WISP 101. The DO s and DON T s of becoming a Wireless ISP



Similar documents
9 Simple steps to secure your Wi-Fi Network.

MikroTik Certified Network Associate (MTCNA) Training outline

OSBRiDGE 5XLi. Configuration Manual. Firmware 3.10R

CAPsMAN Case Study. Uldis Cernevskis MikroTik, Latvia. MUM Pittsburgh September 2014

PFSENSE Load Balance with Fail Over From Version Beta3

DIR-806A. Wireless AC750 Multi-Function Router. DUAL BAND Simultaneous operation in 5GHz band and 2.4GHz band, a/b/g/n/ac compatible

Lab Organizing CCENT Objectives by OSI Layer

LOHU 4951L Outdoor Wireless Access Point / Bridge

Create Virtual AP for Network Campus with Mikrotik

Wireless Tips and Tricks for RouterOS v6. MUM South Africa 2013 Johannesburg Uldis Cernevskis MikroTik

MN-700 Base Station Configuration Guide

Comtrend 1 Port Router Installation Guide CT-5072T

How to configure your Thomson SpeedTouch 780WL for ADSL2+

Cisco Certified Network Associate (CCNA) 120 Hours / 12 Months / Self-Paced WIA Fee: $

User guide for NANOSTATION 2

5GHz 300Mbps a/n Wireless Outdoor Access Point

Preparing the Computers for TCP/IP Networking

GregSowell.com. Mikrotik Basics

running operation mode painless TECHNICAL SPECIFICATION WAN/LAN: One 10/100 Fast Ethernet RJ-45 WPS (WiFi Protected Setup) WAN (Internet connection)

YO-301AP POE AP Datasheet

Output Power (without antenna) 5GHz 2.4GHz

2.4GHz / 5GHz Dual CPU 600Mbps 11N AP/Router

Chapter 3 Connecting the Router to the Internet

ENHWI-N n Wireless Router

Copyright 2008 Link Technologies,Inc. A Proud Vendor Member of the

ESR7550 KEY FEATURES PRODUCT DESCRIPTION

ESR b/g/n SOHO Router PRODUCT OVERVIEW. 2.4 GHz 150Mbps 11N Router/AP

Quick Installation Guide DAP Wireless N 300 Access Point & Router

University of Hawaii at Manoa Professor: Kazuo Sugihara

NBG2105. User s Guide. Quick Start Guide. Wireless Mini Travel Router. Default Login Details. Version 1.00 Edition 1, 11/2012

Chapter 1 Configuring Basic Connectivity

P-660HN n Wireless ADSL2+ 4-port Gateway DEFAULT LOGIN DETAILS. Firmware Version 1.10 Edition 1, 9/2010. IP Address:

WiFi-SB-L3 300M WiFi Router WiFi Bridge WiFi Repeater. WiFi Router WiFi Repeater WiFi Bridge WiFi-SB-L3 Quick Setting Guide

Chapter 1 Configuring Internet Connectivity

PPTP Server Access Through The

APPENDIX 3 LOT 3: WIRELESS NETWORK

Quick Start Guide. WRV210 Wireless-G VPN Router with RangeBooster. Cisco Small Business

Chapter 4 Customizing Your Network Settings

Mikrotik Router OS - Setup and Configuration Guide for Aradial Radius Server

Burning Bridges - Routing Your Bridged WISP Network With MikroTik

RouterBOARD product overview. September, Gon Tel: +44 (0) Fax: +44 (0)

SMC7901WBRA2-B1 Installation Guide

Custom Integration Solutions

ESR b/g/n SOHO Router

WHA-5500CPE. 108 Mbps. 5GHz a Super Range Outdoor CPE. PoE. Long Distance Champion. All-In-One Solution. 25 Kilometers Distance or More

DLB APC v5.77. User s Guide. Revision October Copyright 2011 Deliberant

Wireless N Open Source Access Point

ESR b/g/n SOHO Router

ASUS WL-5XX Series Wireless Router Internet Configuration. User s Guide

802.11b/g/n SOHO Router 2.4GHz 150Mbps 11N AP/Router

Quick Installation Guide of WLAN Broadband Router

Configuring Routers and Their Settings

RouterBOARD Wireless Hacks. Liuedit Master subtitle style Convergingstream

LW310V2 Sweex Wireless 300N Router

ESR (Go Green Series) Wireless-N Broadband Router / AP / Repeater. 2.4 GHz b/g/n 300 Mbps

