Professional Documents
Culture Documents
Mtcna 2015
Mtcna 2015
Mani Raissdana
Support & Testing Engineers for more than 7 years
Specialization: Routing,
Routing Wireless,
Wireless QoS,
QoS Firewall,
Firewall Dude
©MikroTik 2015 4
• MikroTik Certified Trainers
http://www.mikrotik.com/training/partners/europe/turkey
• MikroTik Certified Consultants
http://www.mikrotik.com/consultants/europe/turkey
• Mani Raissdana ‘s Certifications
htt //
http://www.mikrotik.com/certificate_search.php
ik tik / tifi t h h
Search for Mani Raissdana
• Mani Raissdana’s Resume
www.mits-co.com/sites/default/files/Mani%20Raissdana%20Resume.pdf
©MikroTik 2015 5
Turk Cell: +90 (537) 495 3233
vate Ce
Private Cell:: +98
98 (912)
(9 ) 1499 7009
International Cell:+37259431151
Official Phone: +98 (21) 88 400 717 ext:1102
Skype: mani_raissdana
m.raissdana@mits-co.com
raissdana mani@gmail com
raissdana.mani@gmail.com
www.mits-co.com MikroTikEngineers
©MikroTik 2015 8
©MikroTik 2015 9
• Overview of RouterOS software and
RouterBoard capabilities
p
• Hands-on training for MikroTik router
configuration,
g , maintenance and basic
troubleshooting
©MikroTik 2015 10
• Module1: Introduction
• Module2:
M d l 2 Network
N t kMManagementt
• Module3: Firewalling
• Module4: QoS
• Module5: Wireless
• Module6: Bridging
• Module7: Routingg
• Module8: Tunneling
• Module9: Proxy
©MikroTik 2015 11
©MikroTik 2015 12
• Router
R t software
ft and
d hardware
h d manufacturer
f t
• P d t used
Products d by
b ISPs,
ISP companies
i and
d individuals
i di id l
• Make
k Internet technologies
h l i faster,
f powerful
f l and
d affordable
ff d bl
to wider range of users
©MikroTik 2015 13
• 1995:
1995 EEstablished
t bli h d
©MikroTik 2015 14
• Riga, Latvia, Northern Europe, EU
• www.mikrotik.com
• www.routerboard.com
• www.wiki.mikrotik.com
• www.mum.mikrotik.com
• www.forum.mikrotik.com
f ik tik
• www.tiktube.com
• www.mikrotikiran.ir
©MikroTik 2015 15
©MikroTik 2015 16
• RouterOS is a stand-alone operating system
based on the Linux v3
v3.3.5
3 5 kernel
©MikroTik 2015 17
RouterOS is an operating system that will make your device:
• a dedicated router
• a bandwidth shaper
• a (transparent) packet filter
• any 802.11 a , b , g , n and ac wireless device
©MikroTik 2015 18
• Hardware created by MikroTik
• Range from small home routers to carrier-
class access concentrators
©MikroTik 2015 19
• These p
products are pprovided complete
p with cases
and power adapters.
• Ready to use and preconfigured with the most basic
functionality.
• All you need to do is to plug it in and connect to the
Internet or a corporate network.
©MikroTik 2015 20
Router names are selected according to feature set. Here are
some examples:
• CCR : Cloud Core Router
• RB : RouterBoard
• 2,, 5 : 2,4GHZ
, or 5GHz wifi radio
• H : High powered radio
• S : SFP
• U : USB
• i : Injector
• G : Gigabit ethernet
http://wiki.mikrotik.com/wiki/Manual:Product_Naming
©MikroTik 2015 21
©MikroTik 2015 22
• Process of communication is divided into
seven layers
l
• Lowest is physical layer, highest is
application layer
©MikroTik 2015 23
©MikroTik 2015 24
• It is the unique physical address of a
network
t kddevice
i
• It’s used for communication within LAN
• Example: 00:0C:42:20:97:68
©MikroTik 2015 25
• It is logical address of network device
• It is used for communication over networks
• Example:p 159.148.60.20
©MikroTik 2015 26
• Range of logical IP addresses that divides
network
t k iinto
t segments t
• Example: 255.255.255.0 or /24
©MikroTik 2015 27
• Network address is the first IP address of the
subnet
b t
• Broadcast address is the last IP address of
the subnet
• Theyy are reserved and cannot be used
©MikroTik 2015 28
©MikroTik 2015 29
• Select IP address from the same subnet on
l l networks
local t k
• Especially for big network with multiple
subnets
©MikroTik 2015 30
• Clients use different subnet masks /25 and /26
• A has 192.168.0.200/26 IP address
• B use subnet mask /25, available addresses
192.168.0.129-192.168.0.254
• B should not use 192.168.0.129
192.168.0.129-192.168.0.192
192.168.0.192
• B should use IP address from 192.168.0.193 -
192 168 0 254/25
192.168.0.254/25
©MikroTik 2015 31
©MikroTik 2015 32
Null Modem Ethernet
Cable cable
©MikroTik 2015 33
Requires the computer
be connected to the router
via a null-modem
(RS-232 port).
port)
Default is 115200bps,
8 data
d bits,
b 1 stop b
bit,
no parity
p y
©MikroTik 2015 34
Standard IP tools to access router
Telnet communications are in clear text
Available on most Operating Systems
Unsecured!!
