Showing posts with label Wifi. Show all posts
Showing posts with label Wifi. Show all posts
Mikrotik Wifi Hotspot

Mikrotik Wifi Hotspot

Routing

Policy Routing
MikroTik RouterOS supports policy based routing. Routing can be performed based on:
  • Several routing tables are maintained
  • Each routing table has its own static and default routes
  • Selection of routing table to be used is based on several criteria:
  • - Source/destination address
  • - Protocol, port
  • - Interface
View PDF documentation
IP Routes Manual

Routing Protocols
Routing protocols enable information exchange about routing between routers and eases the network administration. Following routing protocols are supported by MikroTik RouterOS:
  • RIP v1 and v2
  • OSPF
  • BGP
RIP Manual
OSPF Manual
BGP Manual

Load Balancing

Load Balancing
Load balancing is implemented as equal cost multipath routing. With load balancing two or more gateways can be specified for the same destination. That applies to the default one as well. Equal cost multipath routes can be created by routing protocols (RIP or OSPF), or by adding a static route with multiple gateways. The routing protocols may create routes with equal cost automatically, if the cost of the interfaces is adjusted properly.
  • A new gateway is chosen for each new connection
  • Single connection packets do not get reordered
  • Load balancing does not provide failover
IP Routes Manual

Tunnels and VPN

PPTP (Point to Point Tunnel Protocol)
PPTP (Point to Point Tunnel Protocol) supports encrypted tunnels over IP. The MikroTik RouterOS implementation includes support for PPTP client and server. General applications of PPTP tunnels
  • For secure router-to-router tunnels over the Internet
  • To link (bridge) local Intranets or LANs (when EoIP is also used)
  • For mobile or remote clients to remotely access an Intranet/LAN of a company (see PPTP setup for Windows for more information)
PPTP Manual

EoIP (Ethernet over IP)
Ethernet over IP (EoIP) Tunneling is a MikroTik RouterOS protocol that creates an Ethernet tunnel between two routers on top of an IP connection. When the bridging function of the router is enabled, all Ethernet traffic (all Ethernet protocols) will be bridged just as if there where a physical Ethernet interface and cable between the two routers (with bridging enabled). This protocol makes multiple network schemes possible.
EoIP Manual

IPSec (IP Security)
IPsec (IP Security) supports secure (encrypted) communications over IP networks.
IPSec Manual

Bridging

Interface Bridging
MikroTik RouerOS supports MAC level bridging of Ethernet packets. Ethernet, Ethernet over IP (EoIP), Prism, Atheros and RadioLAN interfaces are supported. The Bridge Interfaces can also be Firewalled.
  • Spanning Tree Protocol (STP)
  • Multiple bridge interfaces
  • Bridge associations on a per interface basis
  • Protocol can be selected to be forwarded or discarded
  • MAC address table can be monitored in real time
  • IP address assignment for router access
  • Bridge interfaces can be firewalled
Bridge Manual

Transparent Bridging of Remote LANs
Remote LANs can be transparently bridged over secure VPN connections by means of Ethernet over IP tunnels and Ethernet bridge. One MikroTik Router is required per one remote LAN. The Routers should be able to communicate with each other over public network. Secure VPN tunnels are established between them. EoIP tunnels are run over these VPN connections with bridging between EoIP and LAN interfaces.
  • VPN, EoIP, and Bridge features are included in the Base License
  • PPTP, L2TP, or IPsec can be used for secure VPNs
EoIP Manual

Bandwidth Management

Queuing / Bandwidth Management
MikroTik RouterOS supports Class Based Queuing (CBQ) for bandwidth limitation. It is possible to limit just one IP or MAC address, or whole subnet. Queuing can be performed based on:
  • Source/destination address
  • Protocol, port
  • Many other parameters
Bandwidth management Manual

Bandwith Limiting on PPP Connections
PPP connections and HotSpot can be set for certain bandwidth. Following connections can have bandwidth limiting in MikroTik RouterOS:
  • PPP
  • PPPoE
  • PPPTP
General Settings for User Authentication and Accounting
HotSpot Manual

