I know many topics were already open with the same issue but I haven't managed to make it work trying multiple things
hAP ax2 wifi interfaces get's "logged in" to RB5009, but the RB5009 throws an error "no connection to CAPsMAN" on those interfaces
I've put CAPsMAN to listen on vlan10_MGMT and datapath to bridge_Trunk and VLAN ID to 100 (Guest), and I've put CAP to listen on the same vlan10_MGMT, datapath to bridge without VLAN ID... and it doesn't work
Here are the configurations
CAPsMAN (RB5009) (parts ommited for better clarity)
Code: Select all
/interface bridge
add frame-types=admit-only-vlan-tagged name=bridge_Trunk protocol-mode=none vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment=MGMT
set [ find default-name=ether2 ] comment=WAN
set [ find default-name=ether3 ] comment=VoIP
set [ find default-name=ether4 ] comment=Hikvision
set [ find default-name=ether5 ] comment="Switch Arhiva (2. sprat)"
set [ find default-name=ether6 ] comment="Switch Ommited (Podrum)"
set [ find default-name=ether7 ] comment="Switch Ured (1. sprat)"
set [ find default-name=ether8 ] comment="Switch Portirnica (Prizemlje)"
set [ find default-name=sfp-sfpplus1 ] disabled=yes
/interface vlan
add interface=bridge_Trunk name=vlan10_MGMT vlan-id=10
add interface=bridge_Trunk name=vlan11_Servers vlan-id=11
add interface=bridge_Trunk name=vlan12_VoIP vlan-id=12
add interface=bridge_Trunk name=vlan13_Surveillance vlan-id=13
add interface=bridge_Trunk name=vlan14_IoT vlan-id=14
add interface=bridge_Trunk name=vlan99_ITech vlan-id=99
add interface=bridge_Trunk name=vlan100_Guest vlan-id=100
add interface=bridge_Trunk name=vlan101_Ommited vlan-id=101
add interface=bridge_Trunk name=vlan102_Mediji vlan-id=102
add interface=bridge_Trunk name=vlan103_Ommited vlan-id=103
add interface=bridge_Trunk name=vlan104_Skupstina vlan-id=104
add interface=bridge_Trunk name=vlan105_SalaZaSastanke vlan-id=105
add interface=bridge_Trunk name=vlan106_KulturnaRazmena vlan-id=106
add interface=bridge_Trunk name=vlan111_Ommited vlan-id=111
add interface=bridge_Trunk name=vlan112_Ommited vlan-id=112
add interface=bridge_Trunk name=vlan121_Ommited vlan-id=121
/interface wifi channel
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2GHz width=20mhz
add band=5ghz-ax disabled=no frequency=5180,5220,5260,5300,5500,5540,5580,5620 name=5GHz width=20/40mhz
/interface wifi datapath
add bridge=bridge_Trunk disabled=no name=Guest vlan-id=100
/interface wifi security
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes name=Guest wps=disable
/interface wifi configuration
add channel=2GHz country=Croatia datapath=Guest disabled=no manager=capsman mode=ap name=Guest2 security=Guest ssid=\
Internet
add channel=5GHz country=Croatia datapath=Guest disabled=no manager=capsman mode=ap name=Guest5 security=Guest ssid=\
Internet
/interface bridge port
add bridge=bridge_Trunk frame-types=admit-only-untagged-and-priority-tagged interface=ether1 pvid=10
add bridge=bridge_Trunk frame-types=admit-only-untagged-and-priority-tagged interface=ether3 pvid=12
add bridge=bridge_Trunk frame-types=admit-only-untagged-and-priority-tagged interface=ether4 pvid=13
add bridge=bridge_Trunk frame-types=admit-only-vlan-tagged interface=ether5
