How to understand CAPSMAN with older wAP ac and Newer AX devices?

Doing some prep to migrate to v7.

We have an existing hEX (750Gr3) router configured with CAPSMAN running 6.49.19.
We have a bunch of wAP ac units connected to the CAPSMAN and recently newer cAP XL units installed.
I want to bring it all up on v7 code and to use CAPSMAN to manage older (AC) and newer units (AX).
We are changing out the existing hEX to a hEX S.
Do I run two versions of CAPSMAN on the same hEX S?

What recommended order to move all devices over to 7.x code?
We have a bunch of CRS354-48P switches. I believe it would not cause any issues with
upgrading the code to the switches?

I understand I need to run two wireless packages to do this?
What major steps not to miss?

Thank You in Advance!

Hello,

The wAP ac devices would need to have the “wifi-qcom-ac” package installed on them and have the wireless package removed (remove wireless package first then install wifi-qcom-ac). This will give you feature parity with CAPsMAN on ax devices as well as adding some additional functionality like MU-MIMO and WPA3 support. Please note that there are some features you lose from doing so, a full list can be found here: WiFi - RouterOS - MikroTik Documentation

With the wifi-qcom-ac package installed, the hEX S should have no problems with CAPsMAN as well as any other ax devices you add to your network.

If your wap ac are ARM platform you can use wifi-qcom-ac. As well on the cap xl. Then you could use only the wifi capsman without the legacy capsman. Of course watch out for missing features in wifi-qcom-ac. But running only one capsman for all of your devices (AC+AX) makes things cleaner.

We can't answer this for you. Depends on your device configuration.

The Wap Ac are MIPSBE, I believe:

So you will need to run the two CAPSMANs (old and new), which is possible but obviously a bit more complex.

I don’t know, but if your current hex is working, you could, instead of replacing it, keep it besides the new hex s, it depends on how your network layout is, it could be easier to maintain.

The CRS-354’s are running RouterOS, right?

So yes, you can update them, to have everything on a same release.

A good question is which release to update to.

From various reports on the Forum, I believe that the current 7.20 is still a bit rough around the edges, so right now I would go for 7.19.4 or 7.19.6 or - if you are more conservative, 7.15.4.

There are actually 2 versions of wap ac.
MIPSBE and ARM.

On the latter wifi-qcom-ac drivers can be used.

You are right, one is MIPSBE:

https://mikrotik.com/product/RBwAPG-5HacT2HnD

and one is ARM (32 bit):

https://mikrotik.com/product/wap_ac

The difference in the model is evident:

RBwAPG-5HacT2HnD
vs.
RBwAPG-5HacD2HnD

And when it comes to using modern CAPsMAN / wifi drivers, D is actually better than T :wink:

So what am I missing?
I am so confused right now LOL. What changes do I have to make on the hEX S? I see CAPSMAN
the wAP AC has the right version of code now. Do I make any changes on the AX?
All three have the “WiFi” option available in winbox. I can see my WiFi settings in the hEX S but the cAP AX no longer sees any CAPSMAN config being sent.

OK, installed wifi-qcom (not wifi-qcom-ac) back on the cAP ax and ssid’s are back on cAP ax
(I was fiddling before I started to read thru the thread).
What should be installed on the hEX S? Should it be wifi-qcom or wifi-qcom-ac?
So the wAP ac (arm) shows radios (wifi1 and wifi2) are not greyed out anymore though the ssid’s say “SSID not set”.
”CAP” checkbox is enabled on both wAP ac and cAP ax. Not enabled on hEX S.
I will post up latest image shortly.

Ok, after holding the caps reset on wAP ac, now I get “managed by capsman”, but no ssids show up in the wAP ac

I think I am going to throw up now. What an absolute wireless/wifi word salad. What a mess :grimacing:

https://www.youtube.com/watch?v=TNoY60GAKpU

Instead of posting screenshots, please provide export of config, posted between code quotes, please.

image

Capsman controller
caps device (ax and AC)

