CAPsMAN - MUM - MikroTik User...

72
CAPsMAN Recent changes, spectrum usage, security features MUM 2017 Milan | Patrik Schaub | © FMS Internetservice GmbH

Transcript of CAPsMAN - MUM - MikroTik User...

Page 1: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

CAPsMAN

Recent changes, spectrum usage, security features

MUM 2017 Milan | Patrik Schaub | © FMS Internetservice GmbH

Page 2: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

FMS Internetservice GmbH

Company Profile

Page 3: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

FMS Internetservice GmbH

ƒ Value Added Distributorƒ Distributionƒ Trainingƒ Consultingƒ Support

ƒ Founded 1997ƒ 11 employeesƒ Southern Germany

Page 4: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Get in Touch

ƒ Website: http://www.fmsweb.deƒ MikroTik Mirror: http://www.mikrotik-software.deƒ Shop: http://www.mikrotik-shop.deƒ Wiki: http://wiki.fmsweb.deƒ Twitter: https://twitter.com/fmsweb_deƒ Facebook: https://www.facebook.com/fmsinternetservice

ƒ Phone: +49 761 2926500ƒ Email: [email protected]

Page 5: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Training Center

ƒ Official MikroTik trainingsƒ All certification levelsƒ First German speaking

partnerƒ Two trainersƒ Own training facilityƒ Inquiries: [email protected]

Sebastian Inacker: TR11Patrik Schaub: TR23

Page 6: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Distributor Table

Page 7: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Distributor Table

Live Demonstrations:

ƒ Nokia Vplus setup

ƒ Nokia AMS demonstration

ƒ CRS 10G on 10 meter copper(see tomorrow’s CRS presentation)

Page 8: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Distributor Table

ƒ Learn about Vectoring,VDSL+ and G.FAST withAlcatel-Lucent

MikroTik Based Accesspoint

Do you need towers or masts? Contact [email protected]

Page 9: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

CAPsMAN

What is it about and how to get it running

Page 10: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

CAPsMAN Basic Features

ƒ Provisioning (configuration) of access points

ƒ Authentication and access control of clients

ƒ Handling of client traffic

ƒ Monitoring of client connections

Page 11: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Client Traffic: Local Forwarding

CAPsMAN

AP AP AP APLocal

network

ƒ Access point handles trafficƒ Manual access point configuration

Page 12: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Manager Forwarding

CAPsMAN

AP AP AP APLocal

network

ƒ CAPsMAN handles trafficƒ No access point configurationƒ Automatic UDP tunnel

Page 13: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Getting Started

ƒ Install CAPsMAN package (on old ROS versions)ƒ Configure CAPsMANƒ Create provisioning and config on CAPsMANƒ Configure APs (CAPs) to use manager

CAPsMAN configuration CAP configuration

Page 14: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Minimum CAP Configuration (Layer 2)

ƒ Enableƒ Choose CAP interfacesƒ Choose discovery interfaces

Page 15: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Minimum CAPsMAN Configuration

ƒ Enable

ƒ Createbridge

ƒ Add port

Page 16: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Minimum CAPsMAN Configuration

ƒ Provisioning (Condition/Action)ƒ Wireless Config: SSIDƒ Datapath Config: Bridge

Page 17: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest CAPsMAN Features

See what’s new

Page 18: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Changes wireless-rep Package

wireless-cm2 wireless (formerly wireless-rep)

ƒ Optimize 2.4GHz performanceƒ Disable 802.11b legacy mode

Page 19: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Optimize performance w/o 802.11b

ƒ 802.11b uses DSSSmodulation

ƒ 802.11g/n uses OFDMmodulation

ƒ OFDM node have to take care on DSSS nodesƒ DSSS nodes use more air time

Page 20: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Discovery Interface

ƒ List of interfaces, CAPsMAN will listen for CAPsƒ For bridges: use bridge, not port

Curent Stable Current RC

Page 21: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Static Virtual

ƒ capsman - added support for static virtualinterfaces on CAP;

Page 22: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Static Virtual

ƒ Virtual interface e.g. individual: SSIDs, securitysetting, traffic forwarding (VLAN, bridging …)ƒ New virtual interface with each CAPsMAN connect

Page 23: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Static Virtual

ƒ Local forwarding: enabled interfaceƒ Local interface configuration necessary

ƒ E.g. local traffic handling:

ƒ Forwarding traffic to VLANƒ By using virtual interface as bridge port

Page 24: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Static Virtual

1

2

Page 25: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Static Virtual

ƒ wlan7 just disabled, not removed

Page 26: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

ƒ Dynamic bridge port

ƒ Alternative to staticvirtual for

ƒ Only one bridge

ƒ No other settings(e.g IP, routing …)

