| ← Revision 140 as of 2007-09-04 21:44:39  Size: 17093 Comment:  | ← Revision 141 as of 2007-09-04 21:50:25 → Size: 17206 Comment:  | 
| Deletions are marked like this. | Additions are marked like this. | 
| Line 19: | Line 19: | 
| * GPLed, runs on FreeBSD. Uses Ajax or Java applet to keep the connection open. Ftp, pop3, pop3s, RADIUS, LDAP or PAM servers for an authentication back-end. (added by Jim Thompson) | * GPLed, runs on FreeBSD. Uses Ajax (or Java applet) to keep the connection open. When the authenticated user closes his/her browser or OS, the network for the terminal is closed immediately. Ftp, pop3, pop3s, RADIUS, LDAP or PAM servers for an authentication back-end. (added by Jim Thompson) | 
Since we first started talking about using the browser as an authentication tool in December 2000 OpenSource implementations have started to appear. Here is a list of all the software I know of that implements either a CaptivePortal or an ActivePortal solution.
LiveCD
- ZoneCD Gateway http://www.publicip.net/ with NoCat installed - DennyHalim 
- [http://www.lessnetworks.com/ lessnetworks] with NoCat installed - DennyHalim 
- [http://talweg.univ-metz.fr/talweg:en:start talweg] Demo LiveCD 
Open Source
- [http://talweg.univ-metz.fr/talweg:en:start talweg] - It's a http/https captive portal. It uses http redirections to enforce transmissions using a secured https channel. Using of IP/MAC address to maintain sessions are not necessary, the authentication is more secure.
 
- [http://nocat.net/download/NoCatAuth/ NoCatAuth] - Written in perl, supports Linux/iptables and OpenBSD/pfctl. GPLed. Supports authenticating modes against an auth service with a wide variety of backends, including a MySQL database, PAM, RADIUS, LDAP, and more. Also features a non-authenticating "open mode" that merely requires a user to accept an AUP before they can log in. This project is more or less seeking a new maintainer.
 
- [http://nocat.net/download/NoCatSplash/ NoCatSplash] - Written in C, currently under heavy development. Intended to be the successor to NoCatAuth, the gateway process and all its data files fit within 200-250k, making it ideal for embedded environments. 
 
- [http://net.doit.wisc.edu/~dwcarder/captivator/ Captivator-gw] - Captive portal that works inline at Layer 2 in your network. Supports vlans and trunk interfaces. Uses arp to detect if users are still connected. Written in perl, and easy to add new features. Developed at the University of Wisconsin - Madison.
 
- [http://www.cc.saga-u.ac.jp/opengate/index-e.html Opengate developed at Saga University (Japan)] - GPLed, runs on FreeBSD. Uses Ajax (or Java applet) to keep the connection open. When the authenticated user closes his/her browser or OS, the network for the terminal is closed immediately. Ftp, pop3, pop3s, RADIUS, LDAP or PAM servers for an authentication back-end. (added by Jim Thompson)
 
- Still in early beta but it will provide an entire network application framework rather then just a CaptivePortal solution. 
 
- [http://www.geekspeed.net/wicap/ WiCap] by BrianCaswell - Written in Perl and runs under OpenBSD. I believe this is what NovaWireless will be deploying. 
 
- ["WiCap-PHP"] by CalebPhillips - Written in 'C' and PHP, runs under OpenBSD. There is a fork written in Python and PHP. A more betterer implementation of WiCap. 
 
- [http://www.river.com/tools/authhb/ River of Stars] - Wireless heartbeat implementation (presently most usable on an OpenBSD gateway)
 
- [http://www.lanroamer.net/soholanroamerdevframe.html LanRoamer] (Linux 2.4.x) - Based on the Linux 2.4 kernel and GPL'd. (Name changed to LanRoamer by Jim Thompson) 
 
- [http://slan.sourceforge.net/ SLAN] - A GPL'd captive portal implementation using VPN technology. Has Linux and Windows clients.
 
- [http://ceres.unit.liu.se/netlogon-devel/ Netlogon] by Kent Engström at Linköpings University - Not much known, a basic captive portal solution.
 
