CAPsMAN Case Study. Uldis Cernevskis MikroTik, Latvia. MUM Pittsburgh September 2014



Similar documents
MikroTik CAPsMAN. Haydar Fadel May

Create Virtual AP for Network Campus with Mikrotik

WISP 101. The DO s and DON T s of becoming a Wireless ISP

GregSowell.com. Mikrotik Basics

Layer 2 / Layer 3 switches and multi-ssid multi-vlan network with traffic separation

New Obvious and Obscure MikroTik RouterOS v5 features. Budapest, Hungary MUM Europe 2011

Wireless Tips and Tricks for RouterOS v6. MUM South Africa 2013 Johannesburg Uldis Cernevskis MikroTik

Wireless Local Area Networks (WLANs)

FSM73xx GSM73xx GMS72xxR Shared access to the Internet across Multiple routing VLANs using a Prosafe Firewall

Microsoft Lync Certification Configuration Guide for WiNG 5.5

Preparing the Computers for TCP/IP Networking

PePWave Surf Series PePWave Surf Indoor Series: Surf 200, AP 200, AP 400

IEEE a/ac/n/b/g Enterprise Access Points ECW5320 ECWO5320. Management Guide. Software Release v

RouterBOARD Wireless Hacks. Liuedit Master subtitle style Convergingstream

Configuring Switch Ports and VLAN Interfaces for the Cisco ASA 5505 Adaptive Security Appliance

Configure WorkGroup Bridge on the WAP131 Access Point

Apple Airport Extreme Base Station V4.0.8 Firmware: Version 5.4

LifeSize Video Communications Systems Administrator Guide

OSBRiDGE 5XLi. Configuration Manual. Firmware 3.10R

LOHU 4951L Outdoor Wireless Access Point / Bridge

MikroTik Invisible Tools. By : Haydar Fadel 2014

How to configure your Thomson SpeedTouch 780WL for ADSL2+

Enabling Multiple Wireless Networks on RV320 VPN Router, WAP321 Wireless-N Access Point, and Sx300 Series Switches

Note: This case study utilizes Packet Tracer. Please see the Chapter 5 Packet Tracer file located in Supplemental Materials.

CCT vs. CCENT Skill Set Comparison

User guide for NANOSTATION 2

WASP User Manual. Revision: 1.6. (c) 2012 North Pole Engineering, Inc.

Basic IPv6 WAN and LAN Configuration

ECB GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/

CyberData VoIP V2 Speaker with VoIP Clock Kit Configuration Guide for OmniPCX Enterprise

D-Link DAP-1360 Repeater Mode Configuration

VLANs. Application Note

Cisco - Configure the 1721 Router for VLANs Using a Switch Module (WIC-4ESW)

MikroTik Certified Network Associate (MTCNA) Training outline

IP Office Technical Tip

The Use of Mikrotik Router Boards With Radius Server for ISPs.

Guideline for setting up a functional VPN

Integrating a Hitachi IP5000 Wireless IP Phone

NBG2105. User s Guide. Quick Start Guide. Wireless Mini Travel Router. Default Login Details. Version 1.00 Edition 1, 11/2012

UTM10 in multi-ssid, multi-vlan network with WMS5316. Network diagram

Protecting the Home Network (Firewall)

How To Configure Apple ipad for Cyberoam L2TP

Quick Start Guide. WRV210 Wireless-G VPN Router with RangeBooster. Cisco Small Business

V310 Support Note Version 1.0 November, 2011

User Manual. PePWave Surf / Surf AP Indoor Series: Surf 200, E200, AP 200, AP 400. PePWave Mesh Connector Indoor Series: MC 200, E200, 400

MikroTik RouterOS v3. New Obvious and Obscure Mikrotik RouterOS v3.x features

USER GUIDE AC2400. DUAL BAND GIGABIT Wi Fi ROUTER. Model# E8350

Wireless-N. User Guide. PCI Adapter WMP300N (EU) WIRELESS. Model No.

ASUS WL-5XX Series Wireless Router Internet Configuration. User s Guide

Topic 7 DHCP and NAT. Networking BAsics.

Technical Notes TN 1 - ETG FactoryCast Gateway TSX ETG 3021 / 3022 modules. How to Setup a GPRS Connection?