Extending the range of a wireless network by using mesh topology

WLAN Outdoor CPE For 2.4G. Quick Installation Guide

IEEE a/ac/n/b/g Enterprise Access Points ECW5320 ECWO5320. Management Guide. Software Release v

Quick Installation Guide DIR-620. Multifunction Wireless Router Supporting GSM, CDMA, WiMAX with Built-in 4-port Switch

Configuring Wireless Security on ProSafe wireless routers (WEP/WPA/Access list)

USER GUIDE AC2400. DUAL BAND GIGABIT Wi Fi ROUTER. Model# E8350

DSL-2600U. User Manual V 1.0

Before You Begin You must have at least the following: Web Browser Wired Hub/Switch/Router OR Wireless b Router CD-ROM Drive

Using VDOMs to host two FortiOS instances on a single FortiGate unit

The Use of Mikrotik Router Boards With Radius Server for ISPs.

RedRapid X WIRELESS MODEM ROUTER. Quick Installation Guide (DN-7060)

Hacking. Aims. Naming, Acronyms, etc. Sources

PePWave Surf Series PePWave Surf Indoor Series: Surf 200, AP 200, AP 400

P-2302HW/HWL-P1. Quick Start Guide b/g Wireless VoIP Station Gateway. Version 3.60 Edition 1 8/2006

your Gateway Windows network installationguide b wireless series Router model WBR-100 Configuring Installing

Designing AirPort Extreme Networks

Cisco Networking Professional-6Months Project Based Training

User Guide. E-Series Routers

Table of Contents. Wireless Installation Considerations... 10

MikroTik RouterOS Workshop Load Balancing Best Practice. Warsaw MUM Europe 2012

Digi Connect WAN Application Guide Using the Digi Connect WAN and Digi Connect VPN with a Wireless Router/Access Point

ECB1220R. Wireless SOHO Router/Client Bridge

MikroTik RouterOS v3. New Obvious and Obscure Mikrotik RouterOS v3.x features

AP60. 9 Wireless. Wireless-b/g/n Long Range PoE Access Point. Wireless-b/g/n Long Range Radio. Passive PoE and 4-LAN Ports. IP Finder Management 4 LAN

NETVIGATOR Wireless Modem Setup Guide. (TG789Pvn)

5GHz 300Mbps a/n Wireless Outdoor CPE

AP60. Wireless-N POE Access Point. User s Manual

Comtrend 4 Port Router Installation Guide CT-5361T

Integrating a Hitachi IP5000 Wireless IP Phone

Internet Access Setup

Domain 3.0 Networking... 1

Document No. FO1004 Issue Date: Draft: Work Group: FibreOP Technical Team July 23, 2013 Final: Single Static IP Customer Owned LAN Router Support

Chapter 1 Connecting Your Router to the Internet

Digi Connect WAN Application Helper Configuring and Testing the Digi Connect WAN GSM

IP Address and Pre-configuration Information

Quick Installation Guide DSL-2750U/NRU. 3G/ADSL/Ethernet Router with Wi-Fi and Built-in Switch

SOHO 6 Wireless Installation Procedure Windows 95/98/ME with Internet Explorer 5.x & 6.0

ECB GHz Super G 108Mbps Access Point/Client Bridge/Repeater/WDS AP/

INFORMATION TECHNOLOGY MANAGEMENT COMMITTEE LIVINGSTON, NJ ITMC TECH TIP ROB COONCE, MARCH 2008

AC750 WiFi Range Extender

Chapter 2 Configuring Your Wireless Network and Security Settings

Wharf T&T Limited Report of Wireless LAN Technology Trial Version: 1.0 Date: 26 Jan Wharf T&T Limited. Version: 1.0 Date: 26 January 2004

BASIC INSTRUCTIONS TO CONFIGURE ZYXEL P8701T CPE USING THE WEB INTERFACE

Netcomm NB604N. Modem Configuration Guide. Netcomm NB604N. Configuring in Layer2 PPPoE for Windows XP and 2000 IMPORTANT MESSAGE

Transcription:

WISP 101 The DO s and DON T s of becoming a Wireless ISP

WISP 101 topics Choosing your hardware Setting up the Highsite Hardware Software Security Wireless Backhaul Setting up the client

Choosing your hardware Highly dependant on current and future client requirements Routerboard 532 is fine for highsites handling around 20 clients For 20-40 clients consider the newer RB 532A 400Mhz + 64MB RAM For 40+ clients consider using multiple RB532 s or check the Routerboard roadmap for upcoming higher speed units

Setting up the highsite Hardware The hardware you use will determine the highsite setup Remember to allow for future expansion!