Cache

Web Proxy
The MikroTik RouterOS has the squid proxy server implementation. The web proxy can be used as transparent and normal web proxy at the same time. In transparent mode it is possible to use it as standard web proxy, too. Proxy server features:
  • Regular http proxy
  • Transparent proxy. Can be transparent and regular at the same time
  • Access list by source, destination, URL and requested method
  • Cache access list (specifies which objects to cache, and which not)
  • Direct Access List (specifies which resources should be accessed directly, and which - through an another proxy server)
  • Logging facility
Web-Proxy Manual

DNS Cache
DNS cache is used to minimize DNS requests to an external DNS server as well as to minimize DNS resolution time. This is a simple recursive DNS server with local items. When the DNS cache is enabled, the MikroTik router responds to DNS TCP and UDP requests on port 53.
  • can be set as a primary DNS server for any DNS-compliant clients
  • Static DNS entries can be added to the DNS cache
DNS Client and Cache Manual

Router and Network Administration

Remote Router Administration
MikroTik RouterOS supports remote access via Telnet and GUI. Files and software packages can be uploaded/downloaded using ftp. The WinBox GUI allows easy real-time router management and monitoring.
  • Telnet, ftp
  • MAC telnet lets you connect from router to router without need to use TCP/IP layer
  • SSH for secure shell connection to and from router
  • Router Upgrading using ftp to transfer software packages to the router
Basic Setup Guide

Network Administration
Mikrotik RouterOS provides vide variety of network administration and monitoring tools. It allows you to easily find out bottlenecks in your system, track down users clogging up your bandwidth, detects intrusion attempts, etc. Following tools by provided with MikroTik RouterOS:
  • Ping, traceroute are standart and most commonly used tools
  • Bandwidth Tester lets you determine the actual throughput between two MikroTik Routers or your Windows computer and MikroTik Router
  • Torch is brand new tool introduced by MikroTik to monitor in real-time connections going through the router
  • Sniffer catches all the data travelling over the network
Bandwidth Test
Torch

Wireless Setups

Wireless Access Point
MikroTik router with Prism or Atheros wireless card can be configured to be Wireless Access Point. Possible setups are:
  • IEEE 802.11b 2.4GHz 11Mbps AP (Prism II Interface)
  • IEEE 802.11a/b 5GHz 54Mbps and 2.4GHx 11Mbps Mult-Band AP (Atheros Interface)
  • Bridging or routing between the wireless and cable interfaces
  • Bandwidth limitation, firewall, HotSpot Gateway, and other MikroTik RouterOS features
Wireless Interface Manual

Wireless Client
MikroTik router can be used as a wireless client. It can be directly connected to a Base Unit. If you are using MikroTik router for ISP, note that you will be sharing the link with the other clients so the bandwidth will be divided. MikroTik router supports Prism II, Atheros, Aironet and RadioLAN interfaces.
  • Point-to-Point connections
  • Client-to-Access Point Connections
  • Wireless backbone
Wireless Interface Manual

Modem Setups

Dial-In Server
MikroTik router can connect asynchronous modems and serve as dial-in server:
  • Two external modems connected to COM1 and COM2 ports
  • Up to 32 external modems connected to up to four asynchronous interface cards (Moxa)
  • ISDN PCI card support
  • RADIUS authentication and accounting
PPP Manual

Dial-Out
Simply connect a modem to the router via serial interface and it will be possible to dial-up to some ISP.
PPP Manual

Modem Pool
MikroTik router supports multiple modem connections. You can connect up to 8 modems using an octopus cable. Users will be able to dial-up to your router with their modems through the telephone line.
  • Radius Authentication
  • PAP
  • CHAP
PPP Manual

Firewalling

Filtering rules
Filtering rules is the set of conditions and actions that are applied in a certain order until a decision to route or drop the packet is reached. When a particular packet meets all the conditions specified in a given row of the table, the action is carried out specified in that row (whether to route or drop the packet) is carried out. Rules can be applied to the following :
  • Source Address
  • Destination Address
  • Source Port
  • Destination Port
  • Source MAC address
  • and many more ...
Firewall Manual

