Community discussions

MikroTik App
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

WDS seciurity not working

Tue Apr 21, 2020 1:22 am

Hello.

I want to create WDS connection between Mikrotic hap ac2 and it's working only when I have no password for wlan.

How can I protect my network becouse only hide SSID it's not good option

I tried with all types of used passwords, also to control connection only by MAC and always the same - when I have some protection WDS in not connected.

Thank You for help
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Tue Apr 21, 2020 8:30 pm

WDS has no problem working when a password is set, so you have something wrong in your configuration that is why it does not work...
However, there is no reason to use WDS between two Mikrotik Devices, AP-Bridge on one side and Station Bridge to other will bring the same result and it is the preferred mode as well...
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Tue Apr 21, 2020 9:48 pm

OK - so about WDS

I have settings for wlan card and I use it with password (in Seciurity tab with dynamic keys WPA2). I can connect to this network on both routers (different SSID) and I have internet, and routers are connected between each other with using wire.

When in disable wire between them and add change SSID on both of them for the same, also in WDS tab in both routers (wireless settings) i choose dynamic mesh, and connected to bridges I have situations:
* first situation - when I have seciurity the same as before (with WPA2) dynamic WDS connection is not created by router (not shown on wireless interfaces list)
* second situation - settings the same as before with one change - password change for easy one (static) and short one 6 digits, WDS is created on both routers but only Tx transmition is jumping (there is nothing on Rx side) - no connection
* third situation - setting the same as before with one change - password is disabled on both routers, and WDS starts to have Tx and Rx and I have internet on both of therm (when I connect wire directly)

So settings are always the same for this three situations, and I change only type of passwords, and finally I disable password. It's look like it is some issue with have connection which is protected. Password on both routers is the same (tested many times and it was password 123456).
I spend two days with fighting with that, and it was working like manyals on Youtube says with protection disable. When I start to change settings from test setting to real settings I set network password as I thought should be and I did not realized that this is an issue so I changed many times settings and finnaly when I disabled all "protection" I had again working WDS.

So if I made some mistake please tell me how to fix it.

And about Your suggestion - I'm prepering to have 4-5 routers in house so I need to have some solution.
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Wed Apr 22, 2020 1:05 pm

To make things clear, you want to create a WDS-Mesh Network ?
If yes, notice that the security profiles must be identical, not only the same password, but the same 100%...
The same applies to the Wireless config as well...
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Wed Apr 22, 2020 2:42 pm

Yes that is a plan.

Usual other routers usual are connected to "main" router via wire and AP with Mesh are reconnect clients where signal is better.

Here I'm not sure how it should be. I thought that I need to connect all routers to one network with using wlan to make "wire" connection between them with using wifi - for this reason I made WDS between routers. It is my first step, and now I have on both routers internet when I connect to lan ports via wire, also when I have different wlans names I can connect via wifi to both routers and I have internet. Only first router is connected to WAN.

WDS works between routers but only when I have permissions without any password. So I have open network (without any password), and I add MAC filter for that wlan card, and hide SSID.

Config is the same on both routers - as I described before - first try was with WPA2 (even WDS dynamic mesh not created by router), second try same settings with changing WPA2 for WEP (WDS dynamic mesh created - no connection), third try same settings and disable password (everything working).
To confirm that network name and other settings are the same - WDS connection is ok when I have disabled seciurity.
To confirm that passwords are the same on both routers - when I disable one of them I can connect to second one by laptop, when I disable second one I can connect to first one. All without changing password on laptop.

So in my opinion something is wrong with WDS when password is on (both routers are hAP ac2 with FW 6.45.8 ).
All manuals in internet I found are created with default rule in Seciurity tab (so without password).


My goal to have possibiity to connect one router to WAN via wire, other somehow to each other, and to have automatic AP change on phone when I have weak signal from this router to another with better signal (like other mesh works). Of coure I can use repeater, I can have only WDS and AP, but always when You are in move first You need to lose signal from one AP to reconnect to another even if SSID is the same - Mash becouse it's checks connection should do it better...
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Wed Apr 22, 2020 6:39 pm

It is about a year since i last played with WDS Mesh networks, i can assure you it works fine with non default security profile...
I would make a quick test for you but unfortunatelly i do not have 2 wireless devices for testing right now...

