new CAPAC Owner

Good day, in over my head as usual, and after I get this working the rb450gx4 awaits its hex replacement fun. :slight_smile:

Scenario, main router is hex (later will be rb450gx4).
I will have two capACs in the house (one for now).
THey will only act as Access Points.

A. Should I configure them directly or should I enable Capsman on the HEX to set them up or modify (make changes to default setting).
B. I assume I basically go to capsman on the capAC and hit ENABLE (and then use the hex to program? no other selections required if I want to do it that way)
C. Since I wont be doing any routing with them I should really only focus on the wirless settings? (of course I changed default user name and created passwords).
D. Any security stuff I should apply or settings I should disable… (like remove packages not using)
E. Came with version 6.41.3 and intend to upgrade to latest as first move.

All comments, ideas, tips welcome!!

I will tackle VLANS much later.

I found some useful resources here
https://wiki.mikrotik.com/wiki/Manual:Interface/Wireless

and here to explain NV2 (although who the heck has TDMA client devices???)
https://wiki.mikrotik.com/wiki/Manual:Nv2

https://wiki.mikrotik.com/wiki/Wireless_Setups

https://wiki.mikrotik.com/wiki/Manual:Wireless_Debug_Logs (normis recommended in a thread I read)

https://wiki.mikrotik.com/wiki/Manual:Wireless_AP_Client

https://wiki.mikrotik.com/wiki/Manual:Wireless_FAQ

https://paper.bobylive.com/Network/Create_Virtual_AP_for_Campus.pdf

https://wiki.mikrotik.com/wiki/Manual:CAPsMAN

I will post any questions separately. Only comment thus far is that plugNplay the default on my network is flawless.
By default it knows you have no ACL list and thus allows connections. The ACL list is great concept. Not sure what the managment control feature is but it locked out users so disabled it.

Note: Hope to heck that my NEW capAC can host WPA3 as it should be implemented ASAP.

WISPs … and myself. I had to create wireless hop between two wired islands inside one house. I decided to go with dedicated radio for that wireless bridge and while at it, I decided to go with TDMA (started using nv2, currently running nstreme but I can switch to nv2 in no time).

Well just curious as down the line I will probably use a wifi link to a future shed/boathouse and was going to try a wired scenario but now with the 60 products and throughputs, it may not be necessary.
Can one do TMDA over such links and is the throughput better then???

As for the capAC, if I am just using the wireless (AP only bridge), should I assume none of the normal router functioning works or is to be used. Specifically the ACL list seems to be easy to create and with the default forward traffic doesnt have much effect but If I removed the default would the ACL rule come into affect?