MTCNA-v5
-
Upload
marcoantoniomartinezf -
Category
Documents
-
view
234 -
download
2
Transcript of MTCNA-v5
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 1/345
MikroTik CertifiedNetwork Associate
(MTCNA)
Academy Xpertswww.academyxperts.comMauro Escalante C.
[email protected] Certified Trainer
MikroTik Trainer ID #TR0086
© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 2/345
www.academyxperts.com
[email protected]@academyxperts.clwww.academyxperts.crcursos@academyxperts.crwww.academyxperts.hncursos@academyxperts.hnwww.academyxperts.com.arcursos@academyxperts.com.arwww.academyxperts.com.mxcursos@academyxperts.com.mxwww.academyxperts.com.pacursos@academyxperts.com.pa
© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
www.mikrotikxperts.com
[email protected]@mikrotikxperts.clwww.mikrotikxperts.crcursos@mikrotikxperts.crwww.mikrotikxperts.com.bocursos@mikrotikxperts.com.bowww.mikrotikxperts.com.mxcursos@mikrotikxperts.com.mx
A c a d e m y X p e r t s M i k r o T i k X p e r t s
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 3/345
Instructores Academy XpertsAlejandro Teixeira (Chile)
([email protected])• Co-Fundador y CEO de MikroTik Xperts Chile• Co-Fundador y CEO de WiDuit• MikroTik Certified Trainer
• MTCNA, MTCTCE, MTCWE
Gustavo Angulo (Venezuela)
([email protected])• Co-Fundador y CEO de MikroTik Xperts Venezuela• Co-Fundador y CTO de WiDuit• MikroTik Certified Trainer
• MTCNA, MTCTCE, MTCWE• Cisco CCNA Trainer
Luis Cuadrado (Ecuador)([email protected])• Ubiquiti airMAX Certified Trainer
Miguel Ojeda (Ecuador)
([email protected])• Co-Fundador y CTO de MikroTik Xperts• MikroTik Certified Trainer
• MTCNA, MTCTCE, MTCWE, MTCRE• DenwaIP Certified Trainer
Mauro Escalante (Ecuador)([email protected])
• Co-Fundador y CEO de MikroTik Xperts• Co-Fundador y CEO de Network Xperts• MikroTik Certified Trainer
• MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Trainer• Observer/Sniffer Certified Engineer
3©Academy Xperts / MikroTik Xperts 2013 3
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 4/345
Consultores Academy XpertsAlejandro Teixeira (Chile)([email protected])
• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE
Gustavo Angulo (Venezuela)([email protected])
• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Cisco CCNA, Cisco Security
Hamzah Haji (Panamá)([email protected])
•
MikroTik MTCNA, MTCTCE, MTCRELuis Cuadrado (Ecuador)([email protected])
• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Admin
Miguel Ojeda (Ecuador)([email protected])
• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• DenwaIP Certified• Ubiquiti airMAX Certified Admin
Mauro Escalante (Ecuador)([email protected])
• MikroTik MTCNA, MTCTCE, MTCWE, MTCRE• Ubiquiti airMAX Certified Admin• Observer/Sniffer Certified Engineer
Pedro Toribio (Nicaragua, Costa Rica, Honduras)([email protected])
• MikroTik MTCNA, MTCTCEJosé Alfredo García (Bolivia)([email protected])
• MikroTik MTCNA, MTCTCE
4©Academy Xperts / MikroTik Xperts 2013 4
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 5/345
Introducción PersonalPresentarse individualmente
• Nombre• Compañía• Conocimiento previo sobre RouterOS• Conocimiento previo sobre networking• Qué espera de este curso?
Recuerde su número N de claseMi número es: _____
5© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 6/345
Horario
09:00 – 10:30 Sesión I10:30 – 11:00 Break
11:00 – 13:00 Sesión II13:00 – 14:00 Lunch
14:00 – 15:30 Sesión III15:30 – 16:00 Break
16:00 – 17:30+ Sesión IV
6© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 7/345
Objetivos del Curso• Conocer los alcances y capacidades del RouterOS y del
RouterBoard de MikroTik
•
Conocer, practicar y operar los principios básicos delRouterOS, tanto en configuración y mantenimiento comoen resolución de problemas
• Al terminar el curso el alumno estará familiarizado con lamayoría de las características del RouterOS y será capazde aplicar las configuraciones de red más comunes
7© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 8/345
Sobre MikroTik• Fabricante de hardware y software de router• Productos usados por ISPs, PYMES, y para Home• MikroTik fabrica tecnología para internet más rápida,
potente y de un costo adecuado para un amplio rango deusuarios
8
• www.mikrotik.com• www.routerboard.com• wiki.mikrotik.com•
tiktube.com• forum.mikrotik.com• en.wikipedia.org/wiki/MikroTik
Industry Networking hardware
Founded 1995
Headquarters Riga, Latvia
Key people John Tully, CEO Arnis Riekstins, CTO
Products Routers, Firewalls
Revenue 62.5 million Euros (2011)
Net income 20.6 million Euros (2011)
Employees 80 (2012)
© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 9/345
Where is MikroTik ?
9
Riga, LATVIA ,Northern Europe
© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 10/345
Historia de MikroTik•
1995: Fundación• 1997: RouterOS software para x86 (PC)• 2002: Nace RouterBOARD•
2006: Primer MUM (MikroTik User Meeting)
10
Fechas de liberación de las versiones de RouterOS• V6 – May 2013•
v5 – Mar 2010• v4 – Oct 2009• v3 – Jan 2008
© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 11/345
Qué es MikroTik RouterOS ?
11© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
• Hardware•
Configuración• Firewall• Routing• Forwarding• MPLS•
VPN• Wireless• HotSpot• Calidad de Servicio (QoS)• Web Proxy• Herramientas• The Dude• Licencias
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 12/345
Qué es RouterOS ?• MikroTik RouterOS es el sistema operativo del hardware
Mikrotik RouterBOARD• Puede también ser instalado en un PC para convertirlo en
un router con todas las características necesarias:• Routing•
Firewall• Administrador de ancho de banda• Filtro de paquetes• Cualquier dispositivo wireless 802.11a/b/g/n• Enlace backhaul• Gateway Hotspot• VPN server, etc.
• EL RouterOS es un sistema operativo stand-alone basado enel kernel de Linux2.6
12© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
(H d )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 13/345
Qué es RouterOS? – (Hardware )• RouterOS puede instalarse en PCs y otros dispositivos de hardware compatibles
x86, como tarjetas embebidas y sistemas miniITX.• RouterOS soporta computadores multi-core y multi-CPU. Soporta
Multiprocesamiento Simétrico (*SMP: Symmetric Multiprocessing)• Se puede ejecutar en los motherboards Intel más recientes y aprovechar los
nuevos CPUs multicore• RouterOS soporta la instalación en dispositivos de almacenamiento IDE, SATA y
USB. Esto incluye:• HDDs• Tarjetas CF y SD• Discos SDD
• Se necesita al menos 64MB de espacio para instalar RouterOS.•
El RouterOS formateará la partición y se convertirá en el sistema operativo pordefault del dispositivo• Soporta una gran variedad de interfaces de red, incluyendo tarjetas ethernet de
10 Gigabit, tarjetas wireless 802.11a/b/g/n y modems 3G13© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permission
MikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
(H d )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 14/345
• SMP (*)•
Symmetric MultiProcessing• Es una arquitectura de Software y hardware donde dos o más
procesadores idénticos son conectados a una simple memoriacompartida, teniendo acceso a todos los dispositivos I/O (entrada ysalida), y que son controlados por una simple instancia del OS(Sistema Operativo), en el cual todos los procesadores son tratadosen forma igualitaria, sin que ninguno sea reservado para propósitosespeciales.
• En el caso de los procesadores multi-core (multi-núcleo), la
arquitectura SMP se aplica a los núcleos, tratándolos comoprocesadores separados.
14© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? – (Hardware )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 15/345
Qué es RouterBOARD ?• Es el hardware creado por MikroTik• Desde pequeños ruteadores tipo “home” a
concentradores de acceso carrier-class
15© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 16/345
Plataformas
16© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Arquitectura Series
mipsbe RB400, RB700, RB900, RB2011, SXT, OmniTik, Groove, METAL
ppc RB300, RB600, RB800, RB1000
x86 PC / x86, RB230mipsle RB100, RB500, RB Crossroads
tile CCR
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 17/345
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 18/345
Acceso por Puerto Serial
18© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 19/345
19© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Acceso por Puerto Serial (Bootloader )What do you want to configure?
