+ Responder ao Tópico



  1. #1

    Angry reassociating, disconnected, ok, connected

    Não sei o que acontece depois que coloquei a RB 3.2 começou a dar essas msgs, porem a navegação dos clientes estao normais, já fixei o ack 50 62 91 deixei como dynamic indoor sinceramente nao sei o que fazer, alguem já passou por esta situação?

    https://under-linux.org/fotos/wagner...sconnected.jpg

    Desde já agradeço.

  2. #2

    Padrão Minhas Configs

    RouterOS 3.22

    /interface ethernet
    set 0 arp=enabled auto-negotiation=yes comment="" disabled=no full-duplex=yes mac-address=00:0C:42:43:04:8F \
    mtu=1500 name=Link speed=100Mbps
    set 1 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment="" disabled=no full-duplex=yes \
    mac-address=00:0C:42:43:04:90 master-port=none mtu=1500 name=Proxy speed=100Mbps
    set 2 arp=enabled auto-negotiation=yes bandwidth=unlimited/unlimited comment="" disabled=no full-duplex=yes \
    mac-address=00:0C:42:43:04:91 master-port=none mtu=1500 name=ether3 speed=100Mbps
    /interface wireless security-profiles
    set default authentication-types="" eap-methods=passthrough group-ciphers="" group-key-update=5m \
    interim-update=0s mode=none name=default radius-eap-accounting=no radius-mac-accounting=no \
    radius-mac-authentication=no radius-mac-caching=disabled radius-mac-format=XX:XX:XX:XX:XX:XX \
    radius-mac-mode=as-username static-algo-0=none static-algo-1=none static-algo-2=none static-algo-3=none \
    static-key-0="" static-key-1="" static-key-2="" static-key-3="" static-sta-private-algo=none \
    static-sta-private-key="" static-transmit-key=key-0 supplicant-identity=MikroTik tls-certificate=none \
    tls-mode=no-certificates unicast-ciphers="" wpa-pre-shared-key="" wpa2-pre-shared-key=""
    /interface wireless
    set 0 ack-timeout=dynamic adaptive-noise-immunity=none allow-sharedkey=no antenna-gain=0 antenna-mode=ant-a \
    area="" arp=enabled band=2.4ghz-b basic-rates-a/g=12Mbps basic-rates-b=11Mbps burst-time=disabled comment=\
    "" compression=no country=no_country_set default-ap-tx-limit=0 default-authentication=yes \
    default-client-tx-limit=0 default-forwarding=yes dfs-mode=none disable-running-check=no disabled=no \
    disconnect-timeout=3s frame-lifetime=0 frequency=2447 frequency-mode=manual-txpower hide-ssid=no \
    hw-retries=4 mac-address=00:02:6F:61:96:C4 max-station-count=2007 mode=ap-bridge mtu=1500 name=clientes \
    noise-floor-threshold=default on-fail-retry-time=100ms periodic-calibration=default \
    periodic-calibration-interval=60 preamble-mode=long proprietary-extensions=post-2.9.25 radio-name=\
    "Spider Net" rate-set=configured scan-list=default security-profile=default ssid="Spider Net" \
    station-bridge-clone-mac=00:00:00:00:00:00 supported-rates-a/g=12Mbps supported-rates-b=11Mbps tx-power=26 \
    tx-power-mode=card-rates update-stats-interval=disabled wds-cost-range=50-150 wds-default-bridge=none \
    wds-default-cost=100 wds-ignore-ssid=no wds-mode=disabled wmm-support=disabled
    /interface wireless manual-tx-power-table
    set clientes comment="" manual-tx-powers="1Mbps:26,2Mbps:26,5.5Mbps:26,11Mbps:26,6Mbps:26,9Mbps:26,12Mbps:26,18\
    Mbps:26,24Mbps:26,36Mbps:26,48Mbps:26,54Mbps:26,HT20-1:0,HT20-2:0,HT20-3:0,HT20-4:0,HT20-5:0,HT20-6:0,HT20-\
    7:0,HT20-8:0,HT40-1:0,HT40-2:0,HT40-3:0,HT40-4:0,HT40-5:0,HT40-6:0,HT40-7:0,HT40-8:0"
    /interface wireless nstreme
