Académique Documents
Professionnel Documents
Culture Documents
RouterOS v6
MUM South Africa 2013
ohannes!ur"
Uldis #ernevskis
MikroTik
Topics
$
%uickset for Wireless
$
Transparent &ireless links
$
Useful confi"uration settin"s and features
%uickset
$
'e& clicks to setup MikroTik router
$
A( and #() *odes
$
(oint to (oint +rid"e *ode ,startin" fro*
RouterOS v-.21/
0o& to "et %uickset
Win!o1
0o& to "et %uickset
We!2interface
%uickset feature support
$
R+ S3T
$
R+ 4roove
$
R+ Metal
$
R+ 51167116811
$
Other Router+oards ,usin" first &ireless
interface/
%uickset Setup
A( %uickset
$
Access router !9 !ro&ser or Win!o1
$
#onfi"ure A( settin"s
:
;( address< "ate&a9
:
Wireless ,SS;=< fre>uenc9< !and< securit9<
etc./
:
?AT
:
Additional confi"uration
A( %uickset =e*o
#() %uickset
$
Access router !9 !ro&ser or Win!o1
$
#onfi"ure #() settin"s@
:
Router or +rid"e
:
;( address< "ate&a9
:
Wireless ,SS;=< !and< securit9/
#() %uickset =e*o
(oint to (oint +rid"e %uicket
Wireless
Server6A(
#lient6#()
#lient
?et&ork
;nternet
Server6A( +rid"e %uickset
$
Access router !9 !ro&ser or Win!o1
$
#onfi"ure Server6A( settin"s@
:
Wireless +rid"e Mode to Server6A(
:
;( address< "ate&a9
:
Wireless ,SS;=< !and< fre>uenc9< securit9/
Server6A( +rid"e %uickset =e*o
#lient6#() +rid"e %uicket
$
Access router !9 !ro&ser or Win!o1
$
#onfi"ure #lient6#() settin"s@
:
Wireless +rid"e Mode to #lient6#()
:
;( address< "ate&a9
:
Wireless ,SS;=< !and< securit9/
#lient6#() +rid"e %uickset
=e*o
#onnection T9pes
(oint to (oint ,(T(/ (oint to Multi (oint ,(TM(/
(T(6(TM( connection *odes
$
A(2!rid"e6+rid"e A2B Station
$
A(2!rid"e6+rid"e A2B Station2&ds6Station2
!rid"e
$
A(2!rid"e6+rid"e A2B Station2
pseudo!rid"e
$
A(2!rid"e6+rid"e A2B A(2!rid"e6+rid"e
$
A(2!rid"e A2B W=S2slave
RouterOS license re>uire*ents
$
(T( link re>uires at least Cevel 3
:
)1a*ple@ +rid"e A2B Station
$
(TM( link re>uires on A( at least Cevel 8
and on clients at least Cevel 3
:
)1a*ple@ A(2!rid"e A2B Station
Re"ular (TM( setup
Wireless Setup T9pe 2 Routin"
Wireless Setup T9pe 2 +rid"in"
Wireless Setup T9pes
$
+rid"in"
$
Advanta"e
: Cess ;( confi"uration
needed
$
=isadvanta"e
: #lients !roadcast traffic or
flood can lo&er &ireless
net&ork perfor*ance
: ?ot suita!le for lar"e
net&ork
$
Routin"
$
Advanta"e
: ?o !roadcast traffic or
flood that could lo&er
&ireless net&ork
perfor*ance
$
=isadvanta"e
: More confi"uration needed@
*ultiple ;( net&orks or use
of routin" protocols
