+ Responder ao Tópico



  1. #1

    Padrão PC AP Hotspot não acessa a internet

    Olá amigos, sou novato no MK e nãi intendo muito, criei um hotspot, eu faço login mas não acessa nenhuma pagina de internet. Ele funciona com 2 placas de rede, uma com ip 192.168.1.x que é ligado no meu modem roteando, e a outra com o ip 192.168.3.x que esta ligada em um hub.

  2. #2

    Padrão

    Ola amigo, vc tem que postar suas configurações para que podemos ajudar vc.
    Sem postar fica dificil, faz assim entra no new terminal e digite, export file=nomedoarquivo, depois vai files copia o arquivo e cole e no desktop, abra selecione tudo e coloque aqui no forum para que possamos ajudar.

  3. #3

    Padrão Olá Fronteirams, fiz oqe vc me disse :

    / interface ethernet
    set cliente name="cliente" mtu=1500 mac-address=00:08:54:26:3C:C3 arp=enabled \
    disable-running-check=yes auto-negotiation=yes full-duplex=yes \
    cable-settings=default speed=100Mbps comment="" disabled=no
    set internet name="internet" mtu=1500 mac-address=00:02:2A:E0:27:F1 \
    arp=enabled disable-running-check=yes auto-negotiation=yes full-duplex=yes \
    cable-settings=default speed=100Mbps comment="" disabled=no
    / interface wireless security-profiles
    set default name="default" mode=none wpa-unicast-ciphers="" \
    wpa-group-ciphers="" pre-shared-key="" static-algo-0=none static-key-0="" \
    static-algo-1=none static-key-1="" static-algo-2=none static-key-2="" \
    static-algo-3=none static-key-3="" static-transmit-key=key-0 \
    static-sta-private-algo=none static-sta-private-key="" \
    radius-mac-authentication=no group-key-update=5m
    / interface wireless align
    set frame-size=300 active-mode=yes receive-all=no \
    audio-monitor=00:00:00:00:00:00 filter-mac=00:00:00:00:00:00 ssid-all=no \
    frames-per-second=25 audio-min=-100 audio-max=-20
    / interface wireless snooper
    set multiple-channels=yes channel-time=200ms receive-errors=no
    / interface wireless sniffer
    set multiple-channels=no channel-time=200ms only-headers=no receive-errors=no \
    memory-limit=10 file-name="" file-limit=10 streaming-enabled=no \
    streaming-server=0.0.0.0 streaming-max-rate=0
    / interface bridge port
    set cliente bridge=none priority=128 path-cost=10
    set internet bridge=none priority=128 path-cost=10
    / interface l2tp-server server
    set enabled=no max-mtu=1460 max-mru=1460 \
    authentication=pap,chap,mschap1,mschap2 default-profile=default-encryption
    / interface pptp-server server
    set enabled=no max-mtu=1460 max-mru=1460 authentication=mschap1,mschap2 \
    keepalive-timeout=30 default-profile=default-encryption
    / ip pool
    add name="hs-pool-1" ranges=192.168.3.10-192.168.3.254
    / ip telephony region
    / ip telephony gatekeeper
    set gatekeeper=none remote-id="" remote-address=0.0.0.0
    / ip telephony aaa
    set use-radius-accounting=no interim-update=0s
    / ip telephony codec
    move G.711-uLaw-64k/sw
    move G.711-ALaw-64k/sw
    move G.729A-8k/sw
    move G.729-8k/sw
    move G.723.1-6.3k/sw
    move GSM-06.10-13.2k/sw
    move LPC-10-2.5k/sw
    / ip accounting
    set enabled=no account-local-traffic=no threshold=256
    / ip accounting web-access