d - boot delayk - boot keys - serial consolen - silent booto - boot deviceu - cpu modef - cpu frequencyr - reset booter configuratione - format nandg - upgrade firmwarei - board infop - boot protocolb - booter optionst - call debug codel - erase licensex - exit setup
your choice:
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 20/345
20© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Acceso por Puerto Serial (CLI)
System/Serial Console
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 21/345
/system console - /system serial-terminal• Herramientas para comunicarse con otros sistemas que están interconectados
vía puerto serial.• Terminal Serial – monitorear y configurar muchos dispositivos:
• Modems• Dispositivos de red (incluyendo routers MikroTik)• Cualquier dispositivo que se pueda conectar a un puerto serial
(asíncrono)• Consola Serial – configurar facilidades de acceso directo (monitor/teclado y
puerto serial) que son mayormente usados para configuraciones derecuperación
• Si no se desea usar un puerto serial para acceder a otro dispositivo o paraconexión de datos a través de un modem, se puede entonces configurarlo
como una consola serial.• Un puerto serial libre puede ser usado para acceder a otras consolas seriales
de otros routers (u otros equipos como switches) desde un router MikroTik
21© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
System/Serial Console
System/Serial Console
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 22/345
• Para conectar dos hosts (ej: dos PCs o dos routers; NO modems) se necesitaun cable null-modem
•
Se necesita un programa de emulación de terminal (ej: HyperTerminal ominicom) para acceder a la consola serial desde otro computador• Escenarios típicos:
• En sitios donde una instalación MikroTik wireless está junto a un equipo(switches y routers Cisco) que no pueden ser manejados por Telnet através de una red IP
• Monitorear equipos de reportes de clima a través de un puerto serial• Conexión a un modem microonda de alta velocidad que necesita ser
monitoreado y administrado por una conexión serial• La funcionalidad /system serial-terminal se pueden monitorear y
controlar hasta 132 dispositivos (y tal vez, incluso más)• http://wiki.mikrotik.com/wiki/Manual:System/Serial_Console
22© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
System/Serial Console
System Console Special Login
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 23/345
• Special Login – puede ser usado para acceder a otro dispositivo (ej: un switch)que está conectado a través de un cable serial abriendo una sesión telnet/sshque lo llevará directamente a ese dispositivo sin tener que hacer login laprimer RouterOS
• http://wiki.mikrotik.com/wiki/Manual:Special_Login
23© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
System Console – Special Login
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 24/345
Herramientas• Winbox
• Acceso en capa 3• Acceso en capa 2 (MAC Winbox/Telnet)
• Cliente FTP• Filezilla, WSftp …
• Telnet, SSH• Acceso vía red•
Acceso vía puerto serial• NetInstall (MikroTik)
24© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? (Configuración )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 25/345
• RouterOS soporta varios métodos deconfiguración:
• Acceso local con teclado y monitor• Consola serial con una aplicación de terminal•
Acceso Telnet y SSH sobre redes• Herramienta de configuración GUI llamada Winbox• Interfaz de configuración sencilla basada en Web• Interfaz de programación API para construir una
aplicación de control propietariahttp://wiki.mikrotik.com/wiki/API
25© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? – (Configuración )
Qué es RouterOS? (Configuración )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 26/345
• En caso de que no se pueda tener acceso local, o de que
haya un problema con el acceso a nivel de comunicación IP(capa 3), el RouterOS también soporta conexión a nivel deMAC (capa 2), con las herramientas Mac-Telnet y Winbox
• RouterOS posee una poderosa y fácil de aprender interface
de configuración por línea de comando (CLI: Command LineInterface). La CLI además tiene capacidades de scriptingintegrada.
• Winbox GUI sobre IP y MAC• CLI con Telnet, SSH, consola Local y consola Serial• API para programar sus propias herramientas• Interface Web
26© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? – (Configuración )
Qué es RouterOS? (Firewall )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 27/345
• El Firewall implementa filtrado de paquetes y de este modo proveefunciones de seguridad, que son usadas para administrar los datos quefluyen hacia, desde, y a través del router.
• Por medio del NAT (Network Address Translation) se previene el accesono-autorizado a las redes conectadas directamente y al router en símismo. Y también sirve como un filtro para el tráfico de salida.
• RouterOS funciona como un Stateful Firewall , lo cual significa que
desarrolla una inspección del estado de los paquetes, y realiza elseguimiento del estado de las conexiones de red que viajan a través delrouter.
• RouterOS también soporta:• Source y Destination NAT•
NAT Helpers para las aplicaciones populares• UPnP
• El firewall provee marcado interno de conexiones, routing y paquetes.
27© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? – (Firewall )
Qué es RouterOS? – (Firewall )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 28/345
• RouterOS puede filtrar por:• Dirección IP, rango de direcciones, puerto, rango de puertos• Protocolo IP, DSCP y otros parámetros• Soporta Listas de Direcciones estáticas y Dinámicas• Puede hacer match de paquetes por patrón en su contenido,
especificado en Expresiones Regulares, conocido como Layer 7matching
• El Firewall de RouterOS también soporta IPv6
28© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? – (Firewall )
Qué es RouterOS? – (Routing )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 29/345
• RouterOS soporta varios protocolos de ruteo:• Para IPv4 soporta RIP v1 y v2, OSPF v2, BGP v4• Para IPv6 soporta RIPng, OSPF v3 y BGP
• RouterOS tambien soporta• VRF (Virtual Routing Forwarding)• Ruteo basado en Políticas• Ruteo basado en Interface• Ruteo ECMP
• Se puede usar el Filtro del Firewall para marcar conexiones específicas conMarcas de Ruteo (Routing Marks), y hacer que el tráfico marcado use undiferente ISP
• Con el soporte MPLS se introdujo el VRF, que es una tecnología que permiteque múltiples instancias de una tabla de ruteo co-existan dentro del mismorouter al mismo tiempo. Puesto que las instancias de ruteo sonindependientes, las mismas direcciones IP pueden ser usadas sin conflictounas con otras. VRF también incrementa la seguridad de la red.
29© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? (Routing )
Qué es RouterOS? – (Forwarding )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 30/345
• RouterOS soporta el reenvío (forwarding) en Capa 2, incluyendo Bridging,Mesh y WDS.
• WDS permite crear cobertura de wireless usando múltiples APs. Permiteque los paquetes pasen de un AP a otro, como si los APs fuesen puertos enun switch Ethernet. Para optimizar el desempeño del WDS redes de granescala MikroTik diseñó una interface especial de forwarding en capa 2llamado Mesh.
•
(R)STP elimina la posibilidad de la que la misma dirección MAC sea vista enmúltiples puertos bridge, deshabilitando los puertos secundarios hacia esadirección MAC. Esto ayuda a evitar los lazos (loops) y mejora laconfiabilidad de la red. Una alternativa que ofrece MikroTik al RSTP es elHWMP+
•
HWMP+ es protocolo de ruteo específico en capa 2 de MikroTik, elaboradopara redes Mesh. El protocolo HWMP+ es una mejora del Hybrid WirelessMesh Protocol (HWMP) del estándar IEEE 802.11s
30© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? (Forwarding )
Qué es RouterOS? – (MPLS)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 31/345
• MPLS: MultiProtocol Label Switching . Puede ser usado para reemplazar elruteo IP. La decisión de reenvío (forwarding) de paquetes no está basadoen los campos de la cabecera IP y en la tabla de ruteo, sino en etiquetas(lables) que se agregan al paquete. Esto mejora la velocidad del proceso dereenvío porque el next hop lookup (búsqueda del siguiente salto) se vuelvemuy simple comparado con el routing lookup.
• El principal beneficio de MPLS es la eficiencia en el proceso de forwarding.• MPLS permite de una manera fácil crear “enlaces virtuales” (virtual links)
entre los nodos de la red, independientemente del protocolo de la dataencapsulada.
• Es un mecanismo altamente escalable para llevar datos,independientemente del protocolo. Las decisiones del reenvío de paquetesse hacen únicamente en el contenido de la etiqueta, sin la necesidad deexaminar el paquete. Esto permite crear circuitos end-to-end a través decualquier tipo de medio de transporte, usando cualquier protocolo.
31© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? (MPLS)
Qué es Route
rOS? – (MPLS)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 32/345
• Algunas de las características de MPLS:• Etiquetas Estáticas de vinculación (Static label bindings)
para IPv4• Protocolo de Distribución de Etiquetas (Label
Distribution) para IPv4• Túneles de Ingeniería de Tráfico RSVP• VPLS MP-BGP basado en autodiscovery y señalización• MP-BGP basado en MPLS IP VPN
32© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es Route rOS? (MPLS)
Qué es Route
rOS? – (VPN)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 33/345
• RouterOS soporta varios métodos VPN y protocolos de túnelespara establecer conexiones seguras sobre redes abiertas o sobreinternet, o para conectar sitios remotos con enlacesencriptados:
• IPSec – Modo de transporte y túnel, certificado o PSK,protocolos de seguridad AH y ESP
• Point To Point Tunneling: OpenVPN, PPTP, PPPoE, L2TP• Características avanzadas PPP: MLPPP, BCP• Túneles simples: IPIP, EoIP• Soporte para túnel 6to4: IPv6 sobre redes IPv4• VLAN – Soporte IEEE 802.1q Virtual LAN, Soporte Q-in-Q•
MPLS basado en VPNs
33© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es Route rOS? (VPN)
Qué es Route
rOS? – (VPN)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 34/345
• Se puede interconectar de forma segura redes bancarias, usar los recursosde la red de trabajo mientras se viaja, conectarse a la red local doméstica,
o incrementar la seguridad del enlace wireless principal.• Se pueden interconectar 2 oficinas remotas, y pueden usar los recursos
una de otra, como si los computadores estuvieran en el mismo lugar, todoesto de forma segura y encriptada.
• RouterOS también provee varias funciones propietarias de MikroTik, porejemplo EoIP que es un túnel Ethernet entre 2 routers a través de unaconexión IP. La interface EoIP aparece como una interface Ethernet.Cuando se habilita la función bridge, todo el tráfico Ethernet será“bridged ” como si hubiera una interface Ethernet física y un cableEthernet entre los 2 routers. Este protocolo permite que se puedan
realizar múltiples esquemas de red, como por ejemplo la posibilidad deponer en bridge redes LAN sobre el Internet.
34© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es Route rOS? (VPN)
Qué es RouterOS? – (Wireless )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 35/345
• RouterOS soporta varias tecnologías Wireless. Características:• Cliente Wireless y Access Point IEEE 802.11a/b/g/n• Protocolos propietarios Nstreme, Nstreme2 y Nstreme Dual• Client polling• RTS/CTS• Wireless Distribution System (WDS)• Virtual AP• Encripción WEP, WPA, WPA2• Lista de Control de Acceso• Roaming de clientes Wireless• WMM• Protocolo MESH Wireless HWMP+• Protocolo de ruteo Wireless MME
• Nstreme ha permitido establecer el record de longitud de enlace WiFi noaplificado en Italiahttp://en.wikipedia.org/wiki/Long-range_Wi-Fi
35© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Qué es RouterOS? (Wireless )
Qué es RouterOS? – (HotSpot )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 36/345
• El Gateway HotSpot de MikroTik provee el acceso a redes públicaspara clientes inalámbricos o cableados a través de una pantalla de
validación (login/password) cuando abren su browser. Luego devalidado el user/password el usuario tendrá acceso a Internet.• Ideal para Hoteles, Escuelas, Aeropuertos, Cafés Internet, o
cualquier otro lugar público donde no se tiene control sobre lacomputadora del usuario. No se necesita ningún software deinstalación o configuración de red ya que el HotSpot direccionarácualquier requerimiento de conexión hacia la página de validación.
