I'm trying to setup a experimental wireless IDS system. The problem I'm having is that I must be able to follow wireless clients via their MAC address. Currently I only see mac addresses of eth0, and wlan0
I've the follwing working on openwrt latest trunk
network (gateway to network)
^
|
openwrt [ (wlan0) <- + -> (eth0) - - -> (eth1) ]
|
|
network monitor \-> (ids) (192.168.5.5)
The IDS box is fed forwarded traffic vi iptables:
iptables -A PREROUTING -t mangle -f TEE --gw 192.168.5.5
Traffic is being monitored on the ids via wireshark.
Any suggestions on how to keep the wireless mac address intact all the way to the IDS? (ebtables?)
Thanks
(Last edited by smalltime on 14 Sep 2010, 03:45)