MikroTik RouterOS is capable of logging various system events as well as user browsing information. Logs can be saved in router’s memory (RAM), disk, file, sent by email or even sent to remote syslog server. Sometimes it may require saving user browsing log by the law. So, a syslog server is an essential part to any network. In this article, I will discuss how to configure MikroTik Router to keep user browsing log and send that log to remote syslog server. I will also discuss how to install and configure MikroTik Syslog Daemon to view and save browsing log sent from MikroTik Router.
MikroTik Syslog Server Configuration with MT Syslog Daemon
MikroTik RouterOS is capable of catching user browsing log and sending that log to remote syslog server. MikroTik Syslog Daemon provides an easy way to view and save browsing log sent from MikroTik Router. So, configuring MikroTik RouterOS and MT Syslog Server we can easily save and analyse user browsing history if require. Complete MikroTik syslog server configuration with MT Syslog Daemon can be done with the following steps.
Creating MikroTik Firewall rule to keep browsing log
MikroTik logging setup to send firewall log to remote syslog server
MT Syslog Daemon installation and configuration to view and save browsing log
Step 1: MikroTik Firewall Rule to Keep Browsing Log
LAN traffics must go through MikroTik Firewall. So, keeping firewall log, we can easily track any kind of browsing history. The following steps will show how to keep browsing log using MikroTik Firewall.
From Winbox, go to IP > Firewall menu item and click on Firewall Rules tab and then click on PLUS SIGN (+). New Firewall Rule window will appear.
From General tab, choose forward from Chain drop down menu.
Choose tcp from Protocol drop down menu.
Put 80,443 in Dst. Port input box.
Click on Connection State input box and check new
Click on Action button and choose log from Action drop down menu.
Click on Apply and OK button.
Firewall Rule to Keep Browsing Log
MikroTik Router is now ready to keep browsing log. We will now setup MikroTik logging to send browsing log to remote syslog server.
Step 2: MikroTik Logging Setup
MikroTik RouterOS by default saves log to its own disk or memory. But RouterOS usually has limited capacity. So, it is always better to create a syslog server and send and save firewall log to that syslog server. The following steps will show how to configure MikroTik logging to send firewall log to the remote syslog server.
Go to System > Logging menu item and click on Action tab and then click on PLUS SIGN (+). New Log Action window will appear.
Put a meaningful name (such as: RemoteLog) in Name input field.
Choose remote option from Type dropdown menu.
Now put Syslog Server’s IP address (for this article: 172.22.220.2) where MT Syslog Daemon will be run in Remote Address input field.
Default syslog port is 514 which will be set by default in Remote Port input field. So, no need to do anything here.
Click Apply and OK button.
Remote Logging Setup
Now click on Rules tab and then click on PLUS SIGN (+). New Log Rule window will appear.
Choose firewall from Topics dropdown menu.
Choose your created action (RemoteLog) from Action dropdown menu.
Click Apply and OK button.
Remote Loging Rule
MikroTik will now send all firewall logs to the given IP address. To view and save these logs, we have to install and configure any syslog application (such as Visual Syslog Server, Dude or MikroTik Syslog Daemon) which you prefer. For this article, we will use MT Syslog Daemon to view and save MikroTik Firewall Log.
Step 3: Downloading and Running MikroTik Syslog Daemon
MikroTik Syslog Daemon is a Windows based free syslog server that can be used to save, view and search MikroTik Firewall log. MT Syslog Daemon is a light weight application and does not need to install. Just running this application, Firewall log can be viewed and searched. MT Syslog Daemon saves all logs in tmplog file which can be used directly to search any specific log.
The default MT Syslog configuration is capable of catching incoming log message. So, run the MT Syslog executable file and you will find the following window where Firewall Log will be viewed.
If you face any confusion to follow the above steps, watch the following video tutorial about Sending Browsing Log to Remote Syslog Server. I hope it will reduce your any confusion.
How to Configure MikroTik Syslog Server with MT Syslog Daemon has been discussed in this article. I hope you will now be able to configure MikroTik Syslog Server following the above steps properly. However, if you face any confusion to configure MikroTik Syslog Server, feel free to discuss in comment or contact with me from Contact page. I will try my best to stay with you.