Peer-2-peer filtering
Peer to peer filtering is made for network administrators that wish to limit traffic amount that is used for p2p programs like Kazaa, emule, DC and others.Wire range of peer to peer protocols are supported.
P2P Filtering Manual

Masquerading
Masquerading is used for enabling hosts with local addresses to communicate with other networks using the interface address of the gateway router. So instead of your local address the outside hosts will see gateway's interface address.
Masquerading Manual

Network Address Translation (NAT)
NAT is the translation of an IP address used within one network to a different IP address known within another network. You map the local network addresses to one or more outside IP addresses and unmap the global IP addresses on incoming packets back into local IP addresses. This helps ensure security since each outgoing or incoming request must go through a translation process that also offers the opportunity to qualify or authenticate the request or match it to a previous request.
NAT Manual

Logging
You can log everything that is going on in your firewall: what actions were performed, what packets dropped or forwarded. This gives you the opportunity to make correct decision about adding new rules.
Log Management Manual

HOTSPOT

HotSpot Gateway
Enables easy user authentication and accounting in public, private, wired or wireless networks. HotSpot technology allows Internet providers to offer Internet access to customers, while applying certain Internet use rules and limitations. It is very convenient for Internet cafes, hotels, airports, schools and universities. The Internet provider gets a complete real-time accounting of each customer's time spent on the network, data amount sent, received and more.
  • User accounting by time, data transferred/received
  • Bandwidth shaping
  • Quota (session-timeout, downloaded/uploaded traffic limit)
  • DHCP server assigned IP addresses
  • Radius Accounting
  • Real-time user status information
View PDF documentation
HotSpot Manual

User Management System
MikroTik provides complete solution for hotel hotspot/pppoe user management.

  • Printing out HotSpot user vouchers
  • Accounting the usage time since the first log in
  • Suited for any small or medium size hotel
  • Real-time user status information
Wifi Hotspot

Wifi Hotspot

hotspot is a site that offers Internet access over a wireless local area network (WLAN) through the use of a router connected to a link to an Internet service provider. Hotspots typically use Wi-Fi technology.
Hotspots may be found in coffee shops and various other public establishments in many developed urban areas throughout the world.
Public park in Brooklyn, NY has free Wi-Fi from a local corporation
Public access wireless local area networks (LANs) were first proposed by Henrik Sjödin at the NetWorld+Interop conference in TheMoscone Center in San Francisco in August 1993.[1] Sjödin did not use the term hotspot but referred to publicly accessible wireless LANs.
The first commercial venture to attempt to create a public local area access network was a firm founded in Richardson, Texas known as PLANCOM (Public Local Area Network COMmunications). The founders of that venture, Mark Goode, Greg Jackson, and Brett Stewart dissolved the firm in 1998, while Goode and Jackson created MobileStar Networks. The firm was one of the first to sign such public access locations as Starbucks,[2] American Airlines,[3] and Hilton Hotels.[4] The company was sold to Deutsche Telecom in 2001, who then converted the name of the firm into "T-Mobile Hotspot." It was then that the term "hotspot" entered the popular vernacular as a reference to a location where a publicly accessible wireless LAN is available.

Uses

The public can use a laptop or other suitable portable device to access the wireless connection (usually Wi-Fi) provided. Of the estimated 150 million laptops, 14 million PDAs, and other emerging Wi-Fi devices sold per year for the last few years, most include the Wi-Fi feature.
For venues that have broadband Internet access, offering wireless access is as simple as configuring one access point (AP), in conjunction with a router and connecting the AP to the Internet connection. A single wireless router combining these functions may suffice.[5]

Security

Security is a serious concern in connection with Hotspots. There are three possible attack vectors. First, there is the wireless connection between the client and the access point. This needs to be encrypted, so that the connection cannot be eavesdropped or attacked by a man-in-the-middle-attack. Second, there is the Hotspot itself. The WLAN encryption ends at the interface, then travels its network stack unencrypted and then travels over the wired connection up to the BRAS of the ISP. Third, there is the connection from the Access Point to the BRAS of the ISP.
The safest method when accessing the Internet over an Hotspot, with unknown security measures, is end-to-end encryption An example of strong end-to-end encryption is HTTPS. An example for a strong one is SSH.

