Looking for feedback on deploying multiple wifi access points

I’m looking for community input on configuring access points (APs) across a yard site. Each of the circles in the drawing is a metal grain bin ranging from 30 to 70 feet in height. The square buildings have metal roofs and metal sides.

A, B & C are three locations of mANTBox ax 15s (L22UGS-5HaxD2HaxD-15S-US) Wi-Fi access points. The angles suggest the Wi-Fi antenna orientation for coverage. They are approx 2m from the top of the bins. The drawing is not to scale. The circles at the base sit 400m from point A. East to west would be a distance of 300m.

A point-to-point link connects the antenna at point A to point C. Point C is an 85ft tower. The point-to-point ends are above the bins. There is a fiber connection between points B and C. There is a fiber connection to point C from off the map. There you’ll find the edge router. All antennas are in the same VLAN.

My questions are:

Do I need to deploy CAPsMAN?

If yes, can you describe some benefits?

If yes do I need an additional router to manage the service?

Do all points use the same SSID or do I make them different?

Do antennas require placement within a single vlan?

Is a distinct VLAN necessary?

I will apologize upfront if I ask a lot of questions when you respond. I’m trying to learn from your experience. My journey with MikroTik began in the middle of 2025, when I built the network from scratch. I still consider myself a beginner. I am the single point of contact for network support, so getting it right is my sole responsibility.

If you have any observations outside my questions, please send them along. I would like to flesh out the design before I schedule anymore cherry picker visits to the antennas.

How Is the point-to-point link between A and C made?
Generally speaking using CAPsMAN may help in faster transitioning when moving from the coverage of one antenna to another.
Definitely you want a same SSID for all the antennas.
Is the Edge router also a Mikrotik?

  1. Optional, but even with the number of access points, it is a distinct benefit. You will need to set the access points to a CAPsMAN configuration, which is quite basic
  2. Benefits are a single config for the access points and one setup on the CAPsMAN server
  3. If you have an existing Mikrotik device running RouterOS, then No, otherwise, Yes, you need a Mikrotik device running RouterOS
  4. Your choice. The same would be normal
  5. They should all be on the same vLAN or all on the native LAN
  6. A vLAN is optional and in part dictated by the rest of your system. [I think I am right in remembering you posted a while ago about a larger system, of which this looks like a part.] If you need a guest network too, then you could do that without a vLAN, but one would be strongly recommended.

Ubiquiti Nano5A Airos8 point-to-point.

350-360mb is what I am seeing.

Yes edgerouter is Mikrotik RB4011

Then the RB4011 Is the "right device" to run CapsMan.
Another advantage, unless the Cap configuration Is particularly complex Is the simplicity of resetting (if needed) It via Winbox;

Caps-Man is absolutely incredible on paper.

Damn impressive on the bench and test environments.

Unfortunately, it can crumble quickly in the real world.

This is mostly due to Mikrotiks in ability to correct wifi connectivity issues. Just the basics of keeping a client connected and passing traffic is Mikrotik's WIFI weakness.

They are very slow to react to known bugs or incompatibilities. Fixes can take years. (I have the documentation to make that statement.)

Now on the positive.

Caps-Man lets you set up a central controller for multiple access points in seconds. Once connected, the APs report to the controller every few seconds and you can monitor them in real time. Changing a SSID or password can propagate across APs in what appears to be instantly. The controller does not need to "RUN" on any real specialized hardware. I have successfully managed it off a switch I was gonna throw away after a decade of service, with several blown out ports. The APs are dirt cheap especially for outdoor rated gear.

Years ago, Mikrotik allowed you to make access control lists to do per device passwords. This was added when the competition's version 8-10 TIMES more expensive. And once you used these ACLS... you could see from second to second how a client was doing and exactly what radio it was connected to and as it moved. In recent years FT made that even better. Unfortunately it causes problems with some devices on the same SSID. But caps-man makes it easy to have multiple SSIDs and tweakable settings to avoid that problem.

In recent years MultiPhase group works where the ACL list used to have problems. So you can hand out passwords with out needing to know MAC addresses. (Very useful with all these devices defaulting to "private" or "Random" Mac addresses. But this doesn't work with WPA3 from what I am told. (Need to follow up on that one.)

As you may have noticed... I don't put caps-man in the field anymore. Got burned too many times.

I hold out hope and buy APs here and there and go back and forth with support. But I would not put them in an environment where they were expected to actually work.

I have been working on bug with support for months at this point. This is illustrated on my test bench. They were sending one "tip" per day. we reached the point where they were "stuck" again. So much like last time... the emails stopped.

If we follow the pattern from 2018... I will bitch publicly about it until I get a message like before. "We have managed to reproduce the issue..." "If or when we have a solution we will contact you." 5 years later they switches to chip based drivers. Which while they work better... still have their own quirks.

Thanks folks for the responses. Phew, no one came out with comments that made me rethink the deployment. 65ft up on the end of a lift working on antennas is on the fridge of IT work.

Why the necessity for single SSID? I worked in a build once that had multiple AP all using the same SSID. It was difficult to troubleshoot from an RF perspective.

What are the technical advantages for common SSID?

I'm not sold on CAPsMan.

What load does it introduce if I deploy the manager on the edgerouter RB4011?

My AP configurations are stable, no change. The three AP's are static. Fire and forget is my approach. The placement of the antennas cover blind spots. Point B was the first antenna deployed. A&C points came later as complaints of coverage increased.

The east side double row of bins is a blind spot alley. There a plans for some bin upgrades in the future that might open up the opportunity to place and antenna to cover that alley.

The 4011 won't even notice it.
But for three devices it also makes little sense (to me) to use CapsMan/Caps.
See:
help to configure - #11 by jaclaz

A single SSID should provide faster roaming (and less work for DHCP).
CapsMan/Caps should provide even faster roaming (but it isn't "needed").

Single SSID allows for devices to move between access points when their signal gets bad enough.

See above.

Its not caps-man that has been the problem for me... its been the radios themselves.

Next to none. But YOU HAVE TO KEEP THEM CONNECTED TO THE MANAGER. If the manager goes offline all the APs stop working. No SSID they just sit there. So its not like UniF--k where you set up the server and turn it on and off. But as I typed... it uses very few resources. So not much load at all.

I am all about set and forget... have installs that run for years with NO INTERVENTION at all. Some as long as a decade.

@jaclaz

In Caps-Man you can see the instant a client moves between 2 APs. Plus there is a central log of what the signal was at the time. Where it came from and where it went too.

Which is really helpful for location information and troubleshooting.

The instantly available and constantly updating registration table is addictive...

The environment has been a challenge. In addition to metal the height and using cherry picker to access it unnerving. Point C is 85 feet up. Access is via spiral stairs and ladder. Looking down is just metal gratting.

The final AP at point C has yet to be installed. The other two have been in service for a week. Still waiting for first complaint.

With all due respect, your people are slow :astonished_face: (or you did an exceptionally good job :slightly_smiling_face:), here I measure in minutes the time between a minor change or ordinary hiccup of the network and the start of complaining.

I will take the credit:) I will introduce an augh-shite at some point in the future that will wipe out the credit.

I made the change just before the start of shift. I advertised the change to the supervisor the day before, making them aware of how it would impact operations if it went south.

Now I haven't spoken to supervisor this morning. maybe i just haven't been told. I figure if it wasn't working I would have heard about it last week. Hope spring eternal.