MTCNA-v5

345
8/18/2019 MTCNA-v5 http://slidepdf.com/reader/full/mtcna-v5 1/345 MikroTik Certified Network Associate (MTCNA) Academy Xperts www.academyxperts.com Mauro Escalante C. [email protected] MikroTik Certified Trainer MikroTik Trainer ID #TR0086 © MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permission MikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Transcript of MTCNA-v5

Page 1: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 1/345

MikroTik CertifiedNetwork Associate

(MTCNA)

Academy Xpertswww.academyxperts.comMauro Escalante C.

[email protected] Certified Trainer

MikroTik Trainer ID #TR0086

© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 2: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 2/345

www.academyxperts.com

[email protected]@academyxperts.clwww.academyxperts.crcursos@academyxperts.crwww.academyxperts.hncursos@academyxperts.hnwww.academyxperts.com.arcursos@academyxperts.com.arwww.academyxperts.com.mxcursos@academyxperts.com.mxwww.academyxperts.com.pacursos@academyxperts.com.pa

© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

www.mikrotikxperts.com

[email protected]@mikrotikxperts.clwww.mikrotikxperts.crcursos@mikrotikxperts.crwww.mikrotikxperts.com.bocursos@mikrotikxperts.com.bowww.mikrotikxperts.com.mxcursos@mikrotikxperts.com.mx

A c a d e m y X p e r t s M i k r o T i k X p e r t s

Page 3: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 3/345

Instructores Academy XpertsAlejandro Teixeira (Chile)

([email protected])• Co-Fundador y CEO de MikroTik Xperts Chile• Co-Fundador y CEO de WiDuit• MikroTik Certified Trainer

• MTCNA, MTCTCE, MTCWE

Gustavo Angulo (Venezuela)

([email protected])• Co-Fundador y CEO de MikroTik Xperts Venezuela• Co-Fundador y CTO de WiDuit• MikroTik Certified Trainer

• MTCNA, MTCTCE, MTCWE• Cisco CCNA Trainer

Luis Cuadrado (Ecuador)([email protected])• Ubiquiti airMAX Certified Trainer

Miguel Ojeda (Ecuador)

([email protected])• Co-Fundador y CTO de MikroTik Xperts• MikroTik Certified Trainer

• MTCNA, MTCTCE, MTCWE, MTCRE• DenwaIP Certified Trainer

Mauro Escalante (Ecuador)([email protected])

• Co-Fundador y CEO de MikroTik Xperts• Co-Fundador y CEO de Network Xperts• MikroTik Certified Trainer

• MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Trainer• Observer/Sniffer Certified Engineer

3©Academy Xperts / MikroTik Xperts 2013 3

Page 4: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 4/345

Consultores Academy XpertsAlejandro Teixeira (Chile)([email protected])

• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE

Gustavo Angulo (Venezuela)([email protected])

• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Cisco CCNA, Cisco Security

Hamzah Haji (Panamá)([email protected])

MikroTik MTCNA, MTCTCE, MTCRELuis Cuadrado (Ecuador)([email protected])

• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Admin

Miguel Ojeda (Ecuador)([email protected])

• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• DenwaIP Certified• Ubiquiti airMAX Certified Admin

Mauro Escalante (Ecuador)([email protected])

• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Admin• Observer/Sniffer Certified Engineer

Pedro Toribio (Nicaragua, Costa Rica, Honduras)([email protected])

• MikroTik MTCNA, MTCTCEJosé Alfredo García (Bolivia)([email protected])

• MikroTik MTCNA, MTCTCE

4©Academy Xperts / MikroTik Xperts 2013 4

Page 5: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 5/345

Introducción PersonalPresentarse individualmente

• Nombre• Compañía• Conocimiento previo sobre RouterOS• Conocimiento previo sobre networking• Qué espera de este curso?

Recuerde su número N de claseMi número es: _____

5© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 6: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 6/345

Horario

09:00 – 10:30 Sesión I10:30 – 11:00 Break

11:00 – 13:00 Sesión II13:00 – 14:00 Lunch

14:00 – 15:30 Sesión III15:30 – 16:00 Break

16:00 – 17:30+ Sesión IV

6© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 7: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 7/345

Objetivos del Curso• Conocer los alcances y capacidades del RouterOS y del

RouterBoard de MikroTik

Conocer, practicar y operar los principios básicos delRouterOS, tanto en configuración y mantenimiento comoen resolución de problemas

• Al terminar el curso el alumno estará familiarizado con lamayoría de las características del RouterOS y será capazde aplicar las configuraciones de red más comunes

7© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 8: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 8/345

Sobre MikroTik• Fabricante de hardware y software de router• Productos usados por ISPs, PYMES, y para Home• MikroTik fabrica tecnología para internet más rápida,

potente y de un costo adecuado para un amplio rango deusuarios

8

• www.mikrotik.com• www.routerboard.com• wiki.mikrotik.com•

tiktube.com• forum.mikrotik.com• en.wikipedia.org/wiki/MikroTik

Industry Networking hardware

Founded 1995

Headquarters Riga, Latvia

Key people John Tully, CEO Arnis Riekstins, CTO

Products Routers, Firewalls

Revenue 62.5 million Euros (2011)

Net income 20.6 million Euros (2011)

Employees 80 (2012)

© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 9: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 9/345

Where is MikroTik ?

9

Riga, LATVIA ,Northern Europe

© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 10: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 10/345

Historia de MikroTik•

1995: Fundación• 1997: RouterOS software para x86 (PC)• 2002: Nace RouterBOARD•

2006: Primer MUM (MikroTik User Meeting)

10

Fechas de liberación de las versiones de RouterOS• V6 – May 2013•

v5 – Mar 2010• v4 – Oct 2009• v3 – Jan 2008

© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 11: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 11/345

Qué es MikroTik RouterOS ?

11© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

• Hardware•

Configuración• Firewall• Routing• Forwarding• MPLS•

VPN• Wireless• HotSpot• Calidad de Servicio (QoS)• Web Proxy• Herramientas• The Dude• Licencias

Page 12: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 12/345

Qué es RouterOS ?• MikroTik RouterOS es el sistema operativo del hardware

Mikrotik RouterBOARD• Puede también ser instalado en un PC para convertirlo en

un router con todas las características necesarias:• Routing•

Firewall• Administrador de ancho de banda• Filtro de paquetes• Cualquier dispositivo wireless 802.11a/b/g/n• Enlace backhaul• Gateway Hotspot• VPN server, etc.

• EL RouterOS es un sistema operativo stand-alone basado enel kernel de Linux2.6

12© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

(H d )

Page 13: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 13/345

Qué es RouterOS? – (Hardware )• RouterOS puede instalarse en PCs y otros dispositivos de hardware compatibles

x86, como tarjetas embebidas y sistemas miniITX.• RouterOS soporta computadores multi-core y multi-CPU. Soporta

Multiprocesamiento Simétrico (*SMP: Symmetric Multiprocessing)• Se puede ejecutar en los motherboards Intel más recientes y aprovechar los

nuevos CPUs multicore• RouterOS soporta la instalación en dispositivos de almacenamiento IDE, SATA y

USB. Esto incluye:• HDDs• Tarjetas CF y SD• Discos SDD

• Se necesita al menos 64MB de espacio para instalar RouterOS.•

El RouterOS formateará la partición y se convertirá en el sistema operativo pordefault del dispositivo• Soporta una gran variedad de interfaces de red, incluyendo tarjetas ethernet de

10 Gigabit, tarjetas wireless 802.11a/b/g/n y modems 3G13© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permission

MikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

(H d )

Page 14: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 14/345

• SMP (*)•

Symmetric MultiProcessing• Es una arquitectura de Software y hardware donde dos o más

procesadores idénticos son conectados a una simple memoriacompartida, teniendo acceso a todos los dispositivos I/O (entrada ysalida), y que son controlados por una simple instancia del OS(Sistema Operativo), en el cual todos los procesadores son tratadosen forma igualitaria, sin que ninguno sea reservado para propósitosespeciales.

• En el caso de los procesadores multi-core (multi-núcleo), la

arquitectura SMP se aplica a los núcleos, tratándolos comoprocesadores separados.

14© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? – (Hardware )

Page 15: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 15/345

Qué es RouterBOARD ?• Es el hardware creado por MikroTik• Desde pequeños ruteadores tipo “home” a

concentradores de acceso carrier-class

15© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 16: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 16/345

Plataformas

16© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Arquitectura Series

mipsbe RB400, RB700, RB900, RB2011, SXT, OmniTik, Groove, METAL

ppc RB300, RB600, RB800, RB1000

x86 PC / x86, RB230mipsle RB100, RB500, RB Crossroads

tile CCR

Page 17: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 17/345

Page 18: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 18/345

Acceso por Puerto Serial

18© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 19: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 19/345

19© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Acceso por Puerto Serial (Bootloader )What do you want to configure?

d - boot delayk - boot keys - serial consolen - silent booto - boot deviceu - cpu modef - cpu frequencyr - reset booter configuratione - format nandg - upgrade firmwarei - board infop - boot protocolb - booter optionst - call debug codel - erase licensex - exit setup

your choice:

Page 20: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 20/345

20© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Acceso por Puerto Serial (CLI)

System/Serial Console

Page 21: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 21/345

/system console - /system serial-terminal• Herramientas para comunicarse con otros sistemas que están interconectados

vía puerto serial.• Terminal Serial – monitorear y configurar muchos dispositivos:

• Modems• Dispositivos de red (incluyendo routers MikroTik)• Cualquier dispositivo que se pueda conectar a un puerto serial

(asíncrono)• Consola Serial – configurar facilidades de acceso directo (monitor/teclado y

puerto serial) que son mayormente usados para configuraciones derecuperación

• Si no se desea usar un puerto serial para acceder a otro dispositivo o paraconexión de datos a través de un modem, se puede entonces configurarlo

como una consola serial.• Un puerto serial libre puede ser usado para acceder a otras consolas seriales

de otros routers (u otros equipos como switches) desde un router MikroTik

21© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

System/Serial Console

System/Serial Console

Page 22: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 22/345

• Para conectar dos hosts (ej: dos PCs o dos routers; NO modems) se necesitaun cable null-modem

Se necesita un programa de emulación de terminal (ej: HyperTerminal ominicom) para acceder a la consola serial desde otro computador• Escenarios típicos:

• En sitios donde una instalación MikroTik wireless está junto a un equipo(switches y routers Cisco) que no pueden ser manejados por Telnet através de una red IP