• Se puede ejecutar una extensa administración de usuarios haciendodiferentes perfiles, cada uno de los cuales puede permitir diferentes
limitaciones de uptime, subida y descarga, así como tambiénlimitación de la cantidad de tráfico, y mucho más.
36© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Q (HotSpot )
Qué es RouterOS? – (HotSpot )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 37/345
• El HotSpot también soporta autenticación contra servidores RADIUSestándares, y contra el el propio User Manager de MikroTik que
proporcionará una administración centralizada de todos losusuarios en la red.• Acceso Plug-n-Play a la red• Autenticación de los clientes a la red local• User Accounting• Soprote RADIUS para Autenticación y Accounting• Bypass configurable para dispositivos no-interactivos• Walled Garden para las excepciones de browsing• Modos de publicidad (Advertisement) y usuarios de prueba
37© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Q (HotSpot )
Qué es RouterOS? – (Calidad de Servicio )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 38/345
• Control de Ancho de banda es un conjunto de mecanismos quecontrolan la asignación de velocidad de datos, variabilidad del
retardo, entrega oportuna, y la fiabilidad de la entrega.• Quality of Service (QoS) significa que el router puede priorizar y
ajustar el tráfico de red.• Limitar la tasa de datos para ciertas direcciones IP, subredes,
protocolos, puertos y otros parámetros• Limitación de tráfico peer-to-peer• Priorizar el flujo de unos paquetes sobre otros• Usar queue-bursts para una navegación más rápida• Aplicar colas en intervalos de tiempo fijo• Distribuir el tráfico equitativamente entre usuarios, o
dependiendo de la carga del canal.
38© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Q ( )
Qué es RouterOS? – (Calidad de Servicio )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 39/345
• RouterOS soporta el Sistema de QoS HTB (Hierarchical TokenBucket) con soporte de CIR, MIR, burst y prioridad. Provee
encolamiento avanzado, y también una solución sencilla deimplementación QoS con colas Simples.• Se introdujo PCQ para optimizar los sistemas QoS masivos, donde la
mayoría de las colas son exactamente las mismas para diferentessub-streams. Por ejemplo un sub-stream puede ser la bajada osubida de un cliente en particular (IP) o conexión a un server.
• El algoritmo PCQ es muy simple – primero utiliza clasificadores paradistinguir un sub-stream de otro, luego aplica limitación y untamaño de cola FIFO individual en cada sub-stream, entonces
agrupa todos los sub-streams y aplica limitación y un tamaño decola FIFO global.
39© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Q ( )
Qué es RouterOS? – (Web proxy )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 40/345
• Web Proxy: Mejorar la navegación del usuario haciendoalmacenamiento (cache). Características Web Proxy MikroTik:
•
Proxy HTTP• Proxy transparente• Lista de Acceso por origen, destino, URL y método requerido
(firewall HTTP)• Cache de Lista de Acceso para especificar qué objetos serán
almacenados y cuáles no• Lista de Acceso Directa para especificar qué recursos deberían ser
accesados directamente, y cuáles a través de otro proxy server.• Facilidad de bitácora (logging)• Soporte de SOCKS proxy• Soporte de proxy Padre (Parent proxy)• Almacenamiento de cache en dispositivos externos
40© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
( p y )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 41/345
Qué es RouterOS? – (The Dude )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 42/345
• El monitor de red The Dude es una aplicación de MikroTik paraadministrar la red. Escanea automáticamente todos los dispositivos
dentro de las subredes especificadas, dibuja y diseña un mapa delas redes, monitorea servicios de los dispositivos y alerta en caso deque algún servicio tenga problemas.
• No solo monitorea dispositivos RouterOS, sino que puedemonitorear cualquier dispositivo que es accesible por Ping o que
provee información SNMP• Se pueden visualizar gráficos de tráfico y disponibilidad, informes de
interrupciones, e incluso usar The Dude como un Syslog Server• Puede también administrar las configuraciones de dispositivos
RouterOS, y actualizar los upgrades de software y configuracionesen masa
• The Dude es gratis
42© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
( )
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 43/345
Winbox
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 44/345
Winbox• Es la aplicación para configurar el RouterOS• Winbox es un pequeño utilitario que permite la administración del MikroTik
RouterOS usando una Interfaz gráfica de usuario (GUI) simple y rápida.• Es un programa binario nativo en Win32 , pero puede ser ejecutado en
Linux y Mac OSX usando Wine.•
Todas las funciones de la interface Winbox son muy similares a lasfunciones de Consola• Algunas configuraciones avanzadas y críticas no se pueden realizar desde
Winbox, com por ejemplo el cambio de las MAC Address en una interfaz.• El Winbox puede ser descargado desde la zona de descargas de MikroTik (
http://www.mikrotik.com/download ) o desde el acceso via browser alrouter (Ej: http://192.168.88.1 )
44© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Descargar Winbox
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 45/345
g
45© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Descargar Winbox
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 46/345
esca ga W bo
46© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Conectándose con Winbox
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 47/345
Conectándose con Winbox
Click en el botón [...] para ver el router
47© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Comunicación
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 48/345
Comunicación
• El proceso de comunicación está dividido en7 capas
• La capa más baja es la Física, y la capa másalta es la de Aplicación
48© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 49/345
49© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 50/345
50© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 51/345
51© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
AplicaciónEspecifica los métodos para llevar a cabo una tarea iniciada por el usuario.Los protocolos de la capa de aplicación tienden a ser concebidos y ejecutados por los desarrolladores de aplicaciones.
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 52/345
Ejemplo: FTP, Skype, etc.
PresentaciónEspecifica los métodos para la expresión de los formatos de datos y normas de traducción para aplicaciones. Laencriptación se asocia algunas veces con esta capa. Ejemplo: Conversión de EBCDIC a ASCII
SesiónEspecifica métodos para múltiples conexiones que constituyen una sesión de comunicación. Esto puede incluir cerrarconexiones, reiniciar conexiones y puntos de control. Ejemplo: ISO X.25
TransporteEspecifica los métodos para las conexiones o asociaciones entre múltiples programas que se ejecutan en el mismocomputador. Esta capa puede implementar entregas seguras en caso de que no se apliquen en otros lados. Ejemplo:Internet TCP, ISO, TP4)
Network (o Internetwork)Especifica los métodos para comunicar en un esquema de múltiples saltos a través de diferentes potenciales tipos deredes de enlace. Para redes de paquetes, describe un formato de paquete abstracto y su estructura de direccionamientoestándar. Ejemplo: IP datagram, X.25 PLP, ISO CLNP
EnalceEspecifica los métodos para comuncarse a través de un simple enlace, incluyendo protocolos de “control de acceso almedio ” cuando múltiples sistemas comparten el mismo medio. La detección de error se incluye comunmente en estacapa, junto con formatos de dirección de la capa de enlace. Ejemplo: Ethernet, Wi-Fi, ISO 13239/HDLC.
FísicaEspecifica los conectores, tasas de datos, y la forma en que los bits son codificados en algún medio. También describedetección y corrección de bajo nivel, más asignaciones de frecuencia. Ejemplo: V.92, Ethernet 1000BASE-T, SONET/SDH
52© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
MAC address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 53/345
53© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
• Es un identificador de 48 bits (6 bloques hexadecimales) que se asigna deforma única a una tarjeta o dispositivo de red.
• Conocida también como dirección física• Los últimos 24 bits son determinados y configurados por la IEEE, y los
primeros 24 bits por el fabricante utilizando el Identificador UnicoOrganizacional (OUI: Organizationally Unique Identifier)
• El OUI es un número de 24 bits comprado a la Autoridad de Registro de la
IEEE, que identifica a cada empresa u organización• Ejemplo: 00:0C:42:20:97:68
IP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 54/345
• Es la dirección lógica del dispositivo de red• Se utiliza para la comunicación entre redes• Ejemplo: 159.148.60.20
54© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permissionMikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of company Mikrotīkls SIA .
Subredes (subnets)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 55/345
( )• Rango de direcciones IP lógicas que divide la red en
segmentos• Ejemplo: 255.255.255.0 o /24• La dirección de red es la primera dirección IP de la
subred• La dirección de broadcast es la última dirección IP de lasubred
• Estas son reservadas y no pueden ser utilizadas
©Academy Xperts / MikroTik Xperts 2013 55
Subredes (subnets)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 56/345
200.3.25.0 /27
©Academy Xperts / MikroTik Xperts 2013 56
CIDR Subnet Mask HostsDisponibles
CIDR Subnet Mask HostsDisponibles
/32 255 255 255 255 /23 255 255 254 0 512 – 2
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 57/345
©Academy Xperts / MikroTik Xperts 2013 57
/32 255.255.255.255 /23 255.255.254.0 512 – 2/30 255.255.255.252 4 – 2 /22 255.255.252.0 1024 – 2/29 255.255.255.248 8 – 2 /21 255.255.248.0 2048 – 2/28 255.255.255.240 16 – 2 /20 255.255.240.0 4096 – 2/27 255.255.255.224 32 – 2 /19 255.255.224.0 8192 – 2/26 255.255.255.192 64 – 2 /18 255.255.192.0 16384 – 2/25 255.255.255.128 128 – 2 /17 255.255.128.0 32768 – 2/24 255.255.255.0 256 – 2 /16 255.255.0.0 65536 – 2
El prefijo de ruteo está expresado en notación CIDR . Está escrito como la primera dirección de unared, seguido por un caracter slash (/), terminando con la longitud de bit del prefijo. Por ejemplo,192.168.1.0/24 es el prefijo de la red IPv4 que inicia en la dirección indicada, teniendo 24 bitsasignados para el prefijo de red, y los 8 bits remanentes reservados para direccionamiento de host.
