Архив метки: Mikrotik

MikroTik WiFi Frequency Band and Channel Width Explanation

MikroTik WiFi frequency, band and channel width tuning is an important task in any wireless network. If we fail to setup WiFi frequency and channel width parameter properly, we will notice a poor performance of wireless network. WiFi is aimed at use within unlicensed spectrum and the unlicensed spectrum that is usually used for WiFi is 2.4 GHz and 5 GHz band.  2.4 GHz and 5 GHz bands have multiple channels and these channels must be setup properly to get high wireless performance. In my previous article I discussed how to setup MikroTik Wireless Router as a WiFi AP and in this article I will discuss how to setup frequency, band and channel width to get high wireless performance.




IEEE 802.11 Standards and Frequency Band




IEEE 802.11 specifies protocols for implementing Wireless Local Area Network (WLAN) WiFi computer communication in various frequencies including 2.4 GHz and 5 GHz band. IEEE 802.11 has several different variants those use different frequency band. The following table is a summarization of bands used by 802.11 systems.




IEEE 802.11 VARIANTFREQUENCY BANDS USED
  
802.11a5GHz
802.11b2.4GHz
802.11g2.4GHz
802.11n2.4 & 5 GHz
802.11acBelow 6GHz
802.11adUp to 60 GHz
802.11afTV white space (below 1 GHz)
802.11ah700 MHz, 860MHz, 902 MHz, etc.




2.4 GHz Frequency Band




The lower and upper frequency of 2.4 GHz band is 2400 MHz and the upper frequency is 2500 MHz. There are fourteen channels in this frequency spectrum. The 802.11 Wi-Fi standards specify a bandwidth of 22 MHz for each channel but often nominal figures of 20 MHz is given for the Wi-Fi channels and channels are on a 5 MHz incremental. The 20 / 22 MHz bandwidth and channel separation of 5 MHz means that adjacent channels overlap and signals on adjacent channels will interfere with each other.

The following table is summarizing the channel number of 2.4 GHz band and the lower, middle and upper frequency of each channel number.


CHANNEL NUMBERLOWER FREQUENCY
MHZ
CENTER FREQUENCY
MHZ
UPPER FREQUENCY
MHZ
    
1240124122423
2240624172428
3241124222433
4241624272438
5242124322443
6242624372448
7243124422453
8243624472458
9244124522463
10244624572468
11245124622473
12245624672478
13246124722483
14247324842495




Although fourteen channels are available of 2.4 GHz band, all channels are not usable all countries. The following table provides a broad indication of the availability of the different WiFi channels in different parts of the world.




CHANNEL NUMBEREUROPE
(ETSI)
NORTH AMERICA
(FCC)
JAPAN  
    
1✔✔✔
2✔✔✔
3✔✔✔
4✔✔✔
5✔✔✔
6✔✔✔
7✔✔✔
8✔✔✔
9✔✔✔
10✔✔✔
11✔✔✔
12✔No✔
13✔No✔
14NoNo802.11b only




This chart is only provides a general view, and there may be variations between different countries. So, it is always better to check the available channels in your country before implementing 2.4 GHz frequency band.




Non Overlapping Channels in 2.4 GHz Band   




Channel overlapping between two adjacent WiFi AP devices cause frequency interference. So, performance of wireless network will be so poor in overlapping channel. As one WiFi client device can communicate to a WiFi AP at a time using a channel width, the overlapped WiFi AP must wait until the channel being clear. As a result the WiFi performance gets slow.




The channels used for 2.4 GHz band are separated by 5 MHz but each channel has 22 MHz bandwidth. So, channels are usually overlapped. If we look in the above frequency chart, it can be seen that maximum three non-overlapping channel can be found in 2.4 GHz band. There can be five non overlapping channel combinations those are shown in the following diagram.




