Location via proxy:   [ UP ]  
[Report a bug]   [Manage cookies]                

T Us Take in Consideration The Network Diagram Below

Download as pdf or txt
Download as pdf or txt
You are on page 1of 30

t us take in consideration the network diagram below

22
We take as granted that our
R1 router already has internet
access, through port Ether1
23
Create a bridge, that will have
as ports all the wireless
interfaces of our CAPs. It will
serve as “datapath”.
24
Give to the bridge an IP
address with the desired
mask.

25
Add a srcnat-masquerade
rule in IP-Firewall, for
unknown reasons ☺

26
Setup a DHCP-Server in the
BridgeCAPS interface. It will
serve IP addresses to the
clients of the Wifi Network
27
CAPsMAN Setup. Normally
you start from right to left.
Security Cfg. Tab can be the
first.
28
Add a new Security
Configuration. Input
Auth.Type, Encryption and
Passphrase
29
In Datapaths tab, add a new
Datapath Config, input as
Bridge our bridgeCAPS

30
In Configurations tab, add a
new config, Mode: ap,
SSID: yourSSID. Don’t press
OK but go to tab Datapath in
31
this window.
In Datapath, choose our
datapath named: “datapath1”.
In Security, choose our
32 security profile: security1
In Provisioning, we add a new
CAPs Prov., Action: create
enabled, Name Format:
Identity.
33
In CAP Interface, press:
Manager, Enable it.
Press Interfaces button
34
Add the interface where you
have your internet
connection: ether1Wan with
forbid=yes
Last, press OK in CAPs
Manager Window.
35
CAPsMAN

We finished setting-up
CAPsMAN. Now let’s setup the
CAPs.
36
In R2, or all CAPs that we
need to add to this CAPsMAN,
we do the following in
Interface -> Wireless -> CAP
37
Since our R1 router, has
wireless interfaces of its own,
we can also add them to the
CAPsMAN. This is the final
view of our setup.
38
Monitor client connections in
Registration Table.
39
/interface bridge add name=bridgeCAPS
/ip address add interface=bridgeCAPS address=192.168.8.1/24
/caps-man datapath
add bridge=bridgeCAPS client-to-client-forwarding=no local-forwarding=no
name=datapath1
/caps-man security
add authentication-types=wpa-psk,wpa2-psk encryption=aes-ccm name=security1
passphrase=\
mikrotikriga
/caps-man configuration
add datapath=datapath1 mode=ap name=cfg1 security=security1 ssid=YourSSID
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-enabled master-configuration=cfg1 name-format=identity

40
/interface wireless cap set discovery-interfaces=ether1 interfaces=wlan1,wlan2
enabled=yes

41
VS

Any difference?

42
43

Extensive setups

Frequency tunning Virtual SSID


Use only non-overlapping Offer multiple SSID in the same
Permit only g/n APs, giving possibility to have
different networks in the same
Limit data-rates physical setup

VLANs Access Control


Use of VLANs in these networks, Play with access control options,
gives the possibility to create to have as much control as
smaller and isolated networks possible over the clients
for different purposes connecting, based on signal,
mac, etc
Create manually the channels
1,6,11 for 2.4GHZ and put
also the band to 2ghz-g/n to
not use the old nasty 2ghz-b.
Input the channels manually
for each interface.
44
/caps-man access-list
add action=accept allow-signal-out-of-range=10s disabled=no interface=any \
signal-range=-80..120 ssid-regexp=""
add action=reject allow-signal-out-of-range=10s disabled=no interface=any \
signal-range=-120..-81 ssid-regexp=""
Make roaming as easy as
possible.
45
Set slave configurations so
each interface in CAPsMAN
will have automatically added
virtual interfaces for different
purposes
46
Set slave configurations so
each interface in CAPsMAN
will have automatically added
virtual interfaces for different
purposes
47
48

Multiroom Resort Setup

123 x wsAP ac Lite


10 x wAP ac
10 x cAP Ac
6 x CRS328-24P-
4S+RM
1 x CCR1009-7G-1C
49
50

After we setup CAPsMAN, we have:


Conclusion ▫ Much more control over the Wifi Network
▫ Easier expansion
▫ More stable client connections
▫ A nearly unlimited number of options on
configurations of such networks

▫ Happy Clients
▫ Paid Invoices
Thank you for your attention!

Questions?
Drop an e-mail at erioni@gmail.com and/or
follow Mikrotik.Albania in Instagram

51

You might also like