<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>Remote access in Wireless Service Providers</title>
<link>http://www.dslreports.com/forum/r23301575</link>
<description></description>
<language>en</language>
<pubDate>Wed, 10 Feb 2010 11:05:59 EDT</pubDate>
<lastBuildDate>Wed, 10 Feb 2010 11:05:59 EDT</lastBuildDate>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23311598</link>
<description><![CDATA[<A HREF="/useremail/u/655955"><b>viperm</b></A> : Hahah I have been trying that as well with one of our hotspots. I cant get the scripting to work correctly with our DNS server. <br><br>The mikrtoik Wiki site has a decent script but the password config just wont work with simple DNS or visa versa. Simple DNS spits out a unique password with special chractors that mikrotik doesnt understand and thnks its some kind of command and will nto run it.<br><br>Oh well I just get a down notification when it changes and I have a PPTP VPN connection runnign from the hotspto to one of our core routers. So when I get apage its down I look in the core router to see what IP address the PPTP sesion is coming from and then I know what the ip address is of my hot spot etc...<br><br>I then go into wireless orbit and chage it manually so radius starts working again<br><small>--<br>ComTrain Certified Tower Climber. American Tower Certified approved contractor. Wireless consultants.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23311598</guid>
<pubDate>Sun, 08 Nov 2009 19:31:16 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23311572</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : Thanks again Viperm, You nailed it.  :)<br>If you notice in the 2nd pic at top. I've got the outside interface visible. "192.168.1.5", should have been "public IP" address.<br>Previously I had tried using "80" instead of "0-6535". But I didn't have the public IP inserted.<br>Bottom line you corrected it. <br>Now, to figure out how to update rule to update the DHCP.<br>Wonder if there's a script to do same.<br>Untill I buy a static!]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23311572</guid>
<pubDate>Sun, 08 Nov 2009 19:26:16 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23308515</link>
<description><![CDATA[<A HREF="/useremail/u/655955"><b>viperm</b></A> : It was a simple fix he had port 8081 forwarding to ALL TCP ports on his Bullet. You have to be specific on what ports you want to forward to what other ports on your internal devices.<br><br>All I did was tweak his existing dst firewall rule to tell his public ip port 8081 to forward to port 80 of his bullet and bingo bango he is good!<br><br>Took me 30 seconds with a chip and dip in one hand hahaha if he would have posted the pic of the actual rule itself I think we would have seen it right away. <br><small>--<br>ComTrain Certified Tower Climber. American Tower Certified approved contractor. Wireless consultants.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23308515</guid>
<pubDate>Sat, 07 Nov 2009 23:17:03 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23307772</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : ABBO bloody lutely! Mate!<br><br>(absolutely)<br><br>You guys are incredible. I've learned more here than one could imagine. I know Viperm will nail it.<br><br>Very generous peeps.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23307772</guid>
<pubDate>Sat, 07 Nov 2009 19:52:50 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23307757</link>
<description><![CDATA[<A HREF="/useremail/u/660498"><b>TomS_</b></A> : Make sure you post the solution so others know what was wrong and how to fix it! :-)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23307757</guid>
<pubDate>Sat, 07 Nov 2009 19:49:22 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23307177</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : Wow,<br>Thanks so very much. <br>You know it's gonna be something simple. But, yes the AP is directly behind the RouterOS.<br>Internet------->DSL Modem PPPoE------> RouterOS----->ethernet---->BulletM2HP AP------->Wireless clients.<br>I'd really appreciate it Viperm.<br>I was just playing with it. I disabled the "use DNS peer" on the PPoE client now it's down or at least I can't see it from remote. I'll be local to the hotspot shortly. Login and fix that, so I can get to it.<br>It's 2:30.<br>Be up and running @ 4:30. I'll get you later.<br>Tim]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23307177</guid>
<pubDate>Sat, 07 Nov 2009 17:09:54 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23307075</link>
<description><![CDATA[<A HREF="/useremail/u/655955"><b>viperm</b></A> : Is the AP direclty behind the Mikrotik or is there another router etc?<br><br>If you want to hit me off list and give me remote access I can take a look to see if I can get it to work for you.<br><br>Its probably something simple I wont be able to do it till later this evening I have stuff I need to do..<br>PS/ Try gettign rid of the "TO" address in the binding rule we do the same type of setup but never had to put in the TO ip address just the address and thats it<br><br>Thanks<br><small>--<br>ComTrain Certified Tower Climber. American Tower Certified approved contractor. Wireless consultants.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23307075</guid>