    set clientes comment="" disable-csma=no enable-nstreme=no enable-polling=yes framer-limit=3200 framer-policy=\
    none
    /ip hotspot profile
    set default dns-name="" hotspot-address=0.0.0.0 html-directory=hotspot http-proxy=0.0.0.0:0 login-by=http-chap \
    name=default nas-port-type=ethernet radius-accounting=yes radius-default-domain="" radius-interim-update=\
    received radius-location-id="" radius-location-name="" radius-mac-format=XX:XX:XX:XX:XX:XX rate-limit="" \
    smtp-server=0.0.0.0 split-user-domain=no use-radius=yes
    add dns-name=radio.spidernet hotspot-address=192.168.10.1 html-directory=hotspot http-proxy=0.0.0.0:0 \
    login-by=http-chap,http-pap name=profile nas-port-type=ethernet radius-accounting=yes \
    radius-default-domain="" radius-interim-update=received radius-location-id="" radius-location-name="" \
    radius-mac-format=XX:XX:XX:XX:XX:XX rate-limit="" smtp-server=0.0.0.0 split-user-domain=no use-radius=yes
    /ip hotspot user profile
    set default idle-timeout=none keepalive-timeout=2m name=default shared-users=1 status-autorefresh=1m \
    transparent-proxy=no
    add advertise=yes advertise-interval=30m advertise-timeout=immediately advertise-url=aviso.html idle-timeout=\
    none keepalive-timeout=2m name=aviso open-status-page=always shared-users=1 status-autorefresh=1m \
    transparent-proxy=yes
    add advertise=yes advertise-interval=1s advertise-timeout=immediately advertise-url=bloqueado.html \
    idle-timeout=none keepalive-timeout=2m name=bloqueado open-status-page=always shared-users=1 \
    status-autorefresh=1m transparent-proxy=yes
    add idle-timeout=none keepalive-timeout=2m name=300k rate-limit=200k/350k shared-users=1 status-autorefresh=1m \
    transparent-proxy=no
    /ip ipsec proposal
    set default auth-algorithms=sha1 disabled=no enc-algorithms=3des lifetime=30m name=default pfs-group=modp1024
    /ip pool
    add name=pool ranges=192.168.10.2-192.168.10.254
    add name=dhcp_pool1 ranges=10.5.50.2-10.5.50.254
    /ip dhcp-server
    add address-pool=pool authoritative=after-2sec-delay bootp-support=static disabled=no interface=clientes \
    lease-time=3d name=dhcp
    add address-pool=dhcp_pool1 authoritative=after-2sec-delay bootp-support=static disabled=no interface=ether3 \
    lease-time=3d name=dhcp1
    /ip hotspot
    add address-pool=pool addresses-per-mac=3 disabled=no idle-timeout=10m interface=clientes keepalive-timeout=\
    none name=Hot1 profile=profile
    /port
    set 0 baud-rate=auto data-bits=8 flow-control=none name=serial0 parity=none stop-bits=1
    /ppp profile
    set default change-tcp-mss=yes comment="" name=default only-one=default use-compression=default \
    use-encryption=default use-vj-compression=default
    set default-encryption change-tcp-mss=yes comment="" name=default-encryption only-one=default use-compression=\
    default use-encryption=yes use-vj-compression=default
    /interface pppoe-client
    add ac-name="" add-default-route=yes allow=pap,chap,mschap1,mschap2 comment="" dial-on-demand=no disabled=no \
    interface=Link max-mru=1480 max-mtu=1480 mrru=disabled name=speedy password=e185 profile=default \
    service-name="" use-peer-dns=yes [email protected]
    /queue type
    set default kind=pfifo name=default pfifo-limit=50
    set ethernet-default kind=pfifo name=ethernet-default pfifo-limit=50
    set wireless-default kind=sfq name=wireless-default sfq-allot=1514 sfq-perturb=5
