Inconsistent speed HAP AC2 vs HAP Lite

I have a CAPsMAN with a single 2.4Ghz configuration.

I have connected a HAP AC2 device. The CAP master interface shows this:

Flags: M - master, D - dynamic, B - bound, X - disabled, I - inactive, R - running
 0 MDBR name="caps03-hapac2-1" mac-address=48:8F:5A:A1:AB:30 arp-timeout=auto radio-mac=48:8F:5A:A1:AB:30 master-interface=none
        radio-name="488F5AA1AB30" configuration=caps-laci-2.4 l2mtu=1600 current-state="running-ap" current-channel="2452/20-Ce/gn(20dBm)"
        current-rate-set="OFDM:12-54 BW:1x-2x SGI:1x-2x HT:0-15" current-basic-rate-set="OFDM:12 BW:1x HT:0-7" current-registered-clients=1
        current-authorized-clients=1

I do speedtest with this and I get about 60Mbps download speed.

Then I removed the HAP AC2 and connected a HAP Lite device. The CAP master interface shows this:

Flags: M - master, D - dynamic, B - bound, X - disabled, I - inactive, R - running
 0 MDBR name="caps02-1" mac-address=48:8F:5A:6C:9B:33 arp-timeout=auto radio-mac=48:8F:5A:6C:9B:33 master-interface=none radio-name="488F5A6C9B33"
        configuration=caps-laci-2.4 l2mtu=1600 current-state="running-ap" current-channel="2452/20-Ce/gn(20dBm)"
        current-rate-set="OFDM:12-54 BW:1x-2x SGI:1x-2x HT:0-15" current-basic-rate-set="OFDM:12 BW:1x HT:0-7" current-registered-clients=1
        current-authorized-clients=1

I do speedtest with this and I get about 30Mbps download speed.

Some facts:

  • Both devices are on the same desk, side by side, connected to the same switch.
  • Both devices are running the same OS version 6.48
  • Both devices were factory reset with no default config. There is nothing configured on them except a bridge, a dhcp client and /interface wireless cap.
  • No firewall rules at all.
  • The client used for testing the speed is the same phone, located at the exact same location about ~1m away from the devices.
  • The HAP AC2 (RBD52G-5HacD2HnD-TC) has a 2.4Ghz 802.11b/g/n radio with 2 chains, max data date 300Mbps, antenna gain 2.5dBi
  • The HAP Lite (RB941-2nD) has a 2.4Ghz 802.11b/g/n radio with 2 chains, max data date 300Mbps, antenna gain 1.5dBi
  • Both devices are using the exact same frequency, same bandwidth, same basic and supported bitrates.
  • The conditions are close to ideal: indoor usage, weak interference from other APs (they are below -70dB), nothing is blocking signal between testing client and APs etc.
  • There was almost zero CPU load on the devices while I performed the tests.

What I did is that I deleted one provisioned interface and provisioned the other manually, and did a test. Then I switch quickly and do another test. I have repeated these tests multiple times, and they were very consistent. The HAP AC2 always did 60Mbps on average (sometimes 80+), and the HAP Lite never did better than 30Mbps.

The only difference (apart from the wifi chip) is the antenna gain, but it should not make any difference, because the signal strength is -29dBi for the HAP AC2, and -33dBi for the HAP Lite (on average). They are both excellent, and the difference is negligible. It cannot explain the difference in download speed.

So why can’t I get 60Mbps speed out of the HAP Lite?

What speed is the client connected on both CAP’s?

The phone shows 144 Mbps for both CAPs and rx signal strength between -30 and -40 dBm

I have two HAP Lite devices. I just tried the other one. Same result: 30Mbps actual maximum speed. The phone shows that the connection is 144Mbps at -35 dBm.

I cannot explain the speed difference. (CPU load on the SMIPS processor ???)
What is in the wireless registration table of the AP? Looks like : TX rate= 144Mbps/40Mhz/1s/SGI

But still some general remarks.