После недавнего обновления proxmox до 6-й версии перестал работать WoL. Это технология wake on lan для запуска компьютера через сеть. Я использую proxmox для тестовых целей, поэтому ему не обязательно постоянно работать. Я сделал скрипт в mikrotik, с помощью которого удаленно запускаю гипервизор в случае необходимости и пользуюсь им. Потом завершаю работу.
DNS (Domain Name System) Server is an essential part to any computer network. Today web communication cannot imagine without DNS Server. DNS is a client server protocol where DNS Client requests for the domain name resolution and DNS Server response on it. Every network should have a DNS Server because local DNS Server improves network performance by caching DNS information and serving DNS request locally. DNS Server can be configured either Windows or Linux operating system. In this article, I will discuss how to configure a caching DNS Server on CentOS 7/ RedHat 7 Linux with BIND9 Service.
Domain Name System (DNS) and How It Works
Communication between a workstation (PC) and a Server are always done by IP address. So, to get any information from any Web Server, you have to remember the IP address of that Server. But remembering a huge number of public IP addresses is almost impossible for the human being. To solve this issue, DNS technique is introduced in computer networking. The DNS technique can be best compared to a phone book where a user finds a phone number listed by the easier-to-remember name. So, the DNS can be defined as a mapper between human readable names (such as mikrotik.com) and their associated IP Addresses (such as 159.148.147.196). A DNS Server listens on port 53, both UDP and TCP connection.
How DNS Works
When a user types a domain name (such as www.mikrottik.com) in his browser’s navigation bar, the browser first sends a request to the DNS server to get the IP Address of that domain name. The DNS Server replies with the associated IP address of that domain. Getting IP address, the browser is now able to communicate with the Web Server to get requested information.
Now if we use a public DNS server, every time a user request for any domain; the request goes through your WAN connection using paid bandwidth as well as it will make latency. On the other hand, if we use a local DNS Server, the Server will cache the DNS information in memory from the root DNS Server and reply DNS query to the connected clients. This is obviously faster and save paid bandwidth.
BIND9 DNS Server Configuration on CentOS7
The BIND (Berkeley Internet Name Domain) is an open source and most commonly used DNS Service. It is also default DNS Service in UNIX like operating system. So, we can easily install and configure BIND DNS service on CentOS 7. Complete DNS Server configuration on CentOS 7 Linux with BIND Service can be divided into the following 14 steps.
Setting static IP address
SELINUX and Firewall Configuration
Putting local resolver entry and setting static hostname
Installing BIND package from YUM repository
Resetting DNS IP address and verifying resolver configuration
Allowing DNS Server IP and Network in configuration file
Setting Forward and Reverse Zones
Creating Forward and Reverse Zone Files
Setting Ownership to Forward and Reverse Zone Files
Editing Forward Zone File
Editing Reverse Zone File
Restarting DNS service and enabling auto start at boot time
Checking DNS
Viewing and flushing DNS cache
Step 1: Setting Static IP Address
The first step is to setup a static IP address on CentOS 7. It is assumed that you have already installed a fresh CentOS 7 with GNOME Desktop. How to configure static IP address on CentOS 7 with nmtui tool was discussed in my previous article. Configure static IP address following that article according to your IP information. For this configuration, I am using the following IP information.
DNS Server IP: 192.168.40.100/25
Gateway: 192.168.40.1
DNS: 8.8.8.8 (public DNS IP until BIND installation)
At the time of setting these IP information with nmtui tool, the state looks like the below image.
IP Configuration with nmtui tool
Step 2: SELINUX and Firewall Configuration
For simplicity, we do nothing in SELINUX. So, we will first disable SELINUX. To disable SELINUX, open SELINUX configuration file with vim editor and change SELINUX enforcing to disabled and save configuration file.
[root@localhost ~]# vim /etc/selinux/config
# This file controls the state of SELinux on the system.
# SELINUX= can take one of these three values:
# enforcing – SELinux security policy is enforced.
# permissive – SELinux prints warnings instead of enforcing.
# disabled – No SELinux policy is loaded.
SELINUX=disabled
# SELINUXTYPE= can take one of three values:
# targeted – Targeted processes are protected,
# minimum – Modification of targeted policy. Only selected processes are protected.
# mls – Multi Level Security protection.
SELINUXTYPE=targeted
Now we will configure CentOS 7 Firewall so that our DNS server accepts DNS request. The dedicated port for DNS request is 53 (both TCP and UDP). So, we have to allow port 53 in CentOS 7 firewall. Adding DNS service in active Firewall Zone, the 53 port can be allowed in CentOS 7 Firewall.