Non Overlapping Channel Combination
Non Overlapping Channel Combination




From the diagram, it can be seen that Wi-Fi channels 1, 6, 11, or 2, 7, 12, or 3, 8, 13 or 4, 9, 14 (if allowed) or 5, 10 (and possibly 14 if allowed) can be used together as sets. Often WiFi routers are set to channel 6 as the default, and therefore the set of channels 1, 6 and 11 is possibly the most widely used.

The 802.11n standard has the possibility of using signal bandwidth either 20 MHz or 40 MHz. When 40 MHz bandwidth is used to gain the higher data throughput, this obviously reduces the number of channels that can be used.


Non Overlapping Channel 40 MHz Bandwidth
Non Overlapping Channel 40 MHz Bandwidth




The above diagram shows the 802.11n 40 MHz signals. These signals are designated with their equivalent center channel numbers.




In a multi WiFi AP network, the coverage of WiFi AP must be overlap for smooth connection but channel overlapping must be avoided. So, we have to plan properly for designing a multi WiFi AP network. A possible multi WiFi AP network where there will be no channel overlapping can be as the following image.




Non Overlapping Channel Design with Coverage Overlap
Non Overlapping Channel Design with Coverage Overlap




If you use a home wireless router, there may be channel overlapping with your neighbor home wireless router. So, it will be better to discuss with your neighbor for choosing channel according to the above planning.




2.4 GHz WiFi Range




WiFi range absolutely depends on the type of network. A home network serves only a few family members. On the other hand a business network can serve large office buildings or even in a city. The cost to build and maintain business networks increases significantly as the range increases, of course.




A general rule of thumb in home networking says that Wi-Fi routers operating on the 2.4 GHz band can reach up to 150 feet indoors and 300 feet outdoors. Older 802.11a routers that ran on 5 GHz bands reached approximately one-third of these distances. Newer 802.11n and 802.11ac routers that operate on both 2.4 GHz and 5 GHz bands reach greater distances.

Controlling transmit power, the WiFi range can be increased or decreased. For example, if you want to limit the WiFi range only in a room, decrease transmitting power to get less WiFi coverage.


The factors that can influence WiFi range are the access point or router itself, the structure or building (brick walls and metal frames can reduce the WiFi range by 25% or more) you are in and the wireless standard (The 802.11g protocol has an indoor range of 125 feet, while 802.11n has a range of 235 feet) that you are using.




5GHz Frequency Band




The 2.4 GHz band is now becoming more crowded. So, many users are now choosing 5 GHz band because it has more throughput and less interference.




5GHz band was first introduced in 802.11a but the radios were expensive and the band didn’t gain popularity. 802.11n was defined for both 2.4GHz and 5GHz bands, which finally launched 5GHz use. The latest 802.11ac is only defined for 5GHz but all devices still support 802.11n and most also on 2.4GHz.




5GHz band has 23 non-overlapping channels but all channels are not usable for all countries because there are some forbidden channels and some channels have special restrictions. The following table is a summarization of 5GHz channels with 20MHz channel width and region availability.




Channel NumberFrequency MHzEurope
(ETSI)
North America
(FCC)
Japan
     
365180Indoors✔✔
405200Indoors✔✔
445220Indoors✔✔
485240Indoors✔✔
525260Indoors / DFS / TPCDFSDFS / TPC
565280Indoors / DFS / TPCDFSDFS / TPC
605300Indoors / DFS / TPCDFSDFS / TPC
645320Indoors / DFS / TPCDFSDFS / TPC
1005500DFS / TPCDFSDFS / TPC
1045520DFS / TPCDFSDFS / TPC
1085540DFS / TPCDFSDFS / TPC
1125560DFS / TPCDFSDFS / TPC
1165580DFS / TPCDFSDFS / TPC
1205600DFS / TPCNo AccessDFS / TPC
1245620DFS / TPCNo AccessDFS / TPC
1285640DFS / TPCNo AccessDFS / TPC
1325660DFS / TPCDFSDFS / TPC
1365680DFS / TPCDFSDFS / TPC
1405700DFS / TPCDFSDFS / TPC
1495745SRD✔No Access
1535765SRD✔No Access
1575785SRD✔No Access
1615805SRD✔No Access
1655825SRD✔No Access




Note: DFS = Dynamic Frequency Selection; TPC = Transmit Power Control; SRD = Short Range Devices 25 mW max power.