All your AP’s will delay transmission as long as it sees wifi transmissions above “noise+6dBm”, or something like above -96 dBm. (-70 dBm is the usable wifi strength, wifi co-channel interference goes many times further)

Freq 2452 is channel 9. 20-Ce is 40 MHz wide (not recommended with 2.4 GHz band) . It is Ce so the extra 4 channels are on the upper freq side. So you use (7)-8-9-10-(11)-12-13-14-(15) !?!?
I hope this is OK for your country as regulatory domain, which must allow channel 1-13.

Thanks for your comments. I already left the office, I can only check these tomorrow. I think that these frequencies are allowed, I have selected the correct country.

I understand that other APs can cause interference but this still does not explain the difference in average speed. Especially that all settings are the same on the two devices.

I will have to re-check the CPU load again. Otherwise, I’m clueless.

My experience testing different MT wifi APs is that any wireless traffic hits CPU pretty hard. Generally downlink (AP transmits) is harder on CPU than uplink. CAPsMAN forwarding adds another layer of burden on CPU because AP has to encapsulate and decapsulate packets for sending it to (and receiving from) manager. If this envolves encryption, then UL will hammer AP more than DL.

That being said: hAP ac2 has a beast of a CPU compared to hAP lite …

Maybe I accidentally looked at the wrong profiler when I was testing the HAP Lite? I can believe that this will be the root of the problem. I did not pay enough attention to the CPU. I was using WPA2 + AES encryption, so yes that can be a problem. I’m going to try this without encryption (unsecured wifi) tomorrow, just to confirm that the CPU is the bottleneck.

It answers my question, but this is sad. It is a very bad idea to operate an AP without encryption. It is not even legal in some countries and I’ll certainly not use it that way. WEP is not much faster and it is vulnerable. TKIP is also vulnerable. In other words: if it turns out to be a CPU bottleneck, then I’ll probably put these two devices on the self and not use them at all. I might use them later for an IoT project, but I don’t think that I could use them for anything else.

I think that the official page for the product is a bit misleading. The 300Mbps speed is advertised on the official page for HAP Lite (“max data rate”) with big friendly letters. Everybody knows that 2.4Ghz is crowded, and nobody expects to react 300Mbps. But in this case, the max. rate may be limited to 30Mbps under ideal conditions. I’m not saying that the specification is lying about the max data rate of the radio unit itself. But I believe that the max. speed achiveable under normal conditions is much more important than the theoretical data rate of a single component inside the product. If the wireless speed is so limited (e.g. 1/10th of what the radio can do), then it should be shown on the “test results” tab. Yes, I know that the actual speed depends on many factors, and cannot be determined in advance. But a theoretical CPU bound 30Mbps upper limit is not something that “depends on many factors”. The customers deserve to know that, before they buy the product. I also believe that many users are buying these devices for creating access points, and this speed limit is much more important than the “4 port routing test with 25 firewall rules”.

I’m also not saying that this is a bad device in any way. For this amount of money, it can do fantastic things. I’m just saying that not showing such important limitations is bad practice.

Make sure you are using local forwarding, not CAPsMAN forwarding. You will get the highest data rate with local forwarding. CAPsMAN forwarding involves tunneling all traffic back to the CAPsMAN which adds a lot of overhead. Local forwarding is a CAPsMAN setting, you’ll find it in the “Datapaths” tab.

That makes sense (can’t believe WPA2 AES is the bottleneck). Can you please share your CAPsMAN configuration, @nagylz?
/caps-man export (and paste it here in code tags)

To soften a bit the sadness about the hAP Lite. The 300 Mbps is the PHY rate of the interface. It is never the payload, the data throughput, of a 802.11 wifi connection, whatever brand or model of AP.. The wifi overhead is known to be a very important part of the airtime available. With large packets it’s between 25 and 75%. Overhead can be 99% for smaller packets. The higher the PHY rate the higher the 802.11 overhead. And this is even in ideal conditions. https://www.ekahau.com/wp-content/uploads/2020/06/Wi-Fi_Capacity_Analysis_WP.pdf

Mikrotik has limited packet aggregation and the hAP Lite has limited RAM to buffer/aggregate. (I think even CAPsMAN reduces the A-MSDU to 2048 by default, not sure as I never use CAPsMAN, as I’m heading for maximum performance.)

And CAPsMAN is adding another layer of overhead, that will further reduce the throughput.