# hEX S
-----------------------------------------------------------------
# 2025-10-08 07:01:59 by RouterOS 7.19.6
# software id = 
#
# model = E60iUGS
# serial number = <EDITED>
/interface bridge
add admin-mac=04:F4:1C:3F:65:00 auto-mac=no comment=defconf igmp-snooping=yes \
    ingress-filtering=no name=bridge vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment=Internet
set [ find default-name=ether2 ] advertise=1G-baseT-full
/interface wifi
# operated by CAP 48:8F:5A:F5:A4:56%bridge, traffic processing on CAP
# SSID not set
add configuration.mode=ap disabled=no name=cap-wifi3 radio-mac=\
    48:8F:5A:F5:A4:58
# operated by CAP 48:8F:5A:F5:A4:56%bridge, traffic processing on CAP
# SSID not set
add configuration.mode=ap disabled=no name=cap-wifi4 radio-mac=\
    48:8F:5A:F5:A4:59
/interface vlan
add comment=SFSCS interface=bridge name=vlan10 vlan-id=10
add comment="Avaya Phones DHCP" interface=bridge name=vlan11 vlan-id=11
add comment="FAFC Guests" interface=bridge name=vlan20 vlan-id=20
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wifi channel
add band=5ghz-ax frequency=5180 name=5GHZ::CH36 width=20mhz
add band=5ghz-ax frequency=5200 name=5GHZ::CH40 width=20mhz
add band=5ghz-ax frequency=5220 name=5GHZ::CH44 width=20mhz
add band=5ghz-ax frequency=5240 name=5GHZ::CH48 width=20mhz
add band=5ghz-ax frequency=5745 name=5GHZ::CH149 width=20mhz
add band=5ghz-ax frequency=5765 name=5GHZ::CH153 width=20mhz
add band=5ghz-ax frequency=5785 name=5GHZ::CH157 width=20mhz
add band=5ghz-ax frequency=5805 name=5GHZ::CH161 width=20mhz
add band=5ghz-ax frequency=5825 name=5GHZ::CH165 width=20mhz
add band=5ghz-ax disabled=no frequency=5180,5200,5220,5240 name=5GHZ::UNII-1 \
    width=20mhz
add band=5ghz-ax disabled=no frequency=5745,5765,5785,5805,5825 name=\
    5GHZ::UNII-3 width=20mhz
add band=5ghz-ax disabled=no frequency=\
    5180,5200,5220,5240,5745,5765,5785,5805,5825 name=5GHZ::NON-DFS width=\
    20mhz
add band=2ghz-ax frequency=2412 name=2GHZ::CH1 width=20mhz
add band=2ghz-ax frequency=2437 name=2GHZ::CH6 width=20mhz
add band=2ghz-ax frequency=2462 name=2GHZ::CH11 width=20mhz
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2GHZ::AUTO width=\
    20mhz
/interface wifi datapath
add disabled=no name=datapath20-FAFC vlan-id=20
add disabled=no name="datapath1-FAFC Guests" vlan-id=1
add disabled=no name=datapath10-SFSCS vlan-id=10
/interface wifi security
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=\
    ccmp,ccmp-256 name=sec-FAFC
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=\
    ccmp,ccmp-256 name=sec-SFSCS
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=\
    ccmp,ccmp-256 name="sec-FAFC Guests"
add authentication-types=wpa2-psk,wpa3-psk disabled=no encryption=\
    ccmp,ccmp-256 name=sec-SFSCS_Staff
/interface wifi configuration
add channel=2GHZ::AUTO country="United States" datapath=datapath20-FAFC \
    disabled=no mode=ap name=FAFC-2G security=sec-FAFC \
    security.authentication-types="" .encryption="" ssid=FAFC
add channel=5GHZ::NON-DFS country="United States" datapath=datapath20-FAFC \
    disabled=no mode=ap name=FAFC-5G security=sec-FAFC \
    security.authentication-types="" .encryption="" ssid=FAFC
add channel=2GHZ::AUTO country="United States" datapath=\
    "datapath1-FAFC Guests" disabled=no mode=ap name=FAFC-Guests-2G security=\
    "sec-FAFC Guests" security.authentication-types="" .encryption="" ssid=\
    "FAFC Guests"
add channel=5GHZ::NON-DFS country="United States" datapath=\
    "datapath1-FAFC Guests" disabled=no mode=ap name=FAFC-Guests-5G security=\
    "sec-FAFC Guests" security.authentication-types="" .encryption="" ssid=\
    "FAFC Guests"
add channel=2GHZ::AUTO country="United States" datapath=datapath10-SFSCS \
    disabled=no mode=ap name=SFSCS_Staff-2G security=sec-SFSCS_Staff \
    security.authentication-types="" .encryption="" ssid=SFSCS_Staff
add channel=5GHZ::NON-DFS country="United States" datapath=datapath10-SFSCS \
    disabled=no mode=ap name=SFSCS-5G security=sec-SFSCS \
    security.authentication-types="" .encryption="" ssid=SFSCS
add channel=2GHZ::AUTO country="United States" datapath=datapath10-SFSCS \
    disabled=no mode=ap name=SFSCS-2G security=sec-SFSCS \
    security.authentication-types="" .encryption="" ssid=SFSCS
add channel=5GHZ::NON-DFS country="United States" datapath=datapath10-SFSCS \
    disabled=no mode=ap name=SFSCS_Staff-5G security=sec-SFSCS_Staff \
    security.authentication-types="" .encryption="" ssid=SFSCS_Staff
/interface wifi
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=SFSCS-5G disabled=no name=cap-wifi1 radio-mac=\
    D4:01:C3:01:6E:A8
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=FAFC-5G disabled=no mac-address=D6:01:C3:01:6E:A8 \
    master-interface=cap-wifi1 name=cap-wifi1-virtual1
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=FAFC-Guests-5G disabled=no mac-address=D6:01:C3:01:6E:A9 \
    master-interface=cap-wifi1 name=cap-wifi1-virtual2
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=SFSCS_Staff-5G disabled=no mac-address=D6:01:C3:01:6E:AA \
    master-interface=cap-wifi1 name=cap-wifi1-virtual3