• Monitorear equipos de reportes de clima a través de un puerto serial• Conexión a un modem microonda de alta velocidad que necesita ser

monitoreado y administrado por una conexión serial• La funcionalidad /system serial-terminal se pueden monitorear y

controlar hasta 132 dispositivos (y tal vez, incluso más)• http://wiki.mikrotik.com/wiki/Manual:System/Serial_Console

22© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

System/Serial Console

System Console Special Login

Page 23: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 23/345

• Special Login – puede ser usado para acceder a otro dispositivo (ej: un switch)que está conectado a través de un cable serial abriendo una sesión telnet/sshque lo llevará directamente a ese dispositivo sin tener que hacer login laprimer RouterOS

• http://wiki.mikrotik.com/wiki/Manual:Special_Login

23© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

System Console – Special Login

Page 24: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 24/345

Herramientas• Winbox

• Acceso en capa 3• Acceso en capa 2 (MAC Winbox/Telnet)

• Cliente FTP• Filezilla, WSftp …

• Telnet, SSH• Acceso vía red•

Acceso vía puerto serial• NetInstall (MikroTik)

24© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? (Configuración )

Page 25: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 25/345

• RouterOS soporta varios métodos deconfiguración:

• Acceso local con teclado y monitor• Consola serial con una aplicación de terminal•

Acceso Telnet y SSH sobre redes• Herramienta de configuración GUI llamada Winbox• Interfaz de configuración sencilla basada en Web• Interfaz de programación API para construir una

aplicación de control propietariahttp://wiki.mikrotik.com/wiki/API

25© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? – (Configuración )

Qué es RouterOS? (Configuración )

Page 26: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 26/345

• En caso de que no se pueda tener acceso local, o de que

haya un problema con el acceso a nivel de comunicación IP(capa 3), el RouterOS también soporta conexión a nivel deMAC (capa 2), con las herramientas Mac-Telnet y Winbox

• RouterOS posee una poderosa y fácil de aprender interface

de configuración por línea de comando (CLI: Command LineInterface). La CLI además tiene capacidades de scriptingintegrada.

• Winbox GUI sobre IP y MAC• CLI con Telnet, SSH, consola Local y consola Serial• API para programar sus propias herramientas• Interface Web

26© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? – (Configuración )

Qué es RouterOS? (Firewall )

Page 27: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 27/345

• El Firewall implementa filtrado de paquetes y de este modo proveefunciones de seguridad, que son usadas para administrar los datos quefluyen hacia, desde, y a través del router.

• Por medio del NAT (Network Address Translation) se previene el accesono-autorizado a las redes conectadas directamente y al router en símismo. Y también sirve como un filtro para el tráfico de salida.

• RouterOS funciona como un Stateful Firewall , lo cual significa que

desarrolla una inspección del estado de los paquetes, y realiza elseguimiento del estado de las conexiones de red que viajan a través delrouter.

• RouterOS también soporta:• Source y Destination NAT•

NAT Helpers para las aplicaciones populares• UPnP

• El firewall provee marcado interno de conexiones, routing y paquetes.

27© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? – (Firewall )

Qué es RouterOS? – (Firewall )

Page 28: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 28/345

• RouterOS puede filtrar por:• Dirección IP, rango de direcciones, puerto, rango de puertos• Protocolo IP, DSCP y otros parámetros• Soporta Listas de Direcciones estáticas y Dinámicas• Puede hacer match de paquetes por patrón en su contenido,

especificado en Expresiones Regulares, conocido como Layer 7matching

• El Firewall de RouterOS también soporta IPv6

28© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? – (Firewall )

Qué es RouterOS? – (Routing )

Page 29: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 29/345

• RouterOS soporta varios protocolos de ruteo:• Para IPv4 soporta RIP v1 y v2, OSPF v2, BGP v4• Para IPv6 soporta RIPng, OSPF v3 y BGP

• RouterOS tambien soporta• VRF (Virtual Routing Forwarding)• Ruteo basado en Políticas• Ruteo basado en Interface• Ruteo ECMP

• Se puede usar el Filtro del Firewall para marcar conexiones específicas conMarcas de Ruteo (Routing Marks), y hacer que el tráfico marcado use undiferente ISP

• Con el soporte MPLS se introdujo el VRF, que es una tecnología que permiteque múltiples instancias de una tabla de ruteo co-existan dentro del mismorouter al mismo tiempo. Puesto que las instancias de ruteo sonindependientes, las mismas direcciones IP pueden ser usadas sin conflictounas con otras. VRF también incrementa la seguridad de la red.

29© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? (Routing )

Qué es RouterOS? – (Forwarding )

Page 30: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 30/345

• RouterOS soporta el reenvío (forwarding) en Capa 2, incluyendo Bridging,Mesh y WDS.

• WDS permite crear cobertura de wireless usando múltiples APs. Permiteque los paquetes pasen de un AP a otro, como si los APs fuesen puertos enun switch Ethernet. Para optimizar el desempeño del WDS redes de granescala MikroTik diseñó una interface especial de forwarding en capa 2llamado Mesh.

(R)STP elimina la posibilidad de la que la misma dirección MAC sea vista enmúltiples puertos bridge, deshabilitando los puertos secundarios hacia esadirección MAC. Esto ayuda a evitar los lazos (loops) y mejora laconfiabilidad de la red. Una alternativa que ofrece MikroTik al RSTP es elHWMP+

HWMP+ es protocolo de ruteo específico en capa 2 de MikroTik, elaboradopara redes Mesh. El protocolo HWMP+ es una mejora del Hybrid WirelessMesh Protocol (HWMP) del estándar IEEE 802.11s

30© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? (Forwarding )

Qué es RouterOS? – (MPLS)

Page 31: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 31/345

• MPLS: MultiProtocol Label Switching . Puede ser usado para reemplazar elruteo IP. La decisión de reenvío (forwarding) de paquetes no está basadoen los campos de la cabecera IP y en la tabla de ruteo, sino en etiquetas(lables) que se agregan al paquete. Esto mejora la velocidad del proceso dereenvío porque el next hop lookup (búsqueda del siguiente salto) se vuelvemuy simple comparado con el routing lookup.

• El principal beneficio de MPLS es la eficiencia en el proceso de forwarding.• MPLS permite de una manera fácil crear “enlaces virtuales” (virtual links)

entre los nodos de la red, independientemente del protocolo de la dataencapsulada.

• Es un mecanismo altamente escalable para llevar datos,independientemente del protocolo. Las decisiones del reenvío de paquetesse hacen únicamente en el contenido de la etiqueta, sin la necesidad deexaminar el paquete. Esto permite crear circuitos end-to-end a través decualquier tipo de medio de transporte, usando cualquier protocolo.

31© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? (MPLS)

Qué es Route

rOS? – (MPLS)

Page 32: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 32/345

• Algunas de las características de MPLS:• Etiquetas Estáticas de vinculación (Static label bindings)

para IPv4• Protocolo de Distribución de Etiquetas (Label

Distribution) para IPv4• Túneles de Ingeniería de Tráfico RSVP• VPLS MP-BGP basado en autodiscovery y señalización• MP-BGP basado en MPLS IP VPN

32© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es Route rOS? (MPLS)

Qué es Route

rOS? – (VPN)

Page 33: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 33/345

• RouterOS soporta varios métodos VPN y protocolos de túnelespara establecer conexiones seguras sobre redes abiertas o sobreinternet, o para conectar sitios remotos con enlacesencriptados:

• IPSec – Modo de transporte y túnel, certificado o PSK,protocolos de seguridad AH y ESP

• Point To Point Tunneling: OpenVPN, PPTP, PPPoE, L2TP• Características avanzadas PPP: MLPPP, BCP• Túneles simples: IPIP, EoIP• Soporte para túnel 6to4: IPv6 sobre redes IPv4• VLAN – Soporte IEEE 802.1q Virtual LAN, Soporte Q-in-Q•

MPLS basado en VPNs

33© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es Route rOS? (VPN)

Qué es Route

rOS? – (VPN)

Page 34: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 34/345

• Se puede interconectar de forma segura redes bancarias, usar los recursosde la red de trabajo mientras se viaja, conectarse a la red local doméstica,

o incrementar la seguridad del enlace wireless principal.• Se pueden interconectar 2 oficinas remotas, y pueden usar los recursos

una de otra, como si los computadores estuvieran en el mismo lugar, todoesto de forma segura y encriptada.

• RouterOS también provee varias funciones propietarias de MikroTik, porejemplo EoIP que es un túnel Ethernet entre 2 routers a través de unaconexión IP. La interface EoIP aparece como una interface Ethernet.Cuando se habilita la función bridge, todo el tráfico Ethernet será“bridged ” como si hubiera una interface Ethernet física y un cableEthernet entre los 2 routers. Este protocolo permite que se puedan

realizar múltiples esquemas de red, como por ejemplo la posibilidad deponer en bridge redes LAN sobre el Internet.

34© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es Route rOS? (VPN)

Qué es RouterOS? – (Wireless )

Page 35: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 35/345

• RouterOS soporta varias tecnologías Wireless. Características:• Cliente Wireless y Access Point IEEE 802.11a/b/g/n• Protocolos propietarios Nstreme, Nstreme2 y Nstreme Dual• Client polling• RTS/CTS• Wireless Distribution System (WDS)• Virtual AP• Encripción WEP, WPA, WPA2• Lista de Control de Acceso• Roaming de clientes Wireless• WMM• Protocolo MESH Wireless HWMP+• Protocolo de ruteo Wireless MME

• Nstreme ha permitido establecer el record de longitud de enlace WiFi noaplificado en Italiahttp://en.wikipedia.org/wiki/Long-range_Wi-Fi

35© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Qué es RouterOS? (Wireless )

Qué es RouterOS? – (HotSpot )

Page 36: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 36/345

• El Gateway HotSpot de MikroTik provee el acceso a redes públicaspara clientes inalámbricos o cableados a través de una pantalla de

validación (login/password) cuando abren su browser. Luego devalidado el user/password el usuario tendrá acceso a Internet.• Ideal para Hoteles, Escuelas, Aeropuertos, Cafés Internet, o

cualquier otro lugar público donde no se tiene control sobre lacomputadora del usuario. No se necesita ningún software deinstalación o configuración de red ya que el HotSpot direccionarácualquier requerimiento de conexión hacia la página de validación.

• Se puede ejecutar una extensa administración de usuarios haciendodiferentes perfiles, cada uno de los cuales puede permitir diferentes

limitaciones de uptime, subida y descarga, así como tambiénlimitación de la cantidad de tráfico, y mucho más.

36© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Q (HotSpot )

Qué es RouterOS? – (HotSpot )

Page 37: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 37/345

• El HotSpot también soporta autenticación contra servidores RADIUSestándares, y contra el el propio User Manager de MikroTik que

proporcionará una administración centralizada de todos losusuarios en la red.• Acceso Plug-n-Play a la red• Autenticación de los clientes a la red local• User Accounting• Soprote RADIUS para Autenticación y Accounting• Bypass configurable para dispositivos no-interactivos• Walled Garden para las excepciones de browsing• Modos de publicidad (Advertisement) y usuarios de prueba

37© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Q (HotSpot )

Qué es RouterOS? – (Calidad de Servicio )

Page 38: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 38/345

• Control de Ancho de banda es un conjunto de mecanismos quecontrolan la asignación de velocidad de datos, variabilidad del

retardo, entrega oportuna, y la fiabilidad de la entrega.• Quality of Service (QoS) significa que el router puede priorizar y

ajustar el tráfico de red.• Limitar la tasa de datos para ciertas direcciones IP, subredes,

protocolos, puertos y otros parámetros• Limitación de tráfico peer-to-peer• Priorizar el flujo de unos paquetes sobre otros• Usar queue-bursts para una navegación más rápida• Aplicar colas en intervalos de tiempo fijo• Distribuir el tráfico equitativamente entre usuarios, o

dependiendo de la carga del canal.

38© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Q ( )

Qué es RouterOS? – (Calidad de Servicio )

Page 39: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 39/345

• RouterOS soporta el Sistema de QoS HTB (Hierarchical TokenBucket) con soporte de CIR, MIR, burst y prioridad. Provee

encolamiento avanzado, y también una solución sencilla deimplementación QoS con colas Simples.• Se introdujo PCQ para optimizar los sistemas QoS masivos, donde la

mayoría de las colas son exactamente las mismas para diferentessub-streams. Por ejemplo un sub-stream puede ser la bajada osubida de un cliente en particular (IP) o conexión a un server.

• El algoritmo PCQ es muy simple – primero utiliza clasificadores paradistinguir un sub-stream de otro, luego aplica limitación y untamaño de cola FIFO individual en cada sub-stream, entonces

agrupa todos los sub-streams y aplica limitación y un tamaño decola FIFO global.

39© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Q ( )

Qué es RouterOS? – (Web proxy )

Page 40: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 40/345

• Web Proxy: Mejorar la navegación del usuario haciendoalmacenamiento (cache). Características Web Proxy MikroTik:

Proxy HTTP• Proxy transparente• Lista de Acceso por origen, destino, URL y método requerido

(firewall HTTP)• Cache de Lista de Acceso para especificar qué objetos serán

almacenados y cuáles no• Lista de Acceso Directa para especificar qué recursos deberían ser

accesados directamente, y cuáles a través de otro proxy server.• Facilidad de bitácora (logging)• Soporte de SOCKS proxy• Soporte de proxy Padre (Parent proxy)• Almacenamiento de cache en dispositivos externos

40© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

( p y )

Page 41: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 41/345

Qué es RouterOS? – (The Dude )

Page 42: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 42/345

• El monitor de red The Dude es una aplicación de MikroTik paraadministrar la red. Escanea automáticamente todos los dispositivos

dentro de las subredes especificadas, dibuja y diseña un mapa delas redes, monitorea servicios de los dispositivos y alerta en caso deque algún servicio tenga problemas.

• No solo monitorea dispositivos RouterOS, sino que puedemonitorear cualquier dispositivo que es accesible por Ping o que

provee información SNMP• Se pueden visualizar gráficos de tráfico y disponibilidad, informes de

interrupciones, e incluso usar The Dude como un Syslog Server• Puede también administrar las configuraciones de dispositivos

RouterOS, y actualizar los upgrades de software y configuracionesen masa

• The Dude es gratis

42© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

( )

Page 43: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 43/345

Winbox

Page 44: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 44/345

Winbox• Es la aplicación para configurar el RouterOS• Winbox es un pequeño utilitario que permite la administración del MikroTik

RouterOS usando una Interfaz gráfica de usuario (GUI) simple y rápida.• Es un programa binario nativo en Win32 , pero puede ser ejecutado en

Linux y Mac OSX usando Wine.•

Todas las funciones de la interface Winbox son muy similares a lasfunciones de Consola• Algunas configuraciones avanzadas y críticas no se pueden realizar desde

Winbox, com por ejemplo el cambio de las MAC Address en una interfaz.• El Winbox puede ser descargado desde la zona de descargas de MikroTik (

http://www.mikrotik.com/download ) o desde el acceso via browser alrouter (Ej: http://192.168.88.1 )

44© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Descargar Winbox

Page 45: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 45/345

g

45© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Descargar Winbox

Page 46: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 46/345

esca ga W bo

46© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Conectándose con Winbox

Page 47: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 47/345

Conectándose con Winbox

Click en el botón [...] para ver el router

47© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Comunicación

Page 48: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 48/345

Comunicación

• El proceso de comunicación está dividido en7 capas

• La capa más baja es la Física, y la capa másalta es la de Aplicación

48© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 49: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 49/345

49© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 50: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 50/345

50© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Page 51: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 51/345

51© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

AplicaciónEspecifica los métodos para llevar a cabo una tarea iniciada por el usuario.Los protocolos de la capa de aplicación tienden a ser concebidos y ejecutados por los desarrolladores de aplicaciones.

Page 52: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 52/345

Ejemplo: FTP, Skype, etc.

PresentaciónEspecifica los métodos para la expresión de los formatos de datos y normas de traducción para aplicaciones. Laencriptación se asocia algunas veces con esta capa. Ejemplo: Conversión de EBCDIC a ASCII

SesiónEspecifica métodos para múltiples conexiones que constituyen una sesión de comunicación. Esto puede incluir cerrarconexiones, reiniciar conexiones y puntos de control. Ejemplo: ISO X.25

TransporteEspecifica los métodos para las conexiones o asociaciones entre múltiples programas que se ejecutan en el mismocomputador. Esta capa puede implementar entregas seguras en caso de que no se apliquen en otros lados. Ejemplo:Internet TCP, ISO, TP4)

Network (o Internetwork)Especifica los métodos para comunicar en un esquema de múltiples saltos a través de diferentes potenciales tipos deredes de enlace. Para redes de paquetes, describe un formato de paquete abstracto y su estructura de direccionamientoestándar. Ejemplo: IP datagram, X.25 PLP, ISO CLNP

EnalceEspecifica los métodos para comuncarse a través de un simple enlace, incluyendo protocolos de “control de acceso almedio ” cuando múltiples sistemas comparten el mismo medio. La detección de error se incluye comunmente en estacapa, junto con formatos de dirección de la capa de enlace. Ejemplo: Ethernet, Wi-Fi, ISO 13239/HDLC.

FísicaEspecifica los conectores, tasas de datos, y la forma en que los bits son codificados en algún medio. También describedetección y corrección de bajo nivel, más asignaciones de frecuencia. Ejemplo: V.92, Ethernet 1000BASE-T, SONET/SDH

52© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

MAC address

Page 53: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 53/345

53© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

• Es un identificador de 48 bits (6 bloques hexadecimales) que se asigna deforma única a una tarjeta o dispositivo de red.

• Conocida también como dirección física• Los últimos 24 bits son determinados y configurados por la IEEE, y los

primeros 24 bits por el fabricante utilizando el Identificador UnicoOrganizacional (OUI: Organizationally Unique Identifier)

• El OUI es un número de 24 bits comprado a la Autoridad de Registro de la

IEEE, que identifica a cada empresa u organización• Ejemplo: 00:0C:42:20:97:68

IP

Page 54: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 54/345

• Es la dirección lógica del dispositivo de red• Se utiliza para la comunicación entre redes• Ejemplo: 159.148.60.20

54© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .

Subredes (subnets)

Page 55: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 55/345

( )• Rango de direcciones IP lógicas que divide la red en

segmentos• Ejemplo: 255.255.255.0 o /24• La dirección de red es la primera dirección IP de la

subred• La dirección de broadcast es la última dirección IP de lasubred

• Estas son reservadas y no pueden ser utilizadas

©Academy Xperts / MikroTik Xperts 2013 55

Subredes (subnets)

Page 56: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 56/345

200.3.25.0 /27

©Academy Xperts / MikroTik Xperts 2013 56

CIDR Subnet Mask HostsDisponibles

CIDR Subnet Mask HostsDisponibles

/32 255 255 255 255 /23 255 255 254 0 512 – 2

Page 57: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 57/345

©Academy Xperts / MikroTik Xperts 2013 57

/32 255.255.255.255 /23 255.255.254.0 512 – 2/30 255.255.255.252 4 – 2 /22 255.255.252.0 1024 – 2/29 255.255.255.248 8 – 2 /21 255.255.248.0 2048 – 2/28 255.255.255.240 16 – 2 /20 255.255.240.0 4096 – 2/27 255.255.255.224 32 – 2 /19 255.255.224.0 8192 – 2/26 255.255.255.192 64 – 2 /18 255.255.192.0 16384 – 2/25 255.255.255.128 128 – 2 /17 255.255.128.0 32768 – 2/24 255.255.255.0 256 – 2 /16 255.255.0.0 65536 – 2

El prefijo de ruteo está expresado en notación CIDR . Está escrito como la primera dirección de unared, seguido por un caracter slash (/), terminando con la longitud de bit del prefijo. Por ejemplo,192.168.1.0/24 es el prefijo de la red IPv4 que inicia en la dirección indicada, teniendo 24 bitsasignados para el prefijo de red, y los 8 bits remanentes reservados para direccionamiento de host.

La notación CIDR es una especificación compacta de una dirección IP y está asociada con un prefijode ruteo. Classless Inter-Domain Routing (CIDR)es una asignación de dirección IP y una

metodología de agregación de ruta.

CIDR es un método de asignación de dirección IP y de paquetes de ruteo IP.