The marketing numbers are all misleading: they combine all PHY rates (all radio’s, all streams) and present this as capacity.(AC300, AC1200, …)

I’m using local forwarding. I’m going to post the config here in the evening. I still could not get into the office.

All right, I have arrived to the office. I did a quick test and re-checked the CPU usage. /tool profile shows 9% max cpu0 usage and 10% max wireless usage on the HAP Lite. The HAP AC2 actually used more CPU during the test: about 14% main CPU (7%+7%, two cores used simultaneously), and 10% wireless.

  • The HAP Lite still does not go above 30Mbps
  • The HAP AC2 can do 60MBps on average, but sometimes as much as 90Mbps.

Then I did another test, using unencrypted channels (security profile removed), and the result was the same: 30Mbps for HAP Lite and 60-80Mbps for HAP AC2.

So the speed is not limited by the main cpu, or at least the profiler does not show that.

Here is my caps-man configuration, as promised. Very basic setup.

/caps-man channel
add band=2ghz-onlyn extension-channel=Ce frequency=2452 name=channels-laci-2.4
/caps-man datapath
add bridge=bridge l2mtu=1600 local-forwarding=yes mtu=1500 name=datapath-caps-laci
/caps-man rates
add basic=12Mbps name=rates-laci-2.4 supported=12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps
/caps-man configuration
add channel=channels-laci-2.4 country=hungary datapath=datapath-caps-laci installation=any name=caps-laci-2.4 rates=rates-laci-2.4 ssid=lacinet
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm name=security-caps-laci passphrase=abcd12345678
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes upgrade-policy=suggest-same-version
/caps-man manager interface
set [ find default=yes ] forbid=yes
add disabled=no interface=bridge
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=caps-laci-2.4 name-format=identity

I just went through this article. It was a very interesting read. I think that this can hardly explain the 100% speed difference. Here is why:

  • I was using speedtest.net. That downloads a huge test file over https.
  • Sending a big chunk of data sequentially will always use very long packets, equal or close to MTU.
  • The MTU was maximized by the configuration. I don’t think that packet aggregation is allowed to exceed this limit.
  • So the framing overhead must be low, and while packet aggregation can increase speed, I believe that it cannot increase it by 100% in this very specific case.

I might be wrong, I’m not an expert… Just it seems to me that the 100% speed difference cannot be explained with a different aggregation size.

These are all invariant. Both devices were using the same CAPsMAN with the same settings. This does not explain the difference in speed.

This is why we have specifications and published test results. All manufacturers do their marketing with the max theoretical rates, and I don’t blame MikroTik that they do the same. They have to do it, because many customers won’t go further than the marketing material. But the test result tab should include wireless transfer speed test results for any device with a radio in it. I wish MikroTik published ideal maximum wireless transfer rates on that tab. Then I would have bought HAP AC2 devices instead, and everybody (including MikroTik) would have been happier. I don’t mind spending more on a device that I need. But I really mind spending any money on a device that I don’t need and can’t use. Do you see my point? This is bad for everyone.

Oh and by the way, I think that HAP Mini. mAP Lite and cAP Lite are all using the very same QCA9533 CPU and the same radio. I cannot try this now, but I believe that I would get the same disappointing results with those. Those devices are purpose built to be access points. Shouldn’t we have their wireless speed test results on the test results tab? Even if they are measured in ideal conditions, we should have at least something. Frankly, who is interested in the 100M ethernet single port routing test of an access point with a single ethernet port?

There’s no point in using 40MHz channels with 2.4GHz. You are a lot better off reducing that. Also, FYI, the bridge=bridge in your datapath settings doesn’t do anything since you are using local forwarding, so it doesn’t really have to be set at all (although it doesn’t hurt anything).

I’m not sure why you have “caps-man rates” set at all. The default is completely blank and that I believe should use the MikroTik defaults, and I’ve never seen a need to hard set them like that. You might consider going into the rates tab and just disabling or deleting that entire line, and removing the reference to it from your “caps-man configuration”.

