Note: This document was a 'living' document during the planning phase, and as such was never quite up to date. And so far it has not been updated to reflect the final outcome on the installation day. However we're leaving it here in this state to serve as a guide for the next install and/or interested readers. Please don't mistake it as "The whole truth and nothing but the truth.".
This document is a central planning document for the Golden Villa installation day. The address is
http://maps.google.com/maps?q=3385%20Elm%20St%2C%20san%20diego%2C%20ca and the start time is 10am.
The installation has four parts:
Below are the details for each part of the installation.
The main AP will be located on the peak of the roof which contains the office. The AP will be mounted directly on the wall and the antenna will be in a short pole screwed directly onto the roof peak. A supplied Cat-5 cable will run down the roof and through a new hole into the office where it will be connected to a router which will split the cable internet between the office network and wireless network.
The network configuration is detailed here and there is a separate step by step covering the m0n0wall configuration and Netgate HS3000 AP configuration.
The following equipment has been purchased for the installation:
Netgate HS3000 which includes a 50 ft outdoor cat-5 cable
SuperPass 8dBi 10 degree downtilt omni
Hyperlinktech Lightning Protector
Soekris 4501 in case with m0n0wall
Purchase a drill bit to put the cable through the office wall
Purchase sealant to fill the hole after we put the cable through
Solve the problem of extending the ethernet cable if necessary.
Configure the MikroTik
Configure the AP
The second wireless AP will be mounted at the other end of the complex. It will operate in repeater mode.
The following equipment has been purchased for the installation:
We will receive 6 computers running fresh installations of either Win2k or WinXP, complete with keyboard, mouse and monitors. They need to be hooked together into a switch with a D-Link kit which will get the signal from the main AP.
The following equipment has been purchased for the installation:
D-Link Bridge Kit to hook up the lab to the network
Cat-5 cables
Need an 8 port hub
Need a few power strips
Pick up the donated computers
The following equipment has been purchased for the installation:
Eight D-Link Kits - already programmed for socalfreenet.org (thanks John Kim!)
Ground lug
"U" clamps and matching wood screww
Radiator clamps
Here is a brief description of how we configured the two Netgate HS3000 250mW APs we're using at Golden Villas.
Setup is very much like configuring any AP, but with one twist - adding the WDS (Wireless Distribution System) setup. The basic steps are:
At this point we stopped to check that everything was working ok via wireless. Note that the AP resets between almost any setting change, so there is a pause and lost connection during this period.
Next we configured the LAN settings to match the network design, as follows:
At this point, of course, you need to switch the computer IP used. We actually plugged into the previously configured m0n0wall box and connected wirelessly. The m0n0wall gave us an IP and after going through the captive portal we could surf the net as hoped.
The last step was to turn on WDS support. The HS3000 requires that both "master" and "repeater" be set to point to each other. A convenient way to get the required MAC addresses is to use the Wireless Site Survey link, assuming both radios are on. Of course there are also stickers on the metal case and on the box they came in.
Now you're ready to test. This turned out to be a little tricky. Most client software doesn't give you any control over which AP you connect to and may even ping-pong between APs. So not only is hard to force the client to use a particular AP (e.g. the repeater instead of the master), most software won't even tell you the MAC address of the AP you're connected with. Before we worked out the test technique below we saw a lot of strange behaviour. Very slow links, dropped packets etc.
Skipping to what worked, we turned on the master AP but left the antenna disconnected (key step!). A few feet away we put the 2nd 'repeater' AP with its 8dBi omni connected. Then we took a laptop a few rooms away - i.e. far enough for the master to be too weak, but a good signal from the repeater was available. (This proved much better than our first approach of leaving both antennas on and taking the repeater AP a few rooms away.
It was interesting to start a ping to both radios and watch the results. From two separate pings to 10.12.11.130 and 10.12.11.131 the ping time for the connected radio was 1-2ms and double that for the other. As we walked away with the laptop and the client software switched from the master AP to the repeater, the pings first started timing out and then the times reversed with the shorter time for the repeater.
After the above we were satisfied that we had the network ready to install. Phew!
Here are the steps taken to program monowall for use at Golden Villas apartments with a Soekris 4501 box. Read the Network Configuration in conjunction with this guide.
The latest version of m0n0wall available was used, 1.2b3. It was configured as follows.
That's the important settings completed. Everything should basically work at this point and its worth stopping to make sure.
We want to keep the LAN completely firewalled from the WLAN so we need some rules to ensure that it is:
Unfortunately now we can't admin the firewall via wireless on the WLAN, so we add another rule. We make this rule very specific:
At this point it shold now be possible to access https://10.12.11.1 from a client on the WLAN port (i.e. a wireless client once WLAN is connected to an AP).
Some more settings will complete the configuration:
That's it! Save the configuration just to be safe (under Diagnostices -> Backup/Restore).