La notación CIDR es una especificación compacta de una dirección IP y está asociada con un prefijode ruteo. Classless Inter-Domain Routing (CIDR)es una asignación de dirección IP y una
metodología de agregación de ruta.
CIDR es un método de asignación de dirección IP y de paquetes de ruteo IP.
Ejemplo de Selección de dirección IP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 58/345
• Los clientes usan subredes de diferentes máscaras /25 y /26• A tiene la dirección IP 192.168.0.200/ 26 • B usa el subnet mask (máscara de red) / 25
Las direcciones disponibles son:
192.168.0.129 - 192.168.0.254• B no debería usar 192.168.0.129 - 192.168.0.192• B debería usar las siguientes direcciones IP para que se
puedan ver la estación A y las estaciones de B
192.168.0.193 - 192.168.0.254/25
©Academy Xperts / MikroTik Xperts 2013 58
L b t i d C ió
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 59/345
Laboratorio de Conexión
•
Hacer Click en la Mac-Address en Winbox• Default username “admin” sin clave
©Academy Xperts / MikroTik Xperts 2013 59
Diagrama de Clase
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 60/345
g
©Academy Xperts / MikroTik Xperts 2013 60
internet
ether 10.1.1.2 /3010.1.1.6 /30
10.1.1.10 /30……
GatewayDNS
ether110.1.1.1 /30
ether2192.168.N.254 /24
192.168.N.1 /24(N = 1)
ether2192.168.N.254 /24
192.168.N.1 /24(N = 2)
ether2192.168.N.254 /24
192.168.N.1 /24(N = 3)
ether110.1.1.5 /30
ether110.1.1.6 /30
Laptop - Router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 61/345
1. Deshabilitar cualquier interface
(wireless) en su laptop
2. Configurar la dirección IP
192.168. N.1
3. Configurar 255.255.255.0 comola Subnet Mask
4. Configurar 192.168. N.254 como
el Default Gateway y como DNSServer primario
©Academy Xperts / MikroTik Xperts 2013 61
Laptop - Router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 62/345
1. Conectarse al router
con MAC-Winbox
©Academy Xperts / MikroTik Xperts 2013 62
2. Agregar la dirección IP192.168. N.254/24 a lainterface ether2
Laptop - Router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 63/345
• Cierre el Winbox y conéctese de nuevo
usando la dirección IP
• El acceso por MAC-address deberíarealizarse solo cuando no hay acceso pordirección IP
©Academy Xperts / MikroTik Xperts 2013 63
Router - Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 64/345
• La puerta de acceso ( gateway ) a Internet desu clase se puede acceder a través delwireless. Es un AP (Access Point)
• Para conectarse usted tiene que configurarla interface wireless del router como station
©Academy Xperts / MikroTik Xperts 2013 64
Router - Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 65/345
Chequear laconectividad aInternet usando
Traceroute
©Academy Xperts / MikroTik Xperts 2013 65
Laptop - Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 66/345
Su router puede ser también un DNS Server para lared local (laptop)
©Academy Xperts / MikroTik Xperts 2013 66
Laptop - Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 67/345
• Debe configurar su laptop para que use a su router
como DNS Server• Ingrese la IP del router (192.168. N.254) como el DNS
Server• La Laptop puede acceder al router y el router puede
acceder al Internet. Se requiere un paso adicional.• Debe crear una regla de enmascaramiento
(action=masquerade ) para ocultar su red privadadetrás del router.
©Academy Xperts / MikroTik Xperts 2013 67
Private and Public space
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 68/345
• Masquerade is used for Public network access, whereprivate addresses are present
• Private networks include• 10.0.0.0 - 10.255.255.255 (10.0.0.0 /8)• 172.16.0.0 - 172.31.255.255 (172.16.0.0 /12)• 192.168.0.0 - 192.168.255.255 (192.168.0.0 /16)
©Academy Xperts / MikroTik Xperts 2013 68
Laptop - Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 69/345
©Academy Xperts / MikroTik Xperts 2013 69
Check Connectivity
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 70/345
Check Connectivity
Ping www.mikrotik.com from your laptop
©Academy Xperts / MikroTik Xperts 2013 70
What Can Be Wrong
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 71/345
What Can Be Wrong• Router cannot ping further than AP• Router cannot resolve names• Computer cannot ping further than router• Computer cannot resolve names• Is masquerade rule working• Does the laptop use the router as default
gateway and DNS©Academy Xperts / MikroTik Xperts 2013 71
Network Diagram
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 72/345
Network Diagram
Your RouterYour LaptopClass AP
192.168.X.1 192.168.X.254DHCP-Client
©Academy Xperts / MikroTik Xperts 2013 72
User Management• A t th t b t ll d
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 73/345
Access to the router can be controlled•
You can create different types of users
©Academy Xperts / MikroTik Xperts 2013 73
User Management Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 74/345
User Management Lab
• Add new router user with full access•
Make sure you remember user name• Make admin user as read-only• Login with your new user
©Academy Xperts / MikroTik Xperts 2013 74
Upgrading Router Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 75/345
Upgrading Router Lab
• Download packages from ftp://192.168.200.254• Upload them to router with Winbox• Reboot the router• Newest packages are always available on
www.mikrotik.com
©Academy Xperts / MikroTik Xperts 2013 75
Upgrading Router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 76/345
• Use combinedRouterOS
package• Drag it to the
Files window
©Academy Xperts / MikroTik Xperts 2013 76
Package Management
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 77/345
Package Management
RouterOSfunctions are
enabled bypackages
©Academy Xperts / MikroTik Xperts 2013 77
Package Information
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 78/345
©Academy Xperts / MikroTik Xperts 2013 78
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 79/345
Router Identity
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 80/345
y
Option to set name for each router
©Academy Xperts / MikroTik Xperts 2013 80
Router Identity
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 81/345
yIdentity information is shown in different places
©Academy Xperts / MikroTik Xperts 2013 81
Router Identity Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 82/345
y
Set your number + your name as router identity
©Academy Xperts / MikroTik Xperts 2013 82
NTP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 83/345
• Network Time Protocol, to synchronize time• NTP Client and NTP Server support in
RouterOS
©Academy Xperts / MikroTik Xperts 2013 83
Why NTP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 84/345
y
• To get correct clock on router•
For routers without internal memory to saveclock information• For all RouterBOARDs
©Academy Xperts / MikroTik Xperts 2013 84
NTP Client
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 85/345
NTP package is not required
©Academy Xperts / MikroTik Xperts 2013 85
Configuration Backup
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 86/345
• You can backup and restore configuration inthe Files menu of Winbox
• Backup file is not editable
©Academy Xperts / MikroTik Xperts 2013 86
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 87/345
Backup Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 88/345
• Create Backup and Export files
• Download them to your laptop• Open export file with text editor
©Academy Xperts / MikroTik Xperts 2013 88
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 89/345
Netinstall
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 90/345
1.List of routers
2.Net Booting
3.Keep oldconfiguration
4.Packages
5. Install
©Academy Xperts / MikroTik Xperts 2013 90
Optional Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 91/345
• Download Netinstall from ftp://192.168.100.254• Run Netinstall
• Enable Net booting, set address 192.168.x.13• Use null modem cable and Putty to connect• Set router to boot from Ethernet
©Academy Xperts / MikroTik Xperts 2013 91
RouterOS License
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 92/345
• All RouterBOARDs shipped with license• Several levels available, no upgrades• Can be viewed in system license menu• License for PC can be purchased from
mikrotik.com or from distributors
©Academy Xperts / MikroTik Xperts 2013 92
License
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 93/345
©Academy Xperts / MikroTik Xperts 2013 93
Obtain License
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 94/345
Login to
your account
©Academy Xperts / MikroTik Xperts 2013 94
Update License for 802.11N
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 95/345
• 8-symbol software-ID system is introduced• Update key on existing routers to get fullfeatures support ( 802.11N , etc.)
