MTCNA Ver 2
MTCNA Ver 2
MTCNA Ver 2
ABOUT TRAINER
• Ye Wint Aung
MTCNA
MTCINE
MTCNA OUTLINE
• Module 5: Wireless
MODULE 1: INTRODUCTION
• Missions:
• to make Internet technologies faster
• More Powerful affordable to a wider range of users
About MikroTik
• Firewall/bandwidth shaping
• DHCP/Proxy/HotSpot
• Ethernet cable
• WiFi
Null modem cable Ethernet cable
First Time Access
• WinBox - http://www.mikrotik.com/download/winbox.exe
• WebFig
• SSH
• Telnet
• User: admin
• Password: (blank)
MAC WinBox
• Test it !!!
WebFig
• Try it on browser
• Port 80
Quick Set
Package Functionality
advanced-tools netwatch, ip-scan, sms tool, wake-on-LAN
dhcp DHCP client and server
hotspot HotSpot captive portal server
ipv6 IPv6 support
PPP PPP, PPTP, L2TP, PPPoE clients and servers
routing Dynamic routing :RIP,BGP
Security Secure WinBox, SSH, IPsec
system Basic features: static routing, firewall, bridging, etc
wireless 802.11 a/b/g/n/ac support, CAPsMAN v2
RouterOS Extra Packages
Package Functionality
1 Free Demo
• wiki.mikrotik.com
• Forum.mikrotik.com
• mum.mikrotik.com
• support@mikrotik.com
Module-2
DHCP
DHCP
• DHCP Server could even be used without dynamic IP pool and assign
only preconfigured addresses
ARP
• Router’s client will not be able to access the Internet using a different IP
address
DHCP and ARP
• Combined with static leases and reply-only ARP can increase network
security while retaining the ease of use for users
Module-3
Bridging
Bridge
• Network switch is multi-port bridge - each port is a collision domain of one device
Bridge
• Traffic which flows through the bridge can be processed by the firewall•
•
Module-4
Routing
Routing
IP route add
Check Gateway
• Check gateway - every 10 seconds send either ICMP echo request (ping)
or ARP request.•
• If no response from gateway is received for 10 seconds, request times
out.
• After two timeouts gateway is considered unreachable.
• If several routes use the same gateway and there is one that has
checkgateway option enabled, all routes will be subjected to the behaviour
of check-gateway
Default Gateway
• Default gateway: a router (next hop) where all the traffic for which there
automatically
• DAC route
originates from IP
address
configuration
Route Flags
• A - active•
• C - connected•
• D - dynamic•
• S - static•
• O - OSPF•
• b - BGP
Routing
• If there are two or more routes pointing to the same address, the more precise
Wireless
Wireless
802.11a 20MHz
20MHz
802.11n
40MHz
20MHz
40MHz
802.11ac
80MHz
160MHz
Country Regulation
• 802.11n with one chain (SISO) can only achieve 72.2Mbps (on legacy cards
65Mbps)
Transmit Power
• When enabled the router becomes station and ap bridge at the same time •
• Used for increasing the range of an existing AP without the need of Ethernet
cables
Module-5
Summary
Module-6
Firewall
Firewall
• Based on rules which are analysed sequentially until first match is found
• Ordered in chains
Internet
Chain:Forward
Internet
Chain:Output
Internet
Filter Actions
• accept
Ports Services
80/tcp http
443/tcp https
22/tcp ssh
23/tcp telnet
20,21/tcp FTP
8291/tcp Winbox
• There are two NAT types - ‘source NAT’ and ‘destination NAT’
NAT
Summary
Module-7
QOS
Quality Of Service
Specified node(Client
or Server)
Limit Maximum
Bandwidth to the node
Simple Queue
• Instead of setting limits to the client, traffic to the server can also be
throttled
Set Limit at
Per Connection Queuing
Summary
Module-8
Tunnels
Point-to-point Protocol
• RouterOS supports various PPP tunnels such as PPPoE, SSTP, PPTP and others
PPPoE
concentrator)
PPPoE Client
• Choose interface
• Set username and password
PPPoE Client
• If there are more than one PPPoE servers in a broadcast domain service
• Otherwise the client will try to connect to the one which responds first
IP Pool
• Rest of the settings are applied from the selected PPP profile
• Either remove from the bridge or set up PPPoE server on the bridge
• When a connection is made between the PPP client and server, /32
addresses are assigned•
• For the client network address (or gateway) is the other end of the
tunnel (router)
Point-to-point Address
over IP
the Internet
Encapsulation)
Set name,
PPTP server IP address,
username, password
PPTP Client
• Use Add Default Route to send all traffic through the PPTP tunnel•
• Use static routes to send specific traffic through the PPTP tunnel•
over IP•
Set name
SSTP server IP address,
username,
password
SSTP Client
Summary
Module-9
Miscellaneous
Router OS Tools
• RouterOS can generate graphs showing how much traffic has passed
• For each metric there are 4 graphs - daily, weekly, monthly and yearly
Graph
Graph
SNMP
•
The DUDE
• Stored in memory
Summary
MTCNA
Summary
Certification Exam
• This is an open book exam, you are allowed to read your notes, books,
• Good luck!