AX AP & CAPsMAN V2 Dynamic WIFI interfaces

Recently two AX AP's added to my network. Found out that CAPsMAN V2 is required, configured (initially on the same CAPsMAN V1 machine but later on a different machine) the CAPsMAN V2, connect the AX devices and all work fine, almost ........ When I provision the AX AP's new WiFi interfaces are assigned but they are not automatically added to the bridge for some reason. I need to manually added them to the bridge. This is not the correct way of course.

In the new OS release, I read the following:

Changelog van V7.23
*) bridge - fixed dynamic VLAN update for WiFi interfaces;
*) wifi - improved interface provisioning for WiFi 7 access points;
*) wifi - improved on-capsman traffic processing;

I tried the new firmware but this doesn't solve the problem. Any suggestion on how to address this? How to solve this?

My current CAPsMAN v2 config:

/caps-man channel
add band=2ghz-onlyn control-channel-width=20mhz frequency=2412,2437,2462
name=2.4Ghz-Channels skip-dfs-channels=yes
add band=5ghz-onlyac control-channel-width=20mhz frequency=
5180,5200,5220,5240 name=5Ghz-Channels skip-dfs-channels=yes
add band=2ghz-onlyn control-channel-width=20mhz frequency=2412 name=
2.4Ghz-Channel-1 skip-dfs-channels=yes tx-power=12
add band=2ghz-onlyn control-channel-width=20mhz frequency=2437 name=
2.4Ghz-Channel-6 skip-dfs-channels=yes tx-power=12
add band=2ghz-onlyn control-channel-width=20mhz frequency=2462 name=
2.4Ghz-Channel-11 skip-dfs-channels=yes tx-power=12
add band=5ghz-onlyac control-channel-width=20mhz frequency=5180 name=
5Ghz-Channel-1 skip-dfs-channels=yes tx-power=30
add band=5ghz-onlyac control-channel-width=20mhz frequency=5200 name=
5Ghz-Channel-2 skip-dfs-channels=yes tx-power=30
add band=5ghz-onlyac control-channel-width=20mhz frequency=5220 name=
5Ghz-Channel-3 skip-dfs-channels=yes tx-power=30
add band=5ghz-onlyac control-channel-width=20mhz frequency=5240 name=
5Ghz-Channel-4 skip-dfs-channels=yes tx-power=30
add band=5ghz-onlyac control-channel-width=20mhz frequency=5825 name=
5Ghz-Channel-5 skip-dfs-channels=yes tx-power=30
/interface bridge
add name=bridge-lan port-cost-mode=short vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] name=ether1-UplinkToRouter
set [ find default-name=ether5 ] comment="Camera Managent Poort" name=
ether5-CAMManagement
set [ find default-name=sfp1 ] advertise=
10M-baseT-half,10M-baseT-full,100M-baseT-half,100M-baseT-full
/interface vlan
add interface=bridge-lan name=vlan10-Management vlan-id=10
add interface=bridge-lan name=vlan101-Wifi-Haven-Gasten vlan-id=101
add interface=bridge-lan name=vlan103-Wifi-Haven-Management vlan-id=103
add interface=bridge-lan name=vlan104-Cameras vlan-id=104
add interface=bridge-lan name=vlan105-Restaurant vlan-id=105
add interface=bridge-lan name=vlan106-Havenkantoor vlan-id=106
/caps-man datapath
add bridge=bridge-lan local-forwarding=yes name=datapath101 vlan-id=101
vlan-mode=use-tag
add bridge=bridge-lan local-forwarding=yes name=datapath103 vlan-id=103
vlan-mode=use-tag
/caps-man configuration
add channel=5Ghz-Channels country=netherlands datapath=datapath101
installation=any mode=ap name=WiFi-5Ghz-Gast ssid=WiFi
add channel=5Ghz-Channel-1 country=netherlands datapath=datapath101
installation=any mode=ap name=WiFi-5Ghz-Gast-1 ssid=WiFi