©Academy Xperts / MikroTik Xperts 2013 95
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 96/345
Summary
©Academy Xperts / MikroTik Xperts 2013 96
Useful Links
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 97/345
• www.mikrotik.com - manage licenses,documentation
• forum.mikrotik.com - share experience withother users
• wiki.mikrotik.com - tons of examples
©Academy Xperts / MikroTik Xperts 2013 97
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 98/345
Firewall
©Academy Xperts / MikroTik Xperts 2013 98
Firewall
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 99/345
• Protects your router and clients fromunauthorized access
• This can be done by creating rules in FirewallFilter and NAT facilities
©Academy Xperts / MikroTik Xperts 2013 99
Firewall Filter
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 100/345
• Consists of user defined rules that work onthe IF-Then principle
• These rules are ordered in Chains• There are predefined Chains, and User
created Chains
©Academy Xperts / MikroTik Xperts 2013 100
Filter Chains
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 101/345
• Rules can be placed in three default chains• input ( to router)• output ( from router)• forward ( trough the router)
©Academy Xperts / MikroTik Xperts 2013 101
Firewall Chains
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 102/345
InputWinbox
ForwardWWW E-Mail
OutputPing from Router
©Academy Xperts / MikroTik Xperts 2013 102
Firewall Chains
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 103/345
©Academy Xperts / MikroTik Xperts 2013 103
Input
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 104/345
• Chain contains filter rules that protect the
router itself• Let’s block everyone except your laptop
©Academy Xperts / MikroTik Xperts 2013 104
Input
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 105/345
Add an accept rule for yourLaptop IPaddress
©Academy Xperts / MikroTik Xperts 2013 105
Input
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 106/345
Add a drop rule ininput chain todrop everyoneelse
©Academy Xperts / MikroTik Xperts 2013 106
Input Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 107/345
• Change your laptop IP address, 192.168.x. y• Try to connect. The firewall is working• You can still connect with MAC-address,
Firewall Filter is only for IP
©Academy Xperts / MikroTik Xperts 2013 107
Input
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 108/345
• Access to your router is blocked• Internet is not working• Because we are blocking DNS requests as well• Change configuration to make Internet working
©Academy Xperts / MikroTik Xperts 2013 108
Input• Y di bl
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 109/345
You can disableMAC access inthe MAC Server menu
• Change theLaptop IPaddress back to192.168.X. 1,and connectwith IP ©Academy Xperts / MikroTik Xperts 2013 109
Address-List
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 110/345
• Address-list allows you to filter group of theaddresses with one rule
•
Automatically add addresses by address-listand then block
©Academy Xperts / MikroTik Xperts 2013 110
Address-List• Create different lists
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 111/345
•
Subnets, separates ranges, one hostaddresses are supported
©Academy Xperts / MikroTik Xperts 2013 111
Address-List
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 112/345
• Add specific hostto address-list
• Specify timeoutfor temporaryservice
©Academy Xperts / MikroTik Xperts 2013 112
Address-List in Firewall
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 113/345
• Ability to blockby source anddestinationaddresses
©Academy Xperts / MikroTik Xperts 2013 113
Address-List Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 114/345
• Create address-list with allowed IP addresses• Add accept rule for the allowed addresses
©Academy Xperts / MikroTik Xperts 2013 114
Forward
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 115/345
• Chain contains rules that control packets
going trough the router• Control traffic to and from the clients
©Academy Xperts / MikroTik Xperts 2013 115
Forward
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 116/345
• Create a rulethat will blockTCP port 80 (web
browsing)• Must select
protocol to blockports
©Academy Xperts / MikroTik Xperts 2013 116
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 117/345
List of well-known ports
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 118/345
©Academy Xperts / MikroTik Xperts 2013 118
Forward
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 119/345
Create a rule that will
block client’s p2ptraffic
©Academy Xperts / MikroTik Xperts 2013 119
Firewall Log• Let’s log client
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 120/345
pings to the router• Log rule should be
added before otheraction
©Academy Xperts / MikroTik Xperts 2013 120
Firewall Log
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 121/345
©Academy Xperts / MikroTik Xperts 2013 121
Firewall chains
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 122/345
• Except of the built-in chains (input, forward,output), custom chains can be created
• Make firewall structure more simple• Decrease load of the router
©Academy Xperts / MikroTik Xperts 2013 122
Firewall chains in Action•
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 123/345
•
Sequence ofthe firewallcustom chains
•
Customchains can befor viruses,TCP, UDP
protocols, etc.©Academy Xperts / MikroTik Xperts 2013 123
Firewall chain Lab
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 124/345
• Download viruses.rsc from router (access byFTP)
•
Export the configuration by importcommand
• Check the firewall
©Academy Xperts / MikroTik Xperts 2013 124
Connections
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 125/345
©Academy Xperts / MikroTik Xperts 2013 125
Connection State
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 126/345
• Advise, drop invalid connections• Firewall should proceed only new packets, it
is recommended to exclude other types ofstates
• Filter rules have the “connection state”matcher for this purpose
©Academy Xperts / MikroTik Xperts 2013 126
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 127/345
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 128/345
Summary
©Academy Xperts / MikroTik Xperts 2013 128
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 129/345
Network Address
Translation
©Academy Xperts / MikroTik Xperts 2013 129
NAT
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 130/345
• Router is able to change Source orDestination address of packets flowing
trough it• This process is called src-nat or dst-nat
©Academy Xperts / MikroTik Xperts 2013 130
SRC-NAT
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 131/345
SRC-Address NewSRC-Address
Your Laptop Remote Server
©Academy Xperts / MikroTik Xperts 2013 131
DST-NAT
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 132/345
DST-AddressNew DST-Address
Private NetworkServer
Public Host
©Academy Xperts / MikroTik Xperts 2013 132
NAT Chains
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 133/345
• To achieve these scenarios you have to orderyour NAT rules in appropriate chains: dstnat
or srcnat• NAT rules work on IF-THEN principle
©Academy Xperts / MikroTik Xperts 2013 133
DST-NAT
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 134/345
• DST-NAT changes packet’s destinationaddress and port
• It can be used to direct internet users to aserver in your private network
©Academy Xperts / MikroTik Xperts 2013 134
DST-NAT Example
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 135/345
DST-Address207.141.27.45:80
New DST-Address192.168.1.1:80
Web Server192.168.1.1
Some Computer
©Academy Xperts / MikroTik Xperts 2013 135
DST-NAT ExampleCreate a rule to forward traffic to WEB server in
private network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 136/345
©Academy Xperts / MikroTik Xperts 2013 136
Redirect
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 137/345
• Special type of DST-NAT• This action redirects packets to the router
itself• It can be used for proxying services (DNS,
HTTP)
©Academy Xperts / MikroTik Xperts 2013 137
Redirect example
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 138/345
DST-AddressConfigured_DNS_Server:53
New DST-AddressRouter:53
DNS Cache
©Academy Xperts / MikroTik Xperts 2013 138
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 139/345
SRC-NAT
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 140/345
• SRC-NAT changes packet’s source address • You can use it to connect private network to
the Internet through public IP address• Masquerade is one type of SRC-NAT
©Academy Xperts / MikroTik Xperts 2013 140
Masquerade
S Add S Add
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 141/345
Src Address192.168.X.1
Src Addressrouter address
192.168.X.1 Public Server
©Academy Xperts / MikroTik Xperts 2013 141
SRC-NAT Limitations
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 142/345
• Connecting to internal servers from outsideis not possible (DST-NAT needed)
• Some protocols require NAT helpers to workcorrectly
©Academy Xperts / MikroTik Xperts 2013 142
NAT Helpers
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 143/345
©Academy Xperts / MikroTik Xperts 2013 143
Firewall Tips
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 144/345
• Add comments to your rules• Use Connection Tracking or Torch
©Academy Xperts / MikroTik Xperts 2013 144
Connection Tracking
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 145/345
• Connection tracking manages informationabout all active connections.
• It should be enabled for Filter and NAT
©Academy Xperts / MikroTik Xperts 2013 145
Connection Tracking
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 146/345
©Academy Xperts / MikroTik Xperts 2013 146
Torch
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 147/345
Detailed actual traffic report for interface©Academy Xperts / MikroTik Xperts 2013 147
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 148/345
NAT Actions
• Accept
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 149/345
Accept• DST-NAT/SRC-NAT•
Redirect• Masquerade• Netmap
©Academy Xperts / MikroTik Xperts 2013 149
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 150/345
Summary
©Academy Xperts / MikroTik Xperts 2013 150
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 151/345
Bandwidth Limit
©Academy Xperts / MikroTik Xperts 2013 151
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 152/345
Simple Queue
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 153/345
• You must use Target-Address for SimpleQueue
• Rule order is important for queue rules
©Academy Xperts / MikroTik Xperts 2013 153
Simple Queue•
Let’st
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 154/345
Let screatelimitationfor your
laptop• 64k
Upload,
128kDownload
Client’s
address
Limits
to configure©Academy Xperts / MikroTik Xperts 2013 154
Simple Queue
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 155/345
• Check your limits• Torch is showing bandwidth rate
©Academy Xperts / MikroTik Xperts 2013 155
Using Torch
• Select local
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 156/345
Select localnetworkinterface
•
See actualbandwidth Set Interface
Set LaptopAddress
Check the
Results©Academy Xperts / MikroTik Xperts 2013 156
Specific Server Limit•
Let’s create
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 157/345
Let s createbandwidthlimit toMikroTik.com
• DST-address isused for this
• Rules order isimportant
©Academy Xperts / MikroTik Xperts 2013 157
Specific Server Limit•
Ping
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 158/345
Pingwww.mikrotik.com
• Put MikroTik
address to DST-address• MikroTik address
can be used asTarget-address too
MikroTik.comAddress
©Academy Xperts / MikroTik Xperts 2013 158
Specific Server Limit
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 159/345
• DST-address is useful to setunlimited access to the localnetwork resources
• Target-address and DST-addressescan be vice versa
©Academy Xperts / MikroTik Xperts 2013 159
Bandwidth Test Utility•
Bandwidth test can be used to monitor
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 160/345
throughput to remote device• Bandwidth test works between two MikroTik
routers• Bandwidth test utility available for Windows• Bandwidth test is available on MikroTik.com
©Academy Xperts / MikroTik Xperts 2013 160
Bandwidth Test on Router
• Set Test To as testing address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 161/345
