RouterOS + WDS + WPA (PEAP-TKIP)/Radius

Hi there,
We are trying to setup a network using the best encryption we can attain, along with reliability and stability.
We now have a Radius server setup on a Windows 2003 box, we have tested this with some CPE equipment (in WDS configuration) and it works perfectly using PEAP authentication.

We would like to try using RouterOS as the backhaul for our setup, in a WDS configuration allowing us to cover a large area as well as letting our CPE equipment act as an “AP/repeater” in the clients home.

  1. Firstly is this kind of setup possible using RouterOS (WDS + WPA)?
  2. How would I go about configuring RouterOS to do this (Completely new to ROS as such, but have used other wireless OS’s…i.e. IkarusOS)
  3. The equipment we have running ROS so far is a pcengines.ch WRAP board with two NIC’s and one wireless card (802.11b/g 400mW)
  4. CPE equipment are the Senao 3320 boxes and 3054 boxes.
  5. We are using a class B network on 172.16.x.x/16 the Radius server is at 172.16.1.100 and the first routerOS box will be 172.16.1.15/16 on the LAN/wLAN

Thanks in advance for your time.
If you need any more information/or would like to chat to me about this on MSN please drop a PM or reply to this post.

I don’t know much about WDS but isn’t the WPA key based on dynamic keys, meaning each node won’t know the key of its peer? Not sure they all can share WPA keys and let you roam at the same itme. I thought someone told me at MUM it had to be WEP or nothing.

Sam

I don’t know much about WDS but isn’t the WPA key based on dynamic keys, meaning each node won’t know the key of its peer? Not sure they all can share WPA keys and let you roam at the same itme. I thought someone told me at MUM it had to be WEP or nothing.

Sam

I was trying to encrypt the back haul as well, but I allways get the infamos “phaze 4 time out”

I was getting this from a AP to client untill MT advised a new atheros client driver. that fixed that problem, but now what?? this is an AP to AP link..

Craig

I am shooting for a static WDS setup where we input the MAC address of each node we want connected to a paticular AP. Then in turn that AP should be able to route thru back to the server to authenticate its shared secret (thats entered on the box and configured as a RADIUS client). This should let laptops/desktops connect to any AP seamlessly where they will get a login which corresponds to their username/password in the 2003 AD…