f887bf5f 624END
b8012afd
CS
625;
626
627 }else{
628 print CONFIGFILE <<END
8ad457eb
CS
629hw_mode=$wlanapsettings{'HW_MODE'}
630END
b8012afd
CS
631;
632
633 }
634
8ad457eb 635print CONFIGFILE <<END
27731caa
CS
636logger_syslog=-1
637logger_syslog_level=$wlanapsettings{'SYSLOGLEVEL'}
638logger_stdout=-1
54359730 639logger_stdout_level=$wlanapsettings{'DEBUG'}
7d30ef24 640auth_algs=1
27731caa
CS
641ctrl_interface=/var/run/hostapd
642ctrl_interface_group=0
70a7c454 643disassoc_low_ack=1
27731caa
CS
644END
645;
54359730
CS
646 if ( $wlanapsettings{'HIDESSID'} eq 'on' ){
647 print CONFIGFILE <<END
648ssid=$wlanapsettings{'SSID'}
649ignore_broadcast_ssid=2
650END
651;
652
653 }else{
654 print CONFIGFILE <<END
655ssid=$wlanapsettings{'SSID'}
656ignore_broadcast_ssid=0
657END
658;
659
660 }
92f2665d 661
5b4464a9
PM
662 # https://forum.ipfire.org/viewtopic.php?f=22&t=12274&p=79070#p79070
663 if ( $wlanapsettings{'CLIENTISOLATION'} eq 'on' ){
664 print CONFIGFILE <<END
665ap_isolate=1
666END
667;
668 }
669
d823d5f0
AF
670 if ( $wlanapsettings{'NOSCAN'} eq 'on' ){
671 print CONFIGFILE <<END
672noscan=1
673END
674;
675
676 }else{
677 print CONFIGFILE <<END
678noscan=0
679END
680;
681
682 }
683
37a83c83
MT
684 # Management Frame Protection (802.11w)
685 if ($wlanapsettings{'IEEE80211W'} eq "on") {
686 print CONFIGFILE "ieee80211w=2\n";
13cbb92a
MT
687 } elsif ($wlanapsettings{'IEEE80211W'} eq "optional") {
688 print CONFIGFILE "ieee80211w=1\n";
37a83c83
MT
689 } else {
690 print CONFIGFILE "ieee80211w=0\n";
691 }
692
8c2f203c
CS
693 if ( $wlanapsettings{'ENC'} eq 'wpa1'){
694 print CONFIGFILE <<END
695######################### wpa hostapd configuration ############################
891b6138 696#
8c2f203c
CS
697wpa=1
698wpa_passphrase=$wlanapsettings{'PWD'}
891b6138 699wpa_key_mgmt=WPA-PSK
e62efbb7 700wpa_pairwise=TKIP
8c2f203c
CS
701END
702;
703 }elsif ( $wlanapsettings{'ENC'} eq 'wpa2'){
54359730
CS
704 print CONFIGFILE <<END
705######################### wpa hostapd configuration ############################
891b6138 706#
8c2f203c 707wpa=2
54359730 708wpa_passphrase=$wlanapsettings{'PWD'}
891b6138 709wpa_key_mgmt=WPA-PSK
e62efbb7
AF
710rsn_pairwise=CCMP
711END
f832c758
MT
712;
713 }elsif ( $wlanapsettings{'ENC'} eq 'wpa3'){
714 print CONFIGFILE <<END
715######################### wpa hostapd configuration ############################
716#
717wpa=2
718wpa_passphrase=$wlanapsettings{'PWD'}
719wpa_key_mgmt=SAE
720rsn_pairwise=CCMP
721END
e62efbb7
AF
722;
723 } elsif ( $wlanapsettings{'ENC'} eq 'wpa1+2'){
724 print CONFIGFILE <<END
725######################### wpa hostapd configuration ############################
726#
727wpa=3
728wpa_passphrase=$wlanapsettings{'PWD'}
729wpa_key_mgmt=WPA-PSK
730wpa_pairwise=TKIP
731rsn_pairwise=CCMP
54359730 732END
f832c758
MT
733;
734 }elsif ( $wlanapsettings{'ENC'} eq 'wpa2+3'){
735 print CONFIGFILE <<END
736######################### wpa hostapd configuration ############################
737#
738wpa=2
739wpa_passphrase=$wlanapsettings{'PWD'}
740wpa_key_mgmt=WPA-PSK SAE
741rsn_pairwise=CCMP
742END
54359730
CS
743;
744 }
27731caa 745 close CONFIGFILE;
92f2665d 746
8aa49c15 747 open (MACFILE, ">/var/ipfire/wlanap/macfile");
23e368ab
CS
748 foreach(@macs){
749 $_ =~ s/\r//gi;
750 chomp($_);
751 if ( $_ ne "" ){print MACFILE $_;}
752 }
92f2665d 753 close MACFILE;
27731caa 754}