Ejemplo de Selección de dirección IP

Page 58: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 58/345

• Los clientes usan subredes de diferentes máscaras /25 y /26• A tiene la dirección IP 192.168.0.200/ 26 • B usa el subnet mask (máscara de red) / 25

Las direcciones disponibles son:

192.168.0.129 - 192.168.0.254• B no debería usar 192.168.0.129 - 192.168.0.192• B debería usar las siguientes direcciones IP para que se

puedan ver la estación A y las estaciones de B

192.168.0.193 - 192.168.0.254/25

©Academy Xperts / MikroTik Xperts 2013 58

L b t i d C ió

Page 59: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 59/345

Laboratorio de Conexión

Hacer Click en la Mac-Address en Winbox• Default username “admin” sin clave

©Academy Xperts / MikroTik Xperts 2013 59

Diagrama de Clase

Page 60: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 60/345

g

©Academy Xperts / MikroTik Xperts 2013 60

internet

ether 10.1.1.2 /3010.1.1.6 /30

10.1.1.10 /30……

GatewayDNS

ether110.1.1.1 /30

ether2192.168.N.254 /24

192.168.N.1 /24(N = 1)

ether2192.168.N.254 /24

192.168.N.1 /24(N = 2)

ether2192.168.N.254 /24

192.168.N.1 /24(N = 3)

ether110.1.1.5 /30

ether110.1.1.6 /30

Laptop - Router

Page 61: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 61/345

1. Deshabilitar cualquier interface

(wireless) en su laptop

2. Configurar la dirección IP

192.168. N.1

3. Configurar 255.255.255.0 comola Subnet Mask

4. Configurar 192.168. N.254 como

el Default Gateway y como DNSServer primario

©Academy Xperts / MikroTik Xperts 2013 61

Laptop - Router

Page 62: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 62/345

1. Conectarse al router

con MAC-Winbox

©Academy Xperts / MikroTik Xperts 2013 62

2. Agregar la dirección IP192.168. N.254/24 a lainterface ether2

Laptop - Router

Page 63: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 63/345

• Cierre el Winbox y conéctese de nuevo

usando la dirección IP

• El acceso por MAC-address deberíarealizarse solo cuando no hay acceso pordirección IP

©Academy Xperts / MikroTik Xperts 2013 63

Router - Internet

Page 64: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 64/345

• La puerta de acceso ( gateway ) a Internet desu clase se puede acceder a través delwireless. Es un AP (Access Point)

• Para conectarse usted tiene que configurarla interface wireless del router como station

©Academy Xperts / MikroTik Xperts 2013 64

Router - Internet

Page 65: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 65/345

Chequear laconectividad aInternet usando

Traceroute

©Academy Xperts / MikroTik Xperts 2013 65

Laptop - Internet

Page 66: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 66/345

Su router puede ser también un DNS Server para lared local (laptop)

©Academy Xperts / MikroTik Xperts 2013 66

Laptop - Internet

Page 67: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 67/345

• Debe configurar su laptop para que use a su router

como DNS Server• Ingrese la IP del router (192.168. N.254) como el DNS

Server• La Laptop puede acceder al router y el router puede

acceder al Internet. Se requiere un paso adicional.• Debe crear una regla de enmascaramiento

(action=masquerade ) para ocultar su red privadadetrás del router.

©Academy Xperts / MikroTik Xperts 2013 67

Private and Public space

Page 68: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 68/345

• Masquerade is used for Public network access, whereprivate addresses are present

• Private networks include• 10.0.0.0 - 10.255.255.255 (10.0.0.0 /8)• 172.16.0.0 - 172.31.255.255 (172.16.0.0 /12)• 192.168.0.0 - 192.168.255.255 (192.168.0.0 /16)

©Academy Xperts / MikroTik Xperts 2013 68

Laptop - Internet

Page 69: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 69/345

©Academy Xperts / MikroTik Xperts 2013 69

Check Connectivity

Page 70: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 70/345

Check Connectivity

Ping www.mikrotik.com from your laptop

©Academy Xperts / MikroTik Xperts 2013 70

What Can Be Wrong

Page 71: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 71/345

What Can Be Wrong• Router cannot ping further than AP• Router cannot resolve names• Computer cannot ping further than router• Computer cannot resolve names• Is masquerade rule working• Does the laptop use the router as default

gateway and DNS©Academy Xperts / MikroTik Xperts 2013 71

Network Diagram

Page 72: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 72/345

Network Diagram

Your RouterYour LaptopClass AP

192.168.X.1 192.168.X.254DHCP-Client

©Academy Xperts / MikroTik Xperts 2013 72

User Management• A t th t b t ll d

Page 73: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 73/345

Access to the router can be controlled•

You can create different types of users

©Academy Xperts / MikroTik Xperts 2013 73

User Management Lab

Page 74: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 74/345

User Management Lab

• Add new router user with full access•

Make sure you remember user name• Make admin user as read-only• Login with your new user

©Academy Xperts / MikroTik Xperts 2013 74

Upgrading Router Lab

Page 75: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 75/345

Upgrading Router Lab

• Download packages from ftp://192.168.200.254• Upload them to router with Winbox• Reboot the router• Newest packages are always available on

www.mikrotik.com

©Academy Xperts / MikroTik Xperts 2013 75

Upgrading Router

Page 76: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 76/345

• Use combinedRouterOS

package• Drag it to the

Files window

©Academy Xperts / MikroTik Xperts 2013 76

Package Management

Page 77: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 77/345

Package Management

RouterOSfunctions are

enabled bypackages

©Academy Xperts / MikroTik Xperts 2013 77

Package Information

Page 78: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 78/345

©Academy Xperts / MikroTik Xperts 2013 78

Page 79: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 79/345

Router Identity

Page 80: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 80/345

y

Option to set name for each router

©Academy Xperts / MikroTik Xperts 2013 80

Router Identity

Page 81: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 81/345

yIdentity information is shown in different places

©Academy Xperts / MikroTik Xperts 2013 81

Router Identity Lab

Page 82: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 82/345

y

Set your number + your name as router identity

©Academy Xperts / MikroTik Xperts 2013 82

NTP

Page 83: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 83/345

• Network Time Protocol, to synchronize time• NTP Client and NTP Server support in

RouterOS

©Academy Xperts / MikroTik Xperts 2013 83

Why NTP

Page 84: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 84/345

y

• To get correct clock on router•

For routers without internal memory to saveclock information• For all RouterBOARDs

©Academy Xperts / MikroTik Xperts 2013 84

NTP Client

Page 85: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 85/345

NTP package is not required

©Academy Xperts / MikroTik Xperts 2013 85

Configuration Backup

Page 86: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 86/345

• You can backup and restore configuration inthe Files menu of Winbox

• Backup file is not editable

©Academy Xperts / MikroTik Xperts 2013 86

Page 87: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 87/345

Backup Lab

Page 88: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 88/345

• Create Backup and Export files

• Download them to your laptop• Open export file with text editor

©Academy Xperts / MikroTik Xperts 2013 88

Page 89: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 89/345

Netinstall

Page 90: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 90/345

1.List of routers

2.Net Booting

3.Keep oldconfiguration

4.Packages

5. Install

©Academy Xperts / MikroTik Xperts 2013 90

Optional Lab

Page 91: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 91/345

• Download Netinstall from ftp://192.168.100.254• Run Netinstall

• Enable Net booting, set address 192.168.x.13• Use null modem cable and Putty to connect• Set router to boot from Ethernet

©Academy Xperts / MikroTik Xperts 2013 91

RouterOS License

Page 92: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 92/345

• All RouterBOARDs shipped with license• Several levels available, no upgrades• Can be viewed in system license menu• License for PC can be purchased from

mikrotik.com or from distributors

©Academy Xperts / MikroTik Xperts 2013 92

License

Page 93: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 93/345

©Academy Xperts / MikroTik Xperts 2013 93

Obtain License

Page 94: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 94/345

Login to

your account

©Academy Xperts / MikroTik Xperts 2013 94

Update License for 802.11N

Page 95: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 95/345

• 8-symbol software-ID system is introduced• Update key on existing routers to get fullfeatures support ( 802.11N , etc.)

©Academy Xperts / MikroTik Xperts 2013 95

Page 96: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 96/345

Summary

©Academy Xperts / MikroTik Xperts 2013 96

Useful Links

Page 97: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 97/345

• www.mikrotik.com - manage licenses,documentation

• forum.mikrotik.com - share experience withother users

• wiki.mikrotik.com - tons of examples

©Academy Xperts / MikroTik Xperts 2013 97

Page 98: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 98/345

Firewall

©Academy Xperts / MikroTik Xperts 2013 98

Firewall

Page 99: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 99/345

• Protects your router and clients fromunauthorized access

• This can be done by creating rules in FirewallFilter and NAT facilities

©Academy Xperts / MikroTik Xperts 2013 99

Firewall Filter

Page 100: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 100/345

• Consists of user defined rules that work onthe IF-Then principle

• These rules are ordered in Chains• There are predefined Chains, and User

created Chains

©Academy Xperts / MikroTik Xperts 2013 100

Filter Chains

Page 101: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 101/345

• Rules can be placed in three default chains• input ( to router)• output ( from router)• forward ( trough the router)

©Academy Xperts / MikroTik Xperts 2013 101

Firewall Chains

Page 102: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 102/345

InputWinbox

ForwardWWW E-Mail

OutputPing from Router

©Academy Xperts / MikroTik Xperts 2013 102

Firewall Chains

Page 103: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 103/345

©Academy Xperts / MikroTik Xperts 2013 103

Input

Page 104: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 104/345

• Chain contains filter rules that protect the

router itself• Let’s block everyone except your laptop

©Academy Xperts / MikroTik Xperts 2013 104

Input

Page 105: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 105/345

Add an accept rule for yourLaptop IPaddress

©Academy Xperts / MikroTik Xperts 2013 105

Input

Page 106: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 106/345

Add a drop rule ininput chain todrop everyoneelse

©Academy Xperts / MikroTik Xperts 2013 106

Input Lab

Page 107: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 107/345

• Change your laptop IP address, 192.168.x. y• Try to connect. The firewall is working• You can still connect with MAC-address,

Firewall Filter is only for IP

©Academy Xperts / MikroTik Xperts 2013 107

Input

Page 108: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 108/345

• Access to your router is blocked• Internet is not working• Because we are blocking DNS requests as well• Change configuration to make Internet working

©Academy Xperts / MikroTik Xperts 2013 108

Input• Y di bl

Page 109: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 109/345

You can disableMAC access inthe MAC Server menu

• Change theLaptop IPaddress back to192.168.X. 1,and connectwith IP ©Academy Xperts / MikroTik Xperts 2013 109