Configuring Routers and Their Settings

DSL-2600U. User Manual V 1.0

Web Authentication Proxy on a Wireless LAN Controller Configuration Example

BW-1000-ZBS Product. Specification. IEEE a/b/g/n Wireless Smart AP - 1 -

Extending the range of a wireless network by using mesh topology

Use Shrew Soft VPN Client to connect with IPSec VPN Server on RV130 and RV130W

Saturday, August 25, MUM Home INDIA Assignment 2012 Soumil Gupta Bhaya PROPRIETARY WIRELESS PROTOCOLS. N-Streme and Nv2

Chapter 3 Connecting the Router to the Internet

LifeSize Passport TM User and Administrator Guide

Abstract. Avaya Solution & Interoperability Test Lab

Configuring IPSec VPN Tunnel between NetScreen Remote Client and RN300

WAN Failover Scenarios Using Digi Wireless WAN Routers

APPENDIX 3 LOT 3: WIRELESS NETWORK

Appendix A: Configuring Firewalls for a VPN Server Running Windows Server 2003

Installation of the On Site Server (OSS)

A Division of Cisco Systems, Inc. GHz g. Wireless-G. PCI Adapter with RangeBooster. User Guide WIRELESS WMP54GR. Model No.

Chapter 4 Customizing Your Network Settings

132-S Avaya Specialist - IP Office Implement & Support Elective Exam

VOIP-211RS/210RS/220RS/440S. SIP VoIP Router. User s Guide

Network Configuration Setup Guide. Air4G-W

Chapter 1 Configuring Internet Connectivity

FD Wi-Fi Terminals. FD100 Ti /200 Ti /300 Ti Quick set-up Guide

Ruckus Wireless ZoneDirector Command Line Interface

Chapter 3 Management. Remote Management

How to establish a Leased Line Connection

Kvaser BlackBird Getting Started Guide

Version /08/2014. User Manual. DAP-1665 Wireless AC1200 Dual Band Access Point DAP-1665

This techno knowledge paper can help you if: You need to setup a WAN connection between a Patton Router and a NetGuardian.

Establishing a VPN tunnel to CNet CWR-854 VPN router using WinXP IPSec client

Central WLAN management. Centralized WLAN Management. LANCOM WLAN Controller LANCOM WLC Option for Router

HOWTO: How to configure IPSEC gateway (office) to gateway

AC750 WiF Range Extender

Setting up VPN connection: DI-824VUP+ with Windows PPTP client

TotalCloud Phone System

Initial Access and Basic IPv4 Internet Configuration

VIRTUAL NETWORKING WITH "VMware Player" Summary:

SOHO 6 Wireless Installation Procedure Windows 95/98/ME with Internet Explorer 5.x & 6.0

ADMINISTRATION GUIDE Cisco Small Business

1-Port Wireless USB 2.0 Print Server Model # APSUSB201W. Quick Installation Guide. Ver. 2A

Classroom Management network FAQ and troubleshooting

Configuring Network Address Translation (NAT)

Quick Installation Guide

Custom Integration Solutions

How To Configure L2TP VPN Connection for MAC OS X client

Vega 100G and Vega 200G Gamma Config Guide

Linksys WAP300N. User Guide

RAP Installation - Updated

Fireware How To Network Configuration

Transcription:

CAPsMAN Case Study Uldis Cernevskis MikroTik, Latvia MUM Pittsburgh September 2014

CAPsMAN Features Centralized management of RouterOS APs Dual Band AP support Provisioning of APs MAC and IP Layer communication with APs Certificate support for AP communication Full and Local data forwarding mode RADIUS MAC authentication Custom configuration support

Requirements CAPsMAN x86 or RouterBOARD based device Newest RouterOS v6 version Wireless-fp package installed and enabled CAP X86 or RouterBOARD based device Newest RouterOS v6 version Atheros chipset (a/b/g/n/ac) wireless card Wireless-fp package installed and enabled At least Level4 RouterOS license

CAPsMAN Simple Setup

CAPsMAN Simple Setup Enable CAPsMAN service Create Bridge interface Add IP configuration to Bridge interface Create CAPsMAN Configuration Create Provisioning rule Enable CAP mode on the APs

CAPsMAN Simple Setup Enable the CAPsMAN service

CAPsMAN Simple Setup Create Bridge Interface

CAPsMAN Simple Setup 1. Add IP address 2. Add DHCP Server 3. Add NAT rule

CAPsMAN Simple Setup Add New CAPsMAN Configuration

CAPsMAN Simple Setup Add new Provisioning rule

CAPsMAN Simple Setup Configure the AP to use CAP mode Enable wireless-fp package Enable CAP mode By CAP mode button on some boards By configuration in Wireless CAP menu

