1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
|
.\" $OpenBSD: ancontrol.8,v 1.12 2001/08/08 23:58:56 heko Exp $
.\"
.\" Copyright (c) 1997, 1998, 1999
.\" Bill Paul <wpaul@ee.columbia.edu> All rights reserved.
.\"
.\" Redistribution and use in source and binary forms, with or without
.\" modification, are permitted provided that the following conditions
.\" are met:
.\" 1. Redistributions of source code must retain the above copyright
.\" notice, this list of conditions and the following disclaimer.
.\" 2. Redistributions in binary form must reproduce the above copyright
.\" notice, this list of conditions and the following disclaimer in the
.\" documentation and/or other materials provided with the distribution.
.\" 3. All advertising materials mentioning features or use of this software
.\" must display the following acknowledgement:
.\" This product includes software developed by Bill Paul.
.\" 4. Neither the name of the author nor the names of any co-contributors
.\" may be used to endorse or promote products derived from this software
.\" without specific prior written permission.
.\"
.\" THIS SOFTWARE IS PROVIDED BY Bill Paul AND CONTRIBUTORS ``AS IS'' AND
.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
.\" ARE DISCLAIMED. IN NO EVENT SHALL Bill Paul OR THE VOICES IN HIS HEAD
.\" BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR
.\" CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF
.\" SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
.\" INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN
.\" CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF
.\" THE POSSIBILITY OF SUCH DAMAGE.
.\"
.\" $FreeBSD: src/usr.sbin/ancontrol/ancontrol.8,v 1.3 2000/03/02 14:53:33 sheldonh Exp $
.\"
.Dd September 10, 1999
.Dt ANCONTROL 8
.Os
.Sh NAME
.Nm ancontrol
.Nd configure Aironet 4500/4800 devices
.Sh SYNOPSIS
.Nm ancontrol
.Op Ar interface
.Op Fl A
.Op Fl N
.Op Fl S
.Op Fl I
.Op Fl T
.Op Fl C
.Op Fl a Ar AP
.Op Fl b Ar beacon period
.Op Fl c Ar channel number
.Op Fl v Ar 0|1
.Op Fl d Ar 0|1|2|3
.Op Fl e Ar 0|1|2|3
.Op Fl f Ar fragmentation threshold
.Op Fl j Ar netjoin timeout
.Op Fl v Ar 0|1|2|3|4|5|6|7
.Op Fl k Ar key
.Op Fl K Ar 0|1|2
.Op Fl l Ar station name
.Op Fl m Ar macaddress
.Op Fl v Ar 1|2|3
.Op Fl n Ar SSID
.Op Fl o Ar 0|1
.Op Fl p Ar tx power
.Op Fl r Ar RTS threshold
.Op Fl s Ar 0|1|2|3
.Op Fl t Ar 0|1|2|3|4
.Op Fl v Ar 1|2|3|4
.Op Fl W Ar 0|1|2
.Sh DESCRIPTION
The
.Nm
command controls the operation of Aironet wireless networking
devices via the
.Xr an 4
driver.
Most of the parameters that can be changed relate to the
IEEE 802.11 protocol which the Aironet cards implement.
This includes
the station name, whether the station is operating in ad-hoc (point
to point) or infrastructure mode, and the network name of a service
set to join.
.Nm
can also be used to view the current NIC status, configuration
and to dump out the values of the card's statistics counters.
.Pp
The
.Ar interface
argument given to
.Nm
should be the logical interface name associated with the Aironet
device (e.g., an0, an1, etc...).
.Pp
The options are as follows:
.Bl -tag -width Ds
.It Fl A
Display the preferred access point list.
The AP list can be used by
stations to specify the MAC address of access points with which it
wishes to associate.
If no AP list is specified (the default) then
the station will associate with the first access point that it finds
which serves the SSID(s) specified in the SSID list.
The AP list can
be modified with the
.Fl a
option.
.It Fl C
Display current NIC configuration.
This shows the current operation mode,
recieve mode, MAC address, power save settings, various timing settings,
channel selection, diversity, transmit power, and transmit speed.
.It Fl I
Display NIC capability information.
This shows the device type,
frequency, speed, and power level capabilities and firmware revision levels.
.It Fl K Ar "0|1|2"
Set authorization type.
Use 0 for none, 1 for "Open", 2 for "Shared Key".
.It Fl N
Display the SSID list.
This is a list of service set IDs (i.e., network names)
with which the station wishes to associate.
There may be up to three SSIDs
in the list: the station will go through the list in ascending order and
associate with the first matching SSID that it finds.