Locations

Hotspots are often found at restaurants, train stations, airports, libraries, hotels, hospitals, coffee shops, bookstores, fuel stations, department stores, supermarkets, RV parks and campgrounds, public pay phones, and other public places. Many universities and schools have wireless networks in their campus.
According to ABI Research there were a total of 4.9 million global Wi-Fi hotspots in 2012, but that number will end up surpassing 6.3 million by the end of 2013.[6]
In a public pay phone, there is also sometimes a hotspot.

Types

Free hotspots operate in two ways:

  • Using an open public network is the easiest way to create a free HotSpot. All that is needed is a Wi-Fi router. Private users of wireless routers can turn off their authentication requirements, thus opening their connection, intentionally or not, for sharing by anyone in range.
  • Closed public networks use a HotSpot Management System to control the HotSpot. This software runs on the router itself or an external computer. With this software, operators can authorize only specific users to access the Internet, and they often associate the free access to a menu or to a purchase limit. Operators are also now able to limit each user's available bandwidth - each user is therefore restricted to a certain speed to ensure that everyone gets a good quality service. Often this is done through service-level agreements.

Commercial hotspots

A commercial hotspot may feature:
  • A captive portal / login screen that users are redirected to for authentication and payment
  • A payment option using credit card, PayPal, iPass, or other payment service
  • A walled garden feature that allows free access to certain sites
  • Service-oriented provisioning to allow for improved revenue
Many services provide payment services to hotspot providers, for a monthly fee or commission from the end-user income. ZoneCD is a Linux distributionthat provides payment services for hotspots who wish to deploy their own service. Amazingports can be used to set up hotspots that intend to offer both for fee and free internet access.
Major airports and business hotels are more likely to charge for service. Most hotels provide free service to guests; and increasingly, small airports and airline lounges offer free service.
Roaming services are expanding among major hotspot service providers. With roaming service the users of a commercial provider can have access to other provider's hotspots with extra fees, in which such a user will be usually charged on the basis of access-per-minute.

Software Hotspots

Many Wi-Fi adapters built into or easily added to consumer computers include the functionality to operate as hotspots. Manufacturers can enable this functionality through driver-level support. Modern consumer operating systems, including Windows Vista and later and Apple OS X 10.6 and later added features to support this. Third-party software vendors, offer applications to allow users to operate their own Hotspot, whether to share an existing connection or extend the range of another hotspot.

Hotspot 2.0

Also known as HS2 and Wi-Fi Certified Passpoint,[7] Hotspot 2.0 is a new approach to public access Wi-Fi by the Wi-Fi Alliance. The idea is for mobile devices to automatically join a Wi-Fi subscriber service whenever the user enters a Hotspot 2.0 area. The intention is to provide better bandwidth and services-on-demand to end-users, whilst also alleviating mobile carrier infrastructure of traffic overheads.
Hotspot 2.0 is based on the IEEE 802.11u standard, which is a new set of protocols to enable cellular-like roaming. If the device supports 802.11u and is subscribed to a Hotspot 2.0 service it will automatically connect and roam.[8][9]

Supported handsets

  • Android phones
  • Some Samsung Galaxy smartphones[10]
  • Some China tablet PCs
  • iOS 7 devices[11]

Billing

EDCF User-Priority-List
The so-called "User-Fairness-Model[12] " is a dynamic billing model, which allows a volume-based billing, charged only by the amount of payload (data, video, audio). Moreover, the tariff is classified by net traffic and user needs (Pommer, p. 116ff).
If the net traffic increases, then the user has to pay the next higher tariff class. By the way the user is asked for if he still wishes the session also by a higher traffic class. Moreover, in time-critical applications (video, audio) a higher class fare is charged, than for non time-critical applications (such as reading Web pages, e-mail).
Tariff classes of the User-Fairness-Model
The "User-fairness model" can be implemented with the help of EDCF (IEEE 802.11e). A EDCF user priority list shares the traffic in 3 access categories (data, video, audio) and user priorities (UP) (Pommer, p. 117):
  • Data [UP 0|2]
  • Video [UP 5|4]
  • Audio [UP 7|6]
If the net traffic increases, then the frames of the particular access category (AC) are assigned a low priority value (e.g. video UP 5 to UP 4). This is also, if the data transfer is not time-critical.