CAPsMAN Simple Setup Check the Status of the CAPsMAN CAP interface CAPsMAN CAP

CAPsMAN Registration table

Manual Provisioning Changing Provisioning rules doesn't effect already configured CAPs, manual Provisioning required: Remove CAP interface Initiate Provision command on the CAP

CAP to CAPsMAN Connection MAC Layer2: IP (UDP) Layer3: No IP configuration required CAP an CAPsMAN must be in the same Layer 2 network CAP must reach the CAPsMAN using IP protocol Can traverse NAT if necessary Management connection between CAP and CAPsMAN is secured using DTLS CAP client data traffic is not secured if necessary additional encryption by using IPSec or encrypted tunnels is needed

CAPsMAN Selection on CAP CAP attempts to contact CAPsMAN and build available CAPsMAN list: List of CAPsMAN IPs List of CAPsMAN IPs obtained from DHCP Broadcasting on configured interfaces using IP and MAC Layer CAP selects the CAPsMAN based on such rules: If CAPsMAN names setting is matched it will prefer that CAPsMAN earlier in the list MAC layer connectivity to CAPsMAN is preferred over IP connectivity If list is empty it will connect to any available CAPsMAN

CAPsMAN with Layer3 On the CAP specify the IP address of the CAPsMAN

CAPsMAN selection using Name On the CAP specify the CAPsMAN identity name

CAP Identification MAC/IP address System Identity RouterBoard model Main wireless MAC Serial Number of the Board State of the CAP RouterOS version Provided radio count

CAPsMAN static CAP interface No interface name change or setting change after the reboot Additional manual setting override Copy dynamic interface to make static interface

CAPsMAN VirtualAP

CAPsMAN VirtualAP Configuration Create new Bridge interface and IP configuration for the VirtualAPs or use the same bridge interface as Master AP Create a new configuration for the VirtualAP Specify the new configuration in Provisioning rule as Slave Configuration Remove all CAP interfaces Initiate Manual Provisioning on all the CAPs

CAPsMAN VirtualAP Setup

CAPsMAN VirtualAP Setup

CAPsMAN static VirtualAP

CAPsMAN Access List Features MAC Authentication Radius Query support MAC Mask support Signal Range Time Private Passphrase VLAN ID assignment

CAPsMAN Access List Allow Apple devices to connect Rest of the connections pass to the RADIUS

CAPsMAN Local Forwarding Setup

CAPsMAN Local Forwarding Create a Local Forwarding configuration

CAPsMAN Local Forwarding Create Provisioning rule Move above the default Provisioning rule

CAPsMAN Local Forwarding On CAP specify the Bridge interface for CAP or use routing for access to network

CAPsMAN VLAN Assignment

CAPsMAN VLAN Assignment When using Local Forwarding CAPsMAN can assign VLAN ID to specific CAP interface or even specific wireless client Create Slave interface with Vlan tag

CAPsMAN VLAN Assignment Create Access List rule for specific client to get tagged to Management Vlan on the same CAP interface Move the Access List rule above the previous ones

CAPsMAN VLAN Assignment Create VLAN interfaces on the CAPsMAN router interface where the CAPs are connected

CAPsMAN VLAN Assignment Assign IPs to VLAN interfaces on CAPsMAN

CAPsMAN Dual Band CAP If the Channel settings are not specified it will automatically use the supported band/channel If specific Channel settings are required then specific Provisioning rules are required Custom Channel settings Dual band wireless interface support

CAPsMAN Dual Band CAP Create 3 configurations: Config for both bands radio Config for 5ghz only radio Config for 2.4ghz only radio

CAPsMAN Dual Band CAP Create 3 Provisioning rules For A/N,G/N hardware use Both Bands config For A/N hardware use 5ghz config For G/N hardware use 2.4ghz config

CAPsMAN Dual Band CAP

CAPsMAN Configuration override Configuration overrides Channel setting Interface overrides Channel and Configuration setting

CAPsMAN Auto Certificate Enable Certificate and CA Certificate on CAPsMAN

CAPsMAN Auto Certificate Enable request Certificate on CAP

CAPsMAN Auto Certificate Allow CAPsMAN to accept connections only from CAPs with valid certificate

CAP Lock To CAPsMAN Enable Lock To CAPsMAN on CAP certificate is required

CAPsMAN and CAP in one board Enable CAPsMAN Manager and create the configuration Configure the CAP to look for IP 127.0.0.1

CAPsMAN Antenna-gain Antenna-gain value is taken from the CAP interface Must be configured on AP before enable radio in CAP mode Example with 6db antenna-gain and 30db EIRP