Set Test To as testing address• Select protocol•
TCP supports multipleconnections• Authentication might be required
©Academy Xperts / MikroTik Xperts 2013 161
Bandwidth Server
• Set Test To as testing address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 162/345
Set Test To as testing address• Select protocol•
TCP supports multipleconnections• Authentication might be required
©Academy Xperts / MikroTik Xperts 2013 162
Bandwidth Test
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 163/345
• Server should be enabled
• It is advised to use enabledAuthenticate
©Academy Xperts / MikroTik Xperts 2013 163
Traffic Priority• Let’s configure
higher priority for
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 164/345
g p yqueues
• Priority 1 ishigher than 8
• There should beat least two
priority
Select QueuePriority is inAdvanced Tab
Set Higher Priority
©Academy Xperts / MikroTik Xperts 2013 164
Simple Queue Monitor
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 165/345
• It is possible to get graph for each queuesimple rule
• Graphs show how much traffic is passedtrough queue
©Academy Xperts / MikroTik Xperts 2013 165
Simple Queue Monitor
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 166/345
Let’s enable graphing for
Queues
©Academy Xperts / MikroTik Xperts 2013 166
Simple Queue Monitor• Graphs are
available onWWW
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 167/345
WWW• To view graphs
http://router _IP• You can give it
to yourcustomer
©Academy Xperts / MikroTik Xperts 2013 167
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 168/345
Advanced Queing
©Academy Xperts / MikroTik Xperts 2013 168
Mangle•
Mangle is used to mark packets•
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 169/345
• Separate different type of traffic• Marks are active within the router• Used for queue to set different limitation• Mangle do not change packet structure
(except DSCP, TTL specific actions)
©Academy Xperts / MikroTik Xperts 2013 169
Mangle Actions
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 170/345
©Academy Xperts / MikroTik Xperts 2013 170
Mangle Actions• Mark-connection uses connection tracking
• Information about new connection added to
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 171/345
connection tracking table• Mark-packet works with packet directly• Router follows each packet to apply mark-
packet
©Academy Xperts / MikroTik Xperts 2013 171
Optimal Mangle• Queues have packet-mark option only
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 172/345
©Academy Xperts / MikroTik Xperts 2013 172
Optimal Mangle
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 173/345
• Mark new connection with mark-connection• Add mark-packet for every mark-connection
©Academy Xperts / MikroTik Xperts 2013 173
Mangle Example
• Imagine you have second client on the router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 174/345
Imagine you have second client on the routernetwork with 192.168.X.55 IP address
•
Let’s create two different marks ( Gold , Silver ),one for your computer and second for192.168.X.55
©Academy Xperts / MikroTik Xperts 2013 174
Mark Connection
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 175/345
©Academy Xperts / MikroTik Xperts 2013 175
Mark Packet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 176/345
©Academy Xperts / MikroTik Xperts 2013 176
Mangle Example
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 177/345
• Add Marks for second user too• There should be 4 mangle rules for two groups
©Academy Xperts / MikroTik Xperts 2013 177
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 178/345
PCQ• PCQ is advanced Queue type• PCQ uses classifier to divide traffic (from client
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 179/345
PCQ uses classifier to divide traffic (from clientpoint of view; src-address is upload, dst-address is download)
©Academy Xperts / MikroTik Xperts 2013 179
PCQ, one limit to all• PCQ allows to set one limit to all users with
one queue
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 180/345
©Academy Xperts / MikroTik Xperts 2013 180
One limit to all•
Multiple queue rules are changed by one
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 181/345
©Academy Xperts / MikroTik Xperts 2013 181
PCQ, equalize bandwidth•
Equally share bandwidth between customers
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 182/345
©Academy Xperts / MikroTik Xperts 2013 182
Equalize bandwidth• 1M upload/2M download is shared between
users
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 183/345
©Academy Xperts / MikroTik Xperts 2013 183
PCQ Lab
• Teacher is going to make PCQ lab on the
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 184/345
Teacher is going to make PCQ lab on therouter
• Two PCQ scenarios are going to be used withmangle
©Academy Xperts / MikroTik Xperts 2013 184
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 185/345
Summary
©Academy Xperts / MikroTik Xperts 2013 185
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 186/345
Wireless
©Academy Xperts / MikroTik Xperts 2013 186
What is Wireless
• RouterOS supports various radio modulesthat allow communication over the air
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 187/345
that allow communication over the air(2.4GHz and 5GHz)
•
MikroTik RouterOS provides a completesupport for IEEE 802.11a, 802.11b and802.11g wireless networking standards
©Academy Xperts / MikroTik Xperts 2013 187
Wireless Standards
• IEEE 802.11b - 2.4GHz frequencies, 11Mbps
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 188/345
• IEEE 802.11g - 2.4GHz frequencies, 54Mbps•
IEEE 802.11a - 5GHz frequencies, 54Mbps• IEEE 802.11n - draft, 2.4GHz - 5GHz
©Academy Xperts / MikroTik Xperts 2013 188
802.11 b/g Channels1 2 3 4 5 6 7 8 9 10 11
24002483
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 189/345
• (11) 22 MHz wide channels (US)
• 3 non-overlapping channels• 3 Access Points can occupy same area without
interfering©Academy Xperts / MikroTik Xperts 2013 189
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 190/345
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 191/345
Supported Frequencies
• Depending on your country regulations
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 192/345
wireless card might support•
2.4GHz: 2312 - 2499 MHz• 5GHz: 4920 - 6100 MHz
©Academy Xperts / MikroTik Xperts 2013 192
Apply Country Regulations
Set wireless interface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 193/345
to apply your countryregulations
©Academy Xperts / MikroTik Xperts 2013 193
RADIO Name
• W ill RADIO N f th
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 194/345
We will use RADIO Name for the samepurposes as router identity
• Set RADIO Name as Number+Your Name
©Academy Xperts / MikroTik Xperts 2013 194
Wireless Network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 195/345
©Academy Xperts / MikroTik Xperts 2013 195
Station Configuration• Set Interface
mode=station• Select band
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 196/345
• Set SSID, WirelessNetwork Identity
• Frequency is notimportant for client,use scan-list
©Academy Xperts / MikroTik Xperts 2013 196
Connect List
• Set of rules
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 197/345
used bystation toselectaccess-point
©Academy Xperts / MikroTik Xperts 2013 197
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 198/345
Access Point Configuration• Set Interface
mode=ap-bridge• Select band
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 199/345
Select band• Set SSID, Wireless
Network Identity• Set Frequency
©Academy Xperts / MikroTik Xperts 2013 199
Snooper wireless monitor• Use Snooper to
get total view ofthe wirelessnetworks on used
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 200/345
networks on usedband
• Wirelessinterface isdisconnected at
this moment©Academy Xperts / MikroTik Xperts 2013 200
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 201/345
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 202/345
Default Authentication
• Yes, Access-List rules are checked, client is
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 203/345
Yes, Access List rules are checked, client isable to connect, if there is no deny rule
• No, only Access-List rule are checked
©Academy Xperts / MikroTik Xperts 2013 203
Access-List Lab
• Since you have mode=station configured weare going to make lab on teacher’s router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 204/345
are going to make lab on teacher s router •
Disable connection for specific client• Allow connection only for specific clients
©Academy Xperts / MikroTik Xperts 2013 204
Security
• Let’s enable encryption on wireless network • You must use WPA or WPA2 encryption
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 205/345
You must use WPA or WPA2 encryptionprotocols
• All devices on the network should have thesame security options
©Academy Xperts / MikroTik Xperts 2013 205
Security• Let’s create WPA
encryption for ourwireless network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 206/345
• WPA Pre-Shared Key is
mikrotiktraining
©Academy Xperts / MikroTik Xperts 2013 206
Configuration Tip• To view hidden Pre-
Shared Key, click on HidePasswords
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 207/345
• It is possible to viewother hiddeninformation, exceptrouter password
©Academy Xperts / MikroTik Xperts 2013 207
Drop Connections betweenclients
D f lt F di g d t
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 208/345
Default-Forwarding used todisable communicationsbetween clients connectedto the same access-point
©Academy Xperts / MikroTik Xperts 2013 208
Default Forwarding
• Access-List rules have higher priority
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 209/345
• Check your access-list if connection betweenclient is working
©Academy Xperts / MikroTik Xperts 2013 209
Nstreme
• MikroTik proprietary wireless protocol• Improves wireless links, especially long-range
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 210/345
Improves wireless links, especially long rangelinks
• To use it on your network, enable protocolon all wireless devices of this network
©Academy Xperts / MikroTik Xperts 2013 210
Nstreme Lab• Enable Nstreme on
your router• Check the
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 211/345
connection status• Nstreme should be
enabled on both routers
©Academy Xperts / MikroTik Xperts 2013 211
Summary
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 212/345
Summary
©Academy Xperts / MikroTik Xperts 2013 212
Bridging
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 213/345
Bridging
©Academy Xperts / MikroTik Xperts 2013 213
Bridge Wireless Network
Your RouterYour LaptopClass AP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 214/345
Let’s get back to our configuration
192.168.X.1 192.168.X.254DHCP-Client
©Academy Xperts / MikroTik Xperts 2013 214
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 215/345
Bridge
• We are going to bridge local Ethernetinterface with Internet wireless interface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 216/345
• Bridge unites different physical interfaces
into one logical interface• All your laptops will be in the same network
©Academy Xperts / MikroTik Xperts 2013 216
Bridge
• To bridge you need to create
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 217/345
bridge interface
• Add interfaces to bridge ports
©Academy Xperts / MikroTik Xperts 2013 217
Create Bridge• Bridge is configured from / interface
bridge menu
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 218/345
©Academy Xperts / MikroTik Xperts 2013 218
Add Bridge Port• Interfaces are added to bridge via ports
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 219/345
©Academy Xperts / MikroTik Xperts 2013 219
Bridge
• There are no problems to bridge Ethernetinterface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 220/345
•
Wireless Clients ( mode=station ) do notsupport bridging due the limitation of 802.11
©Academy Xperts / MikroTik Xperts 2013 220
Bridge Wireless
• WDS allows to add wireless client to bridge• WDS (Wi l Di t ib ti S t ) bl
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 221/345
WDS (Wireless Distribution System) enables
connection between Access Point and AccessPoint
©Academy Xperts / MikroTik Xperts 2013 221
Set WDS Mode
•
Station-wds isspecial stationmode with WDS
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 222/345
support
©Academy Xperts / MikroTik Xperts 2013 222
