Is it possible to have use one of the Mikrotik routers as a travel router, but without connecting to the Ethernet ports?
It has to be totally wireless.
I’m looking for something like this.
WAN side: connect small router to coffee shop wireless internet
VPN: small router establishes a tunnel to VPN service such ass ProtonVPN
LAN side: small router advertises wireless network so that my iphone and ipad can connect and traverse the VPN[/list][/list]
Yes, this is perfectly possible.
I have a mAPLite configured for that purpose.
It helps to use the ethernet port for config but even that is not needed (though it DOES complicate things and you need to be very careful what you do in which order).
Even one step further (trick I learned from user bpwl): connect list where you define all known to you wireless networks which can be connected to.
And your smartphone hotspot could be one of them (under the assumption nowadays everyone has always his smartphone with him).
References/reading material (instructions which are for mAP/mAPLite but basically they apply to all ROS devices, with some possible optimizations for devices having multiple radios):
To complete your requirements you need to setup your VPN and use one slave SSID which goes with that. So once connected to that, you’re on VPN.
Use another SSID for regular access (but with the added benefit of using the MikroTik firewall to stay behind, though personally I’d always use VPN on public Wifi)
Keep in mind though not all VPN protocols are able to pass all firewalls. Nowadays I like to use Wireguard on ROS7 but I am aware it doesn’t always work. SSTP or OpenVPN might be the best alternative then.
mAPLite is a very good Travel-Router!
I have 3 of them and one is always in my Laptop-Bag
It’s Compact and you can power it with your laptop or Power-Bank,
everyone should have one =)
I do a lot of Job-Hopping…
And realised most company’s have a PoE-Network
So my Main Travel-Router at the moment is a cAPac with a 3D-Printed enclosure.
It’s more powerfull for Firewall, QoS, VPN, etc and has added Features like ether2 & 5Ghz
The only disadvantage is Power , when PoE is not available.
I also make some 10.5" Rackmount enclosures for Mikrotik and other Devices.
It’s designed to be easy to print on a Std Sized 3D-Printer
and you can even attach two together to mount in 19" Rack.
I can’t show actual Picture of Data-Center where i implemented them..
But I attached some Picture to give you an idee.
Sweet !!
I guess with all the holes in the enclosure you don’t have too much temperature issues ?
Because CapAC can get pretty hot … I also have one (930km away in France but it has been lying here on my desk for 6 months beginning of the year to test)
Any particular reason you did not go for standard hap AC2, apart form the powering ?
I used the cAPac insteed of the hAPac because of the PoE Bypass.
Why?
It gives me the posibility to connect and power
an IP-Phone or other small PoE-Device
Sometime i connect the Router between existing devices (like switch and existing IP-Phone)
because no other Cable is free or working
(like i sayed , i do a lot of Job-Hopping at the moment)
My most universal device is the “hAP ac Lite” (not the hAP Lite), but I also carry the mAPLite, and use them in combination if needed.
The mApLite (with repeater function and connect list) also makes the necessary VPN tunnels to some reachable “hAP Lite” TURN servers @home.
ether5 on the hAP ac Lite , with PoE out, powers the mAPLite as WAN device.
While just listing all, the hAP ac Lite is powered via the MQS and a powerbank or the laptop USB as source.