Re: [Dorset] Query about iptables

2022-03-28 Thread Terry Coles
On Monday, 28 March 2022 21:41:16 BST Patrick Wigmore wrote:
> And is this borne out in the testing? Does the Visitor's device get
> issued with an address in the expected range under both the working
> and non-working scenarios? Does it also get told about the same DNS
> server and default gateway (if any) in each case?

Yes.  In both scenarios the Visitor's device gets an IP Address and is told 
about the DNS Server and default gateway, which is the Webserver.  What 
doesn't work is the script that points the Visitors Web Browser to the landing 
Page.

Since I originally posted this, things have moved on.  Yesterday I experienced 
several instances where the system worked with the link to the VPN Server 
connected and a couple when it didn't when it wasn't.  I've been in contact 
with the author of pistrong and he got me to capture some Webserver data in 
both scenarios and we both came to the conclusion that the link to the VPN 
Server was a red herring; the problem lies with nodogsplash.

This used to occur very rarely in the original installation (including before 
the VPN Server went in), but now it seems to be worse.  That is what I am 
looking at now.

> Does the Visitor's device obtain any unintended Internet access at
> all?

No.  The only Internet access is in the initial stage when requests from the 
client devices to certain Google Servers are passed on to allow the device to 
'see' the WiFi Network as a valid network and not a walled garden.  Once the 
connection is established the the Visitor's device is issued with a token 
which provides access to the WMT content, but blocks access to the Internet.

-- 



Terry Coles



-- 
  Next meeting: Online, Jitsi, Tuesday, 2022-05-04 20:00
  Check to whom you are replying
  Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
  New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk


Re: [Dorset] Query about iptables

2022-03-28 Thread Patrick Wigmore
On Sun, 27 Mar 2022 16:13:49 +0100, Terry Coles wrote:
> On Sunday, 27 March 2022 16:07:30 BST Patrick Wigmore wrote:
> > What is the IP address of the user's device, and how does it get
> > allocated to that device?
> 
> The Webserver is also a DHCP Server and a DNS Server.  The bottom
> 100 addresses are reserved for devices that a permanently
> connected, eg river system etc.  The top 100 or so addresses are
> allocated to a user (eg a Visitor) by the DHCP Server.  As soon as
> the user's device is connected to the WiFi network, nodogsplash
> routes his browser to the Webserver.
> 
> In other words, when a Visitor connects to the site WiFi he gets a
> landing page on his device which allows him to choose the content
> he wishes to view.

And is this borne out in the testing? Does the Visitor's device get 
issued with an address in the expected range under both the working 
and non-working scenarios? Does it also get told about the same DNS 
server and default gateway (if any) in each case?

Does the Visitor's device obtain any unintended Internet access at 
all?

Patrick



-- 
  Next meeting: Online, Jitsi, Tuesday, 2022-05-04 20:00
  Check to whom you are replying
  Meetings, mailing list, IRC, ...  http://dorset.lug.org.uk
  New thread, don't hijack:  mailto:dorset@mailman.lug.org.uk