The 802.11n gave us the ability to use 40MHz channels. From there, 802.11ac now allows for 80MHz and even 160MHz wide channels!  These wide channels are created by bonding 20MHz channels together. For example, channels 36 and 40 (each 20MHz) are bound together to make 40MHz channel 38. The following diagram is summarization of 5GHz channel allocation with various channel width and center frequency.




5 GHz Channel Allocations
5 GHz Channel Allocations




The above diagram shows that 5 GHz channels are divided into three units: UNII-1, UNII-2 and UNII-3. UNII-1 channels are almost usable all countries but other channels have limitation in different country.




Assigning Band, Frequency and Channel Width in MikroTik Wireless Router




Band, frequency and channel width can be tuned at the time of wireless AP configuration or CAPsMAN configuration. The following steps will show how to tune band, frequency and channel width in MikroTik Wireless Router that is working as a WiFi AP.




  • From Winbox, click on Wireless button. Wireless Tables window will appear.
  • Double click on WLAN interface where you want to tune wireless frequency and channel parameters. Interface property window will appear.
  • Click on Wireless tab and choose desired frequency band and wireless standard from Band dropdown menu.
  • Choose desired channel width from Channel Width dropdown menu.
  • Choose middle frequency of the channel width from Frequency dropdown menu.
  • Click Apply and OK button.




Band Frequency and Channel Width Tuning in MikroTik Wireless Router
Band, Frequency and Channel Width Tuning in MikroTik Wireless Router




How to plan for WiFi band, frequency and channel width and how to apply in MikroTik Wireless Router have been discussed in this article. I hope you will now be able to plan and tune your wireless network properly. However, if you face any confusion, feel free to discuss in comment or contact me from Contact page. I will try my best to stay with you.



2020-01-10T09:53:15
MikroTik Router Tutorials & Guides

MikroTik WiFi MAC Authentication with UserMan RADIUS Server

MikroTik Wireless Router is popularly used as WiFi AP. MikroTik WiFi AP has a lot of features to tune WiFi network as your requirements. MAC authentication is one the amazing and useful features in MikroTik WiFi. MAC authentication enables filtering MAC address that means no MAC can be able to connect to WiFi AP without authentication.  MAC authentication can be done either local database or RADIUS Server. MAC authentication with RADIUS Server provides facility to manage multiple APs from centralized database. User Manager is a RADIUS Application developed by MikroTik team and can be used to manage PPPoE, Hotspot, DHCP and Wireless user easily. How to install User Manager RADIUS Server with basic configuration was discussed in my previous article. I also discussed how to configure MikroTik Wireless Router as WiFi AP in another article. In this article I will discuss how to manage WiFi user with User Manager RADIUS Server.




Network Diagram




The following network diagram is being followed for this article configuration.




MikroTik WiFi with RADIUS Server
MikroTik WiFi with RADIUS Server




In this network diagram a MikroTik Wireless Router (RB941-2nD) is being used as WiFi AP (IP: 192.168.70.2) which is connected to a WAN Switch where a User Manager RADIUS Server (IP: 192.168.70.3) is also connected.  The WiFi AP will be configured as MAC authenticated AP so that no Wireless device (Laptop, Smart Phone, Notebook and so on) will be connected without providing MAC Address and the MAC Address will be authenticated from RADIUS Server.




MAC Authenticated WiFi AP Configuration with RADIUS Server




The complete MAC authentication WiFi AP configuration with User Manager RADIUS Server can be divided into the following two parts.