My active firewall zone is public. So, the following commands will add DNS service in public zone.
Step 3: Putting Local Resolver Entry and Setting Static Hostname
We will now put local resolver entry in hosts file. For this configuration, I am using domain name systemzone.net and hostname ns1. So, open hosts file and put the below line at the bottom and then save and exit.
We will also put static hostname in hostname file. So, open /etc/hostname name file and put ns1.systemzone.net in it and save the file.
[root@localhost ~]# vim /etc/hostname
ns1.systemzone.net
Now reboot your CentOS 7 Server with reboot command. After rebooting, we will start BIND installation.
[root@localhost ~]# reboot
Step 4: Installing BIND Package from YUM Repository
After restarting, we are now ready to install BIND Package from YUM repository. So, open command prompt and run the following command to install BIND package from YUM repository.
[root@ns1 ~]# yum install bind* -y
This command will install all the necessary packages those are required for BIND DNS service from CentOS 7 repository.
Step 5: Resetting DNS IP Address and Verifying Resolver Configuration
We have put public DNS IP at the time of static IP setting. We will now replace it with our DNS Server IP (192.168.40.100). So, replace current DNS IP with your DNS Server IP using nmtui tool.
Replacing DNS with nmtui tool
After replacing DNS IP address, restart network service to update network information.
[root@ns1 ~]# systemctl restart network
After restarting network service, verify that the resolver configuration file (/etc/resolv.cof) contains information like the following entry.
[root@ns1 ~]# vim /etc/resolv.conf
# Generated by NetworkManager
search systemzone.net
nameserver 192.168.40.100
If everything is OK, NetworkManager will update the resolver information like the above output. If you find that the resolver information is like the above output, follow the next step. Otherwise, follow the below noted instruction.
Note: If you don’t find the above information in resolver file, put information like the above output where search value will be your domain name and nameserver value will be your DNS Server IP address and then reboot your CentOS 7 Server.
Step 6: Allowing DNS Server IP and Local Network in DNS Configuration File
The daemon for BIND package is named. The main configuration of named service is named.conf which is located in etc directory. We will assign DNS Server IP address (192.168.40.100) as well as LAN block (192.168.40.0/25) in this configuration so that LAN IP addresses are able to DNS query from this DNS Server. But before editing any configuration file, we should keep a backup of the original file. So, to keep backup, issue the following command.
Now open the configuration file and find options directive and put DNS Server IP address in listen-on port 53 option, disable listen-on-v6 by hash mark (#) and put LAN block in allow-query option and save and exit from the file. The options directive looks like below.
The default zone file is named.rfc1912.zones (located in etc directory) that contains zone information. We will create a forward zone directive for our domain (systemzone.net) and a reverse zone directive for our LAN block (192.168.40.0/24). So, first keep a backup copy and open the named.rfc1912.zones file and put the following forward and reverse zone directives at the bottom and then save and exit from the file.
#forward zone for systemzone.net domain
zone “systemzone.net” IN {
type master;
file “systemzone.net.for”;
allow-update { none; };
};
#Reverse zone for 192.168.40.0/24 block
zone “40.168.192.in-addr.arpa” IN {
type master;
file “systemzone.net.rev”;
allow-update { none; };
};
If you have another domain and LAN block, create another forward zone and reverse zone directive for them respectively.
The zone directive has the following options.
Options
Description
type
Defines the role of this server for the zone. As it is our master DNS Server, I have set it to Master, which means this server is the authoritative owner of the zone. If this were the second server to host the zone, it would be set to slave. A slave is allowed to host the zone’s database, but in only in read-only.
file
The name of the zone’s database file. Unless an absolute path is included, the file will need to be in the directory set using the directory option at the top of the Bind configuration file. By default, all files for CentOS 7 are kept in /var/named.
allow-query
This option defines which hosts or subnets are allowed to query this server for the zone. As we want that anyone can query this zone, I have set it to any.
Step 8: Creating Forward and Reverse Zone Files
In zone file, we have declared that our forward zone file is systemzone.net.for and reverse zone file is systemzone.net.rev. As the default directory location (defined in named.conf file) is /var/named, we have to create forward and reverse zone files in this directory. So, go to /var/named directory and create these two files.