If i were you i would reset the Wireless configuration on 2 devices and then:
1. Set mode to AP-bridge
2. Set an SSID
3. Assign a Security Profile
4. Enable WDS on bridge in Dynamic-Mesh mode

And test again... Make sure complete wireless configs are identical...

You could also disable default authenticate on the WIreless Tab and use the Connect list to select where exactly your AP wants to establich a WDS with ....
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Wed Apr 22, 2020 10:30 pm

I did reset without default settings, I create IP, DHCP and turn on wifi with default settings on both routers - 5 minutes of work and dynamic mesh WDS done and connected (Alan type AP Bridge, WDS dynamice mesh)

After that I disable from power first router and create seciurity password WPA 12345678 and I was able to connect to router (and IP was taken). Frst router disabled from power.
Second router the same settings with WPA password 123456 and I connect computer to this wifi (again IP was taken) withou putting agian password to coputer (so it was the same, and SSID was also the same - default Mikrotic name).
Turned on power on disabled router and WDS not created. All settings the same - default, olny changed seciurity from default profile (without password and network is open and IP taken without any problems - also tested), the same password becouse I testet to connect form compter witout changing password.

So I think it is some bug in firmware...
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Thu Apr 23, 2020 4:13 am

So I think it is some bug in firmware...
You can always do an update to the latest ROS 6.46.5 ...
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Thu Apr 23, 2020 8:34 pm

6.46.5 and the same issue... - some bug in WDS with seciurity with using password.

So I don't know how to create this Mesh becouse it's impossible to add all new users with manual adding their MAC...

I used WDS 8 years ago with routers 4 times cheaper... and I thought that Mikrotic... - wow - I will have OpenVPN, tunel between two localizations, and mash in each one, and now I need to add manually MACs or use open network.

I hope I did something wrong but what? Maybe I can put/check logs - I don't know...
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Thu Apr 23, 2020 8:39 pm

You can export with hide-sensitive the configuration of 2 APs you perform MESH with...
Post the configurations inside tags...
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Thu Apr 23, 2020 8:57 pm

