5. 配置IP Service,限定远程管理RouerOS 的地址和方式
/ ip service set telnet port=23 address=0.0.0.0/0 disabled=no set ftp port=21 address=0.0.0.0/0 disabled=no set www port=80 address=0.0.0.0/0 disabled=no set hotspot port=8088 address=0.0.0.0/0 disabled=no / ip policy-routing add name="jitong"
6. 配置Hotspot(WEB 认证)
/ ip hotspot
set hotspot-address=(ip_addr) status-autorefresh=1m auth-mac=no
auth-mac-password=no auth-http-cookie=no http-cookie-lifetime=1d
/ ip hotspot profile
set default name="default" session-timeout=0s idle-timeout=0s only-one=yes
tx-bit-rate=0 incoming-filter="" outgoing-filter=""
/ ip hotspot radius-client
set enabled=no accou=yes primary-serv=(ip_addr) secondary-serv=(ip_addr)
shared-secret="" authentication-port=1812 accounting-port=1813
interim-update=0s
7. 配置IP Pool
/ ip pool add name="jitong" ranges=172.16.1.3-172.16.1.254 add name="dianxin" ranges=172.16.2.3-172.16.2.254
8. 启用NAT 后的策略路由配置
应用拓扑见下面的示意图。某校园网络有教育和电信两个出口,网关分别是:202.10.68.1 和
211.99.52.129。首先按正常情况配置好IP 地址、基本路由、防火墙、NAT 等。基本路由配置如下(即主路由表main):[admin@RouerOS] ip route> pr Flags:X -disabled,I -invalid,D -dynamic,J -rejected,C -connect,S -static, r - rip, o - ospf, b -bgp
#
DST-ADDRESS
G GATEWAY
DISTANCE
INTERFACE
0
S 0.0.0.0/0
/ ip service set telnet port=23 address=0.0.0.0/0 disabled=no set ftp port=21 address=0.0.0.0/0 disabled=no set www port=80 address=0.0.0.0/0 disabled=no set hotspot port=8088 address=0.0.0.0/0 disabled=no / ip policy-routing add name="jitong"
6. 配置Hotspot(WEB 认证)
/ ip hotspot
set hotspot-address=(ip_addr) status-autorefresh=1m auth-mac=no
auth-mac-password=no auth-http-cookie=no http-cookie-lifetime=1d
/ ip hotspot profile
set default name="default" session-timeout=0s idle-timeout=0s only-one=yes
tx-bit-rate=0 incoming-filter="" outgoing-filter=""
/ ip hotspot radius-client
set enabled=no accou=yes primary-serv=(ip_addr) secondary-serv=(ip_addr)
shared-secret="" authentication-port=1812 accounting-port=1813
interim-update=0s
7. 配置IP Pool
/ ip pool add name="jitong" ranges=172.16.1.3-172.16.1.254 add name="dianxin" ranges=172.16.2.3-172.16.2.254
8. 启用NAT 后的策略路由配置
应用拓扑见下面的示意图。某校园网络有教育和电信两个出口,网关分别是:202.10.68.1 和
211.99.52.129。首先按正常情况配置好IP 地址、基本路由、防火墙、NAT 等。基本路由配置如下(即主路由表main):[admin@RouerOS] ip route> pr Flags:X -disabled,I -invalid,D -dynamic,J -rejected,C -connect,S -static, r - rip, o - ospf, b -bgp
#
DST-ADDRESS
G GATEWAY
DISTANCE
INTERFACE
0
S 0.0.0.0/0