    set accessible-via-web=no address=0.0.0.0/0
    / ip service
    set telnet port=23 address=0.0.0.0/0 disabled=no
    set ftp port=21 address=0.0.0.0/0 disabled=no
    set www port=80 address=0.0.0.0/0 disabled=no
    set ssh port=22 address=0.0.0.0/0 disabled=no
    set www-ssl port=443 address=0.0.0.0/0 certificate=none disabled=yes
    / ip socks
    set enabled=no port=1080 connection-idle-timeout=2m max-connections=200
    / ip upnp
    set enabled=no allow-disable-external-interface=yes show-dummy-rule=yes
    / ip traffic-flow
    set enabled=no interfaces=all cache-entries=4k active-flow-timeout=30m \
    inactive-flow-timeout=15s
    / ip dns
    set primary-dns=192.168.1.1 secondary-dns=201.10.1.2 allow-remote-requests=no \
    cache-size=2048KiB cache-max-ttl=1w
    / ip dns static
    / ip address
    add address=192.168.3.1/24 network=192.168.3.0 broadcast=192.168.3.255 \
    interface=cliente comment="" disabled=no
    add address=192.168.1.1/24 network=192.168.1.0 broadcast=192.168.1.255 \
    interface=internet comment="" disabled=no
    / ip proxy
    set enabled=no ports=8080 parent-proxy=0.0.0.0:0 \
    maximal-client-connecions=1000 maximal-server-connectons=1000 \
    cache-administrator="webmaster" max-object-size=4096KiB \
    max-disk-cache-size=none max-ram-cache-size=unlimited disk-database=yes
    / ip proxy drive
    set
    / ip proxy access
    add dst-port=23-25 action=deny comment="block telnet & spam e-mail relaying" \
    disabled=no
    add method=CONNECT dst-port=443 action=allow comment="allow CONNECT only to \
    SSL ports 443 \[https\] and 563 \[snews\]" disabled=no
    add method=CONNECT dst-port=563 action=allow comment="allow CONNECT only to \
    SSL ports 443 \[https\] and 563 \[snews\]" disabled=no
    add method=CONNECT action=deny comment="allow CONNECT only to SSL ports 443 \
    \[https\] and 563 \[snews\]" disabled=no
    / ip neighbor discovery
    set cliente discover=yes
    set internet discover=yes
    / ip route
    add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10 \
    comment="" disabled=no
    add dst-address=0.0.0.0/0 gateway=192.168.1.1 scope=255 target-scope=10 \
    comment="" disabled=no
    / ip firewall nat
    add chain=srcnat src-address=192.168.3.0/24 action=masquerade \
    comment="masquerade hotspot network" disabled=no
    add chain=srcnat action=masquerade comment="" disabled=no
    add chain=srcnat src-address=192.168.3.0/24 action=masquerade \
    comment="masquerade hotspot network" disabled=no
    add chain=srcnat src-address=192.168.3.0/24 action=masquerade \
    comment="masquerade hotspot network" disabled=no
    add chain=srcnat src-address=192.168.3.0/24 action=masquerade \
    comment="masquerade hotspot network" disabled=no
    add chain=srcnat src-address=192.168.3.0/24 action=masquerade \
    comment="masquerade hotspot network" disabled=no
    / ip firewall connection tracking
    set enabled=yes tcp-syn-sent-timeout=2m tcp-syn-received-timeout=1m \
    tcp-established-timeout=5d tcp-fin-wait-timeout=2m \
    tcp-close-wait-timeout=1m tcp-last-ack-timeout=30s \
    tcp-time-wait-timeout=2m tcp-close-timeout=10s udp-timeout=30s \
    udp-stream-timeout=3m icmp-timeout=30s generic-timeout=10m

