chilli_config 7.33 KB
Newer Older
Elena Grandi's avatar
Elena Grandi committed
1
2
3
4
5
6
7
8
9
10
11
12
# -*- mode: shell-script; -*-
#
#   Coova-Chilli Default Configurations. 
#   To customize, copy this file to /etc/chilli/config
#   and edit to your liking. This is included in shell scripts
#   that configure chilli and related programs before file 'config'. 


###
#   Local Network Configurations
# 

Elena Grandi's avatar
typo    
Elena Grandi committed
13
HS_WANIF={{ external_ifaces[0] }}           # WAN Interface toward the Internet
14
15
16
HS_LANIF={{ hotspot_iface }}                # Subscriber Interface for client devices
HS_NETWORK={{ hotspot_network | ipaddr('network') }} # HotSpot Network (must include HS_UAMLISTEN)
HS_NETMASK={{ hotspot_network | ipaddr('netmask') }}  # HotSpot Network Netmask
Elena Grandi's avatar
Elena Grandi committed
17
18
19
20
21
22
23
24
25
HS_UAMLISTEN={{ hotspot_uamlisten }}   # HotSpot IP Address (on subscriber network)
HS_UAMPORT=3990            # HotSpot UAM Port (on subscriber network)
HS_UAMUIPORT=4990          # HotSpot UAM "UI" Port (on subscriber network, for embedded portal)

# HS_DYNIP=
# HS_DYNIP_MASK=255.255.255.0
# HS_STATIP=
# HS_STATIP_MASK=255.255.255.0
# HS_DNS_DOMAIN=
26
27
28
29
30
31
32
{% if chilli_range_split is defined %}
# added from fuss-server 10.0.34 when chilly_range_split is defined
HS_DYNIP={{hotspot_network|ipsubnet(hotspot_network|ipaddr('prefix')|int + 1,0)|ipaddr('network')}}
HS_DYNIP_MASK={{hotspot_network|ipsubnet(hotspot_network|ipaddr('prefix')|int + 1,0)|ipaddr('netmask')}}
HS_STATIP={{hotspot_network|ipsubnet(hotspot_network|ipaddr('prefix')|int + 1,1)|ipaddr('network')}}
HS_STATIP_MASK={{hotspot_network|ipsubnet(hotspot_network|ipaddr('prefix')|int + 1,1)|ipaddr('netmask')}}
{% endif %}
Elena Grandi's avatar
Elena Grandi committed
33
34
35
36

# OpenDNS Servers
#HS_DNS1=192.168.1.2
#HS_DNS2=8.8.8.8
37
HS_DNS1={{hotspot_uamlisten}}
38
HS_LOCAL_DNS="off"
Elena Grandi's avatar
Elena Grandi committed
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163


###
#   HotSpot settings for simple Captive Portal
#
HS_NASID=nas01
HS_RADIUS=localhost
HS_RADIUS2=localhost

# needed for LDAP auth on freeradius
HS_RAD_PROTO=pap

HS_UAMALLOW={{ hotspot_network }},{{ first_external_ip}}
HS_RADSECRET=testing123    # Set to be your RADIUS shared secret
HS_UAMSECRET=change-me     # Set to be your UAM secret
HS_UAMALIASNAME=chilli

#  Configure RADIUS proxy support (for 802.1x + captive portal support)
# HS_RADPROXY=on
# HS_RADPROXY_LISTEN=127.0.0.1
# HS_RADPROXY_CLIENT=127.0.0.1
# HS_RADPROXY_PORT=1645
# HS_RADPROXY_SECRET=$HS_RADSECRET
#  Example OpenWrt /etc/config/wireless entry for hostapd
#    option encryption wpa2
#    option server $HS_RADPROXY_LISTEN
#    option port $HS_RADPROXY_PORT
#    option key $HS_RADPROXY_SECRET


#   To alternatively use a HTTP URL for AAA instead of RADIUS:
# HS_UAMAAAURL=http://my-site/script.php

#   Put entire domains in the walled-garden with DNS inspection
# HS_UAMDOMAINS=".paypal.com,.paypalobjects.com"

#   Optional initial redirect and RADIUS settings
# HS_SSID=<ssid>	   # To send to the captive portal
# HS_NASMAC=<mac address>  # To explicitly set Called-Station-Id
# HS_NASIP=<ip address>    # To explicitly set NAS-IP-Address

#   The server to be used in combination with HS_UAMFORMAT to 
#   create the final chilli 'uamserver' url configuration.
HS_UAMSERVER=$HS_UAMLISTEN

#   Use HS_UAMFORMAT to define the actual captive portal url.
#   Shell variable replacement takes place when evaluated, so here
#   HS_UAMSERVER is escaped and later replaced by the pre-defined 
#   HS_UAMSERVER to form the actual "--uamserver" option in chilli.
HS_UAMFORMAT=http://\$HS_UAMLISTEN:\$HS_UAMUIPORT/www/login.chi

#   Same principal goes for HS_UAMHOMEPAGE.
HS_UAMHOMEPAGE=http://\$HS_UAMLISTEN:\$HS_UAMPORT/www/coova.html

#   This option will be configured to be the WISPr LoginURL as well
#   as provide "uamService" to the ChilliController. The UAM Service is
#   described in: http://www.coova.org/CoovaChilli/UAMService
#
# HS_UAMSERVICE=