Address-List

Page 110: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 110/345

• Address-list allows you to filter group of theaddresses with one rule

Automatically add addresses by address-listand then block

©Academy Xperts / MikroTik Xperts 2013 110

Address-List• Create different lists

Page 111: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 111/345

Subnets, separates ranges, one hostaddresses are supported

©Academy Xperts / MikroTik Xperts 2013 111

Address-List

Page 112: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 112/345

• Add specific hostto address-list

• Specify timeoutfor temporaryservice

©Academy Xperts / MikroTik Xperts 2013 112

Address-List in Firewall

Page 113: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 113/345

• Ability to blockby source anddestinationaddresses

©Academy Xperts / MikroTik Xperts 2013 113

Address-List Lab

Page 114: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 114/345

• Create address-list with allowed IP addresses• Add accept rule for the allowed addresses

©Academy Xperts / MikroTik Xperts 2013 114

Forward

Page 115: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 115/345

• Chain contains rules that control packets

going trough the router• Control traffic to and from the clients

©Academy Xperts / MikroTik Xperts 2013 115

Forward

Page 116: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 116/345

• Create a rulethat will blockTCP port 80 (web

browsing)• Must select

protocol to blockports

©Academy Xperts / MikroTik Xperts 2013 116

Page 117: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 117/345

List of well-known ports

Page 118: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 118/345

©Academy Xperts / MikroTik Xperts 2013 118

Forward

Page 119: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 119/345

Create a rule that will

block client’s p2ptraffic

©Academy Xperts / MikroTik Xperts 2013 119

Firewall Log• Let’s log client

Page 120: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 120/345

pings to the router• Log rule should be

added before otheraction

©Academy Xperts / MikroTik Xperts 2013 120

Firewall Log

Page 121: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 121/345

©Academy Xperts / MikroTik Xperts 2013 121

Firewall chains

Page 122: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 122/345

• Except of the built-in chains (input, forward,output), custom chains can be created

• Make firewall structure more simple• Decrease load of the router

©Academy Xperts / MikroTik Xperts 2013 122

Firewall chains in Action•

Page 123: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 123/345

Sequence ofthe firewallcustom chains

Customchains can befor viruses,TCP, UDP

protocols, etc.©Academy Xperts / MikroTik Xperts 2013 123

Firewall chain Lab

Page 124: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 124/345

• Download viruses.rsc from router (access byFTP)

Export the configuration by importcommand

• Check the firewall

©Academy Xperts / MikroTik Xperts 2013 124

Connections

Page 125: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 125/345

©Academy Xperts / MikroTik Xperts 2013 125

Connection State

Page 126: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 126/345

• Advise, drop invalid connections• Firewall should proceed only new packets, it

is recommended to exclude other types ofstates

• Filter rules have the “connection state”matcher for this purpose

©Academy Xperts / MikroTik Xperts 2013 126

Page 127: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 127/345

Page 128: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 128/345

Summary

©Academy Xperts / MikroTik Xperts 2013 128

Page 129: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 129/345

Network Address

Translation

©Academy Xperts / MikroTik Xperts 2013 129

NAT

Page 130: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 130/345

• Router is able to change Source orDestination address of packets flowing

trough it• This process is called src-nat or dst-nat

©Academy Xperts / MikroTik Xperts 2013 130

SRC-NAT

Page 131: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 131/345

SRC-Address NewSRC-Address

Your Laptop Remote Server

©Academy Xperts / MikroTik Xperts 2013 131

DST-NAT

Page 132: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 132/345

DST-AddressNew DST-Address

Private NetworkServer

Public Host

©Academy Xperts / MikroTik Xperts 2013 132

NAT Chains

Page 133: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 133/345

• To achieve these scenarios you have to orderyour NAT rules in appropriate chains: dstnat

or srcnat• NAT rules work on IF-THEN principle

©Academy Xperts / MikroTik Xperts 2013 133

DST-NAT

Page 134: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 134/345

• DST-NAT changes packet’s destinationaddress and port

• It can be used to direct internet users to aserver in your private network

©Academy Xperts / MikroTik Xperts 2013 134

DST-NAT Example

Page 135: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 135/345

DST-Address207.141.27.45:80

New DST-Address192.168.1.1:80

Web Server192.168.1.1

Some Computer

©Academy Xperts / MikroTik Xperts 2013 135

DST-NAT ExampleCreate a rule to forward traffic to WEB server in

private network

Page 136: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 136/345

©Academy Xperts / MikroTik Xperts 2013 136

Redirect

Page 137: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 137/345

• Special type of DST-NAT• This action redirects packets to the router

itself• It can be used for proxying services (DNS,

HTTP)

©Academy Xperts / MikroTik Xperts 2013 137

Redirect example

Page 138: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 138/345

DST-AddressConfigured_DNS_Server:53

New DST-AddressRouter:53

DNS Cache

©Academy Xperts / MikroTik Xperts 2013 138

Page 139: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 139/345

SRC-NAT

Page 140: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 140/345

• SRC-NAT changes packet’s source address • You can use it to connect private network to

the Internet through public IP address• Masquerade is one type of SRC-NAT

©Academy Xperts / MikroTik Xperts 2013 140

Masquerade

S Add S Add

Page 141: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 141/345

Src Address192.168.X.1

Src Addressrouter address

192.168.X.1 Public Server

©Academy Xperts / MikroTik Xperts 2013 141

SRC-NAT Limitations

Page 142: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 142/345

• Connecting to internal servers from outsideis not possible (DST-NAT needed)

• Some protocols require NAT helpers to workcorrectly

©Academy Xperts / MikroTik Xperts 2013 142

NAT Helpers

Page 143: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 143/345

©Academy Xperts / MikroTik Xperts 2013 143

Firewall Tips

Page 144: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 144/345

• Add comments to your rules• Use Connection Tracking or Torch

©Academy Xperts / MikroTik Xperts 2013 144

Connection Tracking

Page 145: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 145/345

• Connection tracking manages informationabout all active connections.

• It should be enabled for Filter and NAT

©Academy Xperts / MikroTik Xperts 2013 145

Connection Tracking

Page 146: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 146/345

©Academy Xperts / MikroTik Xperts 2013 146

Torch

Page 147: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 147/345

Detailed actual traffic report for interface©Academy Xperts / MikroTik Xperts 2013 147

Page 148: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 148/345

NAT Actions

• Accept

Page 149: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 149/345

Accept• DST-NAT/SRC-NAT•

Redirect• Masquerade• Netmap

©Academy Xperts / MikroTik Xperts 2013 149

Page 150: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 150/345

Summary

©Academy Xperts / MikroTik Xperts 2013 150

Page 151: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 151/345

Bandwidth Limit

©Academy Xperts / MikroTik Xperts 2013 151

Page 152: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 152/345

Simple Queue

Page 153: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 153/345

• You must use Target-Address for SimpleQueue

• Rule order is important for queue rules

©Academy Xperts / MikroTik Xperts 2013 153

Simple Queue•

Let’st

Page 154: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 154/345

Let screatelimitationfor your

laptop• 64k

Upload,

128kDownload

Client’s

address

Limits

to configure©Academy Xperts / MikroTik Xperts 2013 154

Simple Queue

Page 155: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 155/345

• Check your limits• Torch is showing bandwidth rate

©Academy Xperts / MikroTik Xperts 2013 155

Using Torch

• Select local

Page 156: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 156/345

Select localnetworkinterface

See actualbandwidth Set Interface

Set LaptopAddress

Check the

Results©Academy Xperts / MikroTik Xperts 2013 156

Specific Server Limit•

Let’s create

Page 157: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 157/345

Let s createbandwidthlimit toMikroTik.com

• DST-address isused for this

• Rules order isimportant

©Academy Xperts / MikroTik Xperts 2013 157

Specific Server Limit•

Ping

Page 158: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 158/345

Pingwww.mikrotik.com

• Put MikroTik

address to DST-address• MikroTik address

can be used asTarget-address too

MikroTik.comAddress

©Academy Xperts / MikroTik Xperts 2013 158

Specific Server Limit

Page 159: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 159/345

• DST-address is useful to setunlimited access to the localnetwork resources

• Target-address and DST-addressescan be vice versa

©Academy Xperts / MikroTik Xperts 2013 159

Bandwidth Test Utility•

Bandwidth test can be used to monitor

Page 160: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 160/345

throughput to remote device• Bandwidth test works between two MikroTik

routers• Bandwidth test utility available for Windows• Bandwidth test is available on MikroTik.com

©Academy Xperts / MikroTik Xperts 2013 160

Bandwidth Test on Router

• Set Test To as testing address

Page 161: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 161/345

Set Test To as testing address• Select protocol•

TCP supports multipleconnections• Authentication might be required

©Academy Xperts / MikroTik Xperts 2013 161

Bandwidth Server

• Set Test To as testing address

Page 162: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 162/345

Set Test To as testing address• Select protocol•

TCP supports multipleconnections• Authentication might be required

©Academy Xperts / MikroTik Xperts 2013 162

Bandwidth Test

Page 163: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 163/345

• Server should be enabled

• It is advised to use enabledAuthenticate

©Academy Xperts / MikroTik Xperts 2013 163

Traffic Priority• Let’s configure

higher priority for

Page 164: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 164/345

g p yqueues

• Priority 1 ishigher than 8

• There should beat least two

priority

Select QueuePriority is inAdvanced Tab

Set Higher Priority

©Academy Xperts / MikroTik Xperts 2013 164

Simple Queue Monitor

Page 165: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 165/345

• It is possible to get graph for each queuesimple rule

• Graphs show how much traffic is passedtrough queue

©Academy Xperts / MikroTik Xperts 2013 165

Simple Queue Monitor

Page 166: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 166/345

Let’s enable graphing for

Queues

©Academy Xperts / MikroTik Xperts 2013 166

Simple Queue Monitor• Graphs are

available onWWW

Page 167: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 167/345

WWW• To view graphs

http://router _IP• You can give it

to yourcustomer

©Academy Xperts / MikroTik Xperts 2013 167

Page 168: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 168/345

Advanced Queing

©Academy Xperts / MikroTik Xperts 2013 168

Mangle•

Mangle is used to mark packets•

Page 169: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 169/345

• Separate different type of traffic• Marks are active within the router• Used for queue to set different limitation• Mangle do not change packet structure

(except DSCP, TTL specific actions)

©Academy Xperts / MikroTik Xperts 2013 169

Mangle Actions

Page 170: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 170/345

©Academy Xperts / MikroTik Xperts 2013 170

Mangle Actions• Mark-connection uses connection tracking

• Information about new connection added to

Page 171: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 171/345

connection tracking table• Mark-packet works with packet directly• Router follows each packet to apply mark-

packet

©Academy Xperts / MikroTik Xperts 2013 171

Optimal Mangle• Queues have packet-mark option only

Page 172: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 172/345

©Academy Xperts / MikroTik Xperts 2013 172

Optimal Mangle

Page 173: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 173/345

• Mark new connection with mark-connection• Add mark-packet for every mark-connection