    set synchronous-default kind=red name=synchronous-default red-avg-packet=1000 red-burst=20 red-limit=60 \
    red-max-threshold=50 red-min-threshold=10
    set hotspot-default kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=5
    add kind=pcq name=cache pcq-classifier=dst-address pcq-limit=50 pcq-rate=4800000 pcq-total-limit=2000
    set default-small kind=pfifo name=default-small pfifo-limit=10
    /queue tree
    add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=0 max-limit=0 name=CACHE-FULL \
    packet-mark=Cache-Packet parent=global-out priority=8 queue=cache
    add burst-limit=0 burst-threshold=0 burst-time=0s disabled=no limit-at=1000000 max-limit=2000000 name=\
    ThunderCache packet-mark=thunder-packs parent=global-out priority=8 queue=default
    /routing bgp instance
    set default as=65530 client-to-client-reflection=yes comment="" disabled=no ignore-as-path-len=no name=default \
    out-filter="" redistribute-connected=no redistribute-ospf=no redistribute-other-bgp=no redistribute-rip=no \
    redistribute-static=no router-id=0.0.0.0
    /routing ospf area
    add area-id=0.0.0.0 authentication=none disabled=no name=backbone type=default
    /snmp
    set contact="" enabled=no engine-boots=0 engine-id="" location="" time-window=15 trap-sink=0.0.0.0 \
    trap-version=1
    /snmp community
    set public address=0.0.0.0/0 authentication-password="" authentication-protocol=MD5 encryption-password="" \
    encryption-protocol=DES name=public read-access=yes security=none write-access=no
    /system logging action
    set memory memory-lines=100 memory-stop-on-full=no name=memory target=memory
    set disk disk-file-count=2 disk-file-name=log disk-lines-per-file=100 disk-stop-on-full=no name=disk target=\
    disk
    set echo name=echo remember=yes target=echo
    set remote bsd-syslog=no name=remote remote=0.0.0.0:514 src-address=0.0.0.0 syslog-facility=daemon \
    syslog-severity=auto target=remote
    /system routerboard settings
    set baud-rate=115200 boot-delay=2s boot-device=nand-if-fail-then-ethernet boot-protocol=bootp cpu-frequency=\
    300MHz enable-jumper-reset=yes enter-setup-on=any-key force-backup-booter=no
    set baud-rate=115200 boot-delay=2s boot-device=nand-if-fail-then-ethernet boot-protocol=bootp cpu-frequency=\
    300MHz enable-jumper-reset=yes enter-setup-on=any-key force-backup-booter=no
    /user group
    add name=read policy=local,telnet,ssh,reboot,read,test,winbox,password,web,sniff,!ftp,!write,!policy
    add name=write policy=local,telnet,ssh,reboot,read,write,test,winbox,password,web,sniff,!ftp,!policy
    add name=full policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,password,web,sniff
    /interface bridge settings
    set use-ip-firewall=no use-ip-firewall-for-pppoe=no use-ip-firewall-for-vlan=no
    /interface ethernet mirror
    set mirror-port=none source-port=none
    /interface l2tp-server server
    set authentication=pap,chap,mschap1,mschap2 default-profile=default-encryption enabled=no max-mru=1460 \
    max-mtu=1460 mrru=disabled
    /interface ovpn-server server
    set auth=sha1,md5 certificate=none cipher=blowfish128,aes128 default-profile=default enabled=no \
    keepalive-timeout=60 mac-address=FE:78:38:0A:C7:77 max-mtu=1500 mode=ip netmask=24 port=1194 \
    require-client-certificate=no
    /interface pptp-server server
    set authentication=mschap1,mschap2 default-profile=default-encryption enabled=no keepalive-timeout=30 max-mru=\
    1460 max-mtu=1460 mrru=disabled