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 223/345
Access Point WDS
• Enable WDS on AP-bridge, usemode=dynamic-mesh
• WDS interfaces are created on the fly
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 224/345
• Use default bridge for WDS interfaces• Add Wireless Interface to Bridge
©Academy Xperts / MikroTik Xperts 2013 224
AP-bridge
• Set AP-bridgesettings
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 225/345
• Add Wirelessinterface to bridge
©Academy Xperts / MikroTik Xperts 2013 225
WDS configuration
• Use dynamic-mesh WDSmode
• WDS interfaces are
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 226/345
created on the fly• Others AP should use
dynamic-mesh too
©Academy Xperts / MikroTik Xperts 2013 226
WDS
• WDS link isestablished
• D i i t f
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 227/345
Dynamic interface
is present
©Academy Xperts / MikroTik Xperts 2013 227
WDS Lab• Delete masquerade rule• Delete DHCP-client on router wireless
interface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 228/345
• Use mode=station-wds on router• Enable DHCP on your laptop• Can you ping neighbor’s laptop
©Academy Xperts / MikroTik Xperts 2013 228
WDS Lab• Your Router is Transparent Bridge now• You should be able to ping neighbor router
and computer now
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 229/345
•
Just use correct IP address
©Academy Xperts / MikroTik Xperts 2013 229
Restore Configuration•
To restore configuration manually• change back to Station mode• Add DHCP Client on correct interface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 230/345
Add DHCP-Client on correct interface• Add masquerade rule• Set correct network configuration to laptop
©Academy Xperts / MikroTik Xperts 2013 230
Summary
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 231/345
©Academy Xperts / MikroTik Xperts 2013 231
Routing
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 232/345
©Academy Xperts / MikroTik Xperts 2013 232
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 233/345
Route
• ip route rules define where packets shouldbe sent
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 234/345
• Let’s look at / ip route rules
©Academy Xperts / MikroTik Xperts 2013 234
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 235/345
Default Gateway
Default gateway:next hop router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 236/345
where all ( 0.0.0.0 )traffic is sent
©Academy Xperts / MikroTik Xperts 2013 236
Set Default Gateway Lab•
Currently you have default gateway receivedfrom DHCP-Client
• Disable automatic receiving of default
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 237/345
Disable automatic receiving of default
gateway in DHCP-client settings• Add default gateway manually
©Academy Xperts / MikroTik Xperts 2013 237
Dynamic Routes• Look at the
other routes•
Routes withDAC are addedautomatically
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 238/345
•
DAC routecomes from IPaddressconfiguration
©Academy Xperts / MikroTik Xperts 2013 238
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 239/345
Static Routes
• Our goal is to ping neighbor laptop
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 240/345
• Static route will help us to achieve this
©Academy Xperts / MikroTik Xperts 2013 240
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 241/345
Static Route
• Additional static route is required to reachyour neighbor laptop
• Because gateway (teacher’s router) does not
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 242/345
Because gateway (teacher s router) does not
have information about student’s privatenetwork
©Academy Xperts / MikroTik Xperts 2013 242
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 243/345
Network Structure
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 244/345
©Academy Xperts / MikroTik Xperts 2013 244
Route To Your Neighbor• Add one route rule• Set Destination, destination is neighbor’s
local network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 245/345
•
Set Gateway, address which is used to reachdestination - gateway is IP address ofneighbor’s router wireless interface
©Academy Xperts / MikroTik Xperts 2013 245
Route Your Neighbor•
Add static route• Set Destination
and Gateway
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 246/345
• Try to pingNeighbor’s Laptop
©Academy Xperts / MikroTik Xperts 2013 246
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 247/345
Dynamic Routes• The same configuration is possible with
dynamic routes• Imagine you have to add static routes to all
neighbors networks
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 248/345
neighbors networks• Instead of adding tons of rules, dynamic
routing protocols can be used
©Academy Xperts / MikroTik Xperts 2013 248
Dynamic Routes
• Easy in configuration, difficult inmanaging/troubleshooting
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 249/345
managing/troubleshooting• Can use more router resources
©Academy Xperts / MikroTik Xperts 2013 249
Dynamic Routes
• We are going to use OSPF• OSPF is very fast and optimal for dynamic
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 250/345
routing• Easy in configuration
©Academy Xperts / MikroTik Xperts 2013 250
OSPF configuration
•
Add correctnetwork toOSPF
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 251/345
•
OSPF protocolwill beenabled
©Academy Xperts / MikroTik Xperts 2013 251
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 252/345
Summary
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 253/345
©Academy Xperts / MikroTik Xperts 2013 253
Local NetworkManagement
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 254/345
©Academy Xperts / MikroTik Xperts 2013 254
Access to Local Network•
Plan network design carefully• Take care of user’s local access to the
network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 255/345
• Use RouterOS features to secure localnetwork resources
©Academy Xperts / MikroTik Xperts 2013 255
ARP•
Address Resolution Protocol• ARP joins together client’s IP address with
MAC-address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 256/345
• ARP operates dynamically, but can also bemanually configured
©Academy Xperts / MikroTik Xperts 2013 256
ARP Table
ARP tableprovides: IPaddress, MAC-
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 257/345
address andInterface
©Academy Xperts / MikroTik Xperts 2013 257
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 258/345
Static ARP configuration• Add Static Entry to
ARP table• Set for interface
arp=reply-only todisable dynamic ARP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 259/345
creation• Disable/enable
interface or reboot
router ©Academy Xperts / MikroTik Xperts 2013 259
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 260/345
DHCP Server
• Dynamic Host Configuration Protocol• Used for automatic IP address distribution
over local network
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 261/345
• Use DHCP only in secure networks
©Academy Xperts / MikroTik Xperts 2013 261
DHCP Server
• To setup DHCP server you should have IPaddress on the interface
• Use setup command to enable DHCP server
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 262/345
• It will ask you for necessary information
©Academy Xperts / MikroTik Xperts 2013 262
DHCP-Server Setup
Click on DHCP Setup
Set Addresses that
DNS server address
Time that client may use
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 263/345
to run Setup WizardSelect interface for
DHCP server
Set Network for DHCP,offered automaticallySet Gateway forDHCP clientswill be given to clientsthat will be assigned to clientsy
IP addressWe are done!
©Academy Xperts / MikroTik Xperts 2013 263
Important
• To configure DHCP server on bridge , setserver on bridge interface
• DHCP server will be invalid , when it is
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 264/345
configured on bridge port
©Academy Xperts / MikroTik Xperts 2013 264
DHCP Server Lab• Setup DHCP server on Ethernet Interface
where Laptop is connected• Change computer Network settings and
enable DHCP-client (Obtain an IP address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 265/345
Automatically)• Check the Internet connectivity
©Academy Xperts / MikroTik Xperts 2013 265
DHCP Server Information
Leases provideinformation aboutDHCP clients
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 266/345
©Academy Xperts / MikroTik Xperts 2013 266
Winbox Configuration Tip
Show or hidedifferentWinbox
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 267/345
columns
©Academy Xperts / MikroTik Xperts 2013 267
Static Lease
• We can make leaseto be static
• Client will not get
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 268/345
other IP address
©Academy Xperts / MikroTik Xperts 2013 268
Static Lease
• DHCP-server could run without dynamicleases
• Clients will receive only preconfigured IP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 269/345
address
©Academy Xperts / MikroTik Xperts 2013 269
Static Lease
• Set Address-Pool tostatic-only
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 270/345
• Create Static leases
©Academy Xperts / MikroTik Xperts 2013 270
HotSpot
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 271/345
©Academy Xperts / MikroTik Xperts 2013 271
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 272/345
HotSpot Usage
• Open Access Points, Internet Cafes, Airports,universities campuses, etc.
• Different ways of authorization
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 273/345
• Flexible accounting
©Academy Xperts / MikroTik Xperts 2013 273
HotSpot Requirements
• Valid IP addresses on Internet and LocalInterfaces
• DNS servers addresses added to ip dns
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 274/345
• At least one HotSpot user
©Academy Xperts / MikroTik Xperts 2013 274
HotSpot Setup
• HotSpot setup is easy• Setup is similar to DHCP Server setup
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 275/345
©Academy Xperts / MikroTik Xperts 2013 275
HotSpot Setup• Run ip hotspot
setup• Select Inteface• Proceed to
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 276/345
answer thequestions Select Interface to
run HotSpot on
HotSpot address willbe selected automaticallyMasquerade HotSpot network
automaticallyAddresses that will be assigned
to HotSpot clientsWhether to use certificate
together with HotSpot or notIP address to redirect SMTP
(e-mails) to your SMTP serverDNS servers addressfor HotSpot clients
DNS name for HotSpot serverAdd first HotSpot user
©Academy Xperts / MikroTik Xperts 2013 276
Important Notes
• Users connected to HotSpot interface will bedisconnected from the Internet
• Client will have to authorize in HotSpot toI
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 277/345
get access to Internet
©Academy Xperts / MikroTik Xperts 2013 277
Important Notes• HotSpot default setup creates additional
configuration:• DHCP-Server on HotSpot Interface•
P l f H tS t Cli t
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 278/345
Pool for HotSpot Clients• Dynamic Firewall rules (Filter and NAT)
©Academy Xperts / MikroTik Xperts 2013 278
HotSpot Help•
HotSpot login page is provided when usertries to access any web-page
• To logout from HotSpot you need to go to
htt // t IP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 279/345
http://router _IP orhttp://HotSpot _DNS
©Academy Xperts / MikroTik Xperts 2013 279
HotSpot Setup Lab
• Let’s create HotSpot on local Interface• Don’t forget HotSpot login and password or
ill t b bl t g t th I t t
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 280/345
you will not be able to get the Internet
©Academy Xperts / MikroTik Xperts 2013 280
HotSpot Network Hosts
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 281/345
Information about clients connected to HotSpot router©Academy Xperts / MikroTik Xperts 2013 281
HotSpot Active Table
Information aboutauthorizedHotSpot clients
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 282/345
©Academy Xperts / MikroTik Xperts 2013 282
User Management
Add/Edit/RemoveHotSpot users
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 283/345
©Academy Xperts / MikroTik Xperts 2013 283
HotSpot Walled-Garden•
Tool to get access to specific resourceswithout HotSpot authorization• Walled-Garden for HTTP and HTTPS•
Walled Garden IP for other resources
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 284/345
Walled-Garden IP for other resources(Telnet, SSH, Winbox, etc.)