add channel=5Ghz-Channel-2 country=netherlands datapath=datapath101
installation=any mode=ap name=WiFi-5Ghz-Gast-2 ssid=WiFi
add channel=5Ghz-Channel-3 country=netherlands datapath=datapath101
installation=any mode=ap name=WiFi-5Ghz-Gast-3 ssid=WiFi
add channel=2.4Ghz-Channels country=netherlands datapath=datapath101
installation=outdoor mode=ap name=WiFi-2.4Ghz-Gast ssid=WiFi
add channel=5Ghz-Channel-4 country=netherlands datapath=datapath101
installation=any mode=ap name=WiFi-5Ghz-Gast-4 ssid=WiFi
/caps-man interface
add configuration=WiFi-5Ghz-Gast-3 disabled=no l2mtu=1600 mac-address=
2C:C8:1B:5B:6F:B7 master-interface=none name=WF21-Restaurant_GRP1-1
radio-mac=2C:C8:1B:5B:6F:B7 radio-name=2CC81B5B6FB7
/caps-man rates
add basic=12Mbps comment=2.4Ghz name=2.4Ghz supported=
6Mbps,9Mbps,12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps
/caps-man configuration
add channel=2.4Ghz-Channel-1 country=netherlands datapath=datapath101
installation=outdoor name=WiFi-2.4Ghz-Gast-Channel-1 rates=2.4Ghz
ssid=WiFi
add channel=2.4Ghz-Channel-6 country=netherlands datapath=datapath101
installation=outdoor mode=ap name=WiFi-2.4Ghz-Gast-Channel-6 rates=
2.4Ghz ssid=WiFi
add channel=2.4Ghz-Channel-11 country=netherlands datapath=datapath101
installation=outdoor mode=ap name=WiFi-2.4Ghz-Gast-Channel-11 rates=
2.4Ghz ssid=WiFi
/caps-man interface
add configuration=WiFi-2.4Ghz-Gast-Channel-11 disabled=no l2mtu=1600
mac-address=2C:C8:1B:5B:6F:B6 master-interface=none name=
WF21-Restaurant_GRP1-2 radio-mac=2C:C8:1B:5B:6F:B6 radio-name=
2CC81B5B6FB6
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm name=WiFi-Beheer
/caps-man configuration
add channel=2.4Ghz-Channel-1 country=netherlands datapath=datapath103
installation=outdoor load-balancing-group="" mode=ap name=
WiFi-2.4Ghz-Beheer-Channel-1 rates=2.4Ghz security=WiFi-Beheer
ssid=WiFi-Beheer
add channel=5Ghz-Channels country=netherlands datapath=datapath103
installation=any mode=ap name=WiFi-5Ghz-Beheer security=
WiFi-Beheer ssid=WiFi-Beheer
add channel=2.4Ghz-Channel-6 country=netherlands datapath=datapath103
installation=outdoor mode=ap name=WiFi-2.4Ghz-Beheer-Channel-6
rates=2.4Ghz security=WiFi-Beheer ssid=WiFi-Beheer
add channel=2.4Ghz-Channel-11 country=netherlands datapath=datapath103
installation=outdoor mode=ap name=WiFi-2.4Ghz-Beheer-Channel-11
rates=2.4Ghz security=WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-1 country=netherlands datapath=datapath103
installation=any mode=ap name=WiFi-5Ghz-Beheer-1 security=
WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-2 country=netherlands datapath=datapath103
installation=any mode=ap name=WiFi-5Ghz-Beheer-2 security=
WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-3 country=netherlands datapath=datapath103
installation=any mode=ap name=WiFi-5Ghz-Beheer-3 security=
WiFi-Beheer ssid=WiFi-Beheer
add channel=2.4Ghz-Channels country=netherlands datapath=datapath103
installation=outdoor mode=ap name=WiFi-2.4Ghz-Beheer security=
WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-4 country=netherlands datapath=datapath103
installation=any mode=ap name=WiFi-5Ghz-Beheer-4 security=
WiFi-Beheer ssid=WiFi-Beheer
/caps-man interface
add configuration=WiFi-5Ghz-Beheer-3 disabled=no l2mtu=1600 mac-address=
2E:C8:1B:5B:6F:B7 master-interface=WF21-Restaurant_GRP1-1 name=