###
#   Features not activated per-default (default to off)
#
# HS_RADCONF=off	   # Get some configurations from RADIUS or a URL ('on' and 'url' respectively)
#
# HS_ANYIP=on		   # Allow any IP address on subscriber LAN
#
# HS_MACAUTH=on		   # To turn on MAC Authentication
#
# HS_MACAUTHDENY=on	   # Put client in 'drop' state on MAC Auth Access-Reject
#
# HS_MACAUTHMODE=local	   # To allow MAC Authentication based on macallowed, not RADIUS
#
# HS_MACALLOW="..."      # List of MAC addresses to authenticate (comma seperated)
#
# HS_USELOCALUSERS=on      # To use the /etc/chilli/localusers file
#
# HS_OPENIDAUTH=on	   # To inform the RADIUS server to allow OpenID Auth
#
# HS_WPAGUESTS=on	   # To inform the RADIUS server to allow WPA Guests
#
# HS_DNSPARANOIA=on	   # To drop DNS packets containing something other
#			   # than A, CNAME, SOA, or MX records
#
# HS_OPENIDAUTH=on	   # To inform the RADIUS server to allow OpenID Auth
#			   # Will also configure the embedded login forms for OpenID
#
# HS_USE_MAP=on		   # Short hand for allowing the required google
#			   # sites to use Google maps (adds many google sites!)
#
###
#   Other feature settings and their defaults
#
# HS_DEFSESSIONTIMEOUT=0   # Default session-timeout if not defined by RADIUS (0 for unlimited)
#
# HS_DEFIDLETIMEOUT=0	   # Default idle-timeout if not defined by RADIUS (0 for unlimited)
#
# HS_DEFBANDWIDTHMAXDOWN=0   # Default WISPr-Bandwidth-Max-Down if not defined by RADIUS (0 for unlimited)
#
# HS_DEFBANDWIDTHMAXUP=0	   # Default WISPr-Bandwidth-Max-Up if not defined by RADIUS (0 for unlimited)

###
# Centralized configuration options examples
# 
# HS_RADCONF=url	   # requires curl
# HS_RADCONF_URL=https://coova.org/app/ap/config

# HS_RADCONF=on		   # gather the ChilliSpot-Config attributes in
#			   # Administrative-User login
# HS_RADCONF_SERVER=rad01.coova.org		 # RADIUS Server
# HS_RADCONF_SECRET=coova-anonymous		 # RADIUS Shared Secret 
# HS_RADCONF_AUTHPORT=1812			 # Auth port
# HS_RADCONF_USER=chillispot			 # Username
# HS_RADCONF_PWD=chillispot			 # Password


###
#   Firewall issues
#
# Uncomment the following to add ports to the allowed local ports list
# The up.sh script will allow these local ports to be used, while the default
# is to block all unwanted traffic to the tun/tap. 
#
# HS_TCP_PORTS="80 443"
164
HS_TCP_PORTS="8080"
165
# HS_UDP_PORTS="123"
166
HS_UDP_PORTS="123 53"
Elena Grandi's avatar
Elena Grandi committed
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183

###
#   Standard configurations
#
HS_MODE=hotspot
HS_TYPE=chillispot
# HS_RADAUTH=1812
# HS_RADACCT=1813
# HS_ADMUSR=chillispot
# HS_ADMPWD=chillispot


###
#   Post-Auth proxy settings
#
# HS_POSTAUTH_PROXY=<host or ip>
# HS_POSTAUTH_PROXYPORT=<port>
184
HS_POSTAUTH_PROXY={{ hotspot_uamlisten }}
185
HS_POSTAUTH_PROXYPORT={{ cp_proxy_port }}
186
HS_WPAD_PROXY={{ hotspot_uamlisten }}:{{ cp_proxy_port }}
187
HS_REDIRSSL=on
Elena Grandi's avatar
Elena Grandi committed
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220

#   Directory specifying where internal web pages can be served
#   by chilli with url /www/<file name>. Only extentions like .html
#   .jpg, .gif, .png, .js are allowed. See below for using .chi as a
#   CGI extension.
HS_WWWDIR=/etc/chilli/www

#   Using this option assumes 'haserl' is installed per-default
#   but, and CGI type program can ran from wwwsh to process requests
#   to chilli with url /www/filename.chi
HS_WWWBIN=/etc/chilli/wwwsh

#   Some configurations used in certain user interfaces
#
HS_PROVIDER=Coova
HS_PROVIDER_LINK=http://www.coova.org/

###
#   WISPr RADIUS Attribute support
#

HS_LOC_NAME="FUSS Captive Portal"  # WISPr Location Name and used in portal

#   WISPr settings (to form a proper WISPr-Location-Id)
# HS_LOC_NETWORK="My Network"	   # Network name
# HS_LOC_AC=408			   # Phone area code
# HS_LOC_CC=1			   # Phone country code
# HS_LOC_ISOCC=US		   # ISO Country code

# Embedded miniportal
# HS_REG_MODE="tos" # or self, other
# HS_RAD_PROTO="pap" # or mschapv2, chap
# HS_USE_MAP=on