www.glcnetworks.com
Using Mikrotik with RADIUS
GLC webinar, 15 December 2016
Achmad Mardiansyah
achmad@glcnetworks.com
GLC Networks, Indonesia
www.glcnetworks.com
Agenda
â—Ź Introduction
â—Ź Radius concept
â—Ź Using Mikrotik with radius
â—Ź GLC radius manager
â—Ź Demo
â—Ź Q & A
2
www.glcnetworks.com
What is GLC?
â—Ź Garda Lintas Cakrawala (www.glcnetworks.com)
â—Ź An Indonesian company
â—Ź Located in Bandung
â—Ź Areas: Training, IT Consulting
â—Ź Mikrotik Certified Training Partner
â—Ź Mikrotik Certified Consultant
â—Ź Mikrotik distributor
3
www.glcnetworks.com
About GLC webinar?
â—Ź First webinar: january 1, 2010 (title:
tahun baru bersama solaris - new
year with solaris OS)
â—Ź As a sharing event with various
topics: linux, networking, wireless,
database, programming, etc
â—Ź Regular schedule: every 2 weeks
â—Ź Irregular schedule: as needed
â—Ź Checking schedule:
http://www.glcnetworks.com/main/sc
hedule
â—Ź You are invited to be a presenter
â—‹ No need to be an expert
â—‹ This is a forum for sharing: knowledge,
experiences, information
4
www.glcnetworks.com
Trainer Introduction
â—Ź Name: Achmad Mardiansyah
â—Ź Base: bandung, Indonesia
â—Ź Linux user since 1999
â—Ź Mikrotik user since 2007
â—Ź Certified Trainer (MTCNA/RE/WE/UME/INE/TCE)
â—Ź Mikrotik Certified Consultant
â—Ź Work: Telco engineer, Sysadmin, PHP programmer,
and Lecturer
â—Ź Personal website: http://achmadjournal.com
â—Ź More info:
http://au.linkedin.com/in/achmadmardiansyah
5
www.glcnetworks.com
Please introduce yourself
â—Ź Your name
â—Ź Your company/university?
â—Ź Your networking experience?
â—Ź Your mikrotik experience?
â—Ź Your expectation from this course?
6
www.glcnetworks.com
What is Mikrotik?
â—Ź Name of a company
â—Ź A brand
â—Ź A program (e.g. mikrotik academy)
â—Ź Headquarter: Riga, Latvia
7
www.glcnetworks.com
What are mikrotik products?
â—Ź Router OS
â—‹ The OS. Specialized for networking
â—‹ Website: www.mikrotik.com/download
â—Ź RouterBoard
â—‹ The hardware
â—‹ RouterOS installed
â—‹ Website: www.routerboard.com
8
www.glcnetworks.com
What Router OS can do?
â—Ź Go to www.mikrotik.com
â—‹ Download: what_is_routeros.pdf
â—‹ Download: product catalog
â—‹ Download: newsletter
9
www.glcnetworks.com
What are Mikrotik training & certifications?
10
Certificate validity is 3 years
www.glcnetworks.com
Radius
11
www.glcnetworks.com
What is RADIUS?
â—Ź Remote Authentication Dial-In User
Service (RADIUS)
â—Ź Client/server protocol
â—Ź Is used for AAA (authentication,
authorization, accounting)
â—Ź Centralised AAA
â—Ź Created by Livingston (now owned by
Lucent)
â—Ź de facto industry standard used by a
number of network product companies
and is a proposed IETF standard.