WF21-Restaurant_GRP1-1-1 radio-mac=00:00:00:00:00:00 radio-name=
2EC81B5B6FB7
add configuration=WiFi-2.4Ghz-Beheer-Channel-11 disabled=no l2mtu=1600
mac-address=2E:C8:1B:5B:6F:B6 master-interface=WF21-Restaurant_GRP1-2
name=WF21-Restaurant_GRP1-2-1 radio-mac=00:00:00:00:00:00 radio-name=
2EC81B5B6FB6
/interface wifi channel
add band=5ghz-ax disabled=no frequency=5500 name=5Ghz-Channel-1 width=20mhz
add band=5ghz-ax disabled=no frequency=5520 name=5Ghz-Channel-2
skip-dfs-channels=10min-cac width=20mhz
add band=5ghz-ax disabled=no frequency=5560 name=5Ghz-Channel-4
skip-dfs-channels=10min-cac width=20mhz
add band=2ghz-ax disabled=no frequency=2412 name=2.4Ghz-Channel-1 width=20mhz
add band=2ghz-ax deprioritize-unii-3-4=no disabled=no frequency=2437 name=
2.4Ghz-Channel-6 width=20mhz
add band=2ghz-ax disabled=no frequency=2462 name=2.4Ghz-Channel-11 width=
20mhz
add band=5ghz-ax disabled=no frequency=5540 name=5Ghz-Channel-3
skip-dfs-channels=all width=20mhz
add band=5ghz-ax disabled=no frequency=5580 name=5Ghz-Channel-5
skip-dfs-channels=10min-cac width=20mhz
/interface wifi datapath
add bridge=bridge-lan client-isolation=yes disabled=no name=datapath101
vlan-id=101
add bridge=bridge-lan disabled=no name=datapath103 vlan-id=103
/interface wifi configuration
add channel=2.4Ghz-Channel-1 channel.deprioritize-unii-3-4=no country=
Netherlands datapath=datapath101 disabled=no installation=outdoor mode=ap
name=WiFi-2.4Ghz-Gast-Channel-1 ssid=WiFi
add channel=5Ghz-Channel-1 country=Netherlands datapath=datapath101 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Gast-Channel-1 ssid=
WiFi
add channel=2.4Ghz-Channel-6 channel.deprioritize-unii-3-4=no country=
Netherlands datapath=datapath101 disabled=no installation=outdoor mode=ap
name=WiFi-2.4Ghz-Gast-Channel-2 ssid=WiFi
add channel=2.4Ghz-Channel-11 channel.deprioritize-unii-3-4=no country=
Netherlands datapath=datapath101 disabled=no installation=outdoor mode=ap
name=WiFi-2.4Ghz-Gast-Channel-3 ssid=WiFi
add channel=5Ghz-Channel-2 country=Netherlands datapath=datapath101 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Gast-Channel-2 ssid=
WiFi
add channel=5Ghz-Channel-3 country=Netherlands datapath=datapath101 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Gast-Channel-3 ssid=
WiFi
add channel=5Ghz-Channel-4 country=Netherlands datapath=datapath101 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Gast-Channel-4 ssid=
WiFi
add channel=5Ghz-Channel-5 country=Netherlands datapath=datapath101 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Gast-Channel-5 ssid=
WiFi
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=ccmp,gcmp
ft=no ft-over-ds=no name=WiFi-Beheer
/interface wifi configuration
add channel=2.4Ghz-Channel-1 country=Netherlands datapath=datapath103
disabled=no installation=outdoor mode=ap name=
WiFi-2.4Ghz-Beheer-Channel-1 security=WiFi-Beheer ssid=
WiFi-Beheer
add channel=5Ghz-Channel-1 country=Netherlands datapath=datapath103 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Beheer-Channel-1
security=WiFi-Beheer ssid=WiFi-Beheer
add channel=2.4Ghz-Channel-6 country=Netherlands datapath=datapath103
disabled=no installation=outdoor mode=ap name=
WiFi-2.4Ghz-Beheer-Channel-2 security=WiFi-Beheer ssid=
WiFi-Beheer
add channel=2.4Ghz-Channel-11 country=Netherlands datapath=datapath103