Highsite Hardware DO use a IP65 rated metal enclosure with STP cable and sinewave PSU DON T use plastic with switch mode power supply unless you enjoy have 2-way radio operators take an axe to your equipment! DO use multiple sector antenna s to distribute the signal DON T use omni-directional antenna s on highsites unless you enjoy other WISP operators taking an axe to your equipment

WAPA Guidelines for Highsites Members will conform to basic WAPA high site requirements, including: Any antenna with a beam width of greater than 120 degrees is restricted to maximum gain of 6dbi in 2400-2483 MHz; Any antenna with a beam width of greater than 120 degrees is restricted to maximum gain of 10dbi in 5470-5875MHz; No Amplifiers may be used; and Power backup system needs to be in place

Setting up the highsite - software Several factors are involved in setting up the RouterOS software The authentication that clients will use will determine how complex setup will be The WISP standard is to use PPPOE for client authentication for easy management and tracking. PPPOE also makes the most efficient use of IP addresses Manual IP addressing can also be used this will be easier to setup but less secure and manageable in the long run

Setting up the highsite - software Your IP addressing scheme will depend on how many sectors you have along with your backhaul and routing strategy DHCP can be used to assign IP addresses for both manual addressing and PPPOE Larger networks can use RADIUS to authenticate PPPOE clients and assign IP addresses Consider Mikrotik Usermanager as an easy to setup and configure RADIUS solution

Highsite Software Setup DO spend some time planning your IP and routing setup get an expert to do it for you if necessary DON T choose a random highsite IP layout you will just have to redo it sometime in the future

Security 1/2 Several methods are available to protect your investment Use wireless access lists to stop unauthorized users connecting to the highsite Considering using WEP / WPA to encrypt communication this will place extra CPU load on the system Use PPPOE with MSCHAPv2 to encrypt username and password setting

Security 2/2 Use firewall address lists to drop all outgoing traffic not listed as a registered client Use separate NAT rules per client as additional security Static ARP or Reply-only can enhance security HotSpot can be used where you require clients to enter a username and password for internet access

Wireless Wireless setup depends on client side equipment Use technology like Nstreme if all clients run Mikrotik to more efficiently manage data transfer and also enhance security Disable Default Authenticate and Default Forward Use 6 channel spacing on 2.4Ghz for multiple sector layouts. Even better use 5.8Ghz for clients Use 5.8 Ghz on backhaul point to point links Use the Regulatory Domain feature of Mikrotik to keep within legal power limits

Backhaul The backhaul link will carry all the traffic for your clients Use 5.8Ghz only to ensure a solid link Use ptp addressing and good security between backhaul links Consider active routing technology such as OSPF to maintain redundancy and load balancing on your network

Backhaul DON T use /30 addressing unless combined with additional security it is very easy to hack DO use multiple paths for redundancy on the network

Setting up the Client Client setup depends on the highsite configuration Typical client setup: Wireless connection PPPoE / IP Address on Wlan interface IP Routing (for manual IP setup) IP DNS (for manual IP setup) LAN IP setup LAN DHCP Setup Masquerade rule

Basic Router Setup Checklist 1. Connect via MAC Winbox to router 2. Add ethernet IP address 192.168.1.254/24 3. Connect to highsite wireless SSID=wisp101 4. Add wlan ip 10.1.1.x/24. Confirm that you can ping 10.1.1.254 5. Add a default route of 10.1.1.254 6. Add a DNS server 10.1.1.254. Allow remote requests 7. Change the router s Identity 8. Add a firewall masquerade rule 9. Setup DHCP Server on the ethernet port 10. Setup / check the client computers IP settings 11. Confirm that you can access the Internet

More Information WAPA Wireless Access Providers Association http://wapa.org.za Mikrotik support in South Africa http://www.mikrotiksa.com david@mikrotiksa.com Mikrotik Global http://www.mikrotik.com