Step 9: Setting Ownership to Forward and Reverse Zone Files
As we have created forward and reverse zone files with root user, the user and group ownership of these files will be root and the named service cannot access the forward and reverse zone files. So, we will change the group ownership of these files to named so that named service be able to read forward and reverse zone files. To change group ownership, issue the following command.
[root@ns1 named]# ll systemzone.net.*
-rw-r—–. 1 root root 152 Mar 21 13:59 systemzone.net.for
-rw-r—–. 1 root root 168 Mar 21 13:59 systemzone.net.rev
[root@ns1 named]# chgrp named systemzone.net.*
[root@ns1 named]# ll systemzone.net.*
-rw-r—–. 1 root named 152 Mar 21 13:59 systemzone.net.for
-rw-r—–. 1 root named 168 Mar 21 13:59 systemzone.net.rev
Step 10: Editing the Forward Zone File
Now open the forward zone file and add the following lines in this file and then save and exit from the file.
[root@ns1 named]# vim systemzone.net.for
$TTL 1D
$ORIGIN systemzone.net.
@ IN SOA ns1.systemzone.net. root.systemzone.net. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
@ IN NS ns1.systemzone.net.
@ IN A 192.168.40.100
ns1 IN A 192.168.40.100
The $TTL (Time-to-Live) directive at the first line defines the duration in seconds that the record may be cached by any resolver. The default value is 1D. You can change as your requirement.
The $ORIGIN directive at the second line defines a base name from which ‘unqualified’ names (those without a terminating dot) substitutions are made when processing the zone file. Zone files which do not contain an $ORIGIN directive, while being perfectly legitimate, can also be highly confusing. In general, we should always define an $ORIGIN directive explicitly unless there is a very good reason not to do. The $ORIGIN values must be ‘qualified’ (they end with a ‘dot’).
The third line called the Start of Authority (SOA) has the following meaning.
@
The first value is the fully qualified domain name of the zone. The ‘@’ character is an alias for the domain name, which was defined in the Bind configuration file, to save admins from having to type the entire name.
IN
Sets the adjacent record type as Internet.
SOA
This is the domain record for the zone’s Start of Authority. It defines who the authoritative name server is, contact info for the administrator, and a few other values.
ns1.systemzone.net.
The fully qualified domain name of the authoritative name server for the zone. (Don’t forget to put the ending ‘dot’)
root.systemzone.net.
The email account of the administrator of the zone. The @ character is replaced by a period. (Don’t forget to put the ending ‘dot’)
Serial
The serial number of version number of the zone file. This value is essential for secondary DNS servers who keep a replica of the zone and need to know if changes have been made.
Refresh
How often a slave (secondary) Bind DNS server should do a zone transfer from the master (primary) server.
Retry
How often a slave should retry a failed zone transfer.
Expire
The duration a slave (secondary) server should answer client query requests after it lost contact with the master (primary) server.
Minimum
The default time-to-live value each record will have, unless specified otherwise by a record.
The third line contains the name server records for the domain (systemzone.net). Every zone requires at least one name server. The name server record has the following options.
Options
Description
@
The ‘@’ character is an alias for the domain name, which was defined in the Bind configuration file. The NS record requires this or the fully-typed out domain name of the zone.
IN
Sets the adjacent record type as Internet.
NS
Sets the record as a Name Server record
ns1.systemzone.net.
The fully qualified domain name of the name server. (Don’t forget to put the ending ‘dot’)
The fourth line contains the Host Record of the domain name (systemzone.net) because we want to resolve our domain also. The Host Record has the following options.
Options
Description
@
The ‘@’ character is an alias for the domain name, which was defined in the Bind configuration file. The NS record requires this or the fully-typed out domain name of the zone.
IN
Sets the adjacent record type as Internet.
A
Sets the record as a Host record
192.168.40.100
The IP address of the Host
The fifth line contains the Host Record of the name sever (ns1.systemzone.net) because every NS record needs a Host Record and clients require this for them to resolve the IP address of the name server.This Host Record has the following meaning.
Options
Description
ns1
Hostname of the Server
IN
Sets the adjacent record type as Internet.
