Hello everyone,
I am having issue with this capsman setup.
CAP server (main router Hap AC), caps - hap ac lite. powered by POE.
all devices have no issue with power, no restart cause power issue or else.
3 caps at the beginning - middle and - the end of the floor.
network 192.168.1.0 staff, no dhcp server.
network 192.168.100.0 guest wifi, with dhcp server
The issue is that wifi is dropping. For 3-5 minutes wifi disappear, clients (tv, phones)
cannot connect. After few minutes all done - they are connected and everythink works.
A lot of dhcp messages like:
16:30:50 dhcp,info dhcp1 deassigned 192.168.100.126 for 64:D8:1B:18:AE:51
16:30:50 dhcp,info dhcp1 assigned 192.168.100.126 for 64:D8:1B:18:AE:51
16:42:46 dhcp,info dhcp1 deassigned 192.168.100.166 for 64:D8:1B:31:4A:73
16:42:46 dhcp,info dhcp1 assigned 192.168.100.166 for 64:D8:1B:31:4A:73
16:44:01 dhcp,info dhcp1 deassigned 192.168.100.101 for 64:D8:1B:31:4C:35
16:44:01 dhcp,info dhcp1 assigned 192.168.100.101 for 64:D8:1B:31:4C:35
16:48:39 dhcp,info dhcp1 deassigned 192.168.100.112 for 64:D8:1B:31:50:D7
16:48:39 dhcp,info dhcp1 assigned 192.168.100.112 for 64:D8:1B:31:50:D7
What is wrong my config?
I try to have stable 2.4 GHz and 5 GHz connections, speed is not important (for example 200mbsp connection, 30-40 is enough)
Can you help me with caps and network settings?
Some TV's one time see 2.4 network, sometimes only 5 GHz network.
Thanks in advance!
this hap ac config:
# 2024-11-14 19:02:52 by RouterOS 7.16.1
# software id = LI54-CF11
#
# model = RBD52G-5HacD2HnD
# serial number = HFK...
/caps-man channel
add band=5ghz-n/ac control-channel-width=20mhz extension-channel=Ce \
frequency=5180,5220,5260,5300,5500,5540,5580,5620 name=5
add band=2ghz-g/n control-channel-width=20mhz extension-channel=disabled \
frequency=2412,2437,2462 name=2.4
/caps-man configuration
add country=bulgaria distance=indoors installation=any mode=ap name=2.4 ssid=\
MyNet
add country=bulgaria distance=indoors installation=any mode=ap name=5 ssid=\
MyNet-ac
/interface bridge
add admin-mac=78:9A:18:F5:5A:16 auto-mac=no comment=defconf name=bridge
/interface wireless
# managed by CAPsMAN
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
distance=indoors frequency=auto installation=indoor mode=ap-bridge ssid=\
MikroTik-F55A1A wireless-protocol=802.11
# managed by CAPsMAN
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-XXXX distance=indoors frequency=auto installation=indoor \
mode=ap-bridge ssid=MikroTik-F55A1A wireless-protocol=802.11
/caps-man datapath
add bridge=bridge client-to-client-forwarding=no local-forwarding=no name=\
datapath1
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
name=security1
/caps-man interface
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FB:3F master-interface=none name=cap11-2.4 radio-mac=\
78:9A:18:5E:FB:3F radio-name=789A185EFB3F security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FB:3E master-interface=none name=cap11-5 radio-mac=\
78:9A:18:5E:FB:3E radio-name=789A185EFB3E security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:73:66:F3 master-interface=none name=cap12-2.4 radio-mac=\
64:D1:54:73:66:F3 radio-name=64D1547366F3 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:73:66:F2 master-interface=none name=cap12-5 radio-mac=\
64:D1:54:73:66:F2 radio-name=64D1547366F2 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:69:66:DD master-interface=none name=cap13-2.4 radio-mac=\
64:D1:54:69:66:DD radio-name=64D1546966DD security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:69:66:DC master-interface=none name=cap13-5 radio-mac=\
64:D1:54:69:66:DC radio-name=64D1546966DC security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EB:AD master-interface=none name=cap14-2.4 radio-mac=\
78:9A:18:60:EB:AD radio-name=789A1860EBAD security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EB:AC master-interface=none name=cap14-5 radio-mac=\
78:9A:18:60:EB:AC radio-name=789A1860EBAC security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:77:8E:F8 master-interface=none name=cap15-2.4 radio-mac=\