Transparent Wireless Cinks
$ Cess confi"uration needed
$ )1tends Ca9er 2 protocol to clients ,&ireless
ethernet s&itch/
$ Suita!le for (((o) access
Transparent Wireless Cinks Setups
$
+rid"e A2B Station2pseudo!rid"e
$
+rid"e A2B Station usin" )O;(
$
+rid"e A2B +rid"e
$
+rid"e A2B Station2&ds
$
+rid"e A2B Station2!rid"e
)O;( !rid"in" setup
+rid"e A2B +rid"e setup
Station2&ds setup
Station2!rid"e setup
Station2!rid"e
$
A( *aintains for&ardin" ta!le &ith infor*ation
on &hat MA# addresses are reacha!le over
&hich station device
$
A( should have !rid"e2*ode para*eter ena!led
in order to accept station2!rid"e clients
$
#an !e connected onl9 to RouterOS A( !ased
devices
$
)ven less confi"uration needed co*pared to
station2&ds *ode
Station2!rid"e confi"uration
$
On A( ena!le the !rid"e2*ode para*eter
$
#onfi"ure client to use station2!rid"e
*ode
$
+rid"e &ireless interface &ith ethernet
interface to *ake transparent link
Wireless protocol li*itations on
transparent links
D02.11 ROS D02.11 ?stre*e ?v2
station
E E E E
station2&ds
E E E
station2pseudo!rid"e
E E E
station2pseudo!rid"e2
clone
E E E
station2!rid"e
E E E
D02.11n
$
Works !oth in 2.8 and -"hF
$
;ncreased data rates : up to 300M!ps or
8-0M!ps
$
20MhF and 2120MhF channel support
$
Uses *ultiple antennas for receive and
trans*it
$
'ra*e a""re"ation
D02.11n 2120MhF channel option
$
Adds additional 20MhF channel to e1istin"
channel
$
#hannel placed !elo& or a!ove the *ain
channel fre>uenc9
$
Adds support for hi"her data2rates :
1-0M!ps6300M!ps68-0M!ps
$
+ack&ards co*pati!le &ith 20MhF clients :
connection *ade to the *ain channel
$
?ot co*pati!le &ith le"ac9 80MhF Tur!o *ode
Up"rade le"ac9 &ireless link to
D02.11nG
$
We reco**end to up"rade 9our le"ac9
&ireless links to D02.11n even if 9ou have
one antenna@
:
0i"her data2rate than le"ac9 &ireless< data2
rates up to 72.2M!ps or 1-0M!ps
:
Real U=( traffic up to 12-M!ps
:
?o need to chan"e antennas or !oard : onl9
&ireless card
D02.11n and W=S
$
D02.11n fra*e a""re"ation canHt !e used
to"ether &ith W=S
$
Ma1 trans*it speed drops fro* 220M!ps to
160M!ps usin" W=S ,U=( traffic/
$
Station2!rid"e has the sa*e speed li*itations as
Station2&ds
$
Avoid usin" W=S or use ?stre*e6?v2 &ireless
protocol to overco*e this li*itation
D02.11n Outdoor Setup
$
'or 2 chain operation su""ested to use
different polariFation for each chain
$
When dual2polariFation antennas are used
isolation of the antenna reco**ended to
!e at least 2-d!