SSH communications are encrypted
Secured!!
d
Manyy Open
p Source ((free)) tools available such as
PuTTY (http://www.putty.org/)
©MikroTik 2015 35
Stands for Command Line Interface
It’ss what you see when you use the console port,
It port
SSH, Telnet, or New Terminal (inside Winbox)
©MikroTik 2015 36
Ethernet
Cable
Winbox
©MikroTik 2015 37
• The application for configuring RouterOS
• It can be downloaded from
www.mikrotik.com
©MikroTik 2015 38
©MikroTik 2015 39
in the browser, scroll down
g
and click “logout”
You will see:
Click on “Winbox”
Winbox Download Winbox
Save “winbox.exe”
©MikroTik 2015 40
Click on the [...] button to see your router
©MikroTik 2015 41
You may or may not have a basic configuration when
freshly installed
You may choose not to take the default basic
configuration
g
Check the following web page to find out how your
device will behave:
http://wiki.mikrotik.com/wiki/Manual:Default_Configura
tions
©MikroTik 2015 42
When connecting for
the first time with
WinBox, click on “OK”
The router now
©MikroTik 2015 43
The minimal steps to setup a basic access to the
Internet (if your router does not have a default
b
basic configuration)
f )
LAN IP addresses, Default g gateway y and DNS
server
WAN IP address
NAT rule (masquerade)
SNTP client and time zone
©MikroTik 2015 44
Intuitive way of connecting to a RouterOS router
Connect to router with Ethernet cable
Launch browser
Type in the IP address
If asked for, log in. Username is “admin” and
password is blank
©MikroTik 2015 45
©MikroTik 2015 46
• Click on the Mac-Address in Winbox
©MikroTik 2015 47
©MikroTik 2015 48
Class AP
Your Laptop Your Router
©MikroTik 2015 49
• Disable any other interfaces (wireless) in
your laptop
l t
• Set 192.168.X.1 as IP address
• Set 255.255.255.0 as Subnet Mask
• Set 192.168.X.254 as Default Gateway
• Set 192.168.X.254 as DNS1
©MikroTik 2015 50
• Connect to router with MAC-Winbox
• Add 192.168.X.254/24
192 168 X 254/24 to Ether5
©MikroTik 2015 51
• Close Winbox and connect again using IP address
©MikroTik 2015 52
Class AP
Your Laptop Your Router
192.168.X.1 192.168.X.254
©MikroTik 2015 53
Class AP
Your Laptop Your Router
192.168.X.1 192.168.X.254
©MikroTik 2015 54
• The Internet gateway of your class is
accessible
ibl over wireless
i l - it is
i an AP (access
(
point)
• To connect you have to configure the
wireless interface of your router as a station
©MikroTik 2015 55
To configure
wireless
l
interface,
d bl l k
double-click
on it’s name
©MikroTik 2015 56
• To see available AP use scan button
• Select MTCNA and click on connect
• Close the scan window
• You are now connected to AP!
• Remember class SSID MTCNA
©MikroTik 2015 57
• The wireless interface also needs an IP
address
dd
• The AP provides automatic IP addresses
over DHCP
• You need to enable DHCP client on your
y
router to get an IP address
©MikroTik 2015 58
©MikroTik 2015 59
Check Internet
connectivity
by traceroute
©MikroTik 2015 60
Class AP
Your Laptop Your Router
DHCP-Client
Wi l
Wireless
©MikroTik 2015 61
• Laptop can access the router and the router
can access th
the iinternet,
t t one more step
t iis
required
• Make a Masquerade rule to hide your
private network behind the router, make
Internet workk in your llaptop
©MikroTik 2015 62
• Masquerade is used for Public network access,
where private addresses are present
• Private networks include 192.168.0.0-192.168.255.255
10.0.0.0-10.255.255.255, 172.16.0.0-172.31.255.255,
©MikroTik 2015 63
©MikroTik 2015 64
©MikroTik 2015 65
©MikroTik 2015 65
Your router can be a DNS server for your local
networkk (laptop)
(l )
©MikroTik 2015 66
• Tell your Laptop to use your router as the
DNS server
• Enter your router IP (192.168.x.254) as the
DNS server in laptop network settings
©MikroTik 2015 67
Ping www.mikrotik.com from your laptop
©MikroTik 2015 68
• Router cannot ping further than AP
• Router cannot resolve names
• Computer
p cannot p
ping
g further than router
• Computer cannot resolve names
• Is masquerade rule working
• Does the laptop use the router as default
gatewa and DNS
gateway
©MikroTik 2015 69
Class AP
Your Laptop
p p Your Router
192.168.X. 192.168.X.25
1 4
DHCP-Client
©MikroTik 2015 70
©MikroTik 2015 71
• Access to the router can be controlled
• You can create different types of users
©MikroTik 2015 72
©MikroTik 2015 73
©MikroTik 2015 74
Fix a known bug.