<pubDate>Sat, 07 Nov 2009 16:38:16 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23306391</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : OK, Tried putting the public ip inplace of the 192.168.1.5 ip. NO luck.<br>If you notice my pic attached. The ip in the "network" column is the DSL gateway.<br>Everything works going out with that config, but just can't get in to access AP IP. Sorry but this is getting outa hand, all the pics... hope it makes.<br>Thanks :uhh:<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23306391?c=1487341&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="44031 bytes" WIDTH=600 HEIGHT=417 SRC="/r0/download/1487341.thumb600~04619e969ca013e34676b41fa6d0f622/public ip.JPG/thumb.jpg" ALT="Click for full size"></A><br>Public IP and gateway</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23306391</guid>
<pubDate>Sat, 07 Nov 2009 13:17:55 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23306336</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : Thanks,<br>I'm trying what you suggested. I think I've been there though.<br>So, you suggest I use my real WAN IP?<br>You know it changes daily (don't have static IP).I Im using DSP PPPoE dynamic. I have a Changeip script to update.<br>But, I'll try using the present "public" WAN IP as dst-address.<br>Also I've attached pics of the IP binding. I'm not sure if I got this right. I had the 10.10.0.99 bound to the Hotspot server IP 10.10.0.1. Then changed it back. to 10.10.0.99 bound to itself..? Right/Wrong?<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23306336?c=1487339&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG TITLE="52329 bytes" BORDER=0 WIDTH=589 HEIGHT=419 SRC="/r0/download/1487339~659e92a250011d93f466bf3de9bf65e1/IP%20binding%20of%20AP%20and%20Camera.JPG"></A><br>IP binding</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23306336</guid>
<pubDate>Sat, 07 Nov 2009 13:02:05 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23306263</link>
<description><![CDATA[<A HREF="/useremail/u/1388952"><b>Airnode</b></A> : chain=dstnat action=dst-nat to-addresses=10.10.0.99 to-ports=0-65535 <br>     protocol=tcp dst-address=192.168.1.5  dst-port=8081<br><br>try this one...should work as long your hotspot binding is right and your<br>try to reach the device from the 192.168.1.0 network ..<br>once again if your trying  to reach WAN you have to use your real WAN address as dst-address.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23306263</guid>
<pubDate>Sat, 07 Nov 2009 12:41:39 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23306114</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : I think I understand what your saying. <br>But this is standard setup with mikrotik. To allow remote access a dst-nat rule is applied as shown.<br>the Hotspot has an "IP binding" which allows the IP behind the Hotspot to get out without authorizing.<br>I've done that and Add below to get to proper port<br>---------------<br>chain=dstnat action=dst-nat to-addresses=10.10.0.99 to-ports=80<br>protocol=tcp dst-address=192.168.1.5 dst-port=8081<br>------------------<br>And I still can't access AP remotely... ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23306114</guid>
<pubDate>Sat, 07 Nov 2009 11:59:11 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23306031</link>
<description><![CDATA[<A HREF="/useremail/u/1388952"><b>Airnode</b></A> : your public ore wan iface is ether1 right? and its configured as pppoe<br>client ?<br><br>but you still gave the ether1 a privat address.. so something is confusing my by that . Not that you can't do that but then the rule never will work since the ether-address *192.168.1.5 is not your really <br>reachible address from outside]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23306031</guid>
<pubDate>Sat, 07 Nov 2009 11:37:22 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23305845</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : No luck with just Mac.]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23305845</guid>
<pubDate>Sat, 07 Nov 2009 10:53:03 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23303685</link>
<description><![CDATA[<A HREF="/useremail/u/961519"><b>surfergeek</b></A> : Thanks, <br><br>But, The Hotspot IP is: 10.10.0.1<br><br>The Wan IP is: 192.168.1.5<br><br>The Access Point IP behind the Hotspot is: 10.10.0.99<br>and is "bound" and bypassing authorization.<br><br>So, trying to get that to work...hmmm<br><br>OKeee, I'll try just the mac address...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23303685</guid>
<pubDate>Fri, 06 Nov 2009 18:31:04 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23303051</link>