.It Fl S
Display NIC status information.
This includes the current operating
status, current BSSID, SSID, channel, beacon period, and currently
associated access point.
The operating mode indicates the state of
the NIC, MAC status and receiver status.
When the
.Dq synced
keyword appears, it means the NIC has successfully associated with an access
point, associated with an ad-hoc
.Dq master
station, or become a
.Dq master
itself.
The beacon period can be anything between 20 and 976 milliseconds.
The default is 100.
.It Fl T
Display the NIC's internal statistics counters.
.It Fl W Ar "0|1|2"
Enable WEP.
Use 0 for no WEP, 1 to enable full WEP, 2 for mixed cell.
.It Fl v Ar "1|2|3|4" Fl a Ar AP
Set preferred access point.
The
.Ar AP
is specified as a MAC address consisting of 6 hexadecimal values
separated by colons.
By default, the
.Fl a
option only sets the first entry in the AP list.
The
.Fl v
modifier can be used to specify exactly which AP list entry is to be
modified.
If the
.Fl v
flag is not used, the first AP list entry will be changed.
.It Fl b Ar beacon period
Set the ad-hoc mode beacon period.
The becon period is specified in
milliseconds.
The default is 100ms.
.It Fl c Ar channel
Set the radio frequency of a given interface.
The
.Ar frequency
should be specified as a channel ID as shown in the table below.
The
list of available frequencies is dependent on radio regulations specified
by regional authorities.
Recognized regulatory authorities include
the FCC (United States), ETSI (Europe), France, and Japan.
Frequencies
in the table are specified in Mhz.
.Bd -filled -offset indent
.Bl -column "Channel ID " "FCC " "ETSI " "France " "Japan "
.Em "Channel ID FCC ETSI France Japan"
1 2412 2412 - -
2 2417 2417 - -
3 2422 2422 - -
4 2427 2427 - -
5 2432 2432 - -
6 2437 2437 - -
7 2442 2442 - -
8 2447 2447 - -
9 2452 2452 - -
10 2457 2457 2457 -
11 2462 2462 2462 -
12 - 2467 2467 -
13 - 2472 2472 -
14 - - - 2484
.El
.Ed
.Pp
If an illegal channel is specified, the
NIC will revert to its default channel.
For NICs sold in the United States
and Europe, the default channel is 3.
For NICs sold in France, the default channel is 11.
For NICs sold in Japan, the only available channel is 14.
Note that two stations must be set to the same channel in order to
communicate.
.It Fl v Ar "0|1" Fl d Ar "0|1|2|3"
Select the antenna diversity.
Aironet devices can be configured with up
to two antennas, and transmit and receive diversity can be configured
accordingly.
Valid selections are as follows:
.Bd -filled -offset indent
.Bl -column "Selection " "Diversity "
.Em "Selection Diversity"
0 Select factory default diversity
1 Antenna 1 only
2 Antenna 2 only
3 Antenna 1 and 2
.El
.Ed
.Pp
The receive and transmit diversity can be set independently.
The user
must specify which diversity setting is to be modified by using the
.Fl v
option: selection
.Ar 0
sets the receive diversity and
.Ar 1
sets the transmit diversity.
.It Fl e Ar "0|1|2|3"
Set the transmit WEP key to use.
Note that until this command is issued, the device will use the
last key programmed. The transmit key is stored in NVRAM.
Currently set transmit key can be checked via
.Fl C
option.
.It Fl f Ar fragmentation threshold
Set the fragmentation threshold in bytes.
This threshold controls the
point at which outgoing packets will be split into multiple fragments.
If a single fragment is not sent successfully, only that fragment will
need to be retransmitted instead of the whole packet.
The fragmentation
threshold can be anything from 64 to 2312 bytes.
The default is 2312.
.It Fl h
Prints a list of available options and sample usage.
.It Fl j Ar netjoin timeout
Set the ad-hoc network join timeout.
When a station is first activated
in ad-hoc mode, it will search out a 'master' station with the desired
SSID and associate with it.
If the station is unable to locate another
station with the same SSID after a suitable timeout, it sets itself up
as the 'master' so that other stations may associate with it.
This
timeout defaults to 10000 milliseconds (10 seconds) but may be changed
with this option.
The timeout should be specified in milliseconds.
.It Fl v Ar "0|1|2|3|4|5|6|7" Fl k Ar key
Set a WEP key.
For 40 bits, prefix 10 hex digits with 0x.
For 128 bits, prefix 26 hex digits with 0x.