A
Sets the record as a Host record
192.168.40.100
The IP address of the Host
Now if you have another server such as FTP Server (IP address is 192.168.40.101) and want to resolve with its hostname (ftp), put the following Host Record at the bottom of the above Host Record.
ftp IN A 192.168.40.101
Step 11: Editing Reverse Zone File
The reverse zone file is required to resolve IP address to name. Open the reverse zone file and put the following lines in this file and then save and exit from the file.
[root@ns1 named]# vim systemzone.net.rev
$TTL 1D
$ORIGIN 40.168.192.in-addr.arpa.
@ IN SOA ns1.systemzone.net. root.systemzone.net. (
0 ; serial
1D ; refresh
1H ; retry
1W ; expire
3H ) ; minimum
IN NS ns1.systemzone.net.
100 IN PTR ns1.systemzone.net.
This file has the similar options like the forward zone file. The only new option is PTR record (at the bottom line) which is the main purpose of reverse zone file. The PTR record is specially required for outgoing server because some mail servers do not allow message without valid PTR record of the outgoing mail server. A PTR record has the following options.
Options
Description
100
The value ‘100’is actually a name and it will be the last octet value of an IP address.
IN
Sets the adjacent record type as Internet.
PTR
Sets the record as a Reverse DNS record
ns1.systemzone.net.
The fully qualified domain name of a Host. (Don’t forget to put the ending ‘dot’)
Now if you have another server such as FTP Server (whose IP address is 192.168.40.101 and FQDN is ftp.systemzone.net) and want to resolve reverse DNS, put the following PTR Record at the bottom of the above PTR Record.
101 IN PTR ftp.systemzone.net.
Step 12: Starting DNS Service and Enabling Auto Start at Boot Time
DNS Server configuration is now complete. Start DNS Service with the following command.
[root@ns1 named]# systemctl start named
To enable auto start the DNS service at the boot time, issue the following command.
[root@ns1 named]# systemctl enable named
If you get any error in DNS configuration, issue the status command to view the error message.
[root@ns1 named]# systemctl status named
Step 13: Checking DNS
The nslookup tool is used to view name to IP address or IP address to name resolution. So, issue the nslookup command to view whether your configured DNS Server can resolve DNS request or not.
[root@ns1 ~]# nslookup systemzone.net
Server: 192.168.40.100
Address: 192.168.40.100#53
Name: systemzone.net
Address: 192.168.40.100
If your output is like the above output, DNS server is able to resolve name to IP address. Issue the following command to view IP address to name resolution.
[root@ns1 ~]# nslookup 192.168.40.100
Server: 192.168.40.100
Address: 192.168.40.100#53
100.40.168.192.in-addr.arpa name = ns1.systemzone.net.
If you get the above output, DNS server is also capable to resolve IP address to name.
The dig tool can also be used to know the status of your forward and reverse zone service. Issue the following dig command to view the status of your forward zone service.
[root@ns1 ~]# dig systemzone.net
If you find status=NOERROR, your forward DNS service is completely ready to function. Now issue the following command to view the status of the reverse zone service.
[root@ns1 ~]# dig -x 192.168.40.100
If you find status=NOERROR, reverse DNS service is also ready to function. Now issue the ping command from your server or assign your DNS Server IP to any other workstation and issue the ping command from there. If everything is OK, your will get name resolution result.
[root@ns1 ~]# ping google.com
Step 14: Viewing and Flushing DNS Cache
DNS name resolution cache is stored in RAM and served from the RAM if any similar request is found. Stored DNS cache can be viewed executing the following command.
[root@ns1 ~]# rndc dumpdb –cache
The above command will store DNS cache into cached_dump.db file which will be found in /var/named/data directory. So, to view cached DNS records simply cat or grep the resulting dumb file. For example:
Sometimes you may need to flush cached DNS records. To flush cached DNS records, issue the following command.
[root@ns1 ~]# rndc flush
Once done, reload DNS/BIND with the following command.
[root@ns1 ~]# rndc reload
server reload successful
If there were no DNS queries after you flushed bind’s cache and reloaded DNS, your new cache dump file (with rndc dumpdb -cache) will be empty.
If you face any confusion to follow the above steps properly, watch the following video about BIND DNS Configuration on CentOS 7. I hope it will reduce your confusion.
