在Kali Rolling虚拟机中使用airbase-ng搭建伪AP无法连接的问题
Let's walk through fixing your fake AP setup—your main issue right now is a mismatched subnet between your DHCP configuration and the at0 interface, but there are a few other checks to make sure everything works smoothly.
1. Fix the Subnet Mismatch (Critical Error)
You set up DHCP to serve addresses in the 192.168.1.0/24 range, but assigned 192.168.2.1 to at0. These don't match, so connecting devices can't get a valid IP address. Here's how to align them:
- Update your
/etc/dhcp/dhcpd.confto match the192.168.2.0/24subnet (we'll stick with this for consistency):
authoritative; default-lease-time 600; max-lease-time 7200; subnet 192.168.2.0 netmask 255.255.255.0 { option subnet-mask 255.255.255.0; option broadcast-address 192.168.2.255; option domain-name-servers 8.8.8.8; option routers 192.168.2.1; range 192.168.2.10 192.168.2.100; }
- Reconfigure the
at0interface properly (make sure you complete the netmask):
ifconfig at0 down ifconfig at0 up 192.168.2.1 netmask 255.255.255.0 broadcast 192.168.2.255
2. Double-Check Airbase-ng Initialization
Make sure your wireless adapter is correctly in monitor mode and airbase-ng is cloning the target AP properly:
- First, kill any processes that might interfere with monitor mode:
airmon-ng check kill airmon-ng start wlan0 # Replace wlan0 with your actual adapter name
- Run airbase-ng with the correct channel (match the target AP's channel to avoid connectivity drops) and ESSID:
airbase-ng -c [TARGET_CHANNEL] -e "[TARGET_ESSID]" mon0 # Replace mon0 with your monitor interface
Heads up: Some adapters don't support all channels or have driver limitations. If you're using a cheap or older adapter, it might not play nice with airbase-ng.
3. Ensure the DHCP Server Starts Correctly
After fixing the subnet, restart the DHCP server and confirm it's running on at0:
systemctl restart isc-dhcp-server systemctl status isc-dhcp-server
- If it fails to start, check the logs for specific errors with
journalctl -u isc-dhcp-server—common issues include typos indhcpd.conforat0not being fully initialized.
4. Set Up IP Forwarding & NAT (For Internet Access)
Even if devices connect, they won't get internet without IP forwarding and NAT configured. Run these commands:
echo 1 > /proc/sys/net/ipv4/ip_forward iptables -t nat -A POSTROUTING -o eth0 -j MASQUERADE # Replace eth0 with your primary internet interface (e.g., wlan0 if you're using another adapter for internet)
Pro tip: To make IP forwarding persistent across reboots, edit
/etc/sysctl.confand uncomment the linenet.ipv4.ip_forward=1.
5. Check for Firewall Interference
Kali's default UFW firewall might be blocking DHCP traffic (which uses UDP ports 67 and 68). Disable it temporarily to test:
ufw disable
If this fixes the issue, you can add specific rules to allow DHCP instead of turning off UFW entirely:
ufw allow in on at0 to any port 67 proto udp ufw allow out on at0 to any port 68 proto udp
6. Verify Adapter Driver Compatibility
Some wireless adapters have buggy or incomplete drivers that cause issues with airbase-ng. Check your adapter and its driver with:
lspci -k | grep -A 3 -i network # For PCI adapters lsusb # For USB adapters
- If your adapter is giving you trouble, consider switching to a known compatible model (like the Alfa AWUS036NH) which has solid monitor mode support.
内容的提问来源于stack exchange,提问作者muhzi