first one (main):
# apr/23/2020 19:54:19 by RouterOS 6.46.5
# software id = 283F-MQLT
#
# model = RBD52G-5HacD2HnD
# serial number = xxxx
/interface mesh
add hwmp-rann-propagation-delay=5 name=Mesh
/interface bridge
add admin-mac=C4:AD:34:08:61:10 auto-mac=no comment=defconf name=Lnet
/interface ethernet
set [ find default-name=ether1 ] name=Internet
/caps-man datapath
add bridge=Lnet name=datapath1
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk,wpa2-eap eap-methods="" name=Most \
radius-mac-authentication=yes supplicant-identity="" wpa2-pre-shared-key=\
1234567890
add authentication-types=wpa-psk,wpa2-psk eap-methods="" \
management-protection=allowed mode=dynamic-keys name=Test \
supplicant-identity="" wpa-pre-shared-key=12345678 wpa2-pre-shared-key=\
12345678
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
country="united states" disabled=no distance=indoors installation=indoor \
mac-address=C4:AD:34:08:61:12 mode=ap-bridge name=Wifi12 \
security-profile=Test ssid=Lnet wds-ignore-ssid=yes wireless-protocol=\
802.11 wps-mode=disabled
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-XXXX country="united states" disabled=no distance=indoors \
installation=indoor mode=ap-bridge name=Wifi15 security-profile=Test \
ssid=Lnet wds-ignore-ssid=yes wireless-protocol=802.11 wps-mode=disabled
add hide-ssid=yes mac-address=C6:AD:34:08:61:12 master-interface=Wifi12 name=\
Most12 security-profile=Test ssid=Dsawes452!%af332asw wds-default-bridge=\
Lnet wds-ignore-ssid=yes wds-mode=dynamic-mesh wps-mode=disabled
add disabled=no hide-ssid=yes keepalive-frames=disabled mac-address=\
C6:AD:34:08:61:15 master-interface=Wifi15 multicast-buffering=disabled \
name=Most15 security-profile=Most ssid=Agh243!&gsas!!s2 \
wds-default-bridge=Lnet wds-ignore-ssid=yes wds-mode=dynamic-mesh \
wps-mode=disabled
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
add hotspot-address=192.168.10.1 html-directory=flash/hotspot name=\
HotSpotServer
/ip pool
add name=LocalPool ranges=192.168.88.100-192.168.88.250
add name=MeshPool ranges=192.168.100.100-192.168.100.250
/ip dhcp-server
add address-pool=LocalPool disabled=no interface=Lnet name=LocalDHCPServer
add address-pool=MeshPool disabled=no interface=Mesh lease-time=1h name=\
MeshDHCPServer
/ip hotspot
add address-pool=MeshPool disabled=no interface=Wifi12 name=LnetHotSpot \
profile=HotSpotServer
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=Lnet comment=defconf interface=ether2
add bridge=Lnet comment=defconf interface=ether3
add bridge=Lnet comment=defconf interface=ether4
add bridge=Lnet comment=defconf interface=ether5
add bridge=Lnet comment=defconf interface=Wifi12
add bridge=Lnet comment=defconf interface=Wifi15
add bridge=Lnet interface=Most12
add bridge=Lnet interface=Most15
add bridge=Lnet disabled=yes interface=*127
/ip neighbor discovery-settings
set discover-interface-list=all
/interface list member
add comment=defconf interface=Lnet list=LAN
add comment=defconf interface=Internet list=WAN
/interface wireless access-list
add mac-address=C6:AD:34:BF:29:22 vlan-mode=no-tag
add mac-address=C6:AD:34:BF:29:25 vlan-mode=no-tag
add mac-address=C6:AD:34:08:61:12 vlan-mode=no-tag
add mac-address=C6:AD:34:08:61:15 vlan-mode=no-tag
/ip address
add address=192.168.88.1/24 comment=defconf interface=Lnet network=\
192.168.88.0
add address=192.168.10.1/24 comment="hotspot network" interface=Mesh network=\
192.168.10.0
/ip dhcp-client
add comment=defconf disabled=no interface=Internet
/ip dhcp-server network
add address=192.168.10.0/24 comment="hotspot network" gateway=192.168.10.1
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=passthrough chain=unused-hs-chain comment=\
"place hotspot rules here" disabled=yes
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment="masquerade hotspot network" \
src-address=192.168.10.0/24
/ip hotspot user
add name=Lnet password=AlaMaKota123 server=LnetHotSpot
/system clock
set time-zone-name=Europe/Warsaw
/system identity
set name=Glowny
/tool graphing interface
add allow-address=192.168.0.0/16 interface=Internet
add allow-address=192.168.0.0/16 interface=Lnet
add allow-address=192.168.0.0/16 interface=Mesh
/tool graphing resource
add allow-address=192.168.0.0/16
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
And second one:
# apr/23/2020 19:52:49 by RouterOS 6.46.5
# software id = 3FBU-1TN7
#
# model = RBD52G-5HacD2HnD
# serial number = zzzz
/interface bridge
add admin-mac=C4:AD:34:BF:29:F5 auto-mac=no comment=defconf name=bridge
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
add authentication-types=wpa2-psk,wpa2-eap eap-methods="" name=Most \
radius-mac-authentication=yes supplicant-identity="" wpa2-pre-shared-key=\
1234567890
add authentication-types=wpa-psk,wpa2-psk eap-methods="" \
management-protection=allowed mode=dynamic-keys name=Test \
supplicant-identity="" wpa-pre-shared-key=12345678 wpa2-pre-shared-key=\
12345678
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
country="united states" disabled=no distance=indoors installation=indoor \
mac-address=C4:AD:34:BF:29:22 mode=ap-bridge name=Wifi22 \
security-profile=Test ssid=Lnet wds-ignore-ssid=yes wireless-protocol=\
802.11 wps-mode=disabled
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-XXXX country="united states" disabled=no distance=indoors \
installation=indoor mac-address=C4:AD:34:BF:29:25 mode=ap-bridge name=\
Wifi25 security-profile=Test ssid=Lnet wds-ignore-ssid=yes \
wireless-protocol=802.11 wps-mode=disabled
add disabled=no hide-ssid=yes mac-address=C6:AD:34:BF:29:22 master-interface=\
Wifi22 name=Most22 security-profile=Test ssid=Dsawes452!%af332asw \
wds-default-bridge=bridge wds-ignore-ssid=yes wds-mode=dynamic-mesh \
wps-mode=disabled
add disabled=no hide-ssid=yes keepalive-frames=disabled mac-address=\
C6:AD:34:BF:29:25 master-interface=Wifi25 multicast-buffering=disabled \
name=Most25 security-profile=Most ssid=Agh243!&gsas!!s2 wds-cost-range=50 \
wds-default-bridge=bridge wds-ignore-ssid=yes wds-mode=dynamic-mesh \
wps-mode=disabled
/ip hotspot profile
set [ find default=yes ] html-directory=flash/hotspot
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
/ip dhcp-server
add address-pool=default-dhcp interface=bridge name=defconf
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=Wifi22
add bridge=bridge comment=defconf interface=Wifi25
add bridge=bridge interface=Most22
add bridge=bridge interface=Most25
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface wireless access-list
add mac-address=C6:AD:34:08:61:12 vlan-mode=no-tag
add mac-address=C6:AD:34:08:61:15 vlan-mode=no-tag
add mac-address=C6:AD:34:BF:29:22 vlan-mode=no-tag
add mac-address=C6:AD:34:BF:29:25 vlan-mode=no-tag
/interface wireless cap
set bridge=bridge caps-man-addresses=192.168.88.1 interfaces=Wifi22
/ip address
add address=192.168.88.2/24 comment=defconf interface=bridge network=\
192.168.88.0
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-relay
add dhcp-server=192.168.88.1 interface=Most22 name=relay1
/ip dhcp-server network
add address=192.168.88.0/24 comment=defconf
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
/ip route
add disabled=yes distance=1 gateway=192.168.88.1
/system clock
set time-zone-name=Europe/Warsaw
/system identity
set name=Poddasze
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
Its workin when seciurity Most is activated (only MAC check), with seciurity Most not working at all.
Both wlans has added virtual cards and WDS is connected to this virtual cards (becouse I can't use password on regular SSID name so WDS networks are hidden)
 