  3. #3

    Padrão

    /interface wireless align
    set active-mode=yes audio-max=-20 audio-min=-100 audio-monitor=00:00:00:00:00:00 filter-mac=00:00:00:00:00:00 \
    frame-size=300 frames-per-second=25 receive-all=no ssid-all=no
    /interface wireless sniffer
    set channel-time=200ms file-limit=10 file-name="" memory-limit=10 multiple-channels=no only-headers=no \
    receive-errors=no streaming-enabled=no streaming-max-rate=0 streaming-server=0.0.0.0
    /interface wireless snooper
    set channel-time=200ms multiple-channels=yes receive-errors=no
    /ip accounting
    set account-local-traffic=no enabled=no threshold=256
    /ip accounting web-access
    set accessible-via-web=no address=0.0.0.0/0
    /ip address
    add address=200.200.200.1/24 broadcast=200.200.200.255 comment="" disabled=no interface=Link network=\
    200.200.200.0
    add address=10.10.0.1/30 broadcast=10.10.0.3 comment="" disabled=no interface=Proxy network=10.10.0.0
    add address=192.168.10.1/24 broadcast=192.168.10.255 comment="" disabled=no interface=clientes network=\
    192.168.10.0
    add address=10.5.50.1/24 broadcast=10.5.50.255 comment="hotspot network" disabled=no interface=ether3 network=\
    10.5.50.0
    /ip dhcp-server config
    set store-leases-disk=5m
    /ip dhcp-server network
    add address=10.5.50.0/24 comment="" gateway=10.5.50.1
    add address=192.168.10.0/24 comment="hotspot network" gateway=192.168.10.1
    /ip dns
    set allow-remote-requests=yes cache-max-ttl=1w cache-size=2048KiB max-udp-packet-size=512 primary-dns=\
    200.204.0.10 secondary-dns=200.204.0.138
    /ip dns static
    add address=10.10.0.1 disabled=yes name=mk.provebuntu ttl=1d
    add address=10.10.0.2 disabled=yes name=provebuntu ttl=1d
    /ip firewall connection tracking
    set enabled=yes generic-timeout=10m icmp-timeout=10s tcp-close-timeout=10s tcp-close-wait-timeout=10s \
    tcp-established-timeout=1d tcp-fin-wait-timeout=10s tcp-last-ack-timeout=10s tcp-syn-received-timeout=5s \
    tcp-syn-sent-timeout=5s tcp-syncookie=no tcp-time-wait-timeout=10s udp-stream-timeout=3m udp-timeout=10s
    /ip firewall mangle
    add action=mark-connection chain=postrouting comment="Marca o com sem TOS" disabled=no dscp=12 \
    new-connection-mark=n-cache passthrough=yes protocol=tcp src-port=3128
    add action=mark-connection chain=postrouting comment="" disabled=no dscp=!12 new-connection-mark=s-cache \
    passthrough=yes protocol=tcp src-port=3128
    add action=mark-packet chain=postrouting comment="Libera Cache Full" connection-mark=n-cache disabled=no \
    new-packet-mark=Cache-Packet passthrough=no
    add action=mark-connection chain=forward comment="THUNDER CACHE FULL" content="THUNDER: THUNDER" disabled=no \
    new-connection-mark=thunder-connection passthrough=yes protocol=tcp
    add action=mark-packet chain=forward comment="" connection-mark=thunder-connection disabled=no \
    new-packet-mark=thunder-packs passthrough=yes protocol=tcp
    /ip firewall nat
    add action=passthrough chain=unused-hs-chain comment="place hotspot rules here" disabled=yes
    add action=masquerade chain=srcnat comment="NAT PROXY" disabled=no src-address=10.10.0.0/30
    add action=dst-nat chain=pre-hotspot comment="REDIRECIONAMENTO PROXY" disabled=yes dst-address=!10.10.0.2 \
    dst-port=80 hotspot=auth in-interface=clientes protocol=tcp src-address=192.168.10.0/24 to-addresses=\
    10.10.0.2 to-ports=3128
    add action=dst-nat chain=dstnat comment="ACESSO EXTERNO PROVEBUNTU" disabled=no dst-port=8080 protocol=tcp \
    to-addresses=10.10.0.2 to-ports=80
    add action=masquerade chain=srcnat comment="masquerade hotspot network" disabled=no src-address=\
    192.168.10.0/24
    add action=masquerade chain=srcnat comment="placa ether 3" disabled=no src-address=10.5.50.0/24
    /ip firewall service-port
    set ftp disabled=no ports=21
    set tftp disabled=no ports=69
    set irc disabled=no ports=6667
    set h323 disabled=no
    set sip disabled=no ports=5060,5061
    set pptp disabled=no
    /ip hotspot service-port
    set ftp disabled=no ports=21
    /ip hotspot user
    add comment="" disabled=no name=admin password=”” profile=default
    /ip hotspot walled-garden
    add action=allow comment="place hotspot rules here" disabled=yes
    /ip hotspot walled-garden ip
    add action=accept comment="" disabled=no dst-address=10.10.0.2
    /ip neighbor discovery
    set Link discover=yes
    set Proxy discover=yes
    set ether3 discover=yes
    set clientes discover=no
    set speedy discover=no
    /ip proxy
    set always-from-cache=no cache-administrator=webmaster cache-hit-dscp=4 cache-on-disk=no enabled=no \
    max-cache-size=unlimited max-client-connections=600 max-fresh-time=3d max-server-connections=600 \
    parent-proxy=0.0.0.0 parent-proxy-port=0 port=8080 serialize-connections=no src-address=0.0.0.0
    /ip service