Security concerns

Some hotspots authenticate users; however, this does not prevent users from viewing network traffic using packet sniffers.[13]
Some vendors provide a download option that deploys WPA support. This conflicts with enterprise configurations that have solutions specific to their internal WLAN.
In order to provide robust security to hotspot users, Wi-Fi Alliance is developing a new hotspot program that aims to encrypt hotspot traffic with WPA2 security. The program is planned to launch in the first half of 2012.[dated info]

Wi-Fi Support

Wi-Fi  is supported by many applications and devices including video game consoles, home networksPDAsmobile phones, major operating systems, and other types of consumer electronics.  

Any products that are tested and approved as "Wi-Fi Certified" (a registered trademark) by the Wi-Fi Alliance are certified as interoperable with each other, even if they are from different manufacturers. For example, a user with a Wi-Fi Certified product can use any brand of access point with any other brand of client hardware that also is also "Wi-Fi Certified". Products that pass this certification are required to carry an identifying seal on their packaging that states "Wi-Fi Certified" and indicates the radio frequency band used (2.5GHz for 802.11b,  802.11g, or 802.11n, and 5GHz for 802.11a).

How Wi-Fi Works

Wi-Fi works with no physical wired connection between sender and receiver by using radio frequency (RF) technology, a frequency within the electromagnetic spectrum associated with radio wave propagation. When an RF current is supplied to an antenna, an electromagnetic field is created that then is able to propagate through space. The cornerstone of any wireless network is an access point (AP). 

The primary job of an access point is to broadcast a wireless signal  that computers can detect and "tune" into. In order to connect to an access point and join a wireless network, computers and devices must be equipped with wireless network adapters 

What Is Wifi

Wi-Fi is the name of a popular wireless networking technology that uses radio waves to provide wireless high-speed Internet and network connections. A common misconception is that the term Wi-Fi is short for "wireless fidelity," however this is not the case. Wi-Fi is simply a trademarked term meaning IEEE 802.11x.

The Wi-Fi Alliance, the organization that owns the Wi-Fi (registered trademark) term specifically defines Wi-Fi as any "wireless local area network (WLAN) products that are based on the Institute of Electrical and Electronics Engineers' (IEEE) 802.11 standards."
Initially, Wi-Fi was used in place of only the 2.4GHz 802.11b standard, however the Wi-Fi Alliance has expanded the generic use of the Wi-Fi term to include any type of network or WLAN product based on any of the 802.11 standards, including 802.11b, 802.11a, dual-band, and so on, in an attempt to stop confusion about wireless LAN interoperability.
Wifi Hardwares

Wifi Hardwares

Distance records

Distance records (using non-standard devices) include 382 km (237 mi) in June 2007, held by Ermanno Pietrosemoli and EsLaRed of Venezuela, transferring about 3 MB of data between the mountain-tops of El Águila and Platillon. The Swedish Space Agency transferred data 420 km (260 mi), using 6 watt amplifiers to reach an overhead stratospheric balloon.

Embedded systems

Embedded serial-to-Wi-Fi module
Increasingly in the last few years (particularly as of 2007), embedded Wi-Fi modules have become available that incorporate a real-time operating system and provide a simple means of wirelessly enabling any device which has and communicates via a serial port.[50] This allows the design of simple monitoring devices. An example is a portable ECG device monitoring a patient at home. This Wi-Fi-enabled device can communicate via the Internet
These Wi-Fi modules are designed by OEMs so that implementers need only minimal Wi-Fi knowledge to provide Wi-Fi connectivity for their products.