©Academy Xperts / MikroTik Xperts 2013 173

Mangle Example

• Imagine you have second client on the router

Page 174: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 174/345

Imagine you have second client on the routernetwork with 192.168.X.55 IP address

Let’s create two different marks ( Gold , Silver ),one for your computer and second for192.168.X.55

©Academy Xperts / MikroTik Xperts 2013 174

Mark Connection

Page 175: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 175/345

©Academy Xperts / MikroTik Xperts 2013 175

Mark Packet

Page 176: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 176/345

©Academy Xperts / MikroTik Xperts 2013 176

Mangle Example

Page 177: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 177/345

• Add Marks for second user too• There should be 4 mangle rules for two groups

©Academy Xperts / MikroTik Xperts 2013 177

Page 178: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 178/345

PCQ• PCQ is advanced Queue type• PCQ uses classifier to divide traffic (from client

Page 179: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 179/345

PCQ uses classifier to divide traffic (from clientpoint of view; src-address is upload, dst-address is download)

©Academy Xperts / MikroTik Xperts 2013 179

PCQ, one limit to all• PCQ allows to set one limit to all users with

one queue

Page 180: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 180/345

©Academy Xperts / MikroTik Xperts 2013 180

One limit to all•

Multiple queue rules are changed by one

Page 181: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 181/345

©Academy Xperts / MikroTik Xperts 2013 181

PCQ, equalize bandwidth•

Equally share bandwidth between customers

Page 182: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 182/345

©Academy Xperts / MikroTik Xperts 2013 182

Equalize bandwidth• 1M upload/2M download is shared between

users

Page 183: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 183/345

©Academy Xperts / MikroTik Xperts 2013 183

PCQ Lab

• Teacher is going to make PCQ lab on the

Page 184: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 184/345

Teacher is going to make PCQ lab on therouter

• Two PCQ scenarios are going to be used withmangle

©Academy Xperts / MikroTik Xperts 2013 184

Page 185: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 185/345

Summary

©Academy Xperts / MikroTik Xperts 2013 185

Page 186: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 186/345

Wireless

©Academy Xperts / MikroTik Xperts 2013 186

What is Wireless

• RouterOS supports various radio modulesthat allow communication over the air

Page 187: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 187/345

that allow communication over the air(2.4GHz and 5GHz)

MikroTik RouterOS provides a completesupport for IEEE 802.11a, 802.11b and802.11g wireless networking standards

©Academy Xperts / MikroTik Xperts 2013 187

Wireless Standards

• IEEE 802.11b - 2.4GHz frequencies, 11Mbps

Page 188: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 188/345

• IEEE 802.11g - 2.4GHz frequencies, 54Mbps•

IEEE 802.11a - 5GHz frequencies, 54Mbps• IEEE 802.11n - draft, 2.4GHz - 5GHz

©Academy Xperts / MikroTik Xperts 2013 188

802.11 b/g Channels1 2 3 4 5 6 7 8 9 10 11

24002483

Page 189: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 189/345

• (11) 22 MHz wide channels (US)

• 3 non-overlapping channels• 3 Access Points can occupy same area without

interfering©Academy Xperts / MikroTik Xperts 2013 189

Page 190: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 190/345

Page 191: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 191/345

Supported Frequencies

• Depending on your country regulations

Page 192: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 192/345

wireless card might support•

2.4GHz: 2312 - 2499 MHz• 5GHz: 4920 - 6100 MHz

©Academy Xperts / MikroTik Xperts 2013 192

Apply Country Regulations

Set wireless interface

Page 193: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 193/345

to apply your countryregulations

©Academy Xperts / MikroTik Xperts 2013 193

RADIO Name

• W ill RADIO N f th

Page 194: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 194/345

We will use RADIO Name for the samepurposes as router identity

• Set RADIO Name as Number+Your Name

©Academy Xperts / MikroTik Xperts 2013 194

Wireless Network

Page 195: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 195/345

©Academy Xperts / MikroTik Xperts 2013 195

Station Configuration• Set Interface

mode=station• Select band

Page 196: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 196/345

• Set SSID, WirelessNetwork Identity

• Frequency is notimportant for client,use scan-list

©Academy Xperts / MikroTik Xperts 2013 196

Connect List

• Set of rules

Page 197: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 197/345

used bystation toselectaccess-point

©Academy Xperts / MikroTik Xperts 2013 197

Page 198: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 198/345

Access Point Configuration• Set Interface

mode=ap-bridge• Select band

Page 199: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 199/345

Select band• Set SSID, Wireless

Network Identity• Set Frequency

©Academy Xperts / MikroTik Xperts 2013 199

Snooper wireless monitor• Use Snooper to

get total view ofthe wirelessnetworks on used

Page 200: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 200/345

networks on usedband

• Wirelessinterface isdisconnected at

this moment©Academy Xperts / MikroTik Xperts 2013 200

Page 201: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 201/345

Page 202: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 202/345

Default Authentication

• Yes, Access-List rules are checked, client is

Page 203: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 203/345

Yes, Access List rules are checked, client isable to connect, if there is no deny rule

• No, only Access-List rule are checked

©Academy Xperts / MikroTik Xperts 2013 203

Access-List Lab

• Since you have mode=station configured weare going to make lab on teacher’s router

Page 204: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 204/345

are going to make lab on teacher s router •

Disable connection for specific client• Allow connection only for specific clients

©Academy Xperts / MikroTik Xperts 2013 204

Security

• Let’s enable encryption on wireless network • You must use WPA or WPA2 encryption

Page 205: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 205/345

You must use WPA or WPA2 encryptionprotocols

• All devices on the network should have thesame security options

©Academy Xperts / MikroTik Xperts 2013 205

Security• Let’s create WPA

encryption for ourwireless network

Page 206: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 206/345

• WPA Pre-Shared Key is

mikrotiktraining

©Academy Xperts / MikroTik Xperts 2013 206

Configuration Tip• To view hidden Pre-

Shared Key, click on HidePasswords

Page 207: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 207/345

• It is possible to viewother hiddeninformation, exceptrouter password

©Academy Xperts / MikroTik Xperts 2013 207

Drop Connections betweenclients

D f lt F di g d t

Page 208: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 208/345

Default-Forwarding used todisable communicationsbetween clients connectedto the same access-point

©Academy Xperts / MikroTik Xperts 2013 208

Default Forwarding

• Access-List rules have higher priority

Page 209: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 209/345

• Check your access-list if connection betweenclient is working

©Academy Xperts / MikroTik Xperts 2013 209

Nstreme

• MikroTik proprietary wireless protocol• Improves wireless links, especially long-range

Page 210: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 210/345

Improves wireless links, especially long rangelinks

• To use it on your network, enable protocolon all wireless devices of this network

©Academy Xperts / MikroTik Xperts 2013 210

Nstreme Lab• Enable Nstreme on

your router• Check the

Page 211: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 211/345

connection status• Nstreme should be

enabled on both routers

©Academy Xperts / MikroTik Xperts 2013 211

Summary

Page 212: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 212/345

Summary

©Academy Xperts / MikroTik Xperts 2013 212

Bridging

Page 213: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 213/345

Bridging

©Academy Xperts / MikroTik Xperts 2013 213

Bridge Wireless Network

Your RouterYour LaptopClass AP

Page 214: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 214/345

Let’s get back to our configuration

192.168.X.1 192.168.X.254DHCP-Client

©Academy Xperts / MikroTik Xperts 2013 214

Page 215: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 215/345

Bridge

• We are going to bridge local Ethernetinterface with Internet wireless interface

Page 216: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 216/345

• Bridge unites different physical interfaces

into one logical interface• All your laptops will be in the same network

©Academy Xperts / MikroTik Xperts 2013 216

Bridge

• To bridge you need to create

Page 217: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 217/345

bridge interface

• Add interfaces to bridge ports

©Academy Xperts / MikroTik Xperts 2013 217

Create Bridge• Bridge is configured from / interface

bridge menu

Page 218: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 218/345

©Academy Xperts / MikroTik Xperts 2013 218

Add Bridge Port• Interfaces are added to bridge via ports

Page 219: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 219/345

©Academy Xperts / MikroTik Xperts 2013 219

Bridge

• There are no problems to bridge Ethernetinterface

Page 220: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 220/345

Wireless Clients ( mode=station ) do notsupport bridging due the limitation of 802.11

©Academy Xperts / MikroTik Xperts 2013 220

Bridge Wireless

• WDS allows to add wireless client to bridge• WDS (Wi l Di t ib ti S t ) bl

Page 221: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 221/345

WDS (Wireless Distribution System) enables

connection between Access Point and AccessPoint

©Academy Xperts / MikroTik Xperts 2013 221

Set WDS Mode

Station-wds isspecial stationmode with WDS

Page 222: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 222/345

support

©Academy Xperts / MikroTik Xperts 2013 222

Page 223: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 223/345

Access Point WDS

• Enable WDS on AP-bridge, usemode=dynamic-mesh

• WDS interfaces are created on the fly

Page 224: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 224/345

• Use default bridge for WDS interfaces• Add Wireless Interface to Bridge

©Academy Xperts / MikroTik Xperts 2013 224

AP-bridge

• Set AP-bridgesettings

Page 225: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 225/345

• Add Wirelessinterface to bridge

©Academy Xperts / MikroTik Xperts 2013 225

WDS configuration

• Use dynamic-mesh WDSmode

• WDS interfaces are

Page 226: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 226/345

created on the fly• Others AP should use

dynamic-mesh too

©Academy Xperts / MikroTik Xperts 2013 226

WDS

• WDS link isestablished

• D i i t f

Page 227: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 227/345

Dynamic interface

is present

©Academy Xperts / MikroTik Xperts 2013 227

WDS Lab• Delete masquerade rule• Delete DHCP-client on router wireless

interface

Page 228: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 228/345

• Use mode=station-wds on router• Enable DHCP on your laptop• Can you ping neighbor’s laptop

©Academy Xperts / MikroTik Xperts 2013 228

WDS Lab• Your Router is Transparent Bridge now• You should be able to ping neighbor router

and computer now

Page 229: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 229/345

Just use correct IP address

©Academy Xperts / MikroTik Xperts 2013 229

Restore Configuration•

To restore configuration manually• change back to Station mode• Add DHCP Client on correct interface

