modul hotspot

40
Hotspot Divisi Training Departemen Teknik PT UFOAKSES SUKSES LUARBIASA Jakarta [email protected]

Upload: sutrisno-sukarno

Post on 28-Dec-2015

49 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Modul Hotspot

Hotspot

Divisi TrainingDepartemen TeknikPT UFOAKSES SUKSES [email protected]

Page 2: Modul Hotspot

Hotspot

HotSpot is used for authentication in local networkAuthentication is based on HTTP/HTTPS protocol meaning it can work with any Internet browserHotSpot is a system combining together various independent features of RouterOS to provide the so called ‘Plug-and-Play’ access

Page 3: Modul Hotspot

Hotspot Scheme

Page 4: Modul Hotspot

Hotspot

User tries to open a webpageRouter checks if the useris already authenticated inthe HotSpot systemIf not, user is redirectedto the HotSpot login pageUser specifies the logininformation

Page 5: Modul Hotspot

Hotspot

If the login information iscorrect, then the routerauthenticates the client in theHotspot system;opens the requested web page;opens a status pop-up windowThe user can access thenetwork through theHotSpot gateway

Page 6: Modul Hotspot

HotSpot Features

User authenticationUser accounting by time, data transmitted/receivedData limitation− by data rate− by amount

Usage restrictions by timeRADIUS supportWalled garden

Page 7: Modul Hotspot

Konfigurasi Router Via Winbox

Page 8: Modul Hotspot

Create Wlan for Hotspot

Page 9: Modul Hotspot

Create Hotspot

Page 10: Modul Hotspot

Aded IP address For gateway Hotspot

Page 11: Modul Hotspot

Create IP adress Hotspot

Page 12: Modul Hotspot

Dhcp Server setup

Page 13: Modul Hotspot

DNS setup

Page 14: Modul Hotspot

Hotspot Complete Setup

Page 15: Modul Hotspot

HotSpot Server Setup

Automatically creates configuration entries in/ip hotspot/ip hotspot profile/ip hotspot users/ip pool/ip dhcp-server/ip dhcp-server networks/ip firewall nat (dynamic rules)

Page 16: Modul Hotspot

Hotspot Profile

Page 17: Modul Hotspot

Uses Radius

Page 18: Modul Hotspot

HotSpot Authentication

HTTP PAP - simplest method, which shows the HotSpot login page and expects to get the user credentials in plain text (maximum compatibility mode)HTTP CHAP - standard method, which includes CHAP computing for the string which will be sent to the HotSpot gateway.HTTPS – plain text authentication using SSL protocol to protect the session

Page 19: Modul Hotspot

HotSpot Authentication

HTTP cookie - after each successful login, a cookie is sent to the web browser and the same cookie is added to active HTTP cookie list. This method may only be used together with HTTP PAP, HTTP CHAP or HTTPS methodsMAC address - authenticates clients as soon as they appear in the hosts list, using client's MAC address as user nameTrial - does not require authentication for a certain amount of time

Page 20: Modul Hotspot

Configure User

Page 21: Modul Hotspot

HotSpot User Profiles

Page 22: Modul Hotspot

HotSpot IP Bindings

Page 23: Modul Hotspot

HotSpot IP Bindings

Setup static NAT translations based on either− the original IP address (or IP network),− the original MAC address.

Allow some addresses to bypass HotSpotauthentication. Usefully for providing IP telephony or server services.Completely block some addresses.

Page 24: Modul Hotspot

HotSpot HTTP-level Walled Garden

Page 25: Modul Hotspot

HotSpot HTTP-level Walled Garden

Walled garden allows to bypass HotSpotauthentication for some resourcesHTTP-level Walled Garden manages HTTP and HTTPS protocolsHTTP-level Walled Garden works like Web-proxy filtering, you can use the same HTTP methods and same regular expressions to make an URL string

Page 26: Modul Hotspot

HotSpot IP-level WalledIP-level Walled Garden works on the IP level, use it like IP firewall filter

Page 27: Modul Hotspot

Login Page Customization

There are HTML template pages on the router FTP for each active HotSpot profileThose HTML pages contain variables which will be replaced with the actual information by the HotSpot before sending to the clientIt is possible to modify those pages, but you must directly download HTML pages from the FTP to modify them correctly

Page 28: Modul Hotspot

Login pages Hotspot

Page 29: Modul Hotspot

User Manager for HotSpot

Centralized Authorization and Accounting systemWorks as a RADIUS serverBuilt in MikroTik RouterOS as a separate package

Page 30: Modul Hotspot

Requirements for User Manager

x86 based router with MikroTik RouterOS v2.9.x and v3.1Router with at least 32MB RAMFree 2MB of HDD spaceRouterOS Level 4 license for more than 10 active sessions (in RouterOS v2.9.x)

Page 31: Modul Hotspot

Features

User Authorization using PAP,CHAPMultiple subscriber support and permission managementCredits/Prepaid support for usersRate-limit attribute supportUser friendly WEB interface supportReport generation by time/amountDetailed sessions and logs supportSimple user adding and voucher printing support

Page 32: Modul Hotspot

New Features

User Authorization using MSCHAPv1,MSCHAPv2User status pageUser sign up systemSupport for decimal places in creditsAuthorize.net and PayPal payment gateway supportDatabase backup featureLicense changes in RouterOS v3.0 for active users:− Level3 – 10 active users− Level4 – 20 active users− Level5 – 50 active users− Level6 – Unlimited active users

Page 33: Modul Hotspot

Supported Services

Hotspot user authorizationPPP/PPtP/PPPoE users authorization,Encryption also supportedDHCP MAC authorizationWireless MAC authorizationRouterOS users authorization

Page 34: Modul Hotspot

User Manager Usage

HotelsAirportsCafésUniversitiesCompaniesISPs

Page 35: Modul Hotspot

User Signup

User can create a new account by filling out the form. An account activation email will be sent to the users email address

Page 36: Modul Hotspot

Billing Hotspotmenggunakan User Manager

Page 37: Modul Hotspot

Konfigurasi Billing

Page 38: Modul Hotspot

Menambahkan Radius

Page 39: Modul Hotspot

Create User

Page 40: Modul Hotspot

Generate User