DHCPDISCOVER not received through CAP

Hi,
I have problems getting accesspoints to work through CAPMAN.

I can provision the radio, and it picks up the new firmware as suggested so the hardware is probably fine.

I have created channels and security cfg, and a configuration referring to a channel and security cfg plus specifying SSID and local forwarding. I have created a master interface with no config, and a subinterface with the config above and referring to the master interface. This subinterface comes online.

The client can see the SSID and connect to it (client logs “4-way handshake → completed”, caps logs the client mac as connected to the subinterface), but it doesn’t get an IP address. No lease is created on the server and the client tries DHCPDISCOVER five times and then gives up.

It looks to me as if I am missing something about connecting the AP to the network, which is a bit odd as the CAP can talk to CAPMAN - provisioning works. The physical interface of the AP is connected to a physical port on the router (RB2011iL-RM) and that port is part of the bridge which is the interface of the DHCP server. I also have a vlan connected to that bridge, and wired clients on that vlan can talk to the DHCP.

Things I’ve tried which didn’t help:
adding the master ap interface to the bridge
adding the subinterface to the bridge
creating a datapath to the bridge and specifying that as part of the configuration

I’ve read, I’ve searched and I’ve pulled my hair but I can’t get it to work. I suspect that there are simply parts of the puzzle that I do not understand, and it is most likely hiding somewhere around the “datapath” or bridging.

Object of the exercise is to have two physical AP’s, each broadcasting two SSID’s - one for 2ghz and one for 5ghz - for a total of 4 SSID’s to avoid the pitfalls of roaming.

Can anybody please help me? If you need parts of the config, I can supply that of course.

with kind regards,
Bent