Page 230: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 230/345

Add DHCP-Client on correct interface• Add masquerade rule• Set correct network configuration to laptop

©Academy Xperts / MikroTik Xperts 2013 230

Summary

Page 231: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 231/345

©Academy Xperts / MikroTik Xperts 2013 231

Routing

Page 232: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 232/345

©Academy Xperts / MikroTik Xperts 2013 232

Page 233: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 233/345

Route

• ip route rules define where packets shouldbe sent

Page 234: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 234/345

• Let’s look at / ip route rules

©Academy Xperts / MikroTik Xperts 2013 234

Page 235: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 235/345

Default Gateway

Default gateway:next hop router

Page 236: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 236/345

where all ( 0.0.0.0 )traffic is sent

©Academy Xperts / MikroTik Xperts 2013 236

Set Default Gateway Lab•

Currently you have default gateway receivedfrom DHCP-Client

• Disable automatic receiving of default

Page 237: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 237/345

Disable automatic receiving of default

gateway in DHCP-client settings• Add default gateway manually

©Academy Xperts / MikroTik Xperts 2013 237

Dynamic Routes• Look at the

other routes•

Routes withDAC are addedautomatically

Page 238: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 238/345

DAC routecomes from IPaddressconfiguration

©Academy Xperts / MikroTik Xperts 2013 238

Page 239: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 239/345

Static Routes

• Our goal is to ping neighbor laptop

Page 240: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 240/345

• Static route will help us to achieve this

©Academy Xperts / MikroTik Xperts 2013 240

Page 241: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 241/345

Static Route

• Additional static route is required to reachyour neighbor laptop

• Because gateway (teacher’s router) does not

Page 242: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 242/345

Because gateway (teacher s router) does not

have information about student’s privatenetwork

©Academy Xperts / MikroTik Xperts 2013 242

Page 243: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 243/345

Network Structure

Page 244: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 244/345

©Academy Xperts / MikroTik Xperts 2013 244

Route To Your Neighbor• Add one route rule• Set Destination, destination is neighbor’s

local network

Page 245: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 245/345

Set Gateway, address which is used to reachdestination - gateway is IP address ofneighbor’s router wireless interface

©Academy Xperts / MikroTik Xperts 2013 245

Route Your Neighbor•

Add static route• Set Destination

and Gateway

Page 246: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 246/345

• Try to pingNeighbor’s Laptop

©Academy Xperts / MikroTik Xperts 2013 246

Page 247: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 247/345

Dynamic Routes• The same configuration is possible with

dynamic routes• Imagine you have to add static routes to all

neighbors networks

Page 248: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 248/345

neighbors networks• Instead of adding tons of rules, dynamic

routing protocols can be used

©Academy Xperts / MikroTik Xperts 2013 248

Dynamic Routes

• Easy in configuration, difficult inmanaging/troubleshooting

Page 249: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 249/345

managing/troubleshooting• Can use more router resources

©Academy Xperts / MikroTik Xperts 2013 249

Dynamic Routes

• We are going to use OSPF• OSPF is very fast and optimal for dynamic

Page 250: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 250/345

routing• Easy in configuration

©Academy Xperts / MikroTik Xperts 2013 250

OSPF configuration

Add correctnetwork toOSPF

Page 251: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 251/345

OSPF protocolwill beenabled

©Academy Xperts / MikroTik Xperts 2013 251

Page 252: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 252/345

Summary

Page 253: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 253/345

©Academy Xperts / MikroTik Xperts 2013 253

Local NetworkManagement

Page 254: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 254/345

©Academy Xperts / MikroTik Xperts 2013 254

Access to Local Network•

Plan network design carefully• Take care of user’s local access to the

network

Page 255: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 255/345

• Use RouterOS features to secure localnetwork resources

©Academy Xperts / MikroTik Xperts 2013 255

ARP•

Address Resolution Protocol• ARP joins together client’s IP address with

MAC-address

Page 256: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 256/345

• ARP operates dynamically, but can also bemanually configured

©Academy Xperts / MikroTik Xperts 2013 256

ARP Table

ARP tableprovides: IPaddress, MAC-

Page 257: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 257/345

address andInterface

©Academy Xperts / MikroTik Xperts 2013 257

Page 258: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 258/345

Static ARP configuration• Add Static Entry to

ARP table• Set for interface

arp=reply-only todisable dynamic ARP

Page 259: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 259/345

creation• Disable/enable

interface or reboot

router ©Academy Xperts / MikroTik Xperts 2013 259

Page 260: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 260/345

DHCP Server

• Dynamic Host Configuration Protocol• Used for automatic IP address distribution

over local network

Page 261: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 261/345

• Use DHCP only in secure networks

©Academy Xperts / MikroTik Xperts 2013 261

DHCP Server

• To setup DHCP server you should have IPaddress on the interface

• Use setup command to enable DHCP server

Page 262: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 262/345

• It will ask you for necessary information

©Academy Xperts / MikroTik Xperts 2013 262

DHCP-Server Setup

Click on DHCP Setup

Set Addresses that

DNS server address

Time that client may use

Page 263: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 263/345

to run Setup WizardSelect interface for

DHCP server

Set Network for DHCP,offered automaticallySet Gateway forDHCP clientswill be given to clientsthat will be assigned to clientsy

IP addressWe are done!

©Academy Xperts / MikroTik Xperts 2013 263

Important

• To configure DHCP server on bridge , setserver on bridge interface

• DHCP server will be invalid , when it is

Page 264: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 264/345

configured on bridge port

©Academy Xperts / MikroTik Xperts 2013 264

DHCP Server Lab• Setup DHCP server on Ethernet Interface

where Laptop is connected• Change computer Network settings and

enable DHCP-client (Obtain an IP address

Page 265: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 265/345

Automatically)• Check the Internet connectivity

©Academy Xperts / MikroTik Xperts 2013 265

DHCP Server Information

Leases provideinformation aboutDHCP clients

Page 266: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 266/345

©Academy Xperts / MikroTik Xperts 2013 266

Winbox Configuration Tip

Show or hidedifferentWinbox

Page 267: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 267/345

columns

©Academy Xperts / MikroTik Xperts 2013 267

Static Lease

• We can make leaseto be static

• Client will not get

Page 268: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 268/345

other IP address

©Academy Xperts / MikroTik Xperts 2013 268

Static Lease

• DHCP-server could run without dynamicleases

• Clients will receive only preconfigured IP

Page 269: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 269/345

address

©Academy Xperts / MikroTik Xperts 2013 269

Static Lease

• Set Address-Pool tostatic-only

Page 270: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 270/345

• Create Static leases

©Academy Xperts / MikroTik Xperts 2013 270

HotSpot

Page 271: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 271/345

©Academy Xperts / MikroTik Xperts 2013 271

Page 272: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 272/345

HotSpot Usage

• Open Access Points, Internet Cafes, Airports,universities campuses, etc.

• Different ways of authorization

Page 273: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 273/345

• Flexible accounting

©Academy Xperts / MikroTik Xperts 2013 273

HotSpot Requirements

• Valid IP addresses on Internet and LocalInterfaces

• DNS servers addresses added to ip dns

Page 274: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 274/345

• At least one HotSpot user

©Academy Xperts / MikroTik Xperts 2013 274

HotSpot Setup

• HotSpot setup is easy• Setup is similar to DHCP Server setup

Page 275: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 275/345

©Academy Xperts / MikroTik Xperts 2013 275

HotSpot Setup• Run ip hotspot

setup• Select Inteface• Proceed to

Page 276: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 276/345

answer thequestions Select Interface to

run HotSpot on

HotSpot address willbe selected automaticallyMasquerade HotSpot network

automaticallyAddresses that will be assigned

to HotSpot clientsWhether to use certificate

together with HotSpot or notIP address to redirect SMTP

(e-mails) to your SMTP serverDNS servers addressfor HotSpot clients

DNS name for HotSpot serverAdd first HotSpot user

©Academy Xperts / MikroTik Xperts 2013 276

Important Notes

• Users connected to HotSpot interface will bedisconnected from the Internet

• Client will have to authorize in HotSpot toI

Page 277: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 277/345

get access to Internet

©Academy Xperts / MikroTik Xperts 2013 277

Important Notes• HotSpot default setup creates additional

configuration:• DHCP-Server on HotSpot Interface•

P l f H tS t Cli t

Page 278: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 278/345

Pool for HotSpot Clients• Dynamic Firewall rules (Filter and NAT)

©Academy Xperts / MikroTik Xperts 2013 278

HotSpot Help•

HotSpot login page is provided when usertries to access any web-page

• To logout from HotSpot you need to go to

htt // t IP

Page 279: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 279/345

http://router _IP orhttp://HotSpot _DNS

©Academy Xperts / MikroTik Xperts 2013 279

HotSpot Setup Lab

• Let’s create HotSpot on local Interface• Don’t forget HotSpot login and password or

ill t b bl t g t th I t t

Page 280: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 280/345

you will not be able to get the Internet

©Academy Xperts / MikroTik Xperts 2013 280

HotSpot Network Hosts

Page 281: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 281/345

Information about clients connected to HotSpot router©Academy Xperts / MikroTik Xperts 2013 281

HotSpot Active Table

Information aboutauthorizedHotSpot clients

Page 282: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 282/345

©Academy Xperts / MikroTik Xperts 2013 282

User Management

Add/Edit/RemoveHotSpot users

Page 283: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 283/345

©Academy Xperts / MikroTik Xperts 2013 283

HotSpot Walled-Garden•

Tool to get access to specific resourceswithout HotSpot authorization• Walled-Garden for HTTP and HTTPS•

Walled Garden IP for other resources

Page 284: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 284/345

Walled-Garden IP for other resources(Telnet, SSH, Winbox, etc.)