  4. #4

    Padrão continuação:

    / ip firewall filter
    / ip firewall service-port
    set ftp ports=21 disabled=no
    set tftp ports=69 disabled=no
    set irc ports=6667 disabled=no
    set h323 disabled=yes
    set quake3 disabled=no
    set mms disabled=no
    set gre disabled=yes
    set pptp disabled=yes
    / ip dhcp-server
    add name="dhcp1" interface=cliente lease-time=1h address-pool=hs-pool-1 \
    bootp-support=static disabled=no
    / ip dhcp-server config
    set store-leases-disk=5m
    / ip dhcp-server lease
    / ip dhcp-server network
    add address=192.168.3.0/24 gateway=192.168.3.1 comment="hotspot network"
    / ip hotspot
    add name="hs-cliente" interface=cliente address-pool=hs-pool-1 profile=hsprof5 \
    idle-timeout=5m keepalive-timeout=none addresses-per-mac=2 disabled=no
    / ip hotspot service-port
    set ftp ports=21 disabled=no
    / ip hotspot profile
    set default name="default" hotspot-address=0.0.0.0 dns-name="" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    add name="hsprof1" hotspot-address=192.168.3.1 dns-name="franzoi.hotspot.com" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    add name="hsprof2" hotspot-address=192.168.3.1 dns-name="" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    add name="hsprof3" hotspot-address=192.168.3.1 dns-name="franzoi.hotspot.com" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    add name="hsprof4" hotspot-address=192.168.3.1 dns-name="franzoi.viaradio.com" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    add name="hsprof5" hotspot-address=192.168.3.1 dns-name="franzoi.viaradio.com" \
    html-directory=hotspot rate-limit="" http-proxy=0.0.0.0:0 \
    smtp-server=0.0.0.0 login-by=cookie,http-chap http-cookie-lifetime=3d \
    split-user-domain=no use-radius=no
    / ip hotspot user
    add name="admin" password="12345" profile=default comment="" disabled=no
    add name="teste" password="teste" profile=default comment="" disabled=no
    add name="Diego" password="diego" profile=default comment="" disabled=no
    add name="diego franzoi" password="df" mac-address=00:22:5F:91:41:C5 \
    profile=default comment="" disabled=no
    / ip hotspot user profile
    set default name="default" idle-timeout=none keepalive-timeout=2m \
    status-autorefresh=1m shared-users=1 transparent-proxy=yes \
    open-status-page=always advertise=no
    / ip ipsec proposal
    add name="default" auth-algorithms=sha1 enc-algorithms=3des lifetime=30m \
    lifebytes=0 pfs-group=modp1024 disabled=no
    / system logging
    add topics=info prefix="" action=memory disabled=no
    add topics=error prefix="" action=memory disabled=no
    add topics=warning prefix="" action=memory disabled=no
    add topics=critical prefix="" action=echo disabled=no
    / system logging action
    set memory name="memory" target=memory memory-lines=100 memory-stop-on-full=no
    set disk name="disk" target=disk disk-lines=100 disk-stop-on-full=no
    set echo name="echo" target=echo remember=yes
    set remote name="remote" target=remote remote=0.0.0.0:514
    / system upgrade mirror
    set enabled=no primary-server=0.0.0.0 secondary-server=0.0.0.0 \
    check-interval=1d user=""
    / system clock dst
    set dst-delta=+01:00 dst-start="jan/01/1970 00:00:00" dst-end="jan/01/1970 \
    00:00:00"
    / system watchdog
    set reboot-on-failure=yes watch-address=none watchdog-timer=yes \
    no-ping-delay=5m automatic-supout=yes auto-send-supout=no
    / system console
    add port=serial0 term="" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    set FIXME term="linux" disabled=no
    / system console screen
    set line-count=25
    / system identity
    set name="MikroTik"
    / system note
    set show-at-login=yes note=""
    / system gps
    set enabled=no set-system-time=no
    / system lcd
    set enabled=no type=24x4 port=parallel contrast=0
    / system lcd page
    set time display-time=5s disabled=yes
    set resources display-time=5s disabled=yes
    set uptime display-time=5s disabled=yes
    set packets display-time=5s disabled=yes
    set bits display-time=5s disabled=yes
    set version display-time=5s disabled=yes
    set cliente display-time=5s disabled=yes
    set internet display-time=5s disabled=yes
    / system ntp server
    set enabled=no broadcast=no multicast=no manycast=yes
    / system ntp client
    set enabled=no mode=unicast primary-ntp=0.0.0.0 secondary-ntp=0.0.0.0
    / system routerboard bios