64:D1:54:77:8E:F8 radio-name=64D154778EF8 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:77:8E:F7 master-interface=none name=cap15-5 radio-mac=\
64:D1:54:77:8E:F7 radio-name=64D154778EF7 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:69:0B:58 master-interface=none name=cap16-2.4 radio-mac=\
64:D1:54:69:0B:58 radio-name=64D154690B58 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:69:0B:57 master-interface=none name=cap16-5 radio-mac=\
64:D1:54:69:0B:57 radio-name=64D154690B57 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EB:BB master-interface=none name=cap17-2.4 radio-mac=\
78:9A:18:60:EB:BB radio-name=789A1860EBBB security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EB:BA master-interface=none name=cap17-5 radio-mac=\
78:9A:18:60:EB:BA radio-name=789A1860EBBA security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:77:8E:F1 master-interface=none name=cap18-2.4 radio-mac=\
64:D1:54:77:8E:F1 radio-name=64D154778EF1 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:77:8E:F0 master-interface=none name=cap18-5 radio-mac=\
64:D1:54:77:8E:F0 radio-name=64D154778EF0 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:73:67:6A master-interface=none name=cap19-2.4 radio-mac=\
64:D1:54:73:67:6A radio-name=64D15473676A security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:73:67:69 master-interface=none name=cap19-5 radio-mac=\
64:D1:54:73:67:69 radio-name=64D154736769 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EC:05 master-interface=none name=cap20-2.4 radio-mac=\
78:9A:18:60:EC:05 radio-name=789A1860EC05 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:60:EC:04 master-interface=none name=cap20-5 radio-mac=\
78:9A:18:60:EC:04 radio-name=789A1860EC04 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:7A:3B:CA master-interface=none name=cap21-2.4 radio-mac=\
64:D1:54:7A:3B:CA radio-name=64D1547A3BCA security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
64:D1:54:7A:3B:C9 master-interface=none name=cap21-5 radio-mac=\
64:D1:54:7A:3B:C9 radio-name=64D1547A3BC9 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FC:D3 master-interface=none name=cap22-2.4 radio-mac=\
78:9A:18:5E:FC:D3 radio-name=789A185EFCD3 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FC:D2 master-interface=none name=cap22-5 radio-mac=\
78:9A:18:5E:FC:D2 radio-name=789A185EFCD2 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FC:E8 master-interface=none name=cap23-2.4 radio-mac=\
78:9A:18:5E:FC:E8 radio-name=789A185EFCE8 security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FC:E7 master-interface=none name=cap23-5 radio-mac=\
78:9A:18:5E:FC:E7 radio-name=789A185EFCE7 security=security1
add configuration=2.4 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FB:8C master-interface=none name=cap24-2.4 radio-mac=\
78:9A:18:5E:FB:8C radio-name=789A185EFB8C security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 datapath=datapath1 disabled=no l2mtu=1600 mac-address=\
78:9A:18:5E:FB:8B master-interface=none name=cap24-5 radio-mac=\
78:9A:18:5E:FB:8B radio-name=789A185EFB8B security=security1
add configuration=2.4 configuration.multicast-helper=full datapath=datapath1 \
disabled=yes l2mtu=1600 mac-address=78:9A:18:F5:5A:1A master-interface=\
none name=hapac-2.4 radio-mac=78:9A:18:F5:5A:1A radio-name=789A18F55A1A \
security=security1
add channel=5 channel.frequency=5180,5220,5260,5300,5500,5540,5580,5620 \
configuration=5 configuration.multicast-helper=full datapath=datapath1 \
disabled=yes l2mtu=1600 mac-address=78:9A:18:F5:5A:1B master-interface=\
none name=hapac-5 radio-mac=78:9A:18:F5:5A:1B radio-name=789A18F55A1B \
security=security1
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk comment=defconf \
disable-pmkid=yes mode=dynamic-keys supplicant-identity=MikroTik
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
add name=dhcp_pool1 ranges=192.168.100.51-192.168.100.199
/ip dhcp-server
add address-pool=dhcp_pool1 interface=bridge name=dhcp1
/queue simple
add disabled=yes name=queue1 target=""
add disabled=yes max-limit=2M/2M name=tec target=192.168.1.9/32
add disabled=yes limit-at=2M/2M max-limit=5M/5M name=Client_C target=\
192.168.1.9/32
add max-limit=999M/999M name="ALL Bandwith" queue=\
pcq-upload-default/pcq-download-default target=192.168.100.0/24
add max-limit=2M/2M name=reception parent="ALL Bandwith" queue=\
pcq-upload-default/pcq-download-default target=192.168.1.9/32
/caps-man access-list
add allow-signal-out-of-range=10s disabled=no mac-address=7A:E9:BD:EE:B3:B1 \
ssid-regexp=""
add action=reject disabled=no interface=all signal-range=-120..-65
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes
/caps-man provisioning
add action=create-disabled hw-supported-modes=gn master-configuration=2.4 \
name-format=prefix-identity name-prefix=2.4
add action=create-disabled hw-supported-modes=ac master-configuration=5 \
name-format=prefix-identity name-prefix=5
/disk settings
set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
add bridge=bridge comment=defconf interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface wireless cap
#
set caps-man-addresses=127.0.0.1 enabled=yes interfaces=wlan1,wlan2
/ip address
add address=192.168.100.1/24 comment=defconf interface=bridge network=\
192.168.100.0
add address=192.168.1.1/24 interface=bridge network=192.168.1.0
/ip cloud
set ddns-enabled=yes ddns-update-interval=1h
/ip dhcp-client
add comment=defconf interface=ether1
/ip dhcp-server lease
add address=192.168.100.185 client-id=1:12:c6:97:41:47:a3 mac-address=\
12:C6:97:41:47:A3 server=dhcp1
/ip dhcp-server network
add address=192.168.100.0/24 comment=defconf dns-server=192.168.100.1,8.8.8.8 \
gateway=192.168.100.1
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan type=A
/ip firewall address-list
add address=IP_IP list=my
add address=IP_IP list=my
add address=IP_IP comment=test1 list=my
add address=IP_IP comment=test1 list=my
/ip firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
"defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=accept chain=input comment="winbox enable" dst-port=8291 protocol=\
tcp src-address-list=my
add action=accept chain=input comment="winbox enable" dst-port=8443 protocol=\
tcp
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
/ip firewall mangle
add action=mark-packet chain=forward disabled=yes new-packet-mark=\
Client1_Packet passthrough=no src-address=192.168.1.15
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat comment="truenas www access" dst-port=40015 \
in-interface-list=WAN protocol=tcp to-addresses=192.168.100.15 to-ports=\
28291
add action=dst-nat chain=dstnat comment="cap winbox" dst-port=18888 \
in-interface-list=WAN protocol=tcp to-addresses=192.168.1.4 to-ports=80
add action=dst-nat chain=dstnat comment="Server RDP" dst-port=13389 \
in-interface-list=WAN protocol=tcp src-address-list=my to-addresses=\
192.168.1.7 to-ports=3389
add action=dst-nat chain=dstnat comment=Video dst-port=8088 \
in-interface-list=WAN protocol=tcp to-addresses=192.168.1.8 to-ports=80
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip service
set www disabled=yes port=8888
set www-ssl certificate=my-rtr disabled=no port=8443
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\
icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" \
dst-port=33434-33534 protocol=udp
add action=accept chain=input comment=\
"defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
ipsec-esp
add action=accept chain=input comment=\
"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment=\
"defconf: drop everything else not coming from LAN" in-interface-list=\
!LAN
add action=accept chain=forward comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment=\
"defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=\
500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
ipsec-esp
add action=accept chain=forward comment=\
"defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
"defconf: drop everything else not coming from LAN" in-interface-list=\
!LAN
/system clock
set time-zone-name=Europe/Sofia
/system identity
set name="HAP AC"
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=europe.pool.ntp.org
add address=pool.ntp.org
/tool graphing interface
add interface=ether1
add interface=bridge
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
