Capsman over PAL network: encapsulation and encryption?

We have a rather satisfying MTik setup with a few APs, broadcasting several WiFi “profiles”.
All APs are wifi6, and managed by main router with capsman.

Everything works perfectly as intended.

I wish to attach a room bit further to the network (cellar). Wifi is out of question here, not even 3/4G is reaching down.

Recently I have came across these powerline adaptors by TPLink (I have used some similars in the past with various success rate):

I’m gonna test these, let’s consider they will be able to join and create their interconnection.

But now there are many questions in my head:

1.) I wish to add a CAP Lite to the cellar. Is Capsman able to manage CAP Lite (considering all other APs are wifi6)?

2.) Can capsman travel through something like this PAL network to manage a remote CAP?

3.) Can I use some level of encapsulation and maybe also encryption between main router and CAP through these PALs (considered main router being on transmit side PAL and CAP lite is on receiving side of PAL).

What are my options here if management has to travel through this PAL network?

Do I have any options at all?

Thank you!

  1. Yes
  2. Yes
  3. Certificates is the solution

No, it would require a different capsman.
Cap lite = “wireless” capsman
AX-Line = wifi capsman

hap ax lite would be the way to go.

As indicated by itimo01, cap lite can not be managed by wifi capsman.
You can use the 2 different capsman controllers on the same device (provided the controller on itself does not have wifi radios, or you would loose functionality on those).
But it’s not practical and it will not result in roaming between both. Besides, since you will only have 1 legacy wifi device, it would be a capsman controller for 1 radio. Quite useless.
You can opt to configure that cap lite as a standalone AP, not being part of capsman.

So AX Lite is the better choice for your basement (as it happens to be, I also have one downstairs since most devices connecting there are 2.4GHz only anyway).

As for encapsulation etc, why bother ? Those powerline adapters already have encryption embedded in their protocol.
That’s why they need to be paired.

Thank you!

I currently don’t have CAP Lite, just I liked its small form-factor. But I diced out it now, as I only have options I don’t like:

  • add it to a different CAPsMAN, which will not used for roaming at all
  • add it as standalone AP

For standalone AP, we do have options from TP-Link being used as PowerLine Adapter and also providing WiFi, for a few $ extra, and then we won’t need to power any other device next to it to get WiFi.

Yeah, I don’t mind at all 2.4GHz, and I also don’t need high throughput.

To be sure: any Wifi6-capable device is suitable for my desired extension of current CAPsMAN, correct? So we are speaking also:

  • SXTsq 5 ax
  • wAP ax

That’s something I was unsure of. Every pair is using some kind of encryption? Is this legit? Are these operating in Layer1?

First one is not really for indoor use :laughing:
Second one, sure. I have one right here next to me on my desk.

Typically at layer 2 from what I can find back.
You can even add a 3th, 4th, … but each time the new one needs to be connected (paired) to an existing device so it can take over the encryption settings.
At least it always has been like that on the devices I used in the past (Devolo and TP-Link).