disabled=no installation=outdoor mode=ap name=
WiFi-2.4Ghz-Beheer-Channel-3 security=WiFi-Beheer ssid=
WiFi-Beheer
add channel=5Ghz-Channel-2 country=Netherlands datapath=datapath103 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Beheer-Channel-2
security=WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-3 country=Netherlands datapath=datapath103 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Beheer-Channel-3
security=WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-4 country=Netherlands datapath=datapath103 disabled=
no installation=outdoor mode=ap name=WiFi-5Ghz-Beheer-Channel-4
security=WiFi-Beheer ssid=WiFi-Beheer
add channel=5Ghz-Channel-5 channel.deprioritize-unii-3-4=no country=
Netherlands datapath=datapath103 disabled=no installation=outdoor mode=ap
name=WiFi-5Ghz-Beheer-Channel-5 security=WiFi-Beheer ssid=
WiFi-Beheer
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/caps-man access-list
add action=accept allow-signal-out-of-range=always disabled=no signal-range=
-75..120
add action=reject allow-signal-out-of-range=10s disabled=no signal-range=
-120..-76
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled comment="==>> 2.4Ghz WIFI Config - Groep1"
hw-supported-modes=gn identity-regexp="._(GRP1)$" master-configuration=
WiFi-2.4Ghz-Gast-Channel-1 name-format=identity
slave-configurations=WiFi-2.4Ghz-Beheer-Channel-1
add action=create-dynamic-enabled comment="==>> 2.4Ghz WIFI Config - Groep2"
hw-supported-modes=gn identity-regexp=".(GRP2)$" master-configuration=
WiFi-2.4Ghz-Gast-Channel-6 name-format=identity
slave-configurations=WiFi-2.4Ghz-Beheer-Channel-6
add action=create-dynamic-enabled comment="==>> 2.4Ghz WIFI Config - Groep3"
hw-supported-modes=gn identity-regexp=".*
(GRP3)$" master-configuration=
WiFi-2.4Ghz-Gast-Channel-11 name-format=identity
slave-configurations=WiFi-2.4Ghz-Beheer-Channel-11
add action=create-dynamic-enabled comment="==>> 5Ghz WIFI Config - Groep1"
hw-supported-modes=ac identity-regexp="._(GRP1)$" master-configuration=
WiFi-5Ghz-Gast-1 name-format=identity slave-configurations=
WiFi-5Ghz-Beheer-1
add action=create-dynamic-enabled comment="==>> 5Ghz WIFI Config - Groep2"
hw-supported-modes=ac identity-regexp=".(GRP2)$" master-configuration=
WiFi-5Ghz-Gast-2 name-format=identity slave-configurations=
WiFi-5Ghz-Beheer-2
add action=create-dynamic-enabled comment="==>> 5Ghz WIFI Config - Groep3"
hw-supported-modes=ac identity-regexp=".*
(GRP3)$" master-configuration=
WiFi-5Ghz-Gast-3 name-format=identity slave-configurations=
WiFi-5Ghz-Beheer-3
add action=create-dynamic-enabled comment="==>> 5Ghz WIFI Config - Groep4"
hw-supported-modes=ac identity-regexp="._(GRP4)$" master-configuration=
WiFi-5Ghz-Gast-4 name-format=identity slave-configurations=
WiFi-5Ghz-Beheer-4
/interface bridge port
add bridge=bridge-lan interface=ether1-UplinkToRouter internal-path-cost=10
path-cost=10
add bridge=bridge-lan frame-types=admit-only-untagged-and-priority-tagged
interface=ether5-CAMManagement internal-path-cost=10 path-cost=10 pvid=
104
add bridge=bridge-lan interface=ether2 internal-path-cost=10 path-cost=10
add bridge=bridge-lan interface=ether3 internal-path-cost=10 path-cost=10
add bridge=bridge-lan interface=ether4 internal-path-cost=10 path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ipv6 settings