  • Enabling MAC authentication from RADIUS Server in WiFi AP
  • User Manager RADIUS Server configuration for authenticating WiFi devices




Part 1: Enabling MAC Authentication from RADIUS Server in MikroTik WiFi AP




MikroTik Wireless Router configuration as WiFi AP was discussed in another article. The default authentication scheme in MikroTik WiFi AP is anyone can connect just knowing SSID and Password. This scheme is obviously not prefer for secure network. So, MAC authentication is the best choice for any wireless network. As MAC authentication is not enabled by default, we have to enable MAC authentication manually to apply this scheme. The following steps will show how to enable RADIUS MAC authentication in MikroTik WiFi AP.




  • From Winbox, click on Wireless menu item. Wireless Tables window will appear.
  • Click on Security Profiles tab and then double click on created WiFi Profile that is being used by WiFi AP. Security Profile window will appear.
  • Click on RADIUS tab and then click on MAC Authentication check box.
  • If you want to MAC accounting, click on MAC Accounting check box and set Interim Update (example: 00:00:59 for one minute interval) time (The time interval for sending accounting status to RADIUS Server).
  • Optionally you can choose MAC address format that you prefer from MAC Format dropdown menu.
  • You can also set whether the MAC will be send as only username or both username and password to RADIUS Server for authentication. The default MAC mode is username only and I am keeping the default setting.
  • Click Apply and OK button.




Enabling MAC Authentication with RADIUS Server
Enabling MAC Authentication with RADIUS Server




MikroTik WiFi AP is now MAC authenticated WiFi AP and the MAC authentication will be checked from RADIUS Server. So, if RADIUS Server allows any MAC address, the device will be allowed to connect to WiFi AP otherwise the device will be rejected.




Now we have to configure RADIUS client in MikroTik RouterOS so that RouterOS can communicate to RADIUS Server to send and receive authentication, authorization and accounting data.  The following steps will show how to configure RADIUS client in MikroTik RouterOS.




  • From Winbox, click on RADIUS menu item. Radius window will appear.
  • Click on PLUS SIGN (+) to add a RADIUS Server. New Radius Server window will appear now.
  • Click on wireless checkbox from Service panel.
  • Put RADIUS Server IP address (in this article: 192.168.70.3) in Address input field.
  • Put Shared secret (in this article: 123) in Secret input field and remember it because you have to provide this secret in RADIUS Server Routers configuration.
  • Click Apply and OK button.
  • From RADIUS window, click on Incoming button. RADIUS Incoming window will appear.
  • Click on Accept checkbox and the default port will be 3799. So, nothing to do. Click Apply and OK button.




RADIUS Client Configuration in RouterOS
RADIUS Client Configuration in RouterOS




RADIUS Client configuration in MikroTik RouterOS has been completed. Now MikroTik RouterOS will be able to communicate with the assigned RADIUS Server.




We will now configure User Manager RADIUS Server so that wireless device can be authenticated from RADIUS Server and get proper authorization.




Part 2: User Manager RADIUS Server Configuration for Authenticating WiFi Devices




User Manager is a RADIUS application and RADIUS Server is used to do AAA (Authentication, Authorization and Accounting) solution.  So, using User Manger RADIUS Server we can do authentication, authorization and accounting of WiFi devices in a Wireless Network. How to install User Manager RADIUS Server with basic configuration was discussed in another article. So, here I will only show how to configure User Manger for authenticating WiFi devices.

At first we will add our Wireless Router as a NAS device of User Manager so that User Manager can reply any RADIUS query of our Wireless Router. The following steps will show how to add MikroTik Wireless Router as a NAS device in User Manager RADIUS Server.


  • Login User Manager Web Interface.
  • Click on Routers menu item. Router page will appear.
  • From top menu bar click on Add menu and then choose New option. Router Details window will appear now.
  • In Main panel, put a meaningful name (example: MikroTik Router) for that client router in Name input field.
  • Put the IP address of the client router (example: 192.168.70.2 that will use User Manager as its RADIUS client) in IP address input field.
  • Put the password that you provide in RouterOS RADIUS Client configuration in Shared secret input field. This password must match otherwise the Wireless Router cannot communicate with this RADIUS Server.
  • In Radius incoming panel, check the CoA (Change of Authorization) check box and put CoA port 3799. This port will be used to send acknowledgment to NAS device for a user’s authorization. For example, if a user exceeds his time limit, RADIUS Server will tell the NAS device to disconnect the user immediately.
  • Click Add button to add this NAS device.