â—Ź RFC 2865
â—Ź RFC 2866 (RADIUS accounting)
12
www.glcnetworks.com
RADIUS implementation
â—Ź Consist of:
â—‹ Radius server
â—‹ NAS (Network Access Server). usually has 2
interfaces:
â–  To radius server
â–  To user
â—Ź Using UDP protocol
â—Ź No need to manager user at NAS
â—Ź Can be used with many technology:
(hotspot, pptp, pppoe, etc)
13
RADIUS
server
NAS
NAS NAS
www.glcnetworks.com
AAA security
• Authentication: only registered user can
access
– What you know: username and password
– What you have: token, sms
– What you are: retina scan, fingerprint
• Authorization: define rights of a user
– Access control
– Data access control
– Restriction
– Type of Service
• Accounting: recording of what user is
doing (useful for billing/reporting)
– Traffic volume
– Online time
– Session
– Log: login, logout
14
www.glcnetworks.com
Radius software
● Freeradius (free and opensource) → the radius engine only (no user
interface)
â—Ź User manager (mikrotik product)
â—Ź GLC radius (freeradius + web interface)
â—Ź Blablabla radius (freeradius + web interface)
â—Ź
15
www.glcnetworks.com
Using RADIUS
16
www.glcnetworks.com
Mikrotik services that can be supported by radius
â—Ź PPP
â—‹ To provide PPPOE, PPTP, SSTP, etc
authentication
â—Ź Hotspot
â—‹ Provide authentication of hotspot user
â—Ź DHCP
â—‹ To allow registered MAC address only
â—Ź Login
â—‹ Provide authentication to access mikrotik devices
â—Ź Wireless
â—‹ To allow registered MAC address accessing our
network
17
www.glcnetworks.com
Configure Mikrotik to query radius manager
â—Ź Service: define services supported by
radius manager
â—Ź Server address: IP address of Radius
server
â—Ź Secret: secret word defined by radius
manager
18
www.glcnetworks.com
Mikrotik User Manager
â—Ź A radius manager software, made
by mikrotik
â—Ź Interface: Web based, CLI
â—Ź Require user-manager package
â—Ź Make sure the harddisk space is
enough to store your data
â—Ź To access
http://mikrotik-ip/userman
19
www.glcnetworks.com
Note: proprietary features
â—Ź Radius specification allows specific implementation of vendor
â—Ź Proprietary features -> the NAS from vendor X has feature Y, which can be
activated if the radius server is from vendor X too
â—Ź Sometimes its not open to public
20
www.glcnetworks.com
GLC RADIUS
21
www.glcnetworks.com
GLC radius software
â—Ź Based on freeradius, MySQL, PHP
â—Ź Recommended to run on linux
â—Ź Source code is closed (for interface)
â—Ź Unlimited user (there was a system with 10000+ user)
â—Ź Support prepaid, postpaid
â—Ź Stable -> it works well
â—Ź Support voucher system
22
www.glcnetworks.com
Some GLC radius
features
23
www.glcnetworks.com
QA
24
www.glcnetworks.com
Interested?
Just come to our
training...
Special price for webinar
attendees...
25
www.glcnetworks.com
End of slides
â—Ź Thank you for your attention
â—Ź Please submit your feedback: http://bit.ly/glcfeedback
● Like our facebook page: “GLC networks”
â—Ź Stay tune with our schedule
26

Using mikrotik with radius

  • 1.
    www.glcnetworks.com Using Mikrotik withRADIUS GLC webinar, 15 December 2016 Achmad Mardiansyah achmad@glcnetworks.com GLC Networks, Indonesia
  • 2.
    www.glcnetworks.com Agenda â—Ź Introduction â—Ź Radiusconcept â—Ź Using Mikrotik with radius â—Ź GLC radius manager â—Ź Demo â—Ź Q & A 2
  • 3.
    www.glcnetworks.com What is GLC? â—ŹGarda Lintas Cakrawala (www.glcnetworks.com) â—Ź An Indonesian company â—Ź Located in Bandung â—Ź Areas: Training, IT Consulting â—Ź Mikrotik Certified Training Partner â—Ź Mikrotik Certified Consultant â—Ź Mikrotik distributor 3
  • 4.
    www.glcnetworks.com About GLC webinar? â—ŹFirst webinar: january 1, 2010 (title: tahun baru bersama solaris - new year with solaris OS) â—Ź As a sharing event with various topics: linux, networking, wireless, database, programming, etc â—Ź Regular schedule: every 2 weeks â—Ź Irregular schedule: as needed â—Ź Checking schedule: http://www.glcnetworks.com/main/sc hedule â—Ź You are invited to be a presenter â—‹ No need to be an expert â—‹ This is a forum for sharing: knowledge, experiences, information 4
  • 5.
    www.glcnetworks.com Trainer Introduction â—Ź Name:Achmad Mardiansyah â—Ź Base: bandung, Indonesia â—Ź Linux user since 1999 â—Ź Mikrotik user since 2007 â—Ź Certified Trainer (MTCNA/RE/WE/UME/INE/TCE) â—Ź Mikrotik Certified Consultant â—Ź Work: Telco engineer, Sysadmin, PHP programmer, and Lecturer â—Ź Personal website: http://achmadjournal.com â—Ź More info: http://au.linkedin.com/in/achmadmardiansyah 5
  • 6.
    www.glcnetworks.com Please introduce yourself â—ŹYour name â—Ź Your company/university? â—Ź Your networking experience? â—Ź Your mikrotik experience? â—Ź Your expectation from this course? 6
  • 7.