- [http://www.itlab.musc.edu/~nathan/authentication_gateway/ Authentication Gateway HOWTO] by Nathan Zorn - Uses a PAM module to insert an iptables rule. Very simple and effective. (Added by LimAko). 
 
- [http://software.stockholmopen.net/index.shtml StockholmOpen] by the Royal Institute of Technology in Stockholm, Sweden - This system is also operator neutral, allowing different users to connect through the access network to different upstream providers. Implementation in C, uses PAM, Linux/FreeBSD. BSD License. (Added by MartinHedenfalk). 
 
- [http://www.opensplash.org OpenSplash] by Aleksandr Melentiev from San Francisco Wireless - Inspired by the simplicity of wicap, intended to run on FreeBSD by utilizing Perl and ipfw. Doesn't provide much functionality, other than a simple AUP agreement. Development version includes abstract authentication system.
 
- [http://www.chillispot.org ChilliSpot] by Mondru AB - ChilliSpot is an open source captive portal or wireless LAN access point controller written in C which supports web based login (external web server required) as well as Wireless Protected Access (WPA), sports a builtin DHCP server and a RADIUS client/proxy server to handle authentication, authorization and accounting (AAA) via an external Radius server. Currently runs on Linux (RedHat, Fedora, Debian binaries and Gentoo ebuild available) but should compile also on FreeBSD, OpenBSD, Solaris, Apple OS X. Previously known as [http://www.mondru.com/hotspotd.html hotspotd], which was available only as binary. Fifth GPL release (0.94): 2004-06-22. (Added by Ovidiu) 
 
- [http://m0n0.ch/wall/ M0n0wall] by Manuel Kasper - Embedded Firewall based on FreeBSD that can run from embedded devices as well as PC's. The Captive Portal software included with it allows for button/AUP pass through, as well as authentication using Radius.
 
- [http://pfsense.org/ pfSense] - Firewall based on FreeBSD6 that can run from embedded devices as well as PC's. The Captive Portal software included with it allows for button/AUP pass through, as well as authentication using Radius.
 
- [http://www.ilesansfil.org/wiki/WiFiDog Wifidog] - The WiFiDog project was started by Île sans fil and is currently in production. Existing captive were either almost impossible to embede or only designed to display disclaimers with no access control at all (No Cat Splash and others). WiFiDog is designed to have optional centralized access control, full bandwidth accounting, node heartbeating and local content specific to each hotspot. It does not rely on a javascript window, so it works with any platform with a web browser, including PDAs and cellphones. It is developed in C to make it easy to include in embedded systems (It has been designed for the LinkSys WRT54G, but runs on any recent linux platform). A typical install only takes 30kb on i386, and a fully functionnal install could be made in under 10 kb if necessary. 
 
- [http://www.openbsd.org/faq/pf/authpf.html Authpf] - User Shell for Authenticating Gateways on OpenBSD. Authpf(8) is a user shell for authenticating gateways. User logs in using SSH.
 
- [http://sweetspot.sf.net sweetspot] - IP-level captive portal with built-in packet filtering and accounting features, Linux based.
 
Free (Closed Source)
- [http://www.2hotspot.com/ 2hotspot] - Instant creation of hotspots for Windows XP,2k,2003. Works with any wireless router or adapter. Optional profit mode makes charging clients extremely easy. Has optional IP-based authentication (no MAC required).
 
Commercial
- [http://www.hotspotsystem.com HotSpotSystem.com] - Commercial or Free HotSpot solution - [http://www.hotspotsystem.com/en/hotspot/hotspot_billing_hotspot_management.html HotSpot PRO] - for creating paid HotSpots 
- [http://www.hotspotsystem.com/en/hotspot/free_hotspot.html HotSpot FREE] - for creating a FREE HotSpot with authentication - Limit accesses with access codes
- Limit bandwidth/data traffic
- 3 different subscription models depending on the number of authentications per month
 
 
- myWIFIzone [http://www.myWIFIzone.com Captive Portal Services] - Windows 2k,XP supports free spot or hotspot, Mthly. fee (free while in Beta test)
- On-line tools for customizing captive portal, adding users, etc.
 
- Patronsoft [http://www.patronsoft.com/firstspot FirstSpot] 
- MikroTik Hotspot RouterOS -- www.mikrotik.com 
- [http://www.aradial.com Aradial] Radius server and [http://www.radius-server.net Radius Billing] software solutions 
- [http://www.aptilo.com/solutions.htm Aptilo's system for hotspot management] - Billing integrated with Credit card brokers, hotel systems, mobile phone systems, etc
- Visitor Access functionality.
- Full plug'n'play support.
 
- Cisco http://www.cisco.com - BBSM [http://www.cisco.com/univercd/cc/td/doc/product/aggr/bbsm/bbsmhs10/index.htm Cisco Building Broadband Service Manager] 
- SSG/SESM [http://www.cisco.com/univercd/cc/td/doc/product/dsl_prod/6400/feat_gd/12_1_5/ssg.htm Cisco Service Selection Gateway] [http://www.cisco.com/en/US/products/hw/routers/ps314/products_data_sheet09186a0080091f30.html Cisco Subscriber Edge Services Manager] 
 
- [http://www.interlinknetworks.com Interlink Networks RADIUS Server Software] High Performance RADIUS Software 
- Nokia http://www.nokia.com - Mobilestar used P020s for the initial deployment of over 600 Starbucks. When Voice Stream bought the remnants of the bankruptcy, all 600+ Starbucks were retrofitted because Nokia's solution did not properly safeguard username and password combinations with an https page. P022 corrected this major bug among a few other things.
- P020 Public Access Zone Controller (discontinued) is an integrated network appliance with a RADIUS client and DHCP server.
- P022 Access Controller (discontinued) Nokia P022 Access Controller--Your IP Gateway to the Internet. The Nokia P022 Access Controller is a gateway between the Wireless LAN network and the Internet. The P022 authenticates the user, monitors network usage in real-time, collects charging information and acts as a router. The Nokia P022 Access Controller can be connected to the Nokia Authentication Server for integration into a mobile operators network or to a RADIUS server for integration into other customer, care and billing systems.
- P030 Mobility Services Manager (discontinued) offers the RADIUS server and billing functions.
 
- Nomadix http://www.nomadix.com 
- T-Mobile HotSpot http://www.t-mobile.com/hotspot (Starbucks Borders FedEx Kinkos Red Roof Hyatt American Delta United USAir...) - Starbucks has a CaptivePortal solution of some sort. Anyone know the details? 
- Yeah, its Cisco's Service Selection Gateway -- Jim Thompson
- In UK, running in cooperation with Aptilo's Service Management Platform for added functionality.
 
- [http://www.mschoice.com/ MS Choice] (site requires IE5) Microsoft's testbed for the Starbucks Deal. - "To prevent such unauthorized access and hacking, OIT developed its own authentication program requiring wireless users to log in through a web browser before access to the Internet is granted. If a user's connection is inactive for a certain amount of time, the authentication system closes the user's access, deterring potential hackers from taking advantage of the connection."
- Not quite true. The Starbucks deal was Mobilestar, and there was precious little Microsoft content in the deal (or company). --Jim Thompson
 
- [http://www.news-info.gatech.edu/news_releases/lawn.html Columbitech's Wireless VPN ] - "... enables mobile professionals to access mission-critical data on the corporate LAN from all major handheld devices, with optimized performance and true end-to-end security from application to application. In addition, Columbitech's solution offers a secure always-on experience. Columbitech Wireless VPN will also support wireless network roaming."
- Mostly a mobile IP / VPN solution.
 
- [http://www.nas.nasa.gov/Resources/Networks/wireless_paper.html NASA's Wireless Firewall Gateway] - A solution using Openbsd, PHP, IPFilter and Apache. There is no source available that I know of.
 
- [http://www.wayport.net Wayport] - Another solution using Linux, perl IPF, and Apache. No source available --Jim Thompson
 
- [http://www.surfandsip.com Surf and Sip] - Hack using FreeBSD, perl, ipfw and mini_httpd. No source available -- MattPeterson 
 
- [http://www.fatport.com FatPort] - Gateway software running OpenBSD, Perl, C, and Apache.
- Auth server running PostgreSQL, etc..
- System can be licensed, but code not available. --KenSimpson 
 
- [http://www.birdstep.com IPzone] Linux,Apache No source available -- Suresh Rasaretnam - The ipzone division of BirdStep has merged with [http://www.aptilo.com Aptilo Networks]. 
 
