Wol forwarder

Hi

I created an add on / app for home assistant that allows to remotely wake up devices on your local network:


WoL Forwarder

This App (add-on) for Home Assistant provides a small daemon to forward Wake-on-LAN (WOL) magic packets on your LAN. Forwarding is protected by SecureOn, with optionally Host (source) and MAC (target) filtering.

Use case:

  • Enable WOL remotely from the internet in a secure way.
  • Many routers deliberately don’t support forwarding broadcasts and only forward to a specific IP/port on the LAN.
  • Broadcasts can be abused for DDoS, so opening the standard WOL ports (7 or 9) on the internet is not ideal.
  • Forwarding should only be allowed when the packet is at least authenticated by SecureOn.
  • Optionally you want to filter on sources (hosts) and / or targets (MAC)

What WOL Forwarder offers:

  • Your router forwards UDP packets from an arbitrary external port (typically >50000) to this WOL forwarder app (addon)
  • The daemon checks whether the incoming UDP packet is a valid WOL packet and validates the SecureOn password.
  • Lists of known sources (hosts) and targets (mac) can be defined and optionally used for filtering
  • Only legimit packets are broadcast on the local network (on a configurable wol_port). Here the SecureOn suffix is removed before broadcasting.
  • Optional HTTP API for monitoring forwarder health status and packet statistics.
  • Optional a webhook ID can be configured to trigger HA when a packet was forward (with source/host and target /Mac info)

How to send WoL packets with SecureOn:

  • There are numerous mobile WOL apps that can send magic packets with a SecureOn password.
  • The Home Assistant’s WOL integration can send SecureOn WOL packets.
  • Or a shell script that can be used:
#!/bin/sh
#Original source: https://heavydeck.net/blog/wake-on-lan-with-netcat/
#Extended with configurable port and SecureOn arguments
#Hardcoded values
PACKET_REPEATS=2

function usage()
{
    echo "Usage: $0 <MAC_ADDRESS> <HOST_ADDRESS> [<PORT> SECURE_ON]"
    echo "Examples:"
    echo "    $0 12:34:56:78:9A:BC 192.168.1.255"
    echo "    $0 12:34:56:78:9A:BC 192.168.1.255 7"
    echo "    $0 12:34:56:78:9A:BC 192.168.1.255 7 31:32:33:34:35:36"
}

# Parse CLI attributes
MAC_REGEX='^[0-9a-f][0-9a-f]:[0-9a-f][0-9a-f]:[0-9a-f][0-9a-f]:[0-9a-f][0-9a-f]:[0-9a-f][0-9a-f]:[0-9a-f][0-9a-f]$'
MAC_ADDR="$1"
MAC_ADDR=`echo "$MAC_ADDR" | grep -i "$MAC_REGEX"`
if [ -z "$MAC_ADDR" ]
then
    echo "Error: Bad MAC address!"
    usage
    exit 1
fi

HOST="$2"
if [ -z "$HOST" ]
then
    echo "Error: No host given!"
    usage
    exit 2
fi

# Port is default 9. Parameter is only mandatory when specifying the optional SecureOn
PORT_REGEX='^[0-9]$'
PORT="$3"
if [ -z "$PORT" ]
then
  PORT=9
fi

# Optional SecureOn in same format as MAC Adress
SECURE_ON="$4"
SECURE_ON=`echo "$SECURE_ON" | grep -i "$MAC_REGEX"`
if [ ! -z "$4" ] && [ -z "$SECURE_ON" ]
then
    echo "Error: Bad SecureOn argument!"
    usage
    exit 3
fi
# Check required programs (nc) exist
NC_WHEREIS=`whereis nc`
if [ -z "$NC_WHEREIS" ]
then
    echo "Warning: Could not verify if NetCat (nc) is on your system Path!"
fi

# Build the magic packet which consists of 0xFF 6 times then the MAC
# Address repeated 16 times
MAGIC_PACKET=':FF:FF:FF:FF:FF:FF'
for i in `seq 1 16`
do
    MAGIC_PACKET="$MAGIC_PACKET:$MAC_ADDR"
done

# Optionally extend with SecureON
if [ ! -z "$SECURE_ON" ]
then
    MAGIC_PACKET="$MAGIC_PACKET:$SECURE_ON"
    echo "Appended the optional SecureOn to the Magic packet"
fi

#Replace colons with escape sequences
MAGIC_PACKET=`echo "$MAGIC_PACKET" | sed 's|:|\\\\x|g'`
echo "Sending magic UDP packet for $MAC_ADDR to $HOST at port $PORT"
#echo -ne "$MAGIC_PACKET" | hexdump -C -v
for i in `seq 1 "$PACKET_REPEATS"`
do
    echo -ne "$MAGIC_PACKET" | nc -w 1 -v -v -u -b "$HOST" "$PORT" || exit 5
done

It was a nice exercise that can be useful for others

With the deprecation of the add-on term, this installation sequence no longer works:

https://github.com/erkr/wol-forwarder#installation

I suggest re-testing all the installation and set-up sequences so that they all work.

Thanks, I will fix the text in the upcoming release :+1:
(Renaming addons to apps is a disaster imo. Half of my searches on apps end up with companion app hits :face_with_peeking_eye:)

Edit: done (v1.1.2)

We told the powers that be a hundred times.
They actually heard me (us), but decided to do it anyway. ¯\(ツ)