I’ve managed (for the second time now) to brick my hAP ac2 by doing an upgrade with the unit powered up via a flaky PoE (I assume it lost power during upgrade).
Now I’m trying to recover the unit using netinstall using the steps described https://help.mikrotik.com/docs/display/ROS/Netinstall.
It took a lot of tries, but I figured out what’s going on: the unit seems to be stuck in ether boot mode. As soon as I power it up, the unit tries the BOOTP protocol:
3 0.137953 0.0.0.0 255.255.255.255 BOOTP 342 Boot Request from c4:ad:34:45:d9:f9 (c4:ad:34:45:d9:f9)
4 0.338094 0.0.0.0 255.255.255.255 BOOTP 342 Boot Request from c4:ad:34:45:d9:f9 (c4:ad:34:45:d9:f9)
5 0.341492 192.168.88.10 255.255.255.255 BOOTP 283 Boot Reply
then it requests “vmlinux” via TFTP
8 0.344002 192.168.88.3 192.168.88.10 TFTP 71 Read Request, File: vmlinux, Transfer type: octet, blksize=1452
9 0.344318 192.168.88.10 192.168.88.3 TFTP 57 Option Acknowledgement, blksize=1452
10 0.345487 192.168.88.3 192.168.88.10 TFTP 60 Acknowledgement, Block: 0
11 0.345545 192.168.88.10 192.168.88.3 TFTP 1498 Data Packet, Block: 1
12 0.347207 192.168.88.3 192.168.88.10 TFTP 60 Acknowledgement, Block: 1
13 0.347254 192.168.88.10 192.168.88.3 TFTP 1498 Data Packet, Block: 2
14 0.348894 192.168.88.3 192.168.88.10 TFTP 60 Acknowledgement, Block: 2
15 0.348938 192.168.88.10 192.168.88.3 TFTP 1498 Data Packet, Block: 3
...
11119 9.762279 192.168.88.10 192.168.88.3 TFTP 1498 Data Packet, Block: 5516
11120 9.763924 192.168.88.3 192.168.88.10 TFTP 60 Acknowledgement, Block: 5516
11121 9.763986 192.168.88.10 192.168.88.3 TFTP 442 Data Packet, Block: 5517 (last)
11122 9.765278 192.168.88.3 192.168.88.10 TFTP 60 Acknowledgement, Block: 5517
and then it starts broadcasting some data (like license, model number, etc.) ad infinitum:
11133 17.901581 0.0.0.0 255.255.255.255 UDP 197 5000 → 5000 Len=155
11134 17.901581 0.0.0.0 255.255.255.255 UDP 197 59813 → 59813 Len=155
...
Contents of the broadcasted packet:
0000 ff ff ff ff ff ff c4 ad 34 45 d9 f9 08 00 45 00 ........4E....E.
0010 00 b7 c9 c5 40 00 40 11 70 71 00 00 00 00 ff ff ....@.@.pq......
0020 ff ff 13 88 13 88 00 a3 91 59 c4 ad 34 45 d9 f9 .........Y..4E..
0030 00 00 00 00 00 00 00 00 87 00 01 00 00 00 44 53 ..............DS
0040 43 56 0a 53 57 4a 42 2d 47 44 52 56 0a 69 38 55 CV.SWJB-GDRV.i8U
0050 46 6f 31 58 7a 69 53 6d 54 4d 6d 71 36 4d 64 4f Fo1XziSmTMmq6MdO
0060 6d 5a 70 48 75 67 69 71 32 65 6b 67 57 77 6b 5a mZpHugiq2ekgWwkZ
0070 6c 4e 68 59 2b 71 59 34 48 35 49 33 53 39 6b 2f lNhY+qY4H5I3S9k/
0080 39 76 31 47 38 53 4a 38 48 52 5a 57 48 49 4a 4f 9v1G8SJ8HRZWHIJO
0090 6d 7a 4f 73 41 2b 69 6a 64 2b 79 70 4a 47 63 31 mzOsA+ijd+ypJGc1
00a0 51 46 41 3d 3d 0a 52 42 44 35 32 47 2d 35 48 61 QFA==.RBD52G-5Ha
00b0 63 44 32 48 6e 44 0a 61 72 6d 0a 36 2e 34 34 0a cD2HnD.arm.6.44.
00c0 37 2e 34 0a 00 7.4..
This is the moment when the unit shows up in the netinstall GUI.
The problem, however, is that when I attempt to install a new RouterOS image, nothing happens on the wire, nothing is sent. The gui says “Installing…” for a while then it reverts back to “Ready” and that’s it.
Any idea what’s going on here and how can I proceed with restoring the unit? I tried to restore routeros 7.4 (which was installed previously) and 7.4.1, using various versions of netinstall 7.4.1, 7.4, 6.49.1, with no success (version 6.49.1 of netinstall doesn’t even “see” the unit).
PS: I managed to boot an OpenWRT image on the unit and ssh’d into it, so the unit itself doesn’t seem to be defective. If I can’t manage to recover routeros, I guess I’ll try to install openwrt on it.