Use "" as the key to erase it.
Supports 4 keys; even numbers are for permanent keys
and odd numbers are for temporary keys.
For example, "-v 1" sets the first temporary key.
(A "permanent" key is stored in NVRAM; a "temporary" key is not.)
Note that the device will use the most recently-programmed key
by default.
Currently set keys can be checked via
.Fl C
option, only the sizes of the keys are returned.
.It Fl l Ar station name
Set the station name used internally by the NIC.
The
.Ar station name
can be any text string up to 16 characters in length.
The default name
is set by the driver to
.Qq OpenBSD .
.It Fl m Ar macaddress
Set the station address for the specified interface.
The
.Ar macaddress
is specified as a series of six hexadecimal values separated by colons,
e.g.: 00:60:1d:12:34:56.
This programs the new address into the card
and updates the interface as well.
.It Fl v Ar "1|2|3" Fl n Ar SSID
Set the desired SSID (network name).
There are three SSIDs which allows
the NIC to work with access points at several locations without needing
to be reconfigured.
The NIC checks each SSID in sequence when searching
for a match.
The SSID to be changed can be specified with the
.Fl v
modifier option.
If the
.Fl v
flag isn't used, the first SSID in the list is set.
.It Fl o Ar 0|1
Set the operating mode of the Aironet interface.
Valid selections are
.Ar 0
for ad-hoc mode and
.Ar 1
for infrastructure mode.
The default driver setting is for infrastructure mode.
.It Fl p Ar tx power
Set the transmit power level in milliwatts.
Valid power settings
vary depending on the actual NIC and can be viewed by dumping the
device capabilities with the
.Fl I
flag.
Typical values are 1, 5, 20, 50, and 100mW.
Selecting 0 sets
the factory default.
.It Fl r Ar RTS threshold
Set the RTS/CTS threshold for a given interface.
This controls the
number of bytes used for the RTS/CTS handhake boundary.
The
.Ar RTS threshold
can be any value between 0 and 2312.
The default is 2312.
.It Fl s Ar 0|1|2|3
Set power save mode.
Valid selections are as follows:
.Bd -filled -offset indent
.Bl -column "Selection " "Power save mode "
.Em "Selection Power save mode"
0 None - power save disabled
1 Constantly awake mode (CAM)
2 Power Save Polling (PSP)
3 Fast Power Save Polling (PSP-CAM)
.El
.Ed
.Pp
Note that for IBSS (ad-hoc) mode, only PSP mode is supported, and only
if the ATIM window is non-zero.
.It Fl t Ar 0|1|2|3|4
Select transmit speed.
The available settings are as follows:
.Bd -filled -offset indent
.Bl -column "TX rate " "NIC speed "
.Em "TX rate NIC speed"
0 Auto -- NIC selects optimal speed
1 1Mbps fixed
2 2Mbps fixed
3 5.5Mbps fixed
4 11Mbps fixed
.El
.Ed
.Pp
Note that the 5.5 and 11Mbps settings are only supported on the 4800
series adapters: the 4500 series adapters have a maximum speed of 2Mbps.
.El
.Sh SECURITY NOTES
WEP ("wired equivalent privacy") is based on the RC4 algorithm,
using a 24 bit initialization vector.
.Pp
RC4 is supposedly vulnerable to certain known plaintext attacks,
especially with 40 bit keys.
So the security of WEP in part depends on how much known plaintext
is transmitted.
.Pp
Because of this, although counter-intuitive, using "shared key"
authentication (which involves sending known plaintext) is less
secure than using "open" authentication when WEP is enabled.
.Pp
Devices may alternate among all of the configured WEP keys when
tranmitting packets.
Therefore, all configured keys (up to four) must agree.
.Sh SEE ALSO
.Xr an 4 ,
.Xr wi 4 ,
.Xr wicontrol 4 ,
.Xr hostname.if 8 ,
.Xr ifconfig 8
.Sh AUTHORS
The
.Nm
command was written by Bill Paul <wpaul@ee.columbia.edu> and ported to
.Ox
by Michael Shalayeff <mickey@openbsd.org>.
.Sh HISTORY
The
.Nm
command first appeared in
.Fx 3.0
and
.Ox 2.7 .
.Sh BUGS
The statistics counters do not seem to show the amount of transmit
and received frames as increasing.
This is likely due to the fact that
the
.Xr an 4
driver uses unmodified packet mode instead of letting the NIC perform
802.11/Ethernet encapsulation itself.
.Pp
Setting the channel does not seem to have any effect.
|