Tor Wifi Gateway

From Leo's Notes
This page was last edited on 12 May 2013, at 20:37.

Introduction

The Tor Wifi Gateway is a planned open wifi access point that lets users connect to the internet via Tor. The purpose of this is to create a gateway which transparently proxies traffic over to Tor (which intrinsically is useful for other projects), perhaps share internet access to neighbors, and perhaps provide access to my stash without authentication.

What Configuration
External Network Interface (to internet) eth0 (10.1.1.11)
Internal Network Interface (to wifi access point) eth1 (192.168.192.10, 192.168.192.11)

Setup

  1. Tor Setup: https://trac.torproject.org/projects/tor/wiki/doc/TransparentProxy#LocalRedirectionandAnonymizingMiddlebox1
  2. DHCP / DNS proxy for the wifi subnet

TOR

Edit the /etc/tor/torrc configuration to contain the following lines:

VirtualAddrNetwork 10.192.0.0/10
AutomapHostsOnResolve 1

TransPort 9040
TransListenAddress 192.168.192.10

DNSPort 53
DNSListenAddress  192.168.192.11

I've placed the DNS server on a separate IP because I will be using dnsmasq as my 'primary' DNS server that users will be using since I wanted my own portal/splash page with my own domain name (ie: torified.wifi).

Troubleshooting

If you are having trouble starting tor as a service with it complaining about being unable to listen on a specific port, ensure you have SELinux configured (or disabled).

DHCP / DNS Server

We will be using dnsmasq as the DHCP/DNS server.

no-resolv
port=53
server=192.168.0.1  # the DNS server
interface=eth1
address=/torified.wifi/192.168.192.10
dhcp-script=/scripts/dnsmasq_dhcp
dhcp-range=192.168.192.20,192.168.192.250,1h
dhcp-option=6,192.168.192.10
dhcp-option=3,192.168.192.10
domain=torified.wifi
log-queries
log-dhcp
conf-dir=/etc/dnsmasq.d

Notice that the DNS server is 192.168.0.1 -- this IP does not in fact exist in my network. I will use IPTables (see below) to redirect this traffic to TOR. Reason I am using this IP is because it is not on the interface since dnsmasq will complain otherwise.

IPTables

#!/bin/sh

IPT=/sbin/iptables
TOR_NET=192.168.192.0/24
TOR_IF=eth1

$IPT -F
$IPT -t nat -F

$IPT -X tor_clients_chain
$IPT -N tor_clients_chain

$IPT -t nat -A PREROUTING -i $TOR_IF -p tcp -d 192.168.192.10 --dport 80 -j ACCEPT
$IPT -t nat -A PREROUTING -i $TOR_IF -p tcp -d 192.168.192.11 --dport 80 -j ACCEPT
$IPT -t nat -A PREROUTING -i $TOR_IF -j tor_clients_chain
$IPT -t nat -A PREROUTING -i $TOR_IF -p tcp  -j DNAT --to-destination 192.168.192.10:80

# To route all traffic through TOR, use:
#$IPT -t nat -A PREROUTING -i $TOR_IF -p udp --dport 53 -j REDIRECT --to-ports 53
#$IPT -t nat -A PREROUTING -i $TOR_IF -p tcp --syn -j REDIRECT --to-ports 9040

# Redirect dns traffic going to 192.168.0.1:53 to 192.168.192.11:53
$IPT -t nat -A OUTPUT -p udp -d 192.168.0.1 --dport 53 -j DNAT --to-destination 192.168.192.11:53

To add additional clients that can access the TOR network, run the following lines per IP:

$IPT -t nat -I tor_clients_chain -p tcp -s $IP --syn -j REDIRECT --to-ports 9040 
$IPT -t nat -I tor_clients_chain -p udp -s $IP --dport 53 -j REDIRECT --to-ports 53

To remove clients from access, run:

$IPT -t nat -D tor_clients_chain -p tcp -s $IP --syn -j REDIRECT --to-ports 9040
$IPT -t nat -D tor_clients_chain -p udp -s $IP --dport 53 -j REDIRECT --to-ports 53

Splash Page

With the basic infrastructure set up, we will now just need to create the splash page which will show the users the TOS, before letting them 'register' onto the network (which will just add their IP to the tor_clients_chain, thereby enabling internet access). The dnsmasq lease time will cause the IPs to 'unregister' after the lease expires when the /scripts/dnsmasq_dhcp script gets executed.

More information tomorrow...