    www.glcnetworks.com What is Mikrotik? â—ŹName of a company â—Ź A brand â—Ź A program (e.g. mikrotik academy) â—Ź Headquarter: Riga, Latvia 7
  • 8.
    www.glcnetworks.com What are mikrotikproducts? â—Ź Router OS â—‹ The OS. Specialized for networking â—‹ Website: www.mikrotik.com/download â—Ź RouterBoard â—‹ The hardware â—‹ RouterOS installed â—‹ Website: www.routerboard.com 8
  • 9.
    www.glcnetworks.com What Router OScan do? â—Ź Go to www.mikrotik.com â—‹ Download: what_is_routeros.pdf â—‹ Download: product catalog â—‹ Download: newsletter 9
  • 10.
    www.glcnetworks.com What are Mikrotiktraining & certifications? 10 Certificate validity is 3 years
  • 11.
  • 12.
    www.glcnetworks.com What is RADIUS? â—ŹRemote Authentication Dial-In User Service (RADIUS) â—Ź Client/server protocol â—Ź Is used for AAA (authentication, authorization, accounting) â—Ź Centralised AAA â—Ź Created by Livingston (now owned by Lucent) â—Ź de facto industry standard used by a number of network product companies and is a proposed IETF standard. â—Ź RFC 2865 â—Ź RFC 2866 (RADIUS accounting) 12
  • 13.
    www.glcnetworks.com RADIUS implementation â—Ź Consistof: â—‹ Radius server â—‹ NAS (Network Access Server). usually has 2 interfaces: â–  To radius server â–  To user â—Ź Using UDP protocol â—Ź No need to manager user at NAS â—Ź Can be used with many technology: (hotspot, pptp, pppoe, etc) 13 RADIUS server NAS NAS NAS
  • 14.
    www.glcnetworks.com AAA security • Authentication:only registered user can access – What you know: username and password – What you have: token, sms – What you are: retina scan, fingerprint • Authorization: define rights of a user – Access control – Data access control – Restriction – Type of Service • Accounting: recording of what user is doing (useful for billing/reporting) – Traffic volume – Online time – Session – Log: login, logout 14
  • 15.
    www.glcnetworks.com Radius software ● Freeradius(free and opensource) → the radius engine only (no user interface) ● User manager (mikrotik product) ● GLC radius (freeradius + web interface) ● Blablabla radius (freeradius + web interface) ● 15
  • 16.
  • 17.
    www.glcnetworks.com Mikrotik services thatcan be supported by radius â—Ź PPP â—‹ To provide PPPOE, PPTP, SSTP, etc authentication â—Ź Hotspot â—‹ Provide authentication of hotspot user â—Ź DHCP â—‹ To allow registered MAC address only â—Ź Login â—‹ Provide authentication to access mikrotik devices â—Ź Wireless â—‹ To allow registered MAC address accessing our network 17
  • 18.
    www.glcnetworks.com Configure Mikrotik toquery radius manager â—Ź Service: define services supported by radius manager â—Ź Server address: IP address of Radius server â—Ź Secret: secret word defined by radius manager 18
  • 19.
    www.glcnetworks.com Mikrotik User Manager â—ŹA radius manager software, made by mikrotik â—Ź Interface: Web based, CLI â—Ź Require user-manager package â—Ź Make sure the harddisk space is enough to store your data â—Ź To access http://mikrotik-ip/userman 19
  • 20.
    www.glcnetworks.com Note: proprietary features â—ŹRadius specification allows specific implementation of vendor â—Ź Proprietary features -> the NAS from vendor X has feature Y, which can be activated if the radius server is from vendor X too â—Ź Sometimes its not open to public 20
  • 21.
  • 22.
    www.glcnetworks.com GLC radius software â—ŹBased on freeradius, MySQL, PHP â—Ź Recommended to run on linux â—Ź Source code is closed (for interface) â—Ź Unlimited user (there was a system with 10000+ user) â—Ź Support prepaid, postpaid â—Ź Stable -> it works well â—Ź Support voucher system 22
  • 23.
  • 24.
  • 25.
    www.glcnetworks.com Interested? Just come toour training... Special price for webinar attendees... 25
  • 26.
    www.glcnetworks.com End of slides ●Thank you for your attention ● Please submit your feedback: http://bit.ly/glcfeedback ● Like our facebook page: “GLC networks” ● Stay tune with our schedule 26