add bridge=bridge_Trunk frame-types=admit-only-vlan-tagged interface=ether6
add bridge=bridge_Trunk frame-types=admit-only-vlan-tagged interface=ether7
add bridge=bridge_Trunk frame-types=admit-only-vlan-tagged interface=ether8
/interface bridge vlan
add bridge=bridge_Trunk comment="MGMT VLAN" tagged=bridge_Trunk,ether5,ether6,ether7,ether8 untagged=ether1,ether4 \
vlan-ids=10
add bridge=bridge_Trunk comment="Servers VLAN" tagged=bridge_Trunk,ether7,ether8 vlan-ids=11
add bridge=bridge_Trunk comment="VoIP VLAN" tagged=bridge_Trunk,ether5,ether6,ether7,ether8 untagged=ether3 vlan-ids=12
add bridge=bridge_Trunk comment="Surveillance VLAN" tagged=bridge_Trunk untagged=ether4 vlan-ids=13
add bridge=bridge_Trunk comment="IoT VLAN" tagged=bridge_Trunk,ether5,ether6,ether7,ether8 vlan-ids=14
add bridge=bridge_Trunk comment="ITech VLAN" tagged=bridge_Trunk,ether7 vlan-ids=99
add bridge=bridge_Trunk comment="Guest VLAN" tagged=bridge_Trunk,ether5,ether6,ether7,ether8 vlan-ids=100
add bridge=bridge_Trunk comment="Ommited VLAN" tagged=bridge_Trunk,ether5,ether7,ether8 vlan-ids=101
add bridge=bridge_Trunk comment="Mediji VLAN" tagged=bridge_Trunk,ether8 vlan-ids=102
add bridge=bridge_Trunk comment="Ommited VLAN" tagged=bridge_Trunk,ether6,ether7 vlan-ids=103
add bridge=bridge_Trunk comment="Ommited VLAN" tagged=bridge_Trunk,ether5,ether7 vlan-ids=111
add bridge=bridge_Trunk comment="Ommited VLAN" tagged=bridge_Trunk,ether7 vlan-ids=112
add bridge=bridge_Trunk comment="Ommited VLAN" tagged=bridge_Trunk,ether8 vlan-ids=121
add bridge=bridge_Trunk comment="Skupstina VLAN" tagged=bridge_Trunk,ether8 vlan-ids=104
add bridge=bridge_Trunk comment="Sala za sastanke VLAN" tagged=bridge_Trunk,ether5 vlan-ids=105
add bridge=bridge_Trunk comment="Kulturna razmena VLAN" tagged=bridge_Trunk,ether6 vlan-ids=106
/interface wifi capsman
set ca-certificate=WiFi-CAPsMAN-CA-789A1884422D certificate=WiFi-CAPsMAN-789A1884422D enabled=yes interfaces=\
vlan10_MGMT package-path="" require-peer-certificate=no upgrade-policy=none
/interface wifi provisioning
add action=create-dynamic-enabled comment="Guest 2GHz" disabled=no master-configuration=Guest2 supported-bands=2ghz-ax
add action=create-dynamic-enabled comment="Guest 5GHz" disabled=no master-configuration=Guest5 supported-bands=5ghz-ax
Code: Select all
/interface bridge
add name=bridge protocol-mode=none
/interface vlan
add interface=bridge name=vlan10_MGMT vlan-id=10
add interface=bridge name=vlan100_Guest vlan-id=100
/interface wifi datapath
add bridge=bridge disabled=no name=datapath
/interface wifi
# managed by CAPsMAN
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap datapath=datapath
# managed by CAPsMAN
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap datapath=datapath
/interface bridge port
add bridge=bridge interface=ether1
add bridge=bridge interface=ether2
add bridge=bridge interface=ether3
add bridge=bridge interface=ether4
/interface wifi cap
set caps-man-addresses=10.1.10.1 certificate=CAP-48A98A663ECA discovery-interfaces=vlan10_MGMT enabled=yes \
slaves-datapath=datapath
/ip dhcp-client
add interface=vlan10_MGMT
/system identity
set name=MT-TEST
/system note
set show-at-login=no