發表文章

OpenWRT dumb AP with WPA3-SAE + 802.11r

圖片
OpenWRT veriosn: 23.05.2 HW: TOTOLINK X5000R Ref: https://vicfree.com/2022/11/openwrt-wpa3-802.11kvr-ap-setup/ Requirement: #install fully wpad package with openssl opkg update opkg install wpad-openssl #disabled firewall, dhcp server and dnsmasq for i in firewall dnsmasq odhcpd; do if /etc/init.d/"$i" enabled; then /etc/init.d/"$i" disable /etc/init.d/"$i" stop fi done Luci setting: /etc/config/wireless: config wifi-iface 'wifinet1' option device 'radio1' option mode 'ap' option ssid 'MY_SSID' option encryption 'sae' option key 'MY_PASSWORD' option ieee80211r '1' option reassociation_deadline '20000' option ft_over_ds '0' option ft_psk_generate_local '0' option ieee80211k '1' option time_zone 'CST-8' ...

OpenVPN Server build on Debian 11

Quote from : https://www.server-world.info/en/note?os=Debian_11&p=openvpn&f=1 [1] Install OpenVPN. root@dlp:~#  apt  -y install openvpn easy-rsa iptables [2] Create CA and Certificates. root@dlp:~#  cd  /usr/share/easy-rsa# initialize root@dlp:/usr/share/easy-rsa# ./easyrsa init-pki init-pki complete; you may now create a CA or requests. Your newly created PKI dir is: /usr/share/easy-rsa/pki # create CA root@dlp:/usr/share/easy-rsa# ./easyrsa build-ca Using SSL: openssl OpenSSL 1.1.1k 25 Mar 2021 # set any pass-phrase Enter New CA Key Passphrase: Re-Enter New CA Key Passphrase: Generating RSA private key, 2048 bit long modulus (2 primes) …….+++++ …………………..+++++ e is 65537 (0x010001) You are about to be asked to enter information that will be incorporated into your certificate request. What you are about to enter is what is called a Distinguished Name or a DN. There are quite a few fields but you ...

OpenVPN.ovpn combined all certification and private key.

edit your client.ovpn: #vim client.ovpn Delete these line or comment it. ca ca.crt cert client.crt key client.key tls-auth ta.key 1 Add these content to client.ovpn <ca> —–BEGIN CERTIFICATE—– ca.crt contend —–END CERTIFICATE—– </ca> <cert> —–BEGIN CERTIFICATE—– client.crt contend —–END CERTIFICATE—– </cert> <key> —–BEGIN PRIVATE KEY—– client.key contend —–END PRIVATE KEY—– </key> key-direction 1 #must have this line <tls-auth> —–BEGIN OpenVPN Static key V1—– ta.key contend —–END OpenVPN Static key V1—– </tls-auth>

OpenWRT install and connect Fortinet VPN

opkg install openfortivpn luci-proto-openfortivpn reboot in Luci add interface proto using openfortivpn fill username, password, ip address, port in advanced, fill “VPN Server’s certificate SHA1 hash” if your fortiSSL cert not trusted by your device. Save and apply restart the interface will connected and get a ip from vpn. Let openwrt’s client can access fortiSSL # iptables -t nat -A POSTROUTING -s 192.168.1.0/24 -o vpn-company -j MASQUERADE add static route then done

Supermicro motherboard when installed Raid card will keep beeping

Tested on X9DRD-iF and LSI 9260-8i You should entering BIOS and close SCU function and disable IPMI function then you can boot normally.

OpenWRT 18版後自訂build預設lan ip

修改package sunsky131221@WSL2:~/openwrt-19.07.2$ vi package/base-files/files/bin/config_generate 將 lan) ipad=${ipaddr:-"192.168.1.1"} ;; 改成自訂(EX:192.168.100.254) lan) ipad=${ipaddr:-"192.168.100.254"} ;; :wq退出 make V=99

OpenWRT 安裝 Strongswan 並架設IKEv2之mschapv2 VPN

我有點懶得排版 就先記錄 之後再考慮整理 1.安裝相關套件 opkg update opkg install curl strongswan-defaultstrongswan-pki ipset strongswan-mod-openssl strongswan-mod-curlstrongswan-mod-dhcp strongswan-mod-eap-tls strongswan-mod-eap-identitystrongswan-mod-kernel-libipsec kmod-tun openssl-utilstrongswan-mod-test-vectors strongswan-mod-farp 2.修改/etc/config/network新增訂一ipsec介面 config interface 'ipsec'option ifname         'ipsec0'option proto            'none'option defaultroute '0'option peerdns                '0'option ipv6              '0' 3.修改/etc/firewall.user新增規則 iptables -I INPUT   -m policy --dir in  --pol ipsec --proto esp -j ACCEPTiptables -I FORWARD -m policy --dir in  --pol ipsec --proto esp -j ACCEPTiptables -I FORWARD -m policy --dir out --pol ipsec --proto esp -j ACCEPTiptables -I OUTPUT  -m policy --dir out --pol ipsec --proto esp -j ACCEPT 4.修改/etc/config/firewall新增zone、forwarding、rules Zone區 config zone option name 'vpn' list network 'ipsec...