Need a new feature.
Improved
p p
performance.
NOTE :
PLEASE read
the changelog!!
©MikroTik 2015 75
Know what architecture (mipsbe, ppc, x86, mipsle,
tile) you are upgrading.
If in doubt, Winbox indicates the architecture in top
left corner!
Know what files you require:
NPK : Base RouterOS image with standard packages
(Always)
ZIP : Additional packages (based on needs)
Changelog : Indicates what as changed and special
i di i
indications (Always)
(Al )
©MikroTik 2015 76
Three ways:
Download file(s)
( ) and copy
py over to router.
“Check
Check for updates”
updates (System -> Packages)
Auto Upgrade
d (System
( -> Auto Upgrade)
d )
©MikroTik 2015 77
Get the package files from
MikroTik’s website
Downloads page
Copy to Router ftp
Reboot
©MikroTik 2015 78
Through the menu “System -> Packages”
Click on “Check
Check for Updates
Updates” then “Download
Download &
Upgrade”
R b t automatically
Reboots t ti ll
©MikroTik 2015 79
Copy required files by all routers to an internal
router (source).
Configure all routers to point to source router
Display
sp ay ava
available
ab e packages
Select and download packages
Reboot and validate
alidate router
©MikroTik 2015 80
©MikroTik 2015 81
Check current version
©MikroTik 2015 82
• Download packages from ftp://100.100.100.1
• Upload them to router with Winbox
• Reboot the router
• Newest packages are always available on
www.mikrotik.com
©MikroTik 2015 83
Option
p to set name for each router
©MikroTik 2015 84
Id i information
Identity i f i isi shown
h in
i different
diff places
l
©MikroTik 2015 85
Set your number + your name as router identity
©MikroTik 2015 86
• Network
N t k Ti
Time P
Protocol,
t l tto synchronize
h i titime
• NTP Client and NTP Server support in
RouterOS
©MikroTik 2015 87
NTP package
k iis nott required
i d
©MikroTik 2015 88
Manage IP services to
Limit resource usage
g ((CPU, memory) y)
Limit security threats (Open ports)
Change TCP ports
Limit accepted IP addresses / IP subnets
To control services, g
go to “IP -> Services”
Disable or enable required services.
©MikroTik 2015 89
Double-click on a service
If needed, specify which
hosts or subnets can
access the service
Good practice to limit
certain services to
network administrators
©MikroTik 2015 90
• You can backup and restore configuration in
the Files menu of Winbox
• Backup file is not editable
Complete system backup
Includes passwords
Assumes that restores will be on same router
©MikroTik 2015 91
• Additionally use export and import commands in CLI
• Export files are editable
• Passwords are not saved with export
• Complete
p or p
partial configuration
g
• Generates a script file or sends to screen
• Use “compact” to show only non-default configurations
((default on ROS6))
• Use “verbose” to show default configurations
©MikroTik 2015 92
©MikroTik 2015 93
Once generated, copy them to a server
With SFTP ((secured approach)
pp )
With FTP, if enabled in IP Services
Using drag and drop from “Files”
Files window
Leaving backup files on the router IS NOT a good
archi al strateg
archival strategy
No tape or CD backups are made of routers
©MikroTik 2015 94
• Create Backup and Export files
• Download them to your laptop
• Open
p export
p file with text editor
©MikroTik 2015 95
• All RouterBOARDs shipped with license
• Several levels available, no upgrades
• Can be viewed in system
y license menu
• License for PC can be purchased from
mikrotik.com or from distributors
©MikroTik 2015 96
http://wiki.mikrotik.com/index.php?title=Manual:Licen
p // / p p
se&redirect=no
©MikroTik 2015 97
©MikroTik 2015 98
©MikroTik 2015 99
©MikroTik 2015 100
• Used for installing and reinstalling RouterOS
• Runs on Windows computers
• Direct network connection to router is
requiredd or over switched
h d LAN
• Available at www.mikrotik.com
• 4 Steps:
1
1. Changing Router
Router’ss boot order
2. Configure Netbooting
3
3. R b
Reboot the
h router
4. Select Packages and click “Install”
1012015
©MikroTik 101
1.List of routers
2.Net Booting
3.Keepp old
configuration
4.Packages
5.Install
1022015
©MikroTik 102
©MikroTik 2015 103
Press the “reset” button until the “ACT” LED
turns off
Router will appear in “Routers/Drives”
Routers/Drives
section
Select it!