set disable-ipv6=yes
/interface bridge vlan
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter untagged=
ether5-CAMManagement vlan-ids=10
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter vlan-ids=101
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter vlan-ids=103
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter vlan-ids=104
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter vlan-ids=105
add bridge=bridge-lan tagged=bridge-lan,ether1-UplinkToRouter vlan-ids=106
/interface ovpn-server server
add mac-address=FE:06:B5:FF:1C:D9 name=ovpn-server1
/interface wifi access-list
add action=accept allow-signal-out-of-range=always disabled=yes interface=any
signal-range=-75..120
add action=reject allow-signal-out-of-range=10s disabled=yes interface=any
signal-range=-120..-76
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes interfaces=
vlan10-Management upgrade-policy=none
/interface wifi provisioning
add action=create-dynamic-enabled comment="==>> 5 Ghz WIFI Config - Groep1"
disabled=no identity-regexp=".(GRP1)$" master-configuration=
WiFi-5Ghz-Gast-Channel-1 name-format=5Ghz
%I slave-configurations=
WiFi-5Ghz-Beheer-Channel-1 slave-name-format=5Ghz_%I_
supported-bands=5ghz-ax,5ghz-ac,5ghz-n
add action=create-dynamic-enabled comment="==>> 5 Ghz WIFI Config - Groep3"
disabled=no identity-regexp=".(GRP3)$" master-configuration=
WiFi-5Ghz-Gast-Channel-3 name-format=%I slave-configurations=
WiFi-5Ghz-Beheer-Channel-3 slave-name-format=%I
supported-bands=
5ghz-ax
add action=create-dynamic-enabled comment="==>> 5 Ghz WIFI Config - Groep4"
disabled=no identity-regexp=".(GRP4)$" master-configuration=
WiFi-5Ghz-Gast-Channel-4 name-format=%I slave-configurations=
WiFi-5Ghz-Beheer-Channel-4 slave-name-format=%I
supported-bands=
5ghz-ax
add action=create-dynamic-enabled comment="==>> 5 Ghz WIFI Config - Groep2"
disabled=no identity-regexp=".(GRP2)$" master-configuration=
WiFi-5Ghz-Gast-Channel-2 name-format=%I slave-configurations=
WiFi-5Ghz-Beheer-Channel-2 slave-name-format=%I
supported-bands=
5ghz-ax
add action=create-dynamic-enabled comment="==>> 2.4 Ghz WIFI Config - Groep1"
common-name-regexp="" disabled=no identity-regexp=".(GRP1)$"
master-configuration=WiFi-2.4Ghz-Gast-Channel-1 name-format=
2.4Ghz
%I slave-configurations=WiFi-2.4Ghz-Beheer-Channel-1
slave-name-format=2.4Ghz_%I_ supported-bands=2ghz-ax,2ghz-g,2ghz-n
add action=create-dynamic-enabled comment="==>> 2.4 Ghz WIFI Config - Groep2"
common-name-regexp="" disabled=no identity-regexp=".(GRP2)$"
master-configuration=WiFi-2.4Ghz-Gast-Channel-2 name-format=%I
slave-configurations=WiFi-2.4Ghz-Beheer-Channel-2 slave-name-format=
%I
supported-bands=2ghz-ax
add action=create-dynamic-enabled comment="==>> 2.4 Ghz WIFI Config - Groep3"
common-name-regexp="" disabled=no identity-regexp=".(GRP3)$"
master-configuration=WiFi-2.4Ghz-Gast-Channel-3 name-format=%I
slave-configurations=WiFi-2.4Ghz-Beheer-Channel-3 slave-name-format=
%I
supported-bands=2ghz-ax
/ip address
add address=172.x.x.x/24 interface=vlan10-Management network=172.x.x.x
/ip dns
set servers=172.x.x.x
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip route
add dst-address=0.0.0.0/0 gateway=172.x.x.x
/system clock
set time-zone-name=Europe/Amsterdam
/system identity
set name=SW09-DudeServer
/system logging
add comment=CAPS topics=caps