Hi, don’t misunderstand me. I cannot explain that low performance with the information given. And I have no intend to start tests (I do have here a hAP Lite, mAP Lite, hAP ac Lite and HAP ac2)

Being very technical I just react on technical statements where I could be more specific about.
So again, don’t take this wrong , the hAP ac2 performance given is low, and the hAP Lite performance is disappointing as it is only half of that already low performance.
(I get 290 Mbps real data rate single direction out of my hAP ac2 connected via a SXTsq chain in the field, on a 433Mbps/40MHz/2S/SGI connection on 5GHz, 802.11ac)

The mAP Lite and cAP Lite have a MIPSBE cpu, and 64MB of RAM.
Only the hAP Lite and hAP mini have this lower hardware: SMIPS cpu and 32 MB of RAM. (SMIPS seems to be a different instruction set as the RouterOS barely gets into the 16 MB ROM when SMIPS is used. There have been workarounds on the forum to squeeze it in.)

The ethernet MTU (1500 bytes) is a different animal than the aggregated packet size for wifi. For 802.11n the maximum A-MPDU is 65535bytes. For 802.11ac the maximum is even 1Mbyte!
And your max internet packet (1492 bytes) is not that much larger than this test with 1000byte packets.
Klembord-1.jpg
http://forum.mikrotik.com/t/how-to-get-rid-of-slow-wifi-can-it-be-done/139640/1
http://forum.mikrotik.com/t/802-11ac-wave2-support/127501/1

Mikrotik has a rather poor aggregation implementation with smaller sizes and static settings. Other brands implement an intelligent adaptive algorithm and the full standard sizes.

And one more: most forum users know that the software “stable” channel is far from stable. The performance of the 6.48(.0) is unknown. Use LongTerm for operating Mikrotik devices.

A setting suggestion I would have, if you don’t already have it, is to try enabling “adaptive noise immunity” on the CAP device itself. This is done through the advanced tab of the wireless interface. You will have to temporarily switch off the CAP functionality in order to change this setting, otherwise it will forbid the change due to being managed by the CAPsMAN.

Just as additional information, my hAP Lite connection.

  • Its used for SSTP tunnels to Mikrotik sites that must be managed, so speed never was an issue.
    -The Internet ISP link is VDSL 30Mbps download, 6 Mbps upload
    -Old Dell laptop, only has 2.4 GHz also.
    -hAP Lite is in the garage near other AP , 3 brick walls to pass, more AP’s in the house and from neighbors

Important, to be checked number, is the TX Rate in the AP (the PHY) . It fluctuates 72Mbps(65Mbps)/20MHz/1S/SGI for TX rate (download), it’s 26 Mbps/20MHz/1S/(LGI) for upload.
20 MHz as normal setting, only 1 stream active (3 wall’s!), -50dBm at PC, -57dBm at AP
Some co-channel interference, but worse some adjacent channel interference (damned ISP with their default “auto” setting @neighborgs !)
PC wrongly reports 144Mbps (that’s what the interface could have as PHY when both streams were used).

Long range throughput test (including VDSL and ISP uplink delays) show 25.94Mps download. Well within the expected performance.
Directly connected to the ISP modem gives the same Speedtest.net result.
The hAP Lite is not the bottleneck.
.

Klembord-1.jpg

Okay, I’ll try that too.

Thanks for the tip. It was leftover from a previous config.

The idea came from Ron Touw, a professional who has 25 years of experience in wireless networks and RF systems in general. By removing support for 802.11 a,b and g and excluding all data rates below 12Mbps, more airtime can be spent with useful data transfer and much less time is used for transmitting beacons. Any wireless device that was manufactured after 2010 will only benefit from this. He is talking about this in this video https://www.youtube.com/watch?v=nCB4hL0f1VQ at 1:09.

I was only looking at the CPU. Both mAP lite and HAP Lite have QCA9533 CPU. But now that you drew my attention, I can see that they have different architectures. I’m confused! How can they have the same CPU but different architecture?

Oh, I see. In that case, one phyisical 802.11n frame can contain up to 40 L2 frames. @bpwl just mentioned that CAPsMAN reduces the A-MSDU to 2048 by default. If that is true, then this also cannot explain the big difference in speed.

I wonder if A-MSDU can be configured in any way?

And why is that? Is it because of some hardware limitation? Or is it just because it was not implemented in software?

Thank you for the tip. I’m going to downgrade on all devices.