Zacharias
Forum Guru
Forum Guru
Posts: 3459
Joined: Tue Dec 12, 2017 12:58 am
Location: Greece

Re: WDS seciurity not working

Thu Apr 23, 2020 9:20 pm

From a quick look at your configurations...

First, since you use Dynamic Mesh, why are you adding manually the WDS interfaces? They will be added automatically, do not add them manually...
Also, remove from the Bridge the WDS interfaces you manually added... They will be added to the Bridge automatically as well...
Next, the wds-ignore-ssid does not work neither on dyncamic-mesh nor on static-mesh, so just let it to default "no"...
Where is your Frequency? You must set same frequencies on all the MESH APs...
 
owca
just joined
Topic Author
Posts: 8
Joined: Sun Apr 19, 2020 7:12 pm

Re: WDS seciurity not working

Thu Apr 23, 2020 9:39 pm

Config look like:
     1. wlan2,4GHz (Wifi12) - 2412Mhz- for regular users with normal seciurity with password 
      
               1a.  Virtual (Most12) - this is virtual build from wlan2,4GHz (the same frequency) as main. It has in settings enabled WDS as dynamic mesh type (here I have stupid SSID, network is hided, 				
               						and seciurity is only MAC) - used to build connection between routers
 						
       2. wlan5,0GHz (Wifi15) - 5180Mhz- for regular users with normal seciurity with password 
       
                2a. Virtual (Most15) - this is virtual build from wlan5,0GHz (the same frequency) as main. It has in settings enabled WDS as dynamic mesh type (here I have stupid SSID, network is hided, 
                					and 	seciurity is only MAC) - used to build connection between routers
                				
WDS is not added becouse of my settings (during export file it was created by router - both Most12 or Most15 virtual wlans has settings for ony MAC)

Becouse it is test I set up both "clones" becouse I'm not sure about range of 5,0GHz so I will choose that one which will work.

I don't know how to format it :/

Who is online

Users browsing this forum: Bing [Bot] and 77 guests