    set telnet address=0.0.0.0/0 disabled=no port=23
    set ftp address=0.0.0.0/0 disabled=no port=21
    set www address=0.0.0.0/0 disabled=no port=80
    set ssh address=0.0.0.0/0 disabled=no port=22
    set www-ssl address=0.0.0.0/0 certificate=none disabled=yes port=443
    set api address=0.0.0.0/0 disabled=yes port=8728
    set winbox address=0.0.0.0/0 disabled=no port=8291
    /ip socks
    set connection-idle-timeout=2m enabled=no max-connections=200 port=1080
    /ip traffic-flow
    set active-flow-timeout=30m cache-entries=4k enabled=no inactive-flow-timeout=15s interfaces=all
    /ip upnp
    set allow-disable-external-interface=yes enabled=no show-dummy-rule=yes
    /ppp aaa
    set accounting=yes interim-update=0s use-radius=yes
    /queue interface
    set Link queue=ethernet-default
    set Proxy queue=ethernet-default
    set ether3 queue=ethernet-default
    set clientes queue=wireless-default
    set speedy queue=default
    /radius
    add accounting-backup=no accounting-port=1813 address=10.10.0.2 authentication-port=1812 called-id="" comment=\
    "" disabled=no domain="" realm="" secret=provebuntu service=hotspot timeout=300ms
    /radius incoming
    set accept=no port=3799
    /routing mme
    set bidirectional-timeout=2 gateway-class=none gateway-keepalive=1m gateway-selection=no-gateway \
    origination-interval=5s preferred-gateway=0.0.0.0 timeout=1m ttl=50
    /routing ospf
    set distribute-default=never metric-bgp=20 metric-connected=20 metric-default=1 metric-rip=20 metric-static=20 \
    mpls-te-area=unspecified mpls-te-router-id=unspecified redistribute-bgp=no redistribute-connected=no \
    redistribute-rip=no redistribute-static=no router-id=0.0.0.0
    /routing rip
    set distribute-default=never garbage-timer=2m metric-bgp=1 metric-connected=1 metric-default=1 metric-ospf=1 \
    metric-static=1 redistribute-bgp=no redistribute-connected=no redistribute-ospf=no redistribute-static=no \
    timeout-timer=3m update-timer=30s
    /store
    add comment="" disabled=no disk=system name=web-proxy1 type=web-proxy
    /system clock manual
    set dst-delta=+00:00 dst-end="jan/01/1970 00:00:00" dst-start="jan/01/1970 00:00:00" time-zone=+00:00
    /system console
    add disabled=no port=serial0 term=vt102
    /system health
    set fan-mode=auto use-fan=main
    /system identity
    set name=Spider
    /system logging
    add action=memory disabled=no prefix="" topics=info
    add action=memory disabled=no prefix="" topics=error
    add action=memory disabled=no prefix="" topics=warning
    add action=echo disabled=no prefix="" topics=critical
    add action=memory disabled=yes prefix="" topics=script
    /system note
    set note="" show-at-login=yes
    /system ntp client
    set enabled=yes mode=unicast primary-ntp=200.19.119.69 secondary-ntp=200.132.0.132
    /system scheduler
    add comment="" disabled=no interval=30m name="atualiza IP" on-event="/ system script run ip" start-time=\
    startup
    /system upgrade mirror
    set check-interval=1d enabled=no primary-server=0.0.0.0 secondary-server=0.0.0.0 user=""
    /system watchdog
    set auto-send-supout=no automatic-supout=yes no-ping-delay=5m watch-address=none watchdog-timer=yes
    /tool bandwidth-server
    set allocate-udp-ports-from=2000 authenticate=yes enabled=yes max-sessions=10
    /tool e-mail
    set from=<> password="" server=0.0.0.0:25 username=""
    /tool graphing
    set store-every=5min
    /tool graphing interface
    add allow-address=0.0.0.0/0 disabled=no interface=all store-on-disk=yes
    /tool mac-server
    add disabled=no interface=all
    /tool mac-server ping
    set enabled=yes
    /tool sniffer
    set file-limit=10 file-name="" filter-address1=0.0.0.0/0:0-65535 filter-address2=0.0.0.0/0:0-65535 \
    filter-protocol=ip-only filter-stream=yes interface=all memory-limit=10 only-headers=no streaming-enabled=\
    no streaming-server=0.0.0.0
    /user aaa
    set accounting=yes default-group=read interim-update=0s use-radius=no

  4. #4

    Padrão Bom essa ae sao minhas configs

    Bom galera desculpa ae pelo exagero.
    Espero que possam me ajudar
    Mais Uma vez Obrigado

  5. #5

  6. #6

  7. #7

    Padrão

    Parece estar tudo certo, oque poderia ser, que pelo geito vc já tentou, seria ter algum cliente precisando de mais ack que outro. Acontecia para mim a mesma coisa quando eu tinha um cliente a 500m e outro a 10km.

    Deixa as configurações avançadas da sua wireless default mesmo, não altere nenhuma delas, depois deixe o ack em modo dinamico, vai na tabela "registration" , e adicione uma coluna, o nome esta como "Ack. Timeout", depois em registration, vai aparecer o ack de cada estação conectada no AP.

    Acho que seria a melhor forma de descobrir quando o mikrotik está reconhecendo de ack para cada um. Tira uma média daquilo e seta na wireless, ou deixa um valor maior.