Routers Configuration in User Manager
Routers Configuration in User Manager




Wireless Router and User Manager RADIUS Server are now ready to communicate with each other. In the next step we will configure RADIUS user that will be authenticated in WiFi AP.




In User Manager RADIUS Server, every user must have a profile otherwise the user cannot be valid. So, before creating user we have to configure profile for the users. In this article we will create three profiles according to the following information.




SNProfile NameLimitation
11 Mb Package1 Mbps download speed
22 Mb Package2 Mbps download speed
35 Mb Package5 Mbps download speed




The following steps will show how to create these three profiles with the described limitation.




  • Click on Profiles menu item. Profile page will appear.
  • From Profiles tab click on PLUS SIGN (+). Create profile pop up window will appear.
  • Put the first Profile name (1 Mb Package) in Name input box and click Create button. Profile and Profile property list will appear that can be changed as required.
  • The created profile has no limitation. To add limitation click on Add new limitation button. Profile part pop up window will appear.
  • In Period panel, you can set Days and Time when this profile will be active. By default it will keep 24/7.
  • From Limits Panel click on New limit button. Limitation details popup window will appear.
  • In Main panel, put a limit name (example: 1Mb) in Name input field.
  • In Rate limits panel, put 1M in Rate limit Tx input field and click Add button. Optionally you can set Burst Tx limit, Burst threshold and Burst time. In MikroTik Wireless Router, the Tx limit (transfer limit from AP to wireless device) is applied and Rx cannot be applied. Rx limit only applicable for RouterOS client. So, don’t need to put Rx limit.
  • Created limit will be available and remain selected in Limits panel. Click Add button to add this limit to user profile.
  • First profile with proper limitation will be created.




User Manager Profile Creation
User Manager Profile Creation




Similarly create 2 Mb and 5 Mb Packages. After creating profiles we will now create user and assign created profile to the user.




The following steps will show how to create user in User Manager RADIUS Server.




  • Click on Users menu item. User page will appear.
  • From top menu bar click on Add and then click on One option. User details popup window will appear.
  • In Main panel, put the device MAC address that you want to allow in Username input filed. As we have chosen MAC Mode only username in WiFi RADIUS configuration, keep the Password field blank.
  • From Constraints panel, you can set IP address for this user from IP address input filed and from Wireless panel, you can set private password (SSID password) for this user from Preshared key input field.
  • You can also put user private information in Private information panel.
  • From Assign profile dropdown menu choose any created profile (example: 1 Mb Package) that you want to assign for this user.
  • Click Add button to create this user.




User Creation in User Manager RADIUS Server
User Creation in User Manager RADIUS Server




You can create as many users as you want for your wireless network following the above steps.




After creating user, now connect the desired wireless device to the WiFi AP. If everything is OK, your desired device will be able to connect to your wireless network and you will find the user’s active session in User Manager RADIUS Server.




User Session in RADIUS Server
User Session in RADIUS Server




You can also find the connected users status in Registration tab in Wireless Tables window. Here you will find the user’s data transfer speed in AP Tx Limit status.




User Registration in Wireless Registration Table
User Registration in Wireless Registration Table




If anyone tries to connect to your WiFi AP who is not allowed, he will be rejected.




A common query is if anyone knows allowed MAC Address and changes his MAC address, he will be able to connect in this hacking process. MikroTik has an easy solution for this situation. Put private password in Preshared key while creating user in User Manager RADIUS Server. To be connected to WiFi AP, a user must match MAC address and Preshared key otherwise he will not be able to connect. So, MAC address hacking will be useless.




If you face any confusion to follow the above steps properly, watch the following video about WiFi MAC Authentication with RADIUS Server. I hope it will reduce your any confusion.