Static Virtual vs. CAP Bridge Setting

Page 27: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Save Selected

ƒ Save selected channelƒ No frequency set = “auto”ƒ Speeds up frequency selection on CAPsMAN start

Page 28: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Save Selected: CAPsMAN Disabled

Page 29: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Save Selected: CAPsMAN Reconnect

Channelselection

2Running

1Inactive

3

Page 30: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Latest Changes: Save Selected

ƒ Auto channel selection sequentiallyƒ The more CAPs the longerƒ Save selected saves last used channelƒ Speeds up CAPsMAN restartƒ Especially with many CAPs

Page 31: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel Planning and Regulation

Missing CAPsMAN Feature

Page 32: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

2,4GHz Channel Planning

ƒ No channel 12/13 with FCCdevicesƒ Public WiFi limited to

channel 1 – 11

ƒ Non overlapping channels:1,6,11

Channel ETSI FCC

1 20dBm 30dBm

2 20dBm 30dBm

3 20dBm 30dBm

4 20dBm 30dBm

5 20dBm 30dBm

6 20dBm 30dBm

7 20dBm 30dBm

8 20dBm 30dBm

9 20dBm 30dBm

10 20dBm 30dBm

11 20dBm 30dBm

12 20dBm n/a

13 20dBm n/a

Page 33: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

2,4GHz Channel Planning

ƒ Auto channel selection sequentiallyƒ The more CAPs the longerƒ Save selected saves last used channelƒ Speeds up CAPsMAN restartƒ Especially with many CAPs

Page 34: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

2,4GHz Channel Planning

ƒ Without CAPsMAN: Use Scan List & Channels

Page 35: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

2,4GHz Channel Planning

ƒ Problem: No scan list option in CAPsMAN

ƒ Configure CAPsMAN interfaces one by one?ƒ Controller advantage reduced

ƒ Work around using CAPsMAN strengthsƒ Provisioning rulesƒ Modular hierarchical configuration

ƒ RegEx and Overrides

Page 36: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel 1-6-11 Setup

Page 37: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel 1-6-11 Setup

4

Catch-All Rule | Avoids static interface creationFind unwanted and misconfigured CAP (802.11b or identity not set)

Require 802.11g, noLegacy support

Check CAP identityby RegEx for wantedchannel

Use configurationaccording to RegEx

12 3

Page 38: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel 1-6-11 Setup

Common central setting blocks for maximum modularity

Just frequency override within every configuration

Page 39: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel 1-6-11 Setup

Interface useschannel 1 (2412MHz)

Identity contains „--2.4CH01“

Page 40: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Channel 1-6-11 Setup

Interface not provisionedCatch all rule | Action = noneReason: not supporting 802.11g

Page 41: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

5GHz Regulation

ƒ Radar detection / DFSƒ Not yet possible with CAPsMAN

ƒ Is currently being implemented

ƒ Frequencies < 5470 MHz only indoorƒ Outdoor setups without scan list?

Page 42: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

5GHz Outdoor Channels

ƒ Solution: etsi 5.5 – 5.7 outdoor

Page 43: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Forcing 30dBm EIRP

ƒ Use etsi 5.5 – 5.7 even indoors?ƒ Force high EIRPƒ Regulation in Germany: 30dBm instead of 23dBmƒ Actually 27dBm due to ATPC missing

Antenna gain setting of CAP accounted!

Page 44: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Tx Power: The more the better?

ƒ WiFi connection is bidirectionalƒ Mobile devices have small Tx power

High EIRP + low gain AP antenna = pointlessƒ Mobile device will hear AP but can not reach itƒ Unnecessary interferenceƒ Hard to select best AP for clientƒ Smartphone shows full bars but can’t connect

ƒ iPhone 5 ~ 12dBm Tx, -0,8dBi = 11,2dBm EIRP

Page 45: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

CAPsMAN Security

Keeping CAPsMAN safe

Page 46: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Upgrade Policy

ƒ automatic CAPRouterOS update

ƒ none: do nothingƒ suggest: try update but

accept different versionƒ require: try update and reject if not possible

ƒ CAP doesn’t need internet connection

Page 47: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Upgrade Policy

ƒ CAP gets software packet from CAPsMANƒ Same architecture: works automaticallyƒ Different architecture: CAP needs extra .npk

ƒ hAP lite (smips) CAP can’t use npk of RB750UPCAPsMAN (mipsbe)