©Academy Xperts / MikroTik Xperts 2013 284
HotSpot Walled-Garden
Allow access tomikrotik.com
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 285/345
©Academy Xperts / MikroTik Xperts 2013 285
Bypass HotSpot• Bypass specific
clients over HotSpot• VoIP phones,
printers, superusers• IP binding is used
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 286/345
IP-binding is usedfor that
©Academy Xperts / MikroTik Xperts 2013 286
HotSpot Bandwidth Limits
• It is possible to set every HotSpot user withautomatic bandwidth limit
• Dynamic queue is created for every client
from profile
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 287/345
from profile
©Academy Xperts / MikroTik Xperts 2013 287
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 288/345
HotSpot Advanced Lab
To give each client 64kupload and 128kdownload, set Rate
Limit
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 289/345
Limit
©Academy Xperts / MikroTik Xperts 2013 289
HotSpot Lab•
Add second user• Allow access to www.mikrotik.com without
HotSpot authentication for your laptop• Add Rate-limit 1M/1M for your laptop
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 290/345
Add Rate limit 1M/1M for your laptop
©Academy Xperts / MikroTik Xperts 2013 290
Tunnels
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 291/345
©Academy Xperts / MikroTik Xperts 2013 291
PPPoE•
Point to Point Protocol over Ethernet is oftenused to control client connections for DSL,cable modems and plain Ethernet networks
• MikroTik RouterOS supports PPPoE clientand PPPoE server
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 292/345
and PPPoE server
©Academy Xperts / MikroTik Xperts 2013 292
PPPoE Client Setup• Add PPPoE
client• You need to
set Interace• Set Login
and
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 293/345
andPassword
©Academy Xperts / MikroTik Xperts 2013 293
PPPoE Client Lab• Teachers are going to create PPPoE server on
their router• Disable DHCP- client on router’s outgoing
interface•
Set up PPPoE client on outgoing interface
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 294/345
p g g• Set Username class , password class
©Academy Xperts / MikroTik Xperts 2013 294
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 295/345
PPPoE Server Setup
• Select Interface• Select Profile
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 296/345
©Academy Xperts / MikroTik Xperts 2013 296
PPP Secret• User’s database
• Add login andPassword
• Select service• Configuration is
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 297/345
Configuration istakef from profile
©Academy Xperts / MikroTik Xperts 2013 297
PPP Profiles
• Set of rules used for PPP clients• The way to set same settings for different
clients
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 298/345
©Academy Xperts / MikroTik Xperts 2013 298
PPP Profile
• Local address -Server address
• Remote Address -Client address
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 299/345
Client address
©Academy Xperts / MikroTik Xperts 2013 299
PPPoE• Important, PPPoE server runs on the
interface• PPPoE interface can be without IP address
configured
• For security, leave PPPoE interface without
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 300/345
IP address configuration
©Academy Xperts / MikroTik Xperts 2013 300
Pools• Pool defines the range of IP addresses for PPP,
DHCP and HotSpot clients• We will use a pool, because there will be more
than one client• Addresses are taken from pool automatically
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 301/345
Addresses are taken from pool automatically
©Academy Xperts / MikroTik Xperts 2013 301
Pool
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 302/345
©Academy Xperts / MikroTik Xperts 2013 302
PPP Status
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 303/345
©Academy Xperts / MikroTik Xperts 2013 303
PPTP• Point to Point Tunnel Protocol providesencrypted tunnels over IP
• MikroTik RouterOS includes support for PPTPclient and server
• Used to secure link between Local Networks
over Internet
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 304/345
• For mobile or remote clients to accesscompany Local network resources
©Academy Xperts / MikroTik Xperts 2013 304
PPTP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 305/345
©Academy Xperts / MikroTik Xperts 2013 305
PPTP configuration
• PPTP configuration is very similar to PPPoE• L2TP configuration is very similar to PPTP
and PPPoE
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 306/345
©Academy Xperts / MikroTik Xperts 2013 306
PPTP client• Add PPTP
Interface• Specify address
of PPTP server•
Set login andpassword
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 307/345
password
©Academy Xperts / MikroTik Xperts 2013 307
PPTP Client• That’s all for PPTP client configuration • Use Add Default Gateway to route all
router’s traffic to PPTP tunnel •
Use static routes to send specific traffic toPPTP tunnel
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 308/345
©Academy Xperts / MikroTik Xperts 2013 308
PPTP Server• PPTP Server
is able to
maintainmultipleclients
•
It is easy toenable PPTP
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 309/345
enable PPTPserver
©Academy Xperts / MikroTik Xperts 2013 309
PPTP Server Clients•
PPTP client settings are stored in ppp secret• ppp secret is used for PPTP, L2TP, PPPoE
clients
• ppp secret database is configured on server
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 310/345
©Academy Xperts / MikroTik Xperts 2013 310
PPP Profile
• The same profile is used for PPTP, PPPoE,L2TP and PPP clients
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 311/345
©Academy Xperts / MikroTik Xperts 2013 311
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 312/345
Proxy
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 313/345
©Academy Xperts / MikroTik Xperts 2013 313
What is Proxy
• It can speed up WEB browsing by cachingdata
• HTTP Firewall
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 314/345
©Academy Xperts / MikroTik Xperts 2013 314
Enable Proxy
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 315/345
The main option is Enable , other settings are optional©Academy Xperts / MikroTik Xperts 2013 315
Transparent Proxy•
User need to set additional configuration tobrowser to use Proxy
• Transparent proxy allows to direct all users
to proxy automatically
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 316/345
©Academy Xperts / MikroTik Xperts 2013 316
Transparent Proxy
• DST-NAT rulesrequired fortransparent proxy
• HTTP traffic shouldbe redirected torouter
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 317/345
©Academy Xperts / MikroTik Xperts 2013 317
HTTP Firewall
• Proxy access list provides option to filter DNSnames
• You can make redirect to specific pages
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 318/345
©Academy Xperts / MikroTik Xperts 2013 318
HTTP Firewall•
Dst-Host, webpageaddress(http://test.com )
• Path, anything afterhttp://test.com/ PATH
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 319/345
©Academy Xperts / MikroTik Xperts 2013 319
HTTP Firewall• Create rule to drop access for specific
web-page• Create rule to make redirect from
unwanted web-page to your companypage
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 320/345
©Academy Xperts / MikroTik Xperts 2013 320
Web-page logging
• Proxy can log visited Web-Pages by users• Make sure you have enough resources for
logs (it is better to send them to remote)
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 321/345
©Academy Xperts / MikroTik Xperts 2013 321
Web-Pages logging
• Add logging rule• Check logs
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 322/345
©Academy Xperts / MikroTik Xperts 2013 322
Caching to External•
Cache can be stored on the external drives• Store manipulates all the external drives• Cache can be stored to IDE, SATA, USB, CF,
MicroSD drives
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 323/345
©Academy Xperts / MikroTik Xperts 2013 323
Store•
Manage all external disks• Newly connected disk should be formatted
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 324/345
©Academy Xperts / MikroTik Xperts 2013 324
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 325/345
Summary
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 326/345
©Academy Xperts / MikroTik Xperts 2013 326
Dude
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 327/345
©Academy Xperts / MikroTik Xperts 2013 327
Dude• Network monitor program
• Automatic discovery of devices• Draw and Layout map of your networks• Services monitor and alerts• It is Free
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 328/345
©Academy Xperts / MikroTik Xperts 2013 328
Dude• Dude consists of two parts:
1.Dude server - the actual monitor program.It does not have a graphical interface. Youcan run Dude server even on RouterOS
2.Dude client - connects to Dude server andshows all the information it receives
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 329/345
©Academy Xperts / MikroTik Xperts 2013 329
Dude Install
• Dude is available atwww.mikrotik.com
• Install is very easy• Read and use next
button
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 330/345
Install Dude Server on computer©Academy Xperts / MikroTik Xperts 2013 330
Dude
• Dude is translated to different languages• Available on wiki.mikrotik.com
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 331/345
©Academy Xperts / MikroTik Xperts 2013 331
Dude First Launch
• Discoveroption isoffered for thefirst launch
• You candiscover localnetwork
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 332/345
etwo
©Academy Xperts / MikroTik Xperts 2013 332
Dude Lab
• Download Dude from ftp://192.168.100.254
• Install Dude• Discover Network• Add laptop and router• Disconnect Laptop from Router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 333/345
©Academy Xperts / MikroTik Xperts 2013 333
Dude Usage
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 334/345
©Academy Xperts / MikroTik Xperts 2013 334
Dude Usage
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 335/345
©Academy Xperts / MikroTik Xperts 2013 335
Troubleshooting
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 336/345
©Academy Xperts / MikroTik Xperts 2013 336
Lost Password
• The only solution to reset password is toreinstall the router
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 337/345
©Academy Xperts / MikroTik Xperts 2013 337
RouterBOARD License• All purchased licenses are stored in the
MikroTik account server• If your router loses the Key for some reason -
just log into mikrotik.com to get it from keyslist
• If the key is not in the list use Request Keyoption
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 338/345
©Academy Xperts / MikroTik Xperts 2013 338
Bad Wireless Signal• check that the antenna connector is
connected 'main' antenna connector• check that there is no water or moisture in
the cable• check that the default settings for the radio
are being used• Use interface wireless reset-configuration
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 339/345
Use interface wireless reset configuration
©Academy Xperts / MikroTik Xperts 2013 339
No Connection• Try different Ethernet port or cable• Use reset jumper on RouterBOARD• Use serial console to view any possible
messages•
Use netinstall if possible• Contact support ([email protected])
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 340/345
©Academy Xperts / MikroTik Xperts 2013 340
Before Certification Test
• Reset the router• Restore backup or restore configuration• Make sure you have access to the Internet
and to training.mikrotik.com
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 341/345
©Academy Xperts / MikroTik Xperts 2013 341
Certification Test
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 342/345
©Academy Xperts / MikroTik Xperts 2013 342
Certification test
• Go to http://training.mikrotik.com• Login with your account• Look for US/Dallas Training
• Select Essential Training Test
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 343/345
©Academy Xperts / MikroTik Xperts 2013 343
Instructions
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 344/345
©Academy Xperts / MikroTik Xperts 2013 344
MTCNA TestApr. 04th, 2013Santiago de Chile, Chile
8/18/2019 MTCNA-v5
http://slidepdf.com/reader/full/mtcna-v5 345/345
345© MikroTik, www.mikrotik.com. All rights reserved. Reprinted with permission
MikroTik, NSTREME, RouterOS and RouterBOARD are registered trademarks of companyMikrotīkls
SIA .