$
;f possi!le test each chain6antenna
separatel9 !efore usin" !oth chains at the
sa*e ti*e
D02.11n speed &ith encr9ption
$
Avoid usin" &ireless
encr9ption &ith TI;(
cipher as it slo&s
do&n the &ireless link
: speed drop fro*
220M!ps to 3DM!ps
$
Use A)S cipher for
D02.11n &ireless
encr9ption
AR531165-11 &ireless support
$
Short 4uart ;nterval support on 20MhF
*ode : data rates up to 72.26188M!ps
$
3 antenna connector support for 313
M;MO setup
$
Up to 3 Spatial Strea*s
$
Up to M#S 23 : data2rate up to 8-0M!ps
$
U=( transfer up to 370M!ps
$
?o support for advanced channels 9et
AR531165-11 &ireless support
0idden node issue
$
;n (TM( setups &hen client doesnHt see
other clients traffic and sends at the sa*e
ti*e A( "ets JcollisionsK : lo&ers
perfor*ance
$
Use h&2protection #TS6RTS or J#TS to
selfK
$
Use ?stre*e or ?v2 protocol
?E2
$
(roprietar9 &ireless protocol developed !9
MikroTik
$
+ased on T=MA ,Ti*e =ivision Multiple
Access/ *edia access technolo"9
$
Works on Atheros chipset cards@
:
AR-813 and ne&er chipset cards ,R-2/
:
? chipset cards ,R-2n<R-20n<R11e/
$
Supported fro* RouterOS v-
T=MA !enefits
$
More throu"hput
$
Co&er latenc9
$
Suited &ell for (oint2to2Multi(oint
net&orks
$
Solves hidden node pro!le*s
?v2 co*pati!ilit9 and coe1istence &ith
other &ireless protocols
$
Onl9 RouterOS devices &ill !e a!le to
participate in ?v2 net&ork
$
Onl9 RouterOS devices &ill see ?v2 A( &hen
scannin"
$
?v2 net&ork &ill distur! other net&orks in the
sa*e channel
$
?v2 net&ork *a9 !e affected !9 an9 ,?v2 or
not/ other net&orks in the sa*e channel
$
?v2 ena!led device &ill not connect to an9 other
T=MA !ased net&ork
?v2 U=( on R+D00
?v2 T#( on R+D00
Split horiFon feature
$
To disa!le
co**unication !et&een
W=S devices usuall9 9ou
&ould need to add !rid"e
fire&all rules &hich *i"ht
!e co*ple1
$
Another solution is to use
split horiFon feature in the
!rid"e ports confi"uration
: packets &ill not !e
for&arded !et&een ports
&ith the sa*e horiFon
value
Split horiFon feature
$
#reate !rid"e interface
$
Add internet access interface to the !rid"e port
$
Add each W=S interface to the !rid"e port and
specif9 the sa*e horiFon value< for e1a*ple 1
$
;f 9ou &ish to allo& co**unication fro* ever9
W=S clients to a specific W=S client then add
that specific W=S to the !rid"e port &ithout
horiFon value
0T T36R3 chain confi"uration
$
When !oard has !oth
antennas connected it is
su""ested to use all the
T36R3 chains to "et the
!est speed and sta!ilit9
$
;n order to use onl9
chain1 the chain0 R3
should !e al&a9s ena!led
in order to *ake the
&ireless link to &ork
Router+oard &ireless !oards
$ )ver9 &ireless Router+oard has
RouterOS default2confi"uration
script ena!led on the first !oot
$ 'or &ireless !oards default2
confi"uration ena!les all availa!le
&ireless chains
$ Make sure that 9ou have antennas
connected to all antenna
connectors to avoid da*a"in"
&ireless cards a*plifierL
$ Also if 9ou use onl9 one chain on
the !oard *ake sure 9ou donHt
ena!le it if 9ou donHt have antenna
connected to it.
Router+oard &ireless !oards
$ Router!oard R11e
&ireless *ini2pcie
card chains are
inverese co*pared
to other *ini2pci
&ireless cards@
: #hain 0 : Ri"ht
: #hain 1 : Ceft
W(A2 (rivate (re Shared Ie9
$
Allo&s to specif9 for a MA# address
different pre2shared ke9 fro* the pre2
shared ke9 in the securit9 profile
$
;t is possi!le to specif9 for each MA#
address different pre2shared ke9
$
;ncreases the securit9 level of the A(
$
#an !e "iven also !9 RA=;US
W(A2 (rivate (re Shared Ie9
Rate2selection : le"ac9
$
Rate2selection default value for RouterOS
versions older than v-.5
$
Re*oved in v6.1 : replaced &ith advanced
$
Works &hen &ireless link is "ood in all data2
rates
$
=oesnHt s&itch so &ell fro* + standard to 4
standard data2rates
$
=oesnMt s&itch fro* A64 to ? data rates &here
fra*e a""re"ation can !e used
$
=oesnHt s&itch fro* 20*hF to 80*hF in ? data2
rates< for e1a*ple< &hen *cs1321- doesnHt &ork
sta!le
Rate2selection : le"ac9
Rate2selection : advanced