Page 48: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Upgrade Policy

1

2

3

Create folder by FTP

4

Page 49: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

WIFI Security

Security types supported by CAPsMAN

Page 50: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Security Overview

ƒ Common WPA2 PSKƒ Conditional WPA2 PSK

(Access List)ƒ MAC based WPA2 PSK

ƒ WPA2 EAP using localcertificates (EAP-TLS)ƒ WPA2 EAP using Radius (passthrough)

ƒ Hotspot

Page 51: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

CAPsMAN with Hotspot

1

42

3

ƒ UDP tunnels directly to hotspot

Secure | Efficient | Scales well | Easy traffic handling

Page 52: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

HSNM a MikroTik Hotspot Extension

Tight MikroTik integration

ƒ Installation + update scriptsƒ PPPoE supportƒ Experienced support team

Excellent addon

ƒ High level Captive Portal featuresƒ Emphasis on graphical design

Page 53: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

HS Network Manager

Advertising, surveys,quizzes

Responsive login

Payment options

GPS tracking(e.g coaches)

Social login

Redundancy,load balancing

SMS authentication

Ticket printer

Page 54: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

HS Network Manager

Screenshot missing

Looking for a Captive Portal? Contact [email protected]

Page 55: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

MAC based PSK with Usermanager

ƒ Separate PSKs per MACƒ Stored in Usermanagerƒ Easy to setupƒ No full Radius necessaryƒ Enhanced securityƒ Access restrictions by device

ƒ Configuration not nicely embedded in CAPsMAN concept

Page 56: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

MAC based PSK with Usermanager

ƒ Device wants to connectƒ CAPsMAN sends MAC to

Radiusƒ Radius returns personal

PSKƒ CAPsMAN compares PSK

ƒ Grant or decline access

Page 57: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

MAC based PSK: Radius

ƒ Setup Radius connectionƒ Serviceƒ IP Addressƒ Optional secret

Page 58: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

MAC based PSK: CAPsMAN

1

2

3

Page 59: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

MAC based PSK: Usermanager

Page 60: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

WPA-Enterprise

Internally Supportedƒ EAP-TLS

Externally Supportedƒ all EAP methodsƒ passthrough

Page 61: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

WPA-Enterprise releated Terms

ƒ 802.1X = 802 AA Standardƒ EAP = Extensible

Authentication Protocolƒ EAP-TLSƒ EAP-TTLSƒ PEAP (EAP-PEAP)

Protected ExtensibleAuthentication Protocol

ƒ PEAPv0 with MSCHAPv2 often called PEAP

Page 62: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

PEAP with MSCHAP

ƒ Authenticate server by serverside certificateƒ Create TLS tunnelƒ Create EAP session through

encrypted tunnelƒ Use EAP-MSCHAP for client

authentication

ƒ WARNING: not secure if server certificate isn’t validated atclient. MSCHAP isn’t secure if fake AP can collect handshakes

Page 63: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Prepare CAPsManager for PEAP

Page 64: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

RADIUS Server Selection

ƒ No support in Usermanagerƒ Freeradius common choiceƒ Microsoft offers Radius

Zeroshellƒ Ready to run applianceƒ Linux basedƒ Includes Freeradiusƒ Includes certificate handling

www.zeroshell.org

Page 65: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Zeroshell Setup

ƒ Download the imageƒ Install VM from CD imageƒ Change IP / set DHCPƒ Change admin password

Default IP: 192.168.0.75User: adminPass: zeroshell

www.zeroshell.org

Page 66: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

ƒ Enable the Radius Server

Zeroshell Configuration

Page 67: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Zeroshell Configuration

www.zeroshell.org2

1

3

ƒ Add an authorised client

Page 68: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Zeroshell Configuration

2

13

ƒ Add an user account

Page 69: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Connect an iPhone with PEAP

Page 70: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

Connect an iPhone with PEAP

Page 71: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

THANK YOU

… and enjoy the Usermeeting

MUM 2017 Milan | Patrik Schaub | © FMS Internetservice GmbH

Page 72: CAPsMAN - MUM - MikroTik User Meetingmum.mikrotik.com/presentations/EU17/presentation_4059_1492080639.pdf · Tx Power: The more the better? ƒWiFi connection is bidirectional ƒMobile

FMS Internetservice GmbH

Phone: +49 761 2926500Web: www.fmsweb.deShop: www.mikrotik-shop.deEmail: [email protected]: https://twitter.com/fmsweb_de

MUM 2017 Milan | Patrik Schaub | © FMS Internetservice GmbH