Professional Documents
Culture Documents
CAPsMAN
Mikrotik User Meeting Yogyakarta,
October 19-20, 2018
Achmad Mardiansyah
achmad@glcnetworks.com
GLC Networks, Indonesia
www.glcnetworks.com
Agenda
● Introduction
● Enterprise wireless
● How CAPsMAN works
● CAPsMAN features
● CAPsMAN tips
● Suggestions for Mikrotik
● Q&A
2
www.glcnetworks.com
What is GLC?
3
www.glcnetworks.com
About me
● Name: Achmad Mardiansyah
● Base: bandung, Indonesia
● Linux user since 1999, mikrotik user since 2007,
● Mikrotik Certified Trainer
(MTCNA/RE/WE/UME/INE/TCE/IPv6)
● Mikrotik Certified Consultant
● Teacher at Telkom University (Bandung, Indonesia)
● Website contributor: achmadjournal.com,
mikrotik.tips, asysadmin.tips
● More info:
http://au.linkedin.com/in/achmadmardiansyah
4
www.glcnetworks.com
Past experiences
● 2018, Malaysia: integrated monitoring system and
bandwidth management for a broadband ISP
● 2017, Libya (north africa): remote wireless migration
for a new Wireless ISP
● 2016, United Kingdom: facilitates workshop for a
wireless ISP, migrating a bridged to routed network
● 2015, West Borneo: supporting wireless
infrastructure project
● 2014, Senegal (west africa): TAC2 engineer for HLR
migration from NOKIA to ERICSSON
● 2013, Malaysia: build a wireless network to support
an international event
www.glcnetworks.com
About Telkom University
6
www.glcnetworks.com
Mikrotik academy @ TEL-U
● Started in 2013
● Embedded into schools curriculum
● 100% hands-on
● Get MTCNA certification
7
www.glcnetworks.com
Enterprise wireless
8
www.glcnetworks.com
Characteristics of enterprise wireless
9
www.glcnetworks.com
How CAPsMAN works
10
www.glcnetworks.com
About CAPsMAN
11
www.glcnetworks.com
CAPsMAN - CAP connectivity
CAPs
ISP MAN
ISP
RO RO
RO RO
12
www.glcnetworks.com
CAPsMAN configuration concepts
CAP interface
Provisioning rules
configuration
13
www.glcnetworks.com
Channels | datapath | security cfg | rates
14
www.glcnetworks.com
configuration
15
www.glcnetworks.com
Provisioning rule
16
www.glcnetworks.com
Master vs slave configuration
Master Slave
● WIll be used to set basic wireless ● Basic wireless parameter will be ignored
parameters: Frequency, channel-width, TX ● Is used to setup additional SSID (Virtual
power AP)
www.glcnetworks.com
CAP interface
master interface
Slave interface
18
www.glcnetworks.com
CAPsMAN features
19
www.glcnetworks.com
Access list
Notes:
20
www.glcnetworks.com
Load balancing AP
before after
CAPs
CAPs
ISP MAN
ISP
MAN
RO
RO RO
RO
21
www.glcnetworks.com
Roaming
22
www.glcnetworks.com
Datapath (local forwarding)
23
www.glcnetworks.com
Datapath (vlan)
no vlan vlan=22
CAPs
CAPs
ISP MAN
ISP
MAN
RO
RO RO
RO
VLAN=22
NO VLAN
NO VLAN NO VLAN
24
www.glcnetworks.com
Datapath (vlan per user)
VLAN=22
VLAN=11
NO VLAN NO VLAN
25
www.glcnetworks.com
Security: EAP (layer 2 authentication)
26
www.glcnetworks.com
MAC based authentication
27
www.glcnetworks.com
CAPsMAN tips
28
www.glcnetworks.com
CAP: use auto certificate
29
www.glcnetworks.com
CAP: high availability
30
www.glcnetworks.com
CAPsMAN: upgrade CAP version
31
www.glcnetworks.com
Wireless survey
32
www.glcnetworks.com
Enable client isolation and port isolation
33
www.glcnetworks.com
Smooth mobility for client
34
www.glcnetworks.com
Flexible provisioning
35
www.glcnetworks.com
Flexible provisioning
36
www.glcnetworks.com
VLAN ID per user
37
www.glcnetworks.com
Suggestions for mikrotik
38
www.glcnetworks.com
Automatic band steering
39
www.glcnetworks.com
Signal visualisation on floor layout
40
www.glcnetworks.com
Detecting rogue access point
41
www.glcnetworks.com
EAP support on usermanager
42
www.glcnetworks.com
Complete controller application
43
www.glcnetworks.com
Training topics
44
www.glcnetworks.com
Interested? Just come to our training...
● Check schedule on our website
● More hands-on
● Not only learn the materials, but also sharing experiences, best-practices, and
networking
45
www.glcnetworks.com
QA
46
www.glcnetworks.com
End of slides
47
www.glcnetworks.com