Community discussions

MikroTik App
 
RedShift
just joined
Topic Author
Posts: 3
Joined: Thu Aug 18, 2005 6:04 pm

Traffic account on a per MAC-address basis

Thu Aug 18, 2005 6:08 pm

Hello,

Is the following scenario possible with the RouterOS software:

Router functions, who keeps traffic logs on a MAC-address basis. Each
MAC-address is able to use an absolute volume of 4 GB per month. After
his limit is reached he is either denied access to outside networks (the
internet) or traffic is shaped so he is only able to reach speeds of 16
kbps or something similar. Ofcourse when the new month starts, the MAC
address has no more limitations untill he reaches his 4 GB limit again.

Ofcourse, if other means other than MAC addresses are available, I'm open for them. The last thing I would like to resort to is to IP-address. It's easily changed. But maybe if there is an option somewhere to deny access to IP-addresses that weren't hand out by the DHCP server.

The setup is a basic router that's connected to the internet, and a local interface whichs, ironically, connects to the local network.

Thanks for your assistance,

Best Regards,

Glenn
 
rikerconsulting
just joined
Posts: 21
Joined: Sat Apr 30, 2005 12:11 am
Contact:

Fri Aug 19, 2005 3:56 am

Are you opposed to using RADIUS?

~ Jason
 
nikhil
Member Candidate
Member Candidate
Posts: 262
Joined: Wed Dec 22, 2004 5:04 pm
Location: US

Fri Aug 19, 2005 4:43 am

how would this be done using radius . Provided that the client(mac-addres) need not have to login . How would we use it for servers whose bandwidth we want to restrict/monitor on kbps or data transfer ?
 
rikerconsulting
just joined
Posts: 21
Joined: Sat Apr 30, 2005 12:11 am
Contact:

Fri Aug 19, 2005 5:59 am

I was thinking use the MAC address for the Hotspot login. Just my initial thinking.

~ Jason
 
nikhil
Member Candidate
Member Candidate
Posts: 262
Joined: Wed Dec 22, 2004 5:04 pm
Location: US

Fri Aug 19, 2005 7:44 am

Is it possible to do this for a set of servers . For example in a colocation environment
 
RedShift
just joined
Topic Author
Posts: 3
Joined: Thu Aug 18, 2005 6:04 pm

Fri Aug 19, 2005 9:14 am

Please tell me how. There's not wireless involved, both sides are just regular ethernet, nor do I use a radius server. The setup is that my parents have a place where students stay for the school year (I don't know what it's called in English. It's a dorm but not on a campus, we have a house with x rooms where the students rent them for a cheap price), and ofcourse they want internet. But we want to limit their usage, so they can't use up all of the traffic, because the line itself has a monthly usage limit.

I've already started experimenting with some firewall rules and scripts I found here lying around in the forum. These are not MAC-based however (on IP-address), and far from automatic. The ideal situation would be for every MAC address the same, but now I have to add a firewall rule for every IP address the server hands out, + if the user sets a static IP it's easily countered. And I also need a solution where the user can view his traffic...
 
wildbill442
Forum Guru
Forum Guru
Posts: 1055
Joined: Wed Dec 08, 2004 7:29 am
Location: Sacramento, CA

Fri Aug 19, 2005 9:23 am

what about using PPPoE? or PPTP for authentication? Then you could use a RADIUS setup and limit bandwidth that way and add another layer of authentication/security to the network...
 
RedShift
just joined
Topic Author
Posts: 3
Joined: Thu Aug 18, 2005 6:04 pm

Fri Aug 19, 2005 9:32 am

what about using PPPoE? or PPTP for authentication? Then you could use a RADIUS setup and limit bandwidth that way and add another layer of authentication/security to the network...
I'm not going to install two computers so I would just have a radius server! These things cost money, the limit is one computer.
 
nikhil
Member Candidate
Member Candidate
Posts: 262
Joined: Wed Dec 22, 2004 5:04 pm
Location: US

Fri Aug 19, 2005 10:21 am

I would like to know how to do mac based even if I have to setup a separate radius machine . I dont mind doing radius in a linux/bsd vmware box.

Thats one way to go and get radius without an additional machine .
 
wildbill442
Forum Guru
Forum Guru
Posts: 1055
Joined: Wed Dec 08, 2004 7:29 am
Location: Sacramento, CA

Fri Aug 19, 2005 1:40 pm

what about using PPPoE? or PPTP for authentication? Then you could use a RADIUS setup and limit bandwidth that way and add another layer of authentication/security to the network...
I'm not going to install two computers so I would just have a radius server! These things cost money, the limit is one computer.
sorry someone mentioned radius so i just took off with it.. but you could do it all on 1 Mikrotik box without a seperate radius server.
 
wildbill442
Forum Guru
Forum Guru
Posts: 1055
Joined: Wed Dec 08, 2004 7:29 am
Location: Sacramento, CA

Fri Aug 19, 2005 1:44 pm

I would like to know how to do mac based even if I have to setup a separate radius machine . I dont mind doing radius in a linux/bsd vmware box.

Thats one way to go and get radius without an additional machine .
Well without using radius you could setup the local interface w/ the ARP setting set to "reply-only" build a static ARP entry for your users, the users will always get the same IP address, you could setup simple queues and bandwidth limit based on IP address.

That way any "unauthorized" users would have to know the IP address and MAC address of a user in order to gain access to the network.

Who is online

Users browsing this forum: cvrnaught, McSee, NetworqAndy and 113 guests