Can you add (one of the) CAP‘s config as well?

Of course, no problem, see below. Your support is appreciated.

[admin@WF22-B-Midden_GRP1] > /export

2026-06-08 10:49:11 by RouterOS 7.23.1

model = L23UGSR-5HaxD2HaxD

/interface bridge
add admin-mac=D0:EA:XX:XX:XX:XX auto-mac=no comment=defconf frame-types=admit-only-vlan-tagged name=bridge-lan vlan-filtering=yes
/interface wifi

managed by CAPsMAN 18:FD:XX:XX:XX:XX%vlan10-management, traffic processing on CAP

mode: AP, SSID: WiFi, channel: 2412/ax

set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap datapath.vlan-id=101 disabled=no

managed by CAPsMAN 18:XX:XX:XX:XX:XX%vlan10-management, traffic processing on CAP

mode: AP, SSID: WiFi, channel: 5500/ax/D

set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap datapath.vlan-id=101 disabled=no
/interface ethernet
set [ find default-name=ether1 ] name=ether1-Uplink
/interface vlan
add interface=bridge-lan name=vlan10-management vlan-id=10
/interface wifi datapath
add bridge=bridge-lan comment=defconf disabled=yes name=capdp
/interface bridge port
add bridge=bridge-lan comment=defconf interface=ether1-Uplink
add bridge=bridge-lan interface=wifi1
add bridge=bridge-lan interface=wifi2
add bridge=bridge-lan interface=*153
add bridge=bridge-lan interface=*154
/interface bridge vlan
add bridge=bridge-lan tagged=bridge-lan,ether1-Uplink,wifi1,wifi2,*153,*154 vlan-ids=10,101,103
/interface wifi cap
set caps-man-addresses=172.XX.XX.XX certificate=request discovery-interfaces=vlan10-management enabled=yes
/ip address
add address=172.XX.XX.XX/24 interface=vlan10-management network=172.XX.XX.XX
/ip dns
set servers=172.X.X.X
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=172.X.X.X routing-table=main
/system clock
set time-zone-name=Europe/Amsterdam
/system identity
set name=WF22-B-Midden_GRP1
/system ntp client
set enabled=yes
/system ntp client servers
add address=172.X.X.X

If there are asterisks in the config, you should remove them.
You should not set vlan id on the wifi interface, CAPsMAN will do that for you. Just set bridge.

Point #21 here:
GP & CSA (Good Practice and Common Sense Advice) for Mikrotik devices

I understand what you mean and know that CAPsMAN normaly the tagging dynamic add.
But in our case that is the issue. The tagging is not done automaticaly by mikrotik (for CAPsMAN V2 and AX AP). That is the reason we add the bridge port and bridge vlan manualy (We know that is not correct).

Where did you see the asterisks? We use the asterisks in the provision rules to group different AP's together and assign a certain channel to that group. This is the only place where we use the asterisks. Please correct me if there is another place an asterisks is used which should not be used. Thanks.

It can be found in the CAP config, two interfaces are added on the bridge.

Also in your config you should not set vlan id on the wifi interface (on the CAP).

Of course unless you have interfaces called *153 and *154.

Don’t add wifi interfaces to the bridge…at all. Just add the ether interface(s).

This is the config I use on cap with no vlans on V7.21.4 [long-term]

/interface bridge
add name=br
/interface wifi
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap
disabled=no
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap
disabled=no
/interface wifi datapath
add bridge=br disabled=no name=datapath1
/interface bridge port
add bridge=br interface=ether1
add bridge=br interface=ether2
add bridge=br interface=wifi1
add bridge=br interface=wifi2
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface wifi cap
set certificate=request discovery-interfaces=br enabled=yes lock-to-caps-man=
yes slaves-datapath=datapath1 slaves-static=yes
/ip dhcp-client
add default-route-tables=main interface=br

On RouterOS 7.20.8 with a mgmt vlan 99

/interface bridge add name=br
/interface vlan add interface=br name=vlan99-mgmt vlan-id=99
/interface wifi datapath add bridge=br disabled=no name=datapath-slave
/interface wifi
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap datapath=datapath-slave disabled=no
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap datapath=datapath-slave disabled=no
/interface bridge port add bridge=br interface=ether1
/ipv6 settings set disable-ipv6=yes
/interface wifi cap set certificate=request discovery-interfaces=br enabled=yes lock-to-caps-man=\ yes slaves-datapath=datapath-slave slaves-static=no
/ip dhcp-client add default-route-tables=main interface=vlan99-mgmt

I'm not using vlan filtering on the cap bridge

Thanks @flynno for sharing the two configs. The main difference compared to my configuration is that I've a 2nd SSID (slave wifi config) and when the CAP is provisioned the wifi interface names have changed.