How to configure BIND DNS Server on CentOS 7 has been discussed in this article. I hope you will now be able to configure your local DNS Server with BIND Service. However, if you face any confusion to install and configure BIND DNS Service on CentOS 7,feel free to discuss in comment or contact me from Contact page. I will try my best to stay with you.
MikroTik производят профессиональное сетевое оборудование с возможностью тонкой настройки. Поэтому для VPN-сервера или клиента маршрутизаторы этой фирмы подходят просто отлично.
Tor Browser is an alternative to VPN and Web Proxy that breaks blocking firewall rule. If any user installs and uses Tor Browser, he/she can hide the public IP address of router and can unblock blocked websites applied on a network. So, administrators should block Tor Nodes along with other blocking firewall rule. In my previous article, I discussed how to block VPN and Proxy access with MikroTik Router and in this article I will discuss how to block Tor Nodes with MikroTik Router.
How to Block Tor Nodes
Tor Browser cannot be blocked by blocking TCP ports because Tor Nodes usually uses TCP port 443 which is a dedicated port for secure HTTP communication. So, to block Tor Browser, we have to find IP addresses of the active Tor Nodes and block those IP addresses with firewall rule.
Finding IP Addresses of Tor Nodes
To block Tor Browser, we have to find IP addresses of the active Tor Nodes. Fortunately, Tor Project provides IP addresses of the active Tor Nodes available from an IP address. So, to find Tor Nodes IP addresses, go to https://check.torproject.org/cgi-bin/TorBulkExitList.py and you will find TorBulkExitList page.
TorBulkExitList Page
Provide public IP address of your router and click on Submit button. Your will now find the available Tor Node IP addresses those are contactable from your IP address.
List of Active Tor Nodes IP Address
Finding IP addresses of the active Tor Nodes, we will now create firewall rule to block these IP addresses so that user cannot communicate with these IP addresses from his Tor Browser.
MikroTik Firewall Rule to Block Tor Nodes
MikroTik Firewall is able to block a group of IP addresses. So, we will first create a firewall rule that will block a group of IP addresses and then we will add IP addresses of Tor Nodes in this group. The following steps will show how to block a group of destination IP addresses with MikroTik Firewall Rule.
Go to IP > Firewall menu item and click on Filter Rules tab and then click on PLUS SIGN (+). New Firewall Rule window will appear.
Choose forward from Chain dropdown menu.
Click on Advanced tab and put a group name (such as Blacklisted IP Address) in Dst. Address List input box.
Click on Action tab and choose drop from Action dropdown menu.
Click Apply and OK button.
MikroTik Firewall Rule to Block Tor IP Address
This rule will block those IP addresses which will have in Blacklisted IP Address group. Now we will add our found Tor Node IP addresses in this group.
Adding IP Addresses in Blacklisted IP Address Group
After creating blocking firewall rule for a group, it is time to add IP address in this group. The following steps will show how to add Tor Node IP address in Blacklisted IP Address group.
Go to IP > Firewall menu item and click on Address Lists tab and then click on PLUS SIGN (+). New Firewall Address List window will appear.
Choose your created group name (Blacklisted IP Address) from Name dropdown menu.
Put a Tor Node IP address (such as 103.208.220.122) that you have found from Tor Bulk Exit List page in Address input field. If you found multiple IP addresses in same subnet, you can provide the whole subnet rather than a single IP address.
Click Apply and OK button.
Adding Tor Node IP Address
Similarly, put all the IP addresses that you have found from Tor Bulk Exit List page in Blacklisted IP address group and then you will find no Tor user will be able to use tor browser.
If you face any confusion to follow above steps properly, watch the following video about blocking Tor Browser with MikroTik Firewall. I hope it will reduce your any confusion.
How to block Tor Browser with MikroTik Firewall has been discussed in this article. I hope you will now be able to block Tor Nodes from your network if required. However, if you face any confusion to block Tor Nodes, feel free to discuss in comment or contact with me from Contact page. I will try my best to stay with you.
Современное общество уже сложно представить без интернета. В каждом доме имеется по несколько девайсов, которые можно легко объединить в домашнюю сеть с помощью Wi-Fi-маршрутизатора. Многие модели стационарных роутеров поддерживают стандарты 3G/4G и имеют слот для сим-карты, что позволяет им для выхода в интернет использовать сети сотовых операторов.