Select required RouterOS version from
“P k
“Packages” ” section
ti
“Install” button becomes available; click it!
42 : NTP Servers
70 : POP3
POP3-Server
Server
Visit www.iana.org/assignments/bootp-dhcp-
parameters/bootp dhcp parameters xhtml for more
parameters/bootp-dhcp-parameters.xhtml
DHCP options
/ dhcp-server
/ip dh option add
dd name=46-node-type
d code=46
d
value=0x0008
Assign a DHCP option to a network
/ip
/ p dhcp-server
p network pprint ((to view available networks))
/ip dhcp-server network set dhcp-option=46-node-type
numbers 1
numbers=1
Assign a WINS server to a network
/i dhcp-server
/ip dh networkk set wins-server=172.16.2.100
i 172 16 2 100
numbers=1 ©MikroTik 2015 119
• Setup DHCP server on Ethernet Interface
where
h L
Laptop
t iis connected
t d
• Change computer Network settings and
enable DHCP-client (Obtain an IP address
Automatically)
• Check the Internet connectivity
124
©MikroTik 2015 124
Allows Ethernet-like interfaces to request an IP
address.
The remote DHCP server will supply:
dd ess/Mask/ e au t gateway/Two
Address/Mask/Default gateway/ wo DNS NS servers
se ve s
(if the remote DHCP server is so configured)
The DHCP client will supply configurable options:
/export file=export
/tool e-mail send to=home@gmail.com
/ g subject="$[/system
j $[/ y
identity get name] export"\body="$[/system clock get
date]] configuration
g file" file=export.rsc
p
B made
Be d aware off network
t k ffailures
il
Automate a change of default gateway, for example, should
the main router fail
Just to have a q
quick view of what is up p
Whatever else you can come up with to simplify and speed
up your job (and make you look efficient!)
©MikroTik 2015 129
Basic connectivity tool that uses ICMP Echo
messages to determine remote host accessibility
andd round-trip
d d l
delay
One of the first tools to use to troubleshoot. If it
pings, the host is alive (from a networking point of
view)
Use it with other tools when troubleshooting. It's
not THE ultimate tool,, but a good
g start
/log print
Forward
WWW E-Mail
E M il
• Automatically
A t ti ll add
dd addresses
dd by
b address-list
dd li t and
d th
then
block
For example,
p y you could create 100 rules to block 100
addresses, or!!
You could create one ggroup p with those 100 addresses and
create only one filter rule.
New DST
DST-Address
Address DST-Address
DST Address
192.168.1.1:80 207.141.27.45:80
New DST
DST-Address
Address
Router:53
DNS Cache
Tree
ee principle:
p c p e: Parent
a e t-C
Child
d
CIRc1+CIRc2+...+CIRcn
CIRc1+CIRc2+ +CIRcn ≤ MIR Parent
MIRc1, MIRc2,..., MIRcn ≤ ©MikroTik
MIR 2015 Parent 208
Queue03
Q 03 will
ill receive
i 6Mb
6Mbps
Queue04 will receive 2Mbps
Queue05 will receive 2Mbps
Clarification: HTB was build in a way
way, that
that, by satisfying all limit-ats,
limit ats main queue no longer have throughput to
distribute
2. Satisfy
y other children limit-at ((Which are the parent
p of
others)
• client download
• client upload
• Target
g to which the simple
p q queue is applied
pp
• A target MUST be specified. It can be
1
1. An IP address
2. A subnet
3. An interface
f
• Target-address
Target address and DST-addresses
DST addresses can
be vice versa
For example, in the case of uploaded traffic, we check input and output interfaces (global) for
packets with the "client_upload" mark and apply the "PCQ_upload" queue type
150 5180 5200 5220 5240 5260 5280 5300 5320 5350
5760 5800
W & dbm
db Ratio:
R ti
1W=30dbm
1W 30dbm
Incoming Power 2W=33dbm
W - mW 3W 36db
3W=36dbm
©MikroTik 2015 254
• Gain: Ability to amplify and spread out Radio Freq… dbi
• Polarity: H or V
Omni Directional:
l (PTMP)
( ) ((360°)
6 )
Solid Dish
Sector
• Ma ua txpowe : Sa
Manual-txpower: Samee as above but without
w t out TX
power restriction
I t ll Dude
Install D d S
Server on computer
t
©MikroTik 2015 350
• Dude is translated to different languages
• Available on wiki.mikrotik.com