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=SFSCS-2G disabled=no name=cap-wifi2 radio-mac=\
    D4:01:C3:01:6E:A9
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=FAFC-2G disabled=no mac-address=D6:01:C3:01:6E:AB \
    master-interface=cap-wifi2 name=cap-wifi2-virtual1
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=FAFC-Guests-2G disabled=no mac-address=D6:01:C3:01:6E:AC \
    master-interface=cap-wifi2 name=cap-wifi2-virtual2
# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP
add configuration=SFSCS_Staff-2G disabled=no mac-address=D6:01:C3:01:6E:AD \
    master-interface=cap-wifi2 name=cap-wifi2-virtual3
/ip dhcp-server option
add code=242 name=avaya-phone value=\
    "'MCIPADD=192.168.2.15,MCPORT=1719,HTTPSRVR=192.168.2.15,L2QVLAN=11'"
/ip pool
add name=default-dhcp ranges=192.168.88.10-192.168.88.254
add name=dhcp_pool2 ranges=192.168.2.101-192.168.3.254
add name=dhcp_pool10 ranges=192.168.0.101-192.168.1.254
add name=dhcp_pool20 ranges=192.168.20.101-192.168.21.254
/ip dhcp-server
add address-pool=default-dhcp disabled=yes interface=bridge name=defconf
add address-pool=dhcp_pool10 interface=vlan10 lease-time=1h name=dhcp10
add address-pool=dhcp_pool20 interface=vlan20 lease-time=1h name=dhcp20
add address-pool=dhcp_pool2 interface=bridge lease-time=1h name=dhcp_bridge
/disk settings
set auto-media-interface=bridge auto-media-sharing=yes auto-smb-sharing=yes
/interface bridge port
add bridge=bridge interface=ether2
add bridge=bridge interface=ether3
add bridge=bridge interface=ether4
add bridge=bridge interface=ether5
add bridge=bridge comment="2.5G Fiber" interface=sfp1
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface bridge vlan
add bridge=bridge comment="Avaya Phones" tagged=bridge,ether2 vlan-ids=11
add bridge=bridge comment=SFSCS tagged=bridge,ether2 vlan-ids=10
add bridge=bridge comment="FAFC Guests" tagged=bridge,ether2 vlan-ids=20
/interface list member
add interface=ether1 list=WAN
add interface=bridge list=LAN
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes interfaces=bridge \
    package-path="" require-peer-certificate=no upgrade-policy=\
    suggest-same-version
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=SFSCS-2G \
    slave-configurations=FAFC-2G,FAFC-Guests-2G,SFSCS_Staff-2G \
    supported-bands=2ghz-ax,2ghz-g,2ghz-n
add action=create-enabled disabled=no master-configuration=SFSCS-5G \
    slave-configurations=FAFC-5G,FAFC-Guests-5G,SFSCS_Staff-5G \
    supported-bands=5ghz-a,5ghz-n,5ghz-ac,5ghz-ax
/ip address
add address=192.168.88.1/24 comment=defconf disabled=yes interface=bridge \
    network=192.168.88.0
add address=76.80.133.138/29 comment="WAN Internet Spectrum" disabled=yes \
    interface=ether1 network=76.80.133.136
add address=192.168.2.1/23 comment="FAFC Vlan1" interface=bridge network=\
    192.168.2.0
add address=192.168.0.1/23 comment=SFSCS interface=vlan10 network=192.168.0.0
add address=192.168.20.1/23 comment="FAFC Guests" interface=vlan20 network=\
    192.168.20.0
/ip dhcp-client
add comment=defconf interface=ether1
/ip dhcp-server network
add address=192.168.0.0/23 dhcp-option=avaya-phone dns-server=\
    192.168.0.62,192.168.0.150,208.67.220.123,208.67.222.123,1.1.1.3,1.0.0.3 \
    domain=sfsbraves.local gateway=192.168.0.1 netmask=23
add address=192.168.2.0/23 dhcp-option=avaya-phone dns-server=\
    208.67.220.123,208.67.222.123,1.1.1.3,1.0.0.3 domain=fafc.org gateway=\
    192.168.2.1 netmask=23
add address=192.168.20.0/23 dhcp-option=avaya-phone dns-server=\
    208.67.220.123,208.67.222.123,1.1.1.3,1.0.0.3 domain=fafc.org gateway=\
    192.168.20.1 netmask=23
add address=192.168.88.0/24 comment=defconf dns-server=192.168.88.1 gateway=\
    192.168.88.1
/ip dns
set allow-remote-requests=yes servers=8.8.8.8
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan type=A
/ip firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
    in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" \
    dst-port=33434-33534 protocol=udp
add action=accept chain=input comment=\
    "defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=\
    udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 \
    protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=input comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
add action=fasttrack-connection chain=forward comment="defconf: fasttrack6" \
    connection-state=established,related
add action=accept chain=forward comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment=\
    "defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" \
    hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=\
    icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=\
    500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=\
    ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=\
    ipsec-esp
add action=accept chain=forward comment=\
    "defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment=\
    "defconf: drop everything else not coming from LAN" in-interface-list=\
    !LAN
/system clock
set time-zone-name=America/Los_Angeles
/system identity
set name=hEXs-FAFC
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN


cAP ax


#
# 2025-10-08 07:08:00 by RouterOS 7.19.6
# software id = 
#
# model = cAPGi-5HaxD2HaxD
# serial number = <EDITED>
/interface bridge
add admin-mac=D4:01:C3:01:6E:A6 auto-mac=no comment=defconf name=bridgeLocal \
    port-cost-mode=short
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: SFSCS, channel: 5825/ax
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap \
    datapath=capdp disabled=no
# managed by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: SFSCS, channel: 2437/ax
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap \
    datapath=capdp disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1 internal-path-cost=10 \
    path-cost=10
add bridge=bridgeLocal comment=defconf interface=ether2 internal-path-cost=10 \
    path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/interface ovpn-server server
add mac-address=FE:9C:88:2B:06:54 name=ovpn-server1
/interface wifi cap
set caps-man-addresses="" certificate=none discovery-interfaces=bridgeLocal \
    enabled=yes slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/system clock
set time-zone-name=America/Los_Angeles
/system identity
set name=cAPax-test


wAP AC


# 2025-10-08 07:09:00 by RouterOS 7.19.6
# software id = 
#
# model = RBwAPG-5HacD2HnD
# serial number = <edited>
/interface bridge
add admin-mac=48:8F:5A:F5:A4:56 auto-mac=no comment=defconf name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal, traffic processing on CAP
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap \
    datapath=capdp disabled=no
# managed by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal, traffic processing on CAP
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap \
    datapath=capdp disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
/interface wifi cap
set certificate=request discovery-interfaces=bridgeLocal enabled=yes \
    slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal
/system clock
set time-zone-name=America/Los_Angeles
/system identity
set name=wAPac-test

I have place all three device configs within the preformatted option you requested.

Thank you for Looking!

Only as a reference for further analysis:

  1. the hex S has MAC: 04:F4:1C:3F:65:00
  2. the Cap Ax has MAC: D4:01:C3:01:6E:A6
  3. the Wap Ac has MAC: 48:8F:5A:F5:A4:56

Cap Ax has:
'# managed by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal, traffic processing on CAP
(so the CAP Manager is the hex S), good, and it also has:
'# mode: AP, SSID: SFSCS, channel: 5825/ax
and
'# mode: AP, SSID: SFSCS, channel: 2437/ax
(I would say "good")

The Wap Ac has:
'# operated by CAP 48:8F:5A:F5:A4:56%bridge, traffic processing on CAP
(so the CAP manager is "itself" :confused: )
And it has no mode AP,SSID and channel
(I would say "wrong")

Then the hexS has TWO /wifi sections, one with 2 interfaces ( wifi 3 and 4) operated by the Wap Ac:
'# operated by CAP 48:8F:5A:F5:A4:56%bridge, traffic processing on CAP

and one with 8 interfaces operated by the Cap Ax:
'# operated by CAP D4:01:C3:01:6E:A6%bridge, traffic processing on CAP

So WHICH device is actually the CAPSMAN?
It seems to me like you somehow created some sort of circular reference on the Wap Ac.
I bolded to highlight them the managed vs. operated.

I wiped the wAP AC with “no default config” and reloaded, set as cap, reloaded and it still shows no ssids being sent to wAP ac from hEX. I have only one capsman configured on hEX, other two devices do not have capsman configured and are both set as cap.

But does it say operated or managed?
And if managed, is it managed "by CAPsMAN 04:F4:1C:3F:65:00%bridgeLocal"?