Discussion:
Hostspot question...
George..
2004-05-28 01:07:57 UTC
Permalink
Hello all,

I have a hotspot configured in an external ethernet AP device with the
wizard..
As far as I checked, it works fine..

I want to allow a specific client to connect with his MT router, to this
AP, without all this login procedure.
Should I give him a static ip ? What do I have to do with the fw ?







George A. Michalopoulos

Thessaloniki's Wireless Metropolitan Network
http://TWMN.net
Lee Quince
2004-05-28 01:46:46 UTC
Permalink
Setup managle rule to mark the packets going to the MT box.

-----Original Message-----
From: routeros-***@bruno.pmi.lv
[mailto:routeros-***@bruno.pmi.lv] On Behalf Of George..
Sent: 28 May 2004 02:08
To: ***@bruno.pmi.lv
Subject: [MikroTik] Hostspot question...


Hello all,

I have a hotspot configured in an external ethernet AP device with the
wizard.. As far as I checked, it works fine..

I want to allow a specific client to connect with his MT router, to this
AP, without all this login procedure. Should I give him a static ip ?
What do I have to do with the fw ?







George A. Michalopoulos

Thessaloniki's Wireless Metropolitan Network
http://TWMN.net


_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
To post to the list, address emails to ***@bruno.pmi.lv
To unsubscribe/subscribe: email to RouterOS-***@bruno.pmi.lv ,
with text in the body "unsubscribe <password>" or "subscribe"
Dev Team
2004-05-28 18:31:23 UTC
Permalink
Hello Lee,

Friday, May 28, 2004, 4:46:46 AM, you wrote:

LQ> Setup managle rule to mark the packets going to the MT box.

what do you mean by that ?
how can i bypass the hotspot procedure with this ?

LQ> -----Original Message-----
LQ> From: routeros-***@bruno.pmi.lv
LQ> [mailto:routeros-***@bruno.pmi.lv] On Behalf Of George..
LQ> Sent: 28 May 2004 02:08
LQ> To: ***@bruno.pmi.lv
LQ> Subject: [MikroTik] Hostspot question...


LQ> Hello all,

LQ> I have a hotspot configured in an external ethernet AP device with the
LQ> wizard.. As far as I checked, it works fine..

LQ> I want to allow a specific client to connect with his MT router, to this
LQ> AP, without all this login procedure. Should I give him a static ip ?
LQ> What do I have to do with the fw ?







LQ> George A. Michalopoulos

LQ> Thessaloniki's Wireless Metropolitan Network
LQ> http://TWMN.net


LQ> _______________________________________________
LQ> ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
LQ> To post to the list, address emails to ***@bruno.pmi.lv
LQ> To unsubscribe/subscribe: email to
LQ> RouterOS-***@bruno.pmi.lv ,
LQ> with text in the body "unsubscribe <password>" or "subscribe"
LQ> _______________________________________________
LQ> ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
LQ> To post to the list, address emails to ***@bruno.pmi.lv
LQ> To unsubscribe/subscribe: email to
LQ> RouterOS-***@bruno.pmi.lv ,
LQ> with text in the body "unsubscribe <password>" or "subscribe"
--
Best regards,
Dev mailto:***@sae.gr
Kevin Summers
2004-05-28 20:27:32 UTC
Permalink
Simplest thing to do is use either PPTP or PPPoE. Have the user
set up the necessary client interface on his MT to log in to your
MT and it will bypass your HotSpot firewall rules.

If the HotSpot function is being controlled by an external device
then there's nothing you can do from the perspective of your MT
to allow him through. You would have to check the device and see
if there is a setting to allow specific users in without requiring a
login.

Kevin Summers
KISTech Internet
www.kistech.com



-----Original Message-----
From: routeros-***@bruno.pmi.lv
[mailto:routeros-***@bruno.pmi.lv]On Behalf Of Dev Team
Sent: Friday, May 28, 2004 11:31 AM
To: Lee Quince
Cc: General questions about MikroTik RouterOS
Subject: Re[2]: [MikroTik] Hostspot question...