<description><![CDATA[<A HREF="/useremail/u/655955"><b>viperm</b></A> : Try using the mac address instead of the IP address in the Hotspot Bypass rules I have had that issue before using the IP not sure why.<br><br>Also to make sure your firewall rules work shut off hotspot for a few min and try if it still does not work you need to work on your firewall rules then enable hotspot again after you get it working.<br><br>I think his rules are correct we just public to private and this is how we have ours.. We just leave this server wide open heheheh<br><br> 5   ;;; XYZ server<br>     chain=dstnat action=dst-nat to-addresses=10.10.10.2 protocol=tcp <br>     dst-address=208.xxx.xxx.xxx dst-port=0-65535 <br><small>--<br>ComTrain Certified Tower Climber. American Tower Certified approved contractor. Wireless consultants.</small>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23303051</guid>
<pubDate>Fri, 06 Nov 2009 16:05:04 EDT</pubDate>
</item>

<item>
<title>Re: Remote access</title>
<link>http://www.dslreports.com/forum/remark,23302519</link>
<description><![CDATA[<A HREF="/useremail/u/1303751"><b>Rhaas</b></A> : <textarea name="code" class="text" cols=50 rows=10>3 chain=dstnat action=dst-nat to-addresses=10.10.0.99 to-ports=80&#012;protocol=tcp dst-address=192.168.1.5 dst-port=8081&#012;</textarea><!--end code block--><br>I *think* you have this backwards, the to-address should be 192.168.1.5 (address of the hotspot) and the dst-address should be 10.10.0.99 (address of the M2)<br>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23302519</guid>
<pubDate>Fri, 06 Nov 2009 14:23:16 EDT</pubDate>
</item>

<item>
<title>Remote access</title>
<link>http://www.dslreports.com/forum/remark,23301575</link>
<description><![CDATA[<A HREF="/useremail/u/1409765"><b>livewireless</b></A> : I can't get Mikrotik support to get an answer to my problem.<br>I just purchased a license and supposedly get 30 days support.<br>Can anyone suggest a solution<br>I'm simply trying to remotely access an AP (bullet M2HP) behind the hotspot setup on RouterOS4.2.<br>The AP has static IP and binding to the Hotspot server with "bypass" rule.<br>I've done a "nat-dst" rule and a "port forward".<br>I just cannot get it right seemingly. The only thing I see different than the standard Hotspot setup is my PPPoE client.<br>I'm wondering if the hotspot needs to be made aware of this to get packets out correctly?<br><br>Internet------>DSL PPPoE Modem--------->RouterOS4.2----->PPPoE client------->public interface (192.168.1.5)-------->Hotspot server local interface (10.10.0.1)------ethernet----->BulletM2HP Wireless AP (10.10.0.99)---------->Wireless clients.<br>---------------------------------------------------<br>Here's the firewall /NAT rules:<br><br>[admin@MikroTik] /ip firewall nat> print<br>Flags: X - disabled, I - invalid, D - dynamic <br> 0 X ;;; place hotspot rules here<br>     chain=unused-hs-chain action=passthrough <br><br> 1   ;;; masquerade hotspot network<br>     chain=srcnat action=masquerade src-address=10.10.0.0/24 <br><br> 2   chain=.... action=accept <br><br> 3   chain=dstnat action=dst-nat to-addresses=10.10.0.99 to-ports=80 <br>     protocol=tcp dst-address=192.168.1.5 dst-port=8081<br>---------------------------------------------------------<br>Route<br>---------------------------------------------------------<br>[admin@MikroTik] /ip route> print<br>Flags: X - disabled, A - active, D - dynamic, <br>C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme, <br>B - blackhole, U - unreachable, P - prohibit <br> #      DST-ADDRESS        PREF-SRC        GATEWAY            DISTANCE<br> 0 ADS  0.0.0.0/0                          151.164.184.154    1       <br> 1 ADC  10.10.0.0/24       10.10.0.1       ether2             0       <br> 2 ADC  151.164.184.154/32 76.244.162.133  pppoe-out1         0       <br> 3 ADC  192.168.1.0/24     192.168.1.5     ether1             0 <br>-------------------------------------------------------<br>Help please, anyone.<br>Thanks,<div class="borderless"><TABLE WIDTH=95% align=center border=0 CELLPADDING=4"><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23301575?c=1487300&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG TITLE="26792 bytes" BORDER=0 WIDTH=424 HEIGHT=217 SRC="/r0/download/1487300~0ac83fd965b2ebb263487116494c6765/addresses.JPG"></A><br>Addresses</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23301575?c=1487301&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="87467 bytes" WIDTH=600 HEIGHT=396 SRC="/r0/download/1487301.thumb600~fdbf08aa36bd485fdb6f1fbc0693f7ab/firewall.JPG/thumb.jpg" ALT="Click for full size"></A><br>Firewall</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23301575?c=1487302&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG TITLE="32173 bytes" BORDER=0 WIDTH=586 HEIGHT=217 SRC="/r0/download/1487302~44036c6113d39d8d7b2afa75cd07e15a/interfaces.JPG"></A><br>Interfaces</TD></TR><TR><TD ALIGN=CENTER VALIGN=CENTER BGCOLOR=#FFFFFF nwrap COLSPAN=3 WIDTH=100%><A HREF="/speak/slideshow/23301575?c=1487304&ret=L2ZvcnVtL3IyMzMwMTU3NS54bWw%3D"><IMG class="apic" BORDER=0 TITLE="34651 bytes" WIDTH=600 HEIGHT=119 SRC="/r0/download/1487304.thumb600~526db9e8effdcda97c50c065deed6efa/Route.JPG/thumb.jpg" ALT="Click for full size"></A><br>Route list</TD></TABLE></div>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,23301575</guid>
<pubDate>Fri, 06 Nov 2009 11:47:36 EDT</pubDate>
</item>

</channel>
</rss>