In your config you have statically added the two WIFI interfaces to the bridge, this is good and works as your WIFI interface names are not changing. In my situation this doesn't work due to the changing WIFI interface names, each time a higher sequence number is added to the interface name.

Still searching for a solution. More suggestions from anyone?

Could it be that the CAPsMAN V1 and V2 are running ont he same device? Anyone having this setup running on one device as well and doesn't have any issues?

I have a live network on CAPsMAN v1 and in the datapath, I have "Local Forwarding" set to no, this does not add the wifi interfaces to any bridge on the CAP device but does on the CAPsMAN controller device

Thanks for sharing. Our 18 AP's on CAPsMAN V1 are working perfectly. The issue is on the AX AP's which require CAPsMAN V2. The AX devices simply don't work with with CAPsMAN V2. The problem is happing with the V2 CAPsMAN.

Interfaces will only be added to bridge once they enter running state (client connects)

I want to continue on this topic as I've not found a solution to the problem.

This is the starting situation, the CAP is NOT connected to the CAPsMAN V2 and only Wifi1, Wifi2 and Ether1-Uplink are added to the bridge (manually). See screenshot:

Then I switch on the CAP to be connected to the CAPsMAN V2. Everything seems to be working fine, the 4 WIFI interfaces (2x on 2.4Ghz and 2x on 5Ghz) are managed by the CAPsMAN V2.

But the to dynamic created Wifi interfaces, Wifi22 and Wifi23 are NOT added automatically to the bridge. Therefore I cannot make a Wifi connection to the "slave" SSID. Only when I manually add the two dynamic Wifi interfaces to the bridge I can make the connection.

How can this be resolved? I've searched for hours and cannot find the solution to this challenge! Suggestions? Do you need any additional config info? If so, let me know, happy to share.

On the CAPsMAN V1 it is al working fine, the dynamically created Wifi interfaces are added to the bridge automatically!

Have you tried to create a datapath for the slaves?

Thanks great suggestion, I've not tried that. But when trying to select something on the CAP the dropdown box is empty:

My CAPsMAN V2 provisioning looks like:

And also on the CAPsMAN V2 the datapath is configured as follow:

Suggestions? How to change/update the config?

Maybe you didn't create the datapath first in /interface/wifi/datapath on the cAP? That setting just points to the local bridge on the cAP.

Once it is created, you can add it to each radio in /interface/wifi and then to the slaves-datapath setting you showed in /interface/wifi/cap. That's all shown in the base config example with VLANs in the help.

Here is the cAP part of that config example:

/interface bridge
add name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
set [ find default-name=wifi1 ] configuration.manager=capsman datapath=capdp disabled=no
set [ find default-name=wifi2 ] configuration.manager=capsman datapath=capdp disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
add bridge=bridgeLocal comment=defconf interface=ether3
add bridge=bridgeLocal comment=defconf interface=ether4
add bridge=bridgeLocal comment=defconf interface=ether5
/interface wifi cap
set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp
/ip dhcp-client
add interface=bridgeLocal disabled=no

When I was getting CAPsMAN set up to work with AX devices and VLANs I basically only needed the above config on the cAP. No other wifi or bridge settings were required.

I did add DHCP-client and some other optional management related settings (logging, SNMP). That was a few revisions ago though. But I put the above config plus my changes into an .rsc, copied to a cAP reset to defaults and reset it again, running that rsc as a "run after reset" script to get it as clean as possible.

Wauw Wauw Wauw! Excellent feedback. Thanks for the explanation and support. This was the trick. I've set it up as per instructions and now dynamically the wifi interfaces are added to the bridge. Issue solved. Thanks again.