Multiple access points

Increasing the number of Wi-Fi access points provides network redundancy, support for fast roaming and increased overall network-capacity by using more channels or by defining smaller cells. Except for the smallest implementations (such as home or small office networks), Wi-Fi implementations have moved toward "thin" access points, with more of the network intelligence housed in a centralized network appliance, relegating individual access points to the role of "dumb" transceivers. Outdoor applications may use mesh topologies.

Network security

The main issue with wireless network security is its simplified access to the network compared to traditional wired networks such as Ethernet, with wired networking one must either gain access to a building (physically connecting into the internal network) or break through an external firewall. To enable Wi-Fi, one merely needs to be within the wireless range of the Wi-Fi network. Most business networks protect sensitive data and systems by attempting to disallow external access. Enabling wireless connectivity reduces security if the network uses inadequate or no encryption.
An attacker who has gained access to a Wi-Fi network router can initiate a DNS spoofing attack against any other user of the network by forging a response before the queried DNS server has a chance to reply.

Securing methods

A common measure to deter unauthorized users involves hiding the access point's name by disabling the SSID broadcast. While effective against the casual user, it is ineffective as a security method because the SSID is broadcast in the clear in response to a client SSID query. Another method is to only allow computers with known MAC addresses to join the network, but determined eavesdroppers may be able to join the network by spoofing an authorized address.
Wired Equivalent Privacy (WEP) encryption was designed to protect against casual snooping but it is no longer considered secure. Tools such as AirSnort or Aircrack-ng can quickly recover WEP encryption keys.Because of WEP's weakness the Wi-Fi Alliance approved Wi-Fi Protected Access (WPA) which uses TKIP. WPA was specifically designed to work with older equipment usually through a firmware upgrade. Though more secure than WEP, WPA has known vulnerabilities.
The more secure WPA2 using Advanced Encryption Standard was introduced in 2004 and is supported by most new Wi-Fi devices. WPA2 is fully compatible with WPA.
A flaw in a feature added to Wi-Fi in 2007, called Wi-Fi Protected Setup, allows WPA and WPA2 security to be bypassed and effectively broken in many situations. The only remedy as of late 2011 is to turn off Wi-Fi Protected Setup,[58] which is not always possible.

Piggybacking

Piggybacking refers to access to a wireless Internet connection by bringing one's own computer within the range of another's wireless connection, and using that service without the subscriber's explicit permission or knowledge.
During the early popular adoption of 802.11, providing open access points for anyone within range to use was encouraged[by whom?] to cultivate wireless community networks, particularly since people on average use only a fraction of their downstream bandwidth at any given time.
Recreational logging and mapping of other people's access points has become known as wardriving. Indeed, many access points are intentionally installed without security turned on so that they can be used as a free service. Providing access to one's Internet connection in this fashion may breach the Terms of Service or contract with the ISP. These activities do not result in sanctions in most jurisdictions; however, legislation and case law differ considerably across the world. A proposal to leave graffiti describing available services was called warchalking. A Florida court case determined that owner laziness was not to be a valid excuse.[citation needed]
Piggybacking often occurs unintentionally, since most access points are configured without encryption by default[citation needed] and operating systems can be configured to connect automatically to any available wireless network. A user who happens to start up a laptop in the vicinity of an access point may find the computer has joined the network without any visible indication. Moreover, a user intending to join one network may instead end up on another one if the latter has a stronger signal. In combination with automatic discovery of other network resources (see DHCP andZeroconf) this could possibly lead wireless users to send sensitive data to the wrong middle-man when seeking a destination (see Man-in-the-middle attack). For example, a user could inadvertently use an unsecure network to log into a website, thereby making the login credentials available to anyone listening, if the website uses an unsecure protocol such as HTTP.

Safety

The World Health Organization (WHO) says "there is no risk from low level, long-term exposure to wi-fi networks" and the United Kingdom's Health Protection Agency reports that exposure to Wi-Fi for a year results in the "same amount of radiation from a 20-minute mobile phone call". 
A small percentage of Wi-Fi users have reported adverse health issues after repeat exposure and use of Wi-Fi, though there has been no publication of any effects being observable in double-blind studies. A review of studies involving 725 people that claimed electromagnetic hypersensitivity found no evidence for their claims.