I am shipping some WAP ACs to an office and I’d like to remote into their LAN and configure them from the LAN side. Unfortunately since the WAP AC ships with only wireless config possible, I wanted to know what the easiest way to reset the unit for LAN configuration is.
My current thought is to have them connect to the wifi and disable all the firewall rules through a web browser. Is this enough to permit LAN configuration, or do I need to have them change MAC server and discovery interfaces too? Will there be any IP conflict with the default IP? The fewer steps the better .
I’m not sure I understand the question but … I would suggest that you blank them out and only activate Romon (with a password). Of course, same has to be applied to your router at the remote location. You can then use Romon to winbox into your wap ac s at the remote location. Of course, they have to be plugged into the main router and powered.
Sent from my cell phone via Tapatalk. Sorry for the errors.
The issue is I’m sending them direct from a distributor, so they have the stock Mikrotik configuration, I won’t have a chance to edit it myself. So the people in the office need instructions from me to reset it in the simplest way so I can access it from the LAN port when they plug it in. I think all I need to do is remove the DROP firewall rules from the default config and then look for the IP in the DHCP table on the network.
I see. You’ll still need someone that is tech-litterate to do anything. Show them how to refuse the default config at first startup with WBox then have them copy-paste your romon commands. Again, I’m not familiar w WAP ac’s default config, but if ether1 is LAN, you’ll have a dhcp server on the LAN… Bad!!! If it’s WAN well yes, you could disable the FW rules but that is more error prone for a newby. I think my suggestion is simpler and faster.
Sent from my cell phone via Tapatalk. Sorry for the errors.
That’s the issue with the default config - it blocks all LAN access, or I would just remote desktop in and do it myself. I ended up backing up and resetting one of my own units and confirmed disabling the firewall rules is enough to allow access via LAN.