Hello Lee,

Friday, May 28, 2004, 4:46:46 AM, you wrote:

LQ> Setup managle rule to mark the packets going to the MT box.

what do you mean by that ?
how can i bypass the hotspot procedure with this ?

LQ> -----Original Message-----
LQ> From: routeros-***@bruno.pmi.lv
LQ> [mailto:routeros-***@bruno.pmi.lv] On Behalf Of George..
LQ> Sent: 28 May 2004 02:08
LQ> To: ***@bruno.pmi.lv
LQ> Subject: [MikroTik] Hostspot question...


LQ> Hello all,

LQ> I have a hotspot configured in an external ethernet AP device with the
LQ> wizard.. As far as I checked, it works fine..

LQ> I want to allow a specific client to connect with his MT router, to this
LQ> AP, without all this login procedure. Should I give him a static ip ?
LQ> What do I have to do with the fw ?







LQ> George A. Michalopoulos

LQ> Thessaloniki's Wireless Metropolitan Network
LQ> http://TWMN.net


LQ> _______________________________________________
LQ> ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
LQ> To post to the list, address emails to ***@bruno.pmi.lv
LQ> To unsubscribe/subscribe: email to
LQ> RouterOS-***@bruno.pmi.lv ,
LQ> with text in the body "unsubscribe <password>" or "subscribe"
LQ> _______________________________________________
LQ> ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
LQ> To post to the list, address emails to ***@bruno.pmi.lv
LQ> To unsubscribe/subscribe: email to
LQ> RouterOS-***@bruno.pmi.lv ,
LQ> with text in the body "unsubscribe <password>" or "subscribe"



--
Best regards,
Dev mailto:***@sae.gr

_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
To post to the list, address emails to ***@bruno.pmi.lv
To unsubscribe/subscribe: email to RouterOS-***@bruno.pmi.lv ,
with text in the body "unsubscribe <password>" or "subscribe"
Andrew Luck
2004-05-28 19:17:35 UTC
Permalink
George

If you give the user a fixed IP then it should be possible to set a firewall
rule to always allow traffic from this IP.

I find the firewall rules are easier to comprehend in the WinBox interface.
Select IP --> Firewall --> Filter Rules and select the 'Hotspot-Temp' chain.
These are the filter rules active before the client authenticates. Add
another filter before the final reject statement with the Source IP
specified.

I use a similar setup to allow access to a mail server before
authentication.

Regards

Andrew

----- Original Message -----
From: "George.." <tech-***@twmn.net>
To: <***@bruno.pmi.lv>
Sent: Friday, May 28, 2004 2:07 AM
Subject: [MikroTik] Hostspot question...
Post by George..
Hello all,
I have a hotspot configured in an external ethernet AP device with the
wizard..
As far as I checked, it works fine..
I want to allow a specific client to connect with his MT router, to this
AP, without all this login procedure.
Should I give him a static ip ? What do I have to do with the fw ?
George A. Michalopoulos
Thessaloniki's Wireless Metropolitan Network
http://TWMN.net
_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
with text in the body "unsubscribe <password>" or "subscribe"
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.691 / Virus Database: 452 - Release Date: 26/05/2004
George..
2004-05-28 23:50:53 UTC
Permalink
I suppose I have to add a rule to Input chain first,
Then jump to hotspot-temp,
Then allow everything to this ip and return to input chan, right ?