©Academy Xperts / MikroTik Xperts 2013 284

HotSpot Walled-Garden

Allow access tomikrotik.com

Page 285: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 285/345

©Academy Xperts / MikroTik Xperts 2013 285

Bypass HotSpot• Bypass specific

clients over HotSpot• VoIP phones,

printers, superusers• IP binding is used

Page 286: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 286/345

IP-binding is usedfor that

©Academy Xperts / MikroTik Xperts 2013 286

HotSpot Bandwidth Limits

• It is possible to set every HotSpot user withautomatic bandwidth limit

• Dynamic queue is created for every client

from profile

Page 287: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 287/345

from profile

©Academy Xperts / MikroTik Xperts 2013 287

Page 288: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 288/345

HotSpot Advanced Lab

To give each client 64kupload and 128kdownload, set Rate

Limit

Page 289: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 289/345

Limit

©Academy Xperts / MikroTik Xperts 2013 289

HotSpot Lab•

Add second user• Allow access to www.mikrotik.com without

HotSpot authentication for your laptop• Add Rate-limit 1M/1M for your laptop

Page 290: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 290/345

Add Rate limit 1M/1M for your laptop

©Academy Xperts / MikroTik Xperts 2013 290

Tunnels

Page 291: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 291/345

©Academy Xperts / MikroTik Xperts 2013 291

PPPoE•

Point to Point Protocol over Ethernet is oftenused to control client connections for DSL,cable modems and plain Ethernet networks

• MikroTik RouterOS supports PPPoE clientand PPPoE server

Page 292: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 292/345

and PPPoE server

©Academy Xperts / MikroTik Xperts 2013 292

PPPoE Client Setup• Add PPPoE

client• You need to

set Interace• Set Login

and

Page 293: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 293/345

andPassword

©Academy Xperts / MikroTik Xperts 2013 293

PPPoE Client Lab• Teachers are going to create PPPoE server on

their router• Disable DHCP- client on router’s outgoing

interface•

Set up PPPoE client on outgoing interface

Page 294: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 294/345

p g g• Set Username class , password class

©Academy Xperts / MikroTik Xperts 2013 294

Page 295: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 295/345

PPPoE Server Setup

• Select Interface• Select Profile

Page 296: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 296/345

©Academy Xperts / MikroTik Xperts 2013 296

PPP Secret• User’s database

• Add login andPassword

• Select service• Configuration is

Page 297: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 297/345

Configuration istakef from profile

©Academy Xperts / MikroTik Xperts 2013 297

PPP Profiles

• Set of rules used for PPP clients• The way to set same settings for different

clients

Page 298: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 298/345

©Academy Xperts / MikroTik Xperts 2013 298

PPP Profile

• Local address -Server address

• Remote Address -Client address

Page 299: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 299/345

Client address

©Academy Xperts / MikroTik Xperts 2013 299

PPPoE• Important, PPPoE server runs on the

interface• PPPoE interface can be without IP address

configured

• For security, leave PPPoE interface without

Page 300: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 300/345

IP address configuration

©Academy Xperts / MikroTik Xperts 2013 300

Pools• Pool defines the range of IP addresses for PPP,

DHCP and HotSpot clients• We will use a pool, because there will be more

than one client• Addresses are taken from pool automatically

Page 301: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 301/345

Addresses are taken from pool automatically

©Academy Xperts / MikroTik Xperts 2013 301

Pool

Page 302: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 302/345

©Academy Xperts / MikroTik Xperts 2013 302

PPP Status

Page 303: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 303/345

©Academy Xperts / MikroTik Xperts 2013 303

PPTP• Point to Point Tunnel Protocol providesencrypted tunnels over IP

• MikroTik RouterOS includes support for PPTPclient and server

• Used to secure link between Local Networks

over Internet

Page 304: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 304/345

• For mobile or remote clients to accesscompany Local network resources

©Academy Xperts / MikroTik Xperts 2013 304

PPTP

Page 305: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 305/345

©Academy Xperts / MikroTik Xperts 2013 305

PPTP configuration

• PPTP configuration is very similar to PPPoE• L2TP configuration is very similar to PPTP

and PPPoE

Page 306: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 306/345

©Academy Xperts / MikroTik Xperts 2013 306

PPTP client• Add PPTP

Interface• Specify address

of PPTP server•

Set login andpassword

Page 307: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 307/345

password

©Academy Xperts / MikroTik Xperts 2013 307

PPTP Client• That’s all for PPTP client configuration • Use Add Default Gateway to route all

router’s traffic to PPTP tunnel •

Use static routes to send specific traffic toPPTP tunnel

Page 308: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 308/345

©Academy Xperts / MikroTik Xperts 2013 308

PPTP Server• PPTP Server

is able to

maintainmultipleclients

It is easy toenable PPTP

Page 309: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 309/345

enable PPTPserver

©Academy Xperts / MikroTik Xperts 2013 309

PPTP Server Clients•

PPTP client settings are stored in ppp secret• ppp secret is used for PPTP, L2TP, PPPoE

clients

• ppp secret database is configured on server

Page 310: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 310/345

©Academy Xperts / MikroTik Xperts 2013 310

PPP Profile

• The same profile is used for PPTP, PPPoE,L2TP and PPP clients

Page 311: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 311/345

©Academy Xperts / MikroTik Xperts 2013 311

Page 312: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 312/345

Proxy

Page 313: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 313/345

©Academy Xperts / MikroTik Xperts 2013 313

What is Proxy

• It can speed up WEB browsing by cachingdata

• HTTP Firewall

Page 314: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 314/345

©Academy Xperts / MikroTik Xperts 2013 314

Enable Proxy

Page 315: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 315/345

The main option is Enable , other settings are optional©Academy Xperts / MikroTik Xperts 2013 315

Transparent Proxy•

User need to set additional configuration tobrowser to use Proxy

• Transparent proxy allows to direct all users

to proxy automatically

Page 316: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 316/345

©Academy Xperts / MikroTik Xperts 2013 316

Transparent Proxy

• DST-NAT rulesrequired fortransparent proxy

• HTTP traffic shouldbe redirected torouter

Page 317: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 317/345

©Academy Xperts / MikroTik Xperts 2013 317

HTTP Firewall

• Proxy access list provides option to filter DNSnames

• You can make redirect to specific pages

Page 318: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 318/345

©Academy Xperts / MikroTik Xperts 2013 318

HTTP Firewall•

Dst-Host, webpageaddress(http://test.com )

• Path, anything afterhttp://test.com/ PATH

Page 319: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 319/345

©Academy Xperts / MikroTik Xperts 2013 319

HTTP Firewall• Create rule to drop access for specific

web-page• Create rule to make redirect from

unwanted web-page to your companypage

Page 320: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 320/345

©Academy Xperts / MikroTik Xperts 2013 320

Web-page logging

• Proxy can log visited Web-Pages by users• Make sure you have enough resources for

logs (it is better to send them to remote)

Page 321: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 321/345

©Academy Xperts / MikroTik Xperts 2013 321

Web-Pages logging

• Add logging rule• Check logs

Page 322: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 322/345

©Academy Xperts / MikroTik Xperts 2013 322

Caching to External•

Cache can be stored on the external drives• Store manipulates all the external drives• Cache can be stored to IDE, SATA, USB, CF,

MicroSD drives

Page 323: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 323/345

©Academy Xperts / MikroTik Xperts 2013 323

Store•

Manage all external disks• Newly connected disk should be formatted

Page 324: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 324/345

©Academy Xperts / MikroTik Xperts 2013 324

Page 325: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 325/345

Summary

Page 326: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 326/345

©Academy Xperts / MikroTik Xperts 2013 326

Dude

Page 327: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 327/345

©Academy Xperts / MikroTik Xperts 2013 327

Dude• Network monitor program

• Automatic discovery of devices• Draw and Layout map of your networks• Services monitor and alerts• It is Free

Page 328: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 328/345

©Academy Xperts / MikroTik Xperts 2013 328

Dude• Dude consists of two parts:

1.Dude server - the actual monitor program.It does not have a graphical interface. Youcan run Dude server even on RouterOS

2.Dude client - connects to Dude server andshows all the information it receives

Page 329: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 329/345

©Academy Xperts / MikroTik Xperts 2013 329

Dude Install

• Dude is available atwww.mikrotik.com

• Install is very easy• Read and use next

button

Page 330: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 330/345

Install Dude Server on computer©Academy Xperts / MikroTik Xperts 2013 330

Dude

• Dude is translated to different languages• Available on wiki.mikrotik.com

Page 331: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 331/345

©Academy Xperts / MikroTik Xperts 2013 331

Dude First Launch

• Discoveroption isoffered for thefirst launch

• You candiscover localnetwork

Page 332: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 332/345

etwo

©Academy Xperts / MikroTik Xperts 2013 332

Dude Lab

• Download Dude from ftp://192.168.100.254

• Install Dude• Discover Network• Add laptop and router• Disconnect Laptop from Router

Page 333: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 333/345

©Academy Xperts / MikroTik Xperts 2013 333

Dude Usage

Page 334: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 334/345

©Academy Xperts / MikroTik Xperts 2013 334

Dude Usage

Page 335: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 335/345

©Academy Xperts / MikroTik Xperts 2013 335

Troubleshooting

Page 336: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 336/345

©Academy Xperts / MikroTik Xperts 2013 336

Lost Password

• The only solution to reset password is toreinstall the router

Page 337: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 337/345

©Academy Xperts / MikroTik Xperts 2013 337

RouterBOARD License• All purchased licenses are stored in the

MikroTik account server• If your router loses the Key for some reason -

just log into mikrotik.com to get it from keyslist

• If the key is not in the list use Request Keyoption

Page 338: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 338/345

©Academy Xperts / MikroTik Xperts 2013 338

Bad Wireless Signal• check that the antenna connector is

connected 'main' antenna connector• check that there is no water or moisture in

the cable• check that the default settings for the radio

are being used• Use interface wireless reset-configuration

Page 339: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 339/345

Use interface wireless reset configuration

©Academy Xperts / MikroTik Xperts 2013 339

No Connection• Try different Ethernet port or cable• Use reset jumper on RouterBOARD• Use serial console to view any possible

messages•

Use netinstall if possible• Contact support ([email protected])

Page 340: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 340/345

©Academy Xperts / MikroTik Xperts 2013 340

Before Certification Test

• Reset the router• Restore backup or restore configuration• Make sure you have access to the Internet

and to training.mikrotik.com

Page 341: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 341/345

©Academy Xperts / MikroTik Xperts 2013 341

Certification Test

Page 342: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 342/345

©Academy Xperts / MikroTik Xperts 2013 342

Certification test

• Go to http://training.mikrotik.com• Login with your account• Look for US/Dallas Training

• Select Essential Training Test

Page 343: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 343/345

©Academy Xperts / MikroTik Xperts 2013 343

Instructions

Page 344: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 344/345

©Academy Xperts / MikroTik Xperts 2013 344

MTCNA TestApr. 04th, 2013Santiago de Chile, Chile

Page 345: MTCNA-v5

8/18/2019 MTCNA-v5

http://slidepdf.com/reader/full/mtcna-v5 345/345

345© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permission

MikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of companyMikrotīkls

SIA .