- [http://www.controlap.com ControlAP] Win*,*nix,MacOS, Zaurus,PocketPC - JAVA VM needed - No source available, web-based administration - free 30 days trial. 
- [http://www.dnsredirector.com DNS Redirector] - Forces a splash page (welcome, coupon, registration, or terms & conditions) the first time someone tries to surf the Internet on your network. 
- For paid wifi, free-spots, or any public network.
- Runs on Windows 2K/XP/2003 Server.
- Also useful for content filtering, time of day restriction, ad blocking or replacement with your own ads.
- Very customizable; redirects browsing to your own HTML/ASP/PHP welcome, blocked, restricted, or warning pages served by IIS or Apache.
 
- [http://www.iea-software.com/airmarshal Air Marshal Authentication Gateway] Commercial Linux-based captive portal for HotSpots, Fixed Wireless and Wired Networks. - RADIUS Auth, Acct, Disconnect, PreAuth (MAC), WISPr, Ascend Filters, Failover 
- SSL and browser based CHAP protects credentials and private customer data
- Supports Static Routing, NAT and transparent L2 bridging
- Guest / Anon Access /w daily usage limits
- Local accts: UL/DL rate shaping, expiration, time and data usage limits
- Network TCP/UDP listeners authenticate servers, Nintendo DS, etc
- Walled gardens, commercial interruptions, customizable client HTML UI
- Session data mirroring/intercept to remote collector
- FREE for up to 5 concurrent logon sessions
 
- [http://www.linspot.com/ LinSpot] - U can get the Linux-version via email at beta@linspot.com It is a free and easy software to sell your Wireless Internet Access. 
 
- [http://www.sputnik.com/ Sputnik Managed Wi-Fi Networks] "Everything you need to deploy and manage a profitable Wi-Fi network." - Plug 'n Play provisioning
- User authentication and tracking
- Manage 1 or 1,000 access points remotely
- Modules for accepting PayPal payments 
- Modules for accepting credit card payments (Note: Requires a hosted billing account with Aria Systems.)
- Modules for "Pre-Paid Cards"
- Give customers monthly & renewing subscription options 
- Supports RADIUS accounting
- Buy the Sputnik Control Center and run it on your own server or subscribe to SputnikNet and have them host it for you. 
- Firmware images for the Linksys WRT54G(S) freely downloadable. (When combined with a subscription to SputnikNet you'll be up and running in no time!) 
 
- [http://www.lucidlink.com Free Secure WiFi Client] LucidLink WiFi Security. 
- [http://www.wilibox.com/ WILIBOX Embedded Linux Platform] Commercial Linux-based software platform targeting WISPs. Demo download available. - Supports common access point and router hardware platforms
- 802.11 stack supports multiple virtual APs (multiple BSSIDs) and multiple client mode STA (station) connections concurrently
- Hotspot features: WEB login redirection (captive portal), UAT, SMTP redirection, RADIUS and others
- RCMS - Remote Configuration Management System, firmware management and status reporting
 
- [http://www.wisper.se WisperMesh Pro and WUMPS - Wisper User Management and Provisioning System] - Hosted or standalone HotZone management system for WiFi MESH networks 
- Pre-paid cards can customized and printed to pre-cut business card sheets
- Premium-SMS, Paypal and Credit Card payments.
- Central management for nodes settings and firmware, user accounting and status reports
- Support for multiple BSSID's and VLAN's with independent QoS for Internet, VoWLAN and multicast streaming media
 
- [http://worldspot.net WorldSpot] - Hosted hotspot management portal. Free for free hotspots.
- Chillispot compatible (implies compatibility with opensource firmware like DD-WRT, OpenWrt, or any linux platform) 
- No need for PC, only a linux compatible wifi router needed.
- Advanced pre-paid cards
- Wysiwyg cards customization and printing
- Wysiwyg welcome page customization
- Paypal online billing soon.
 

