Mikrotik Note
Mikrotik Note
Internet Access
2
LAB: Internet Access
Connectivity Test
Ping 192.168.1.1
Ping 8.8.8.8
Ping www.google.com 3
DHCP Server
4
LAB : DHCP Server
Wizard Manual
IP DHCP Server Setup IP Pool
Interface = ether2 Name= Pool1
Address Space = 192.168.1.0/24 Range = 192.168.1.2-192.168.1.254
Gateway = 192.168.1.1 IP DHCP Server Add
Range = 192.168.1.2-192.168.1.254 Name = DHCP Server
DNS = 8.8.8.8 , 8.8.4.4 Interface = ether2
Lease Time = 3d 00:00:00 Lease time = 3d 00:00:00
Address pool = Pool1 [Pool name]
[ ]Add ARP Leases
Network (Tab) Add
Address = 192.168.1.0/24
Gateway = 192.168.1.1
DNS = 8.8.8.8 , 8.8.4.4
5
Content Filtering
6
content=youtube ,facebook, google 7
Blocking website using Regular Expression
(Layer 7 Protocol)
8
Layer 7 Protocol regex
Name = Youtube
^..+\.(youtube.com|googlevideo.com|akamaihd.net).*$
Mangle Rule
Chain = forward
Advanced
Layer 7 Protocol =Youtube
Action
Action = mark connection
new Connection Mark = youtube _conn
Checked = Passthrough
9
Firewall
Chain = Forward
Protocol = udp | tcp
Connection Mark = youtube_conn
Action
Action = drop
10
Layer 7 Protocol (Regular Expression)
^.+(youtube.com|facebook.com).*$
1 ^..+\.(facebook.com|facebook.net|fbcdn.com|fbsbx.com|fbcdn.net|fb.com|tfbn
w.net).*$
1 ^.+(youtube.com|www.youtube.com|m.youtube.com|ytimg.com|s.ytimg.com|
ytimg.l.google.com|youtube.l.google.com|i.google.com|googlevideo.com|youtu.be
).*$
11
QoS
Separate simple queues for each user
12
13
Parent User1, User2, User3, User4, User5, User6
14
Security
15
MAC Filtering
1. Interface LAN
ARP = Reply Only
2. IP ARP Add
IP Address = Client IP (you want to use)
MAC Address = PC MAC (you want to use)
Interface = LAN
16
VPN
PPTP (Remote VPN)
17
18
Login to the Mikrotik RouterOS via
Winbox and go to the IP —> Pool:
19
Now go to the PPP Section. Click
“PPTP Server” and check the
Enabled:
20
Now switch to the “Secrets” tab of
the PPP window. Click on the plus
sign to create new user, add the
name(which act as username),
password and profile that we have
created in the previous step:
21
From the “Filter Rules” tab, add
the new rule. Set the chain to
input, protocol to tcp and Dst.
port to 1723:
22
PPTP Client Setup on Windows 7:
From “Control Panel“, select the “Network and Sharing Center” and then choose “Set up a
new connection or network“:
23
Verify the pptp logs on Mikrotik by hitting Log:
24