快捷搜索:

RouterOS平台下Hotspot设置

我的routeros是2块网卡,ether1连接adsl,做pppoe client,ether2连接局域网。

首先按照论坛上置顶的阐明精确安装并设置设置设备摆设摆设routeros,实现客户性能够正常上网。

然后terminal routeros

改变www办事端口为8081:

/ip service set www port=8081

改变hotspot办事端口为80,为用户登录页面做筹备:

/ip service set hotspot port=80

Setup hotspot profile to mark authenticated users with flow name "hs-auth":

/ip hotspot profile set default mark-flow="hs-auth" login-method=enabled-address

增添一个用户:

/ip hotspot user add name=user1 password=1

重定向所有未授权用户的tcp哀求到hotspot办事

/ip firewall dst-nat add in-interface="ether2" flow="!hs-auth" protocol=tcp action=redirect

to-dst-port=80 comment="redirect unauthorized clients to hotspot service"

容许dns哀求、icmp ping ;回绝其他未经认证的所有哀求:

/ip firewall add name=hotspot-temp comment="limit unauthorized hotspot clients"

/ip firewall rule forward add in-interface=ether2 action=jump

jump-target=hotspot-temp comment="limit access for unauthorized hotspot clients"

/ip firewall rule input add in-interface=ether2 dst-port=80 protocol=tcp

action=accept comment="accept requests for hotspot servlet"

/ip firewall rule input add in-interface=ether2 dst-port=67 protocol=udp

action=accept comment="accept requests for local DHCP server"

/ip firewall rule input add in-interface=ether2 action=jump

jump-target=hotspot-temp comment="limit access for unauthorized hotspot clients"

/ip firewall rule hotspot-temp add flow="hs-auth" action=return

comment="return if connection is authorized"

/ip firewall rule hotspot-temp add protocol=icmp action=return

comment="allow ping requests"

/ip firewall rule hotspot-temp add protocol=udp dst-port=53 action=return

comment="allow dns requests"

/ip firewall rule hotspot-temp add action=reject

comment="reject access for unauthorized clients"

创建hotspot通道给认证后的hotspot用户

Create hotspot chain for authorized hotspot clients:

/ip firewall add name=hotspot comment="account authorized hotspot clients"

Pass all through going traffic to hotspot chain:

/ip firewall rule forward add action=jump jump-target=hotspot

comment="account traffic for authorized hotspot clients"

客户机输入任何网址,都自动跳转到登岸页面,输入账号密码,继承浏览。

假如应用ftp、pop3等,也必须先经由过程网页登录,才可以应用,当然应用winbox的时刻也必须先登录。

您可能还会对下面的文章感兴趣: