Caps wireless mode

Hey there.
I have two caps, same model: RB962UiGS-5HacT2HnT
There is the same CapsMan managing them.
Why is there difference between them? One is AP BRIDGE mode, one is STATION mode. One is on auto frequency, one is on on specific frequency? They have the same provisioned settings from the capsmanager!
Thanx in advance!
station.png
ap bridge.png

You could check the CAPs: or just reset the config of the CAP and set it to CAPs mode.

These are the settings from the CAPs.
The print screens are from the CAPs winbox settings. I could try to reset it, but I am asking for an opinion of why the two are different and the setting cannot be managed.

My opinion is that you misconfigured one accesspoint. Untill proven otherwise…

Hope this helps :sunglasses:

Most likely option, yes.

It might help to provide description of your full network, which devices are present, how are they connected, which one is supposed to be capsman manager, ...
Apart from having those 2 caps reset to caps mode (which will make SURE they are not configured wrong), it might also help to show config of capsman manager.

They are all connected through LAN.

[admin@MikroTik IT] /caps-man/provisioning> print
Flags: X - disabled

[admin@MikroTik IT] /caps-man/configuration> pr
0 name="sga's config" mode=ap ssid="" hide-ssid=no country=romania
distance=indoors security=sga security datapath=datapath-sga

[admin@MikroTik IT] /caps-man/datapath> pr
0 name="datapath-sga" client-to-client-forwarding=yes bridge=bridge1
local-forwarding=yes

[admin@MikroTik IT] /caps-man/security> pr
[admin@MikroTik IT] /caps-man/security> pes=wpa2-psk encryption=aes-ccm

[admin@MikroTik IT] /caps-man/remote-cap> print
Columns: ADDRESS, NAME, STATE, RADIOS

ADDRESS NAME STATE RADIOS

0 192.168.31.170/57039 CAP-CC2DE0AA3193 Run 2
1 B8:69:F4:39:3D:C3/31301 CAP-B869F4393DC3 Run 2
2 B8:69:F4:F4:E8:F9/33339 CAP-B869F4F4E8F9 Run 2
3 192.168.31.173/39297 CAP-CC2DE0ABD5AE Run 2
4 E4:8D:8C:D3:B2:94/19825 CAP-E48D8CD3B294 Run 2
5 192.168.31.171/57730 CAP-CC2DE0AA31C3 Run 2
6 192.168.31.172/32779 CAP-CC2DE0AA31DB Run 2
7 B8:69:F4:3C:4C:96/49947 [B8:69:F4:3C:4C:96] Run 2

[admin@MikroTik IT] /caps-man/radio> print
Flags: P - PROVISIONED
Columns: RADIO-MAC, INTERFACE, REMOTE-CAP-NAME, REMOTE-CAP-IDENTITY

RADIO-MAC INTERFACE REMOTE-CAP-NAME REMOTE-CAP-IDENTITY

0 P CC:2D:E0:AA:31:9A IT Cap's MAN cap - 2 Ghz CAP-CC2DE0AA3193 MikroTik IT
1 P CC:2D:E0:AA:31:99 IT Cap's MAN cap - 5 Ghz CAP-CC2DE0AA3193 MikroTik IT
2 P B8:69:F4:39:3D:C5 CAP 4 - Parcare - 2 Ghz CAP-B869F4393DC3 MikroTik Wap AC Parcare
3 P B8:69:F4:39:3D:C4 CAP 4 - Parcare - 5 Ghz CAP-B869F4393DC3 MikroTik Wap AC Parcare
4 P B8:69:F4:F4:E8:FB CAP 7 - Avize etaj2 - 2 Ghz CAP-B869F4F4E8F9 MikroTik Avize Etaj
5 P B8:69:F4:F4:E8:FA CAP 7 - Avize etaj2 - 5 Ghz CAP-B869F4F4E8F9 MikroTik Avize Etaj
6 P CC:2D:E0:AB:D5:B5 CAP 3 - Felicia - 2 Ghz CAP-CC2DE0ABD5AE MikroTik Felicia Cap3
7 P CC:2D:E0:AB:D5:B4 CAP 3 - Felicia - 5 Ghz CAP-CC2DE0ABD5AE MikroTik Felicia Cap3
8 P E4:8D:8C:D3:B2:9A CAP 6 - ELH et. 1 - 2 Ghz CAP-E48D8CD3B294 MikroTik Inspectie et. 1
9 P E4:8D:8C:D3:B2:99 CAP 6 - ELH et. 1 - 5 Ghz CAP-E48D8CD3B294 MikroTik Inspectie et. 1
10 P CC:2D:E0:AA:31:CA CAP 1 - RURPA - 2 Ghz CAP-CC2DE0AA31C3 MikroTik Rurpa Cap1
11 P CC:2D:E0:AA:31:C9 CAP 1 - RURPA - 5 Ghz CAP-CC2DE0AA31C3 MikroTik Rurpa Cap1
12 P CC:2D:E0:AA:31:E2 CAP 2 - Aparare - 2 Ghz CAP-CC2DE0AA31DB MikroTik Aparare Cap2
13 P CC:2D:E0:AA:31:E1 CAP 2 - Aparare - 5 Ghz CAP-CC2DE0AA31DB MikroTik Aparare Cap2
14 P B8:69:F4:3C:4C:9D CAP 8 - Rezerva Liber - 2 Ghz [B8:69:F4:3C:4C:96] MikroTik REZERVA
15 P B8:69:F4:3C:4C:9C CAP 8 - Rezerva Liber - 5 Ghz [B8:69:F4:3C:4C:96] MikroTik REZERVA

This is the settings from the CAPsMAN.

Thanks for the info, can you also add:

CAPs1

/export file=anynameyoulike

CAPs2

/export file=anynameyoulike

CAPsMAN

/export file=anynameyoulike

Just remove serial and any other info and post in between code tags by using the </> button.

I have reseted the one that showed “AP bridge” and now it’s “station” like the others.

That is the correct setting?

Thanx in advance.

CAPs1 (just reseted and now in station mode)

# 2024-05-21 09:34:26 by RouterOS 7.14.3
# software id = 3GUM-KJBT
#
# model = RB962UiGS-5HacT2HnT
# serial number = 
/interface bridge
add admin-mac=B8:69:F4:3C:4C:96 auto-mac=no comment=defconf name=bridgeLocal
/interface wireless
# managed by CAPsMAN
# channel: 2452/20-Ce/gn(17dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan1 ] disabled=no ssid=MikroTik
# managed by CAPsMAN
# channel: 5200/20-eCee/ac/P(21dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan2 ] disabled=no ssid=MikroTik
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
add bridge=bridgeLocal comment=defconf interface=ether3
add bridge=bridgeLocal comment=defconf interface=ether4
add bridge=bridgeLocal comment=defconf interface=ether5
add bridge=bridgeLocal comment=defconf interface=sfp1
/interface wireless cap
# 
set bridge=bridgeLocal discovery-interfaces=bridgeLocal enabled=yes \
    interfaces=wlan1,wlan2
/ip dhcp-client
add comment=defconf interface=bridgeLocal
/system clock
set time-zone-name=Europe/Bucharest
/system identity
set name="MikroTik Rezerva"
/system note
set show-at-login=no

CAPs2 (an old one - added a few years ago):

# 2024-05-21 09:36:44 by RouterOS 7.14.3
# software id = 877H-9R8V
#
# model = RB962UiGS-5HacT2HnT
# serial number = 
/interface bridge
add name=bridge1 port-cost-mode=short
/interface wireless
# managed by CAPsMAN
# channel: 2412/20-Ce/gn(20dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan1 ] antenna-gain=0 country=no_country_set \
    disabled=no frequency-mode=manual-txpower ssid=MikroTik station-roaming=\
    enabled
# managed by CAPsMAN
# channel: 5180/20-Ceee/ac/P(23dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan2 ] antenna-gain=0 country=no_country_set \
    disabled=no frequency-mode=manual-txpower ssid=MikroTik station-roaming=\
    enabled
/interface list
add name=WAN
add name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/interface bridge port
add bridge=bridge1 ingress-filtering=no interface=ether1 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether2 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether3 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether4 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether5 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=sfp1 internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface=wlan1 internal-path-cost=10 \
    path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface list member
add interface=ether1 list=WAN
add interface=ether2 list=LAN
add interface=ether3 list=LAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=sfp1 list=LAN
add interface=wlan1 list=LAN
/interface ovpn-server server
set auth=sha1,md5
/interface wireless cap
# 
set bridge=bridge1 certificate=request discovery-interfaces=\
    ether1,ether2,ether3,ether4,ether5,sfp1 enabled=yes interfaces=\
    wlan1,wlan2 lock-to-caps-man=yes
/ip address
add address=192.168.31.171/24 interface=bridge1 network=192.168.31.0
/ip dns
set servers=8.8.8.8,192.168.31.51
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=192.168.31.1
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/routing bfd configuration
add disabled=no
/system clock
set time-zone-name=Europe/Bucharest
/system identity
set name="MikroTik Rurpa Cap1"
/system note
set show-at-login=no

CAPsMAN:

# 2024-05-21 09:37:04 by RouterOS 7.14.3
# software id = 9499-6WIS
#
# model = RB962UiGS-5HacT2HnT
# serial number = 
/interface bridge
add name=bridge1 port-cost-mode=short
/interface ethernet
set [ find default-name=ether4 ] comment="link 1 etaj 2"
/interface wireless
# managed by CAPsMAN
# channel: 2412/20-Ce/gn(20dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan1 ] antenna-gain=0 band=2ghz-b/g/n channel-width=\
    20/40mhz-Ce country=no_country_set disabled=no frequency=auto \
    frequency-mode=manual-txpower mode=ap-bridge ssid="SGA Mures" \
    station-roaming=enabled
# managed by CAPsMAN
# channel: 5240/20-eeeC/ac/P(21dBm), SSID: SGA Mures, local forwarding
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
    20/40/80mhz-Ceee country=romania disabled=no frequency=auto mode=\
    ap-bridge ssid="SGA Mures" station-roaming=enabled wireless-protocol=\
    802.11 wps-mode=disabled
/caps-man datapath
add bridge=bridge1 client-to-client-forwarding=yes local-forwarding=yes name=\
    datapath-sga
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
    name="sga security"
/caps-man configuration
add country=romania datapath=datapath-sga distance=indoors hide-ssid=no mode=\
    ap name="sga's config" security="sga security" ssid="SGA Mures"
/caps-man interface
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:CA master-interface=none name="CAP 1 - RURPA - 2 Ghz" \
    radio-mac=CC:2D:E0:AA:31:CA radio-name=CC2DE0AA31CA
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:C9 master-interface=none name="CAP 1 - RURPA - 5 Ghz" \
    radio-mac=CC:2D:E0:AA:31:C9 radio-name=CC2DE0AA31C9
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:E2 master-interface=none name="CAP 2 - Aparare - 2 Ghz" \
    radio-mac=CC:2D:E0:AA:31:E2 radio-name=CC2DE0AA31E2
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:E1 master-interface=none name="CAP 2 - Aparare - 5 Ghz" \
    radio-mac=CC:2D:E0:AA:31:E1 radio-name=CC2DE0AA31E1
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AB:D5:B5 master-interface=none name="CAP 3 - Felicia - 2 Ghz" \
    radio-mac=CC:2D:E0:AB:D5:B5 radio-name=CC2DE0ABD5B5
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AB:D5:B4 master-interface=none name="CAP 3 - Felicia - 5 Ghz" \
    radio-mac=CC:2D:E0:AB:D5:B4 radio-name=CC2DE0ABD5B4
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:39:3D:C5 master-interface=none name="CAP 4 - Parcare - 2 Ghz" \
    radio-mac=B8:69:F4:39:3D:C5 radio-name=B869F4393DC5
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:39:3D:C4 master-interface=none name="CAP 4 - Parcare - 5 Ghz" \
    radio-mac=B8:69:F4:39:3D:C4 radio-name=B869F4393DC4
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:39:3E:07 master-interface=none name="CAP 5 - Liber - 2 Ghz" \
    radio-mac=B8:69:F4:39:3E:07 radio-name=B869F4393E07
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:39:3E:06 master-interface=none name="CAP 5 - Liber - 5 Ghz" \
    radio-mac=B8:69:F4:39:3E:06 radio-name=B869F4393E06
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    E4:8D:8C:D3:B2:9A master-interface=none name="CAP 6 - ELH et. 1 - 2 Ghz" \
    radio-mac=E4:8D:8C:D3:B2:9A radio-name=E48D8CD3B29A
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    E4:8D:8C:D3:B2:99 master-interface=none name="CAP 6 - ELH et. 1 - 5 Ghz" \
    radio-mac=E4:8D:8C:D3:B2:99 radio-name=E48D8CD3B299
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:F4:E8:FB master-interface=none name=\
    "CAP 7 - Avize etaj2 - 2 Ghz" radio-mac=B8:69:F4:F4:E8:FB radio-name=\
    B869F4F4E8FB
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:F4:E8:FA master-interface=none name=\
    "CAP 7 - Avize etaj2 - 5 Ghz" radio-mac=B8:69:F4:F4:E8:FA radio-name=\
    B869F4F4E8FA
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:3C:4C:9D master-interface=none name=\
    "CAP 8 - Rezerva Liber - 2 Ghz" radio-mac=B8:69:F4:3C:4C:9D radio-name=\
    B869F43C4C9D
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    B8:69:F4:3C:4C:9C master-interface=none name=\
    "CAP 8 - Rezerva Liber - 5 Ghz" radio-mac=B8:69:F4:3C:4C:9C radio-name=\
    B869F43C4C9C
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:9A master-interface=none name="IT Cap's MAN cap - 2 Ghz" \
    radio-mac=CC:2D:E0:AA:31:9A radio-name=CC2DE0AA319A
add configuration="sga's config" disabled=no l2mtu=1600 mac-address=\
    CC:2D:E0:AA:31:99 master-interface=none name="IT Cap's MAN cap - 5 Ghz" \
    radio-mac=CC:2D:E0:AA:31:99 radio-name=CC2DE0AA3199
/interface list
add name=WAN
add name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wifi datapath
add bridge=bridge1 disabled=no name=datapath_ax
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disable-pmkid=yes disabled=no \
    encryption=ccmp,gcmp,ccmp-256,gcmp-256 name="sga security ax" wps=disable
/interface wifi configuration
add country=Romania datapath=datapath_ax disabled=no mode=ap name=\
    "sga's config AX" security="sga security ax" ssid="SGA Mures AX"
/interface wifi
add configuration="sga's config AX" configuration.mode=ap datapath=\
    datapath_ax disabled=no name="CAP AX 1 - 111" radio-mac=48:A9:8A:9D:06:65 \
    security="sga security ax"
add configuration="sga's config AX" configuration.mode=ap datapath=\
    datapath_ax disabled=no name="CAP AX 1 - 222" radio-mac=48:A9:8A:9D:06:66 \
    security="sga security ax"
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
    supplicant-identity=MikroTik
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes upgrade-policy=\
    require-same-version
/interface bridge port
add bridge=bridge1 ingress-filtering=no interface=ether1 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether2 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether3 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether4 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=ether5 internal-path-cost=\
    10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=sfp1 internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface="IT Cap's MAN cap - 2 Ghz" \
    internal-path-cost=10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface="IT Cap's MAN cap - 5 Ghz" \
    internal-path-cost=10 path-cost=10
add bridge=bridge1 ingress-filtering=no interface=wlan1 internal-path-cost=10 \
    path-cost=10
add bridge=bridge1 ingress-filtering=no interface=wlan2 internal-path-cost=10 \
    path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface list member
add interface=ether2 list=LAN
add interface=ether3 list=LAN
add interface=ether4 list=LAN
add interface=ether5 list=LAN
add interface=sfp1 list=LAN
add interface=wlan2 list=LAN
add interface=wlan1 list=LAN
add interface=ether1 list=LAN
/interface ovpn-server server
set auth=sha1,md5
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes package-path="" \
    require-peer-certificate=no upgrade-policy=suggest-same-version
/interface wireless cap
# 
set bridge=bridge1 certificate=request discovery-interfaces=bridge1 enabled=\
    yes interfaces=wlan1,wlan2 lock-to-caps-man=yes
/ip address
add address=192.168.31.170/24 interface=bridge1 network=192.168.31.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add disabled=yes interface=bridge1
/ip dns
set servers=192.168.31.51,192.168.30.241,8.8.8.8
/ip route
add check-gateway=ping disabled=no dst-address=0.0.0.0/0 gateway=192.168.31.1
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/routing bfd configuration
add disabled=no
/system clock
set time-zone-name=Europe/Bucharest
/system identity
set name="MikroTik IT"
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=162.159.200.123
add address=157.90.24.29
/system watchdog
set auto-send-supout=yes send-email-from=mikrotik@sgams.dam.rowater.ro \
    send-email-to=mynamechangedhere@sgams.dam.rowater.ro send-smtp-server=\
    192.168.30.51

Guys, if you see the red 'managed by capsman" on the interface, it means all settings are in the capsman side. NOTHING in this device is used, all this “station” mode, does not matter. Actual config you can see on the CAPsMAN side, not on thre managed unit. All is ok in your setup and it should be working.

Thanks, glad they are both reporting the same mode. You could consider resetting CAPs2 as well, there seems to be some legacy settings present.

Ok. Thanx.

I managed to have two instances of CAPsMAN on the same device. Is there a way to have a single instance that manages both AC and newer AX CAPs?

I will reset them all again, It is quite easy. Thank you!

Only ax and ac ARM devices can be handled by the same instance of CAPsMAN, any mipsbe device requires the old(er) CAPsMAN.

Sooo many “but”s. It works, but. It works only with…
Thank you for the clarification