    set
    / system health
    set state-after-reboot=enabled
    / port
    set serial0 name="serial0" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
    flow-control=hardware
    set serial1 name="serial1" baud-rate=9600 data-bits=8 parity=none stop-bits=1 \
    flow-control=hardware
    / ppp profile
    set default name="default" use-compression=default use-vj-compression=default \
    use-encryption=default only-one=default change-tcp-mss=default comment=""
    add name="Cliente" use-compression=no use-vj-compression=no use-encryption=no \
    only-one=default change-tcp-mss=yes comment=""
    set default-encryption name="default-encryption" use-compression=default \
    use-vj-compression=default use-encryption=yes only-one=default \
    change-tcp-mss=default comment=""
    / ppp aaa
    set use-radius=no accounting=yes interim-update=0s
    / queue type
    set default name="default" kind=pfifo pfifo-limit=50
    set ethernet-default name="ethernet-default" kind=pfifo pfifo-limit=50
    set wireless-default name="wireless-default" kind=sfq sfq-perturb=5 \
    sfq-allot=1514
    set synchronous-default name="synchronous-default" kind=red red-limit=60 \
    red-min-threshold=10 red-max-threshold=50 red-burst=20 red-avg-packet=1000
    set hotspot-default name="hotspot-default" kind=sfq sfq-perturb=5 \
    sfq-allot=1514
    / queue simple
    add name="Cliente" dst-address=0.0.0.0/0 interface=all parent=none priority=8 \
    queue=default/default limit-at=0/0 max-limit=0/0 total-queue=default \
    disabled=no
    / user
    add name="admin" group=full address=0.0.0.0/0 comment="system default user" \
    disabled=no
    / user group
    add name="read" policy=local,telnet,ssh,reboot,read,test,winbox,password,web,!f\
    tp,!write,!policy
    add name="write" policy=local,telnet,ssh,reboot,read,write,test,winbox,password\
    ,web,!ftp,!policy
    add name="full" policy=local,telnet,ssh,ftp,reboot,read,write,policy,test,winbo\
    x,password,web
    / user aaa
    set use-radius=no accounting=yes interim-update=0s default-group=read
    / radius incoming
    set accept=no port=1700
    / driver
    / snmp
    set enabled=no contact="" location=""
    / snmp community
    set public name="public" address=0.0.0.0/0 read-access=yes
    / tool bandwidth-server
    set enabled=yes authenticate=yes allocate-udp-ports-from=2000 max-sessions=10
    / tool mac-server ping
    set enabled=yes
    / tool e-mail
    set server=0.0.0.0 from="<>"
    / tool sniffer
    set interface=all only-headers=no memory-limit=10 file-name="" file-limit=10 \
    streaming-enabled=no streaming-server=0.0.0.0 filter-stream=yes \
    filter-protocol=ip-only filter-address1=0.0.0.0/0:0-65535 \
    filter-address2=0.0.0.0/0:0-65535
    / tool graphing
    set store-every=5min
    / routing bgp instance
    set default as=65530 router-id=0.0.0.0 redistribute-static=no \
    redistribute-connected=no redistribute-rip=no redistribute-ospf=no \
    redistribute-other-bgp=no name="default" out-filter="" disabled=no
    / routing rip
    set redistribute-static=no redistribute-connected=no redistribute-ospf=no \
    redistribute-bgp=no metric-static=1 metric-connected=1 metric-ospf=1 \
    metric-bgp=1 update-timer=30s timeout-timer=3m garbage-timer=2m
    / routing ospf
    set router-id=0.0.0.0 distribute-default=never redistribute-connected=no \
    redistribute-static=no redistribute-rip=no redistribute-bgp=no \
    metric-default=1 metric-connected=20 metric-static=20 metric-rip=20 \
    metric-bgp=20
    / routing ospf area
    set backbone area-id=0.0.0.0 authentication=none prefix-list-import="" \
    prefix-list-export="" disabled=no

  5. #5

    Padrão

    Faz um teste assim em ip/firewall/nat, mascare somente o link, click no botao + em chain coloque srcnat depois em out interface coloque o nome da interface do link, em action, action coloque masquerade.
    Última edição por fronteirams; 19-04-2010 às 00:19.

  6. #6

    Padrão

    uma dica é vc nao pegar e restaurar backups de outros mikrotiks...
    configure ele do zero, e depois vá incrementando a sua configuração conforme vc precise, ou quiser aprender!

  7. #7

    Padrão

    Diego,
    apaga as 6 regras de srcnat iguais que tem no seu firewall e coloca essa:

    /ip firewall nat
    add chain=srcnat src-address=192.168.3.0/24 out-interface=internet action=masquerade \
    comment="masquerade hotspot network" disabled=no

    Abs.