Mikrotik or others on AX wifi access point

Guys, if this CAP AX would not be so a) huge and b) ugly I would dive right into the AX pool. But there is nothing from Mikrotik to replace some neat looking CAP AC. Maybe WAP AX…

I like configuration as code, that I can export/import, and have the full list of what was/is setup in one place, can diff and reason about.

I’ve only seen this with Cisco devices in school, but nowhere in SOHO/end-user-consumer (price) class of devices. I didn’t work with many, though.

But, I often feel like other brands offer better stability and reliability, but at cost of being very limited regarding features, and missing configuration as code - human readable export/import.

Well, I can say that looking at TP-Link Omada software it seems packed with a lot of features. It even has CLI… Didn’t explore that yet but I think it’s possible to export configuration.

For me, and in my use case, stability is main selling point. And PPSK… Which Mikrotik still doesn’t have…

access list entry with a passphrase and vlan-id is pretty much what other vendors advertise as PPSK?

Except that with EPSK… you can set the password and let devices connect.

In D-PSK you can set it up so the first devices to connect with that password owns it.

Is DPSK something proprietary by Ruckus?

It’s not… For access list to work you first need to create rule and add MAC address if I’m right. I don’t want to do that. Here I have one SSID and I input different password for VLAN I want my device to connect.

MAC address is not mandatory. Tried that recently. Created an entry with just passphrase and SSID and I was able to connect using that passphrase.

You created entry with a single SSID for multiple VLANs without inputting MAC address first ?

Yeah that never worked before. You need to enter the MAC address that ties to that Access list PSK.

I can’t test this as vlan assignment is unsupported on wifi-qcom-ac.



/interface wifi access-list add action=accept passphrase=foobar12 ssid-regexp=ap-guest

And why can I connect using passphrase “foobar12” on the SSID ap-guest which has a completely different global passphare configured? A thing that never worked (for you) just worked for me?

And on wifi-qcom it should also make vlan assignment:

/interface wifi access-list add action=accept passphrase=vlan10 vlan-id=10 ssid-regexp=your-ssid
/interface wifi access-list add action=accept passphrase=vlan20 vlan-id=20 ssid-regexp=your-ssid

Don’t need to test, it doesn’t work… Whole point of PPSK is to have one SSID and multiple PPSK profiles with different passwords.

What VLAN get’s assigned depends on password you input. On TP-Link you have PPSK with or without RADIUS for eg.

What Mikrotik have is overcomplicated workaround.

EDIT: Can you assing different VLAN ?

You are kidding or trolling, right?

https://community.tp-link.com/en/business/forum/topic/620762

What Mikrotik offers via access lists is IMHO the same what is describes by TP-LINK as:

1. Configuration Guide for PPSK without RADIUS.

And this doesn’t look “undercomplicated” either.

Mikrotik does not offer “autogeneration of PPSK”. OK - accepted. Maybe it works with Radius - can’t figure that out. And as far as I understood and found out, PPSK is not even a 802.11 standard at all. Ruckus, Cambium, TP-Link all brewing their own thingy. So does Mikrotik with their access list poor man’s PPSK method.

Auto generation is key point here… You can do that with RADIUS, but you need to use WPA-EAP which IoT devices often don’t support, you need MAC address as you have only one SSID and ONE password.

I believe you can do it without RADIUS on Mikrotik but still… You need MAC address of the device to assign correct VLAN to it. With other vendors you don’t need that, you have multiple passwords for that.

Don’t you gotta have a controller for all the good functions though, fast roaming etc… sounds more complicated than it needs to be unless you move all the way to another product/products. Sounds like you want Professional Network Technology for a £5

No, primary thing for me is to have stable wifi and in the last year or so unfortunately Mikrotik is not be able to provide that and honestly cost of Mikrotik wireless is pretty much the same as TP-Link or Unifi and they work better than Mikrotik wireless and that’s the fact.

Just as TP-Link or Unifi have their controllers, Mikrotik have CAPsMAN. Also Mikrotik have topic about their controller so one day we will have the same on Mikrotik.

Second day on TP-Link, not a single disconnect…

I will be more than happy to return to Mikrotik wireless, WHEN their wireless become competitive…

Switches and routers, great devices, there is no match regarding price, features and reliability but wireless… I have a feeling Mikrotik have wireless in their lineup just so they can say we have APs.

Wow… they finally got that working… too bad I had to change vendors 6 years ago.
Been deploying WiFi6 for like 4 years now.

Caps-man on the old drivers required the access list to have a mac address for PER DEVICE PASSWORDS to work.

Do you mean under stationary circumstances, or when moving around?

I’m having disconnects, instead of roaming, if I manage to get out of coverage of all AP(s), not just slowly fade away from original AP, and then enter area covered by other AP, but not by original AP anymore. I.e. when I move from one AP to other AP through a dead spot of all AP(s). But, that’s due to bad positioning (I want to hide them, plus cable management limitations) of limited amount of AP(s) with combination of 15cm, 20cm, 30cm, and 45cm thick walls and concrete floor.

Otherwise, it’s often stable and without issues.

One issue I had with “wifi”, when I connected after long time, was actually caused by bad configuration of CAKE queue. LAN access worked flawlessly straight after connecting, but WAN rx/tx was throttled after connection. I discovered the issue by having just one device sitting idle, but connected to wifi, and when I working with it after long inactivity, it behaved as “if I just connected to the wifi”. The CAKE queue interpreted inactivity as slow connection speed (autorate ingress), and throttled traffic. But, that’s off topic,… the point is, that it wasn’t wifi’s fault.

What I feel is different - performance at range. It seems to me, that other vendors can cover bigger range (distance + wall signal attenuation) than MikroTik AP’s, and connection is more stable even if device is too far from AP. But, that might be just subjective and false,.. I didn’t do a thorough side by side testing in the same building, with the same positioning and everything,… But, I would say other vendors are slightly better, from 5% to 35% depending on circumstances. I would welcome some experiment results on this. Because, performance is affected a lot by positioning of antennas. Just making device to lie flat, instead of standing vertically made a big difference. Somewhere signal was boosted, somewhere lowered.

Both.

Both APs are placed in the same spot and what I noticed with TP-Link is that roaming is working much more smoother and better. Going from one AP to another I don’t even notice that device roamed to another AP.

With cAP ax it was always disconnect, switching to 5G then reconnection to AP. Some devices on cAP ax won’t roam at all while on TP-Link they roam without a problem.

Stability is also different story. In my bathroom, which is only one brick wall away from AP Mikrotik struggles to maintain connection with frequent dropouts… So one brick wall, distance maybe 4 meters. TP-Link switch from 5 to 2.4GHz but signal bar is on full, no dropouts etc.

Outdoor use, my garage is maybe 10 meters from my house and I park my cars infront of the garage. With Mikrotik there is no way I get wifi. With TP-Link i get wifi and I can manage 50-60 Mbps DL and 30 Mbps UL. So range is greater, stability is better, roaming is working flawlesly.

Walking around the house signal from TP-Link is about 3-7 dBm better than Mikrotik. Have in mind that i bought cheapest TP-Link wifi6 AP.

Only thing that making me a problem is my laptop with AX200 wifi card. It keeps disconnecting after 5 min when using PPSK and keep asking for password. No other device do that, not my home laptop, not my wife’s laptop nor any other device. That’s something i have to research why is happening.