Well, it does not work ;(
Post by Lee Quince
-----Original Message-----
Sent: Friday, May 28, 2004 10:18 PM
Subject: Re: [MikroTik] Hostspot question...
George
If you give the user a fixed IP then it should be possible to
set a firewall rule to always allow traffic from this IP.
I find the firewall rules are easier to comprehend in the
WinBox interface. Select IP --> Firewall --> Filter Rules and
select the 'Hotspot-Temp' chain. These are the filter rules
active before the client authenticates. Add another filter
before the final reject statement with the Source IP specified.
I use a similar setup to allow access to a mail server before
authentication.
Regards
Andrew
----- Original Message -----
Sent: Friday, May 28, 2004 2:07 AM
Subject: [MikroTik] Hostspot question...
Post by George..
Hello all,
I have a hotspot configured in an external ethernet AP
device with the
Post by George..
wizard.. As far as I checked, it works fine..
I want to allow a specific client to connect with his MT router, to
this AP, without all this login procedure. Should I give
him a static
Post by George..
ip ? What do I have to do with the fw ?
George A. Michalopoulos
Thessaloniki's Wireless Metropolitan Network
http://TWMN.net
_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
unsubscribe/subscribe: email to
text in the body "unsubscribe <password>" or "subscribe"
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.691 / Virus Database: 452 - Release Date: 26/05/2004
Kevin Summers
2004-05-29 00:09:44 UTC
Permalink
The input chain controls only what is being sent directly to an
IP address on the router. If the packet is meant to pass through
the router then you use the Forward chain.

There is typically very little, if anything, in the input and output
chains for our routers. A little housekeeping to prevent attacks
on it, and some allow rules to let people get to the HotSpot servlet.
Other than that, almost everything you want to allow or deny will
be specified in the forward chain.

Kevin Summers
KISTech Internet
www.kistech.com



-----Original Message-----
From: routeros-***@bruno.pmi.lv
[mailto:routeros-***@bruno.pmi.lv]On Behalf Of George..
Sent: Friday, May 28, 2004 4:51 PM
To: 'Andrew Luck'; 'General questions about MikroTik RouterOS'
Subject: RE: [MikroTik] Hostspot question...


I suppose I have to add a rule to Input chain first,
Then jump to hotspot-temp,
Then allow everything to this ip and return to input chan, right ?

Well, it does not work ;(
Post by Lee Quince
-----Original Message-----
Sent: Friday, May 28, 2004 10:18 PM
Subject: Re: [MikroTik] Hostspot question...
George
If you give the user a fixed IP then it should be possible to
set a firewall rule to always allow traffic from this IP.
I find the firewall rules are easier to comprehend in the
WinBox interface. Select IP --> Firewall --> Filter Rules and
select the 'Hotspot-Temp' chain. These are the filter rules
active before the client authenticates. Add another filter
before the final reject statement with the Source IP specified.
I use a similar setup to allow access to a mail server before
authentication.
Regards
Andrew
----- Original Message -----
Sent: Friday, May 28, 2004 2:07 AM
Subject: [MikroTik] Hostspot question...
Post by George..
Hello all,
I have a hotspot configured in an external ethernet AP
device with the
Post by George..
wizard.. As far as I checked, it works fine..
I want to allow a specific client to connect with his MT router, to
this AP, without all this login procedure. Should I give
him a static
Post by George..
ip ? What do I have to do with the fw ?
George A. Michalopoulos
Thessaloniki's Wireless Metropolitan Network
http://TWMN.net
_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
unsubscribe/subscribe: email to
text in the body "unsubscribe <password>" or "subscribe"
---
Outgoing mail is certified Virus Free.
Checked by AVG anti-virus system (http://www.grisoft.com).
Version: 6.0.691 / Virus Database: 452 - Release Date: 26/05/2004
_______________________________________________
ALL POSTS SHOULD BE ABOUT GENERAL ROUTEROS QUESTIONS
To post to the list, address emails to ***@bruno.pmi.lv
To unsubscribe/subscribe: email to RouterOS-***@bruno.pmi.lv ,
with text in the body "unsubscribe <password>" or "subscribe"
Joe Mehaffey
2004-05-29 00:07:44 UTC
Permalink
I use the Mangle (mark) rule to mark a certain MAC address as "already
authenticated by the hotspot" in one of my systems running 2.7.20 code.
This is documents as item #3 at:
http://www.gpsinformation.org/hotspot/mikrotikapplications.html
However, one gentleman who tried it with 2.8.6 reported that the mangle
rule did not work with that version. I am unsure if the feature is
"broken" in that version of the MTOS or if simply they changed the
syntax is someway. Perhaps if you have a problem, someone else here
can assist. I am not presently running 2.8.x in any of my production boxes.

Joe

Loading...