Mikrotik RB with virtula AP

Creating the virtual AP

vap1

Click “Wireless” and then “interfaces”.

vap2

Select “VirtualAP”

vap3

For “general” see “wlan2” position.

vap4

Change this name, as an example: “ap-guest”. Click on “apply”.

vap5

Click “Wireless”.

vap6

At “SSID” give a name to transmit the AP. Click “apply” and “OK”.

vap7

Thus, virtual access point is created.

Assign IP address and set up a DHCP server

vap8

Click “IP” and then “addresses”.

vap9

Click on the blue cross to allocate an IP address.

vap12

Under “Interface” virtual access point. Enter to “address” the virtual access point an IP address with a / 24 behind. Click “apply” and “ok”.

vap13

Click “IP” then “DHCP server”, now follow steps that are created automatically, but we will go over this again

vap14

Click DHCP setup

vap15

Select the virtual access point. Click “next”.

vap16

When “DHCP address space” click “next”.

vap17

At “gateway for DHCP network” will appear the IP address that you have given to the virtual access point. Then click “next”.

vap18

At “addresses to give out” click “next”.

vap19

“DNS servers” enter the IP addresses of your internet provider. Click “next”.

vap17

With “lease time” (this is the time that the DHCP server will reserve the IP address to a specific PC) let alone the institution or change it, click on “next”.

vap21

The DHCP server is configured.

Wet settings

vap22

Click “IP” and then on “firewall.”

vap23

Click further by “NAT” and then click on the blue cross.

vap24

  • In “chain” select “srcnat”.
  • In “src address” you fill in the IP range.
  • In “Out interface”, select the Ethernet interface connected to the ISP modem.

vap25

In “action” select “masquerade”.

To avoid setting the two IP ranks can achieve together we can set firewall rules.

vap29

Click “IP” and then on “firewall.”

vap26

  • For “general” to select “chain” “input”
  • When “Scr address” you enter the IP range 192.168.88.0/24 in.
  • At “Dst address” you enter the IP range 192.168.11.0/24 in.

vap27

 

Click on “action” in “action” select “drop”. This will prevent users of the IP range 192.168.88.0/24 will have access to IP range 192.168.11.0/24.

Now we do the reverse. Users on the IP range 192.168.11.0/24 will also gain access to the IP range 10.98.88.0/24.

vap28

  • For “general” to select “chain” “input”
  • When “Scr address” you enter the IP range 192.168.11.0/24 in.
  • At “Dst address” you enter the IP range 192.168.88.0/24 in.

vap27

Click on “action” in “action” select “drop”.

Thus, it is ready for use.

 

source:wirelessinfo.be

846 total views, 1 views today

Print Friendly