RB4011iGS+5HacQ2HnD-IN Issues

Hello.

I want to use wifi adapters as cap interfaces, but sometimes only 5Ghz sometimes both of them continuously restarting (every second).
I tried with Frame-Lifetime: 0.01 or 0.02, disabling chains 2 and 3, setting manual tx power 20dBm and less - still the same.
I have Metal AP and wAP ac - they work just fine.
I already tried different scenarios: only 4011 wifi as cap, all devices (which I have) as caps, but no matter what I’m doing only 4011 fails.

Jan/22/2021 16:48:15 caps,info CAP connected to RB4011 (::ffff:10.0.0.1:5246), CommonName 'CAPsMAN-536FB1C7A5C3'
Jan/22/2021 16:48:15 caps,info 00:98:66:EB:F5:3F@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:15 caps,info B4:E6:2D:4B:B7:47@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:15 caps,info B4:E6:2D:4B:B7:86@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:15 caps,info B4:E6:2D:4B:B8:A3@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:15 caps,info DC:4F:22:6F:70:62@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:15 caps,info [::ffff:192.168.88.1:49591,Join,[08:55:31:1F:AF:BC]] joined, provides radio(s): 48:8F:5A:C8:9A:29,08:55:31:1F:AF:C7
Jan/22/2021 16:48:15 caps,info CAP joined RB4011 (::ffff:10.0.0.1:5246)
Jan/22/2021 16:48:15 caps,info cap 4011 - 2.4GHz: selected channel 2462/20-eC/gn(20dBm) (fixed)
Jan/22/2021 16:48:17 caps,info DC:4F:22:6F:70:62@cap 4011 - 2.4GHz connected, signal strength -60
Jan/22/2021 16:48:17 interface,info cap 4011 - 2.4GHz detect LAN
Jan/22/2021 16:48:17 caps,info B4:E6:2D:4B:B7:86@cap 4011 - 2.4GHz connected, signal strength -56
Jan/22/2021 16:48:18 caps,info 00:98:66:EB:F5:3F@cap 4011 - 2.4GHz connected, signal strength -55
Jan/22/2021 16:48:18 system,info,account user thefear logged in from 192.168.88.244 via winbox
Jan/22/2021 16:48:18 caps,info B4:E6:2D:4B:B8:A3@cap 4011 - 2.4GHz connected, signal strength -54
Jan/22/2021 16:48:19 caps,info cap 4011 - 5GHz: selected channel 5320/20-eeeC/ac/DP(23dBm)+5775/80(30dBm)
Jan/22/2021 16:48:23 caps,info CAP sent max keepalives without response
Jan/22/2021 16:48:23 caps,info CAP disconnected from RB4011 (::ffff:10.0.0.1:5246)
Jan/22/2021 16:48:26 caps,info CAP selected CAPsMAN RB4011 (::ffff:10.0.0.1:5246)
Jan/22/2021 16:48:26 caps,info CAP connected to RB4011 (::ffff:10.0.0.1:5246), CommonName 'CAPsMAN-536FB1C7A5C3'
Jan/22/2021 16:48:26 caps,info 00:98:66:EB:F5:3F@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:26 caps,info B4:E6:2D:4B:B7:86@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:26 caps,info B4:E6:2D:4B:B8:A3@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:26 caps,info DC:4F:22:6F:70:62@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:26 caps,info [::ffff:192.168.88.1:56082,Join,[08:55:31:1F:AF:BC]] joined, provides radio(s): 48:8F:5A:C8:9A:29,08:55:31:1F:AF:C7
Jan/22/2021 16:48:26 caps,info CAP joined RB4011 (::ffff:10.0.0.1:5246)
Jan/22/2021 16:48:26 caps,info cap 4011 - 2.4GHz: selected channel 2462/20-eC/gn(20dBm) (fixed)
Jan/22/2021 16:48:26 caps,info B4:E6:2D:4B:B7:47@cap Metal AP connected, signal strength -70
Jan/22/2021 16:48:26 dhcp,info dhcp1 deassigned 192.168.88.52 from B4:E6:2D:4B:B7:47
Jan/22/2021 16:48:26 dhcp,info dhcp1 assigned 192.168.88.52 to B4:E6:2D:4B:B7:47
Jan/22/2021 16:48:27 caps,info DC:4F:22:6F:70:62@cap 4011 - 2.4GHz connected, signal strength -59
Jan/22/2021 16:48:27 interface,info cap 4011 - 2.4GHz detect LAN
Jan/22/2021 16:48:29 caps,info 00:98:66:EB:F5:3F@cap 4011 - 2.4GHz connected, signal strength -55
Jan/22/2021 16:48:30 caps,info cap 4011 - 5GHz: selected channel 5320/20-eeeC/ac/DP(23dBm)+5775/80(30dBm)
Jan/22/2021 16:48:32 caps,info B4:E6:2D:4B:B7:86@cap 4011 - 2.4GHz connected, signal strength -55
Jan/22/2021 16:48:33 interface,info ip-tunnel-RSAUTOS detect WAN
Jan/22/2021 16:48:33 caps,info B4:E6:2D:4B:B8:A3@cap 4011 - 2.4GHz connected, signal strength -54
Jan/22/2021 16:48:34 caps,info CAP sent max keepalives without response
Jan/22/2021 16:48:34 caps,info CAP disconnected from RB4011 (::ffff:10.0.0.1:5246)
Jan/22/2021 16:48:36 caps,info CAP selected CAPsMAN RB4011 (::ffff:192.168.88.1:5246)
Jan/22/2021 16:48:36 caps,info CAP connected to RB4011 (::ffff:192.168.88.1:5246), CommonName 'CAPsMAN-536FB1C7A5C3'
Jan/22/2021 16:48:36 caps,info 00:98:66:EB:F5:3F@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:36 caps,info B4:E6:2D:4B:B7:86@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:36 caps,info B4:E6:2D:4B:B8:A3@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:36 caps,info DC:4F:22:6F:70:62@cap 4011 - 2.4GHz disconnected, interface disabled
Jan/22/2021 16:48:36 caps,info [::ffff:192.168.88.1:58188,Join,[08:55:31:1F:AF:BC]] joined, provides radio(s): 48:8F:5A:C8:9A:29,08:55:31:1F:AF:C7
Jan/22/2021 16:48:36 caps,info CAP joined RB4011 (::ffff:192.168.88.1:5246)

I tried to use wifi interfaces without cap configuration, and it’s a lot better, but not perfect.
Wi-Fi not restarting anymore (http://forum.mikrotik.com/t/rb4011-wlan1-disabling-itself/125605/263), but 5GHz drops packets (around 5% of them). 2.4GHz is ok.
mikrotik ping 2.4ghz.png
mikrotik ping 5ghz.png
PS. A already tried with different RouterOS versions - still the same. Before 4011 I used RB450G with wAP ac - no issues at all.

UPDATE:

LAN Bridge network for CAPsMAN is - 192.168.88.0/24

I noticed in logs that both 4011 caps trying to connect to 10.0.0.1 (which is local ip address for ip-tunnel).
No issues with 3rd cap interface Metal AP. Only with 4011.

When I disable the ip 10.0.0.1 both caps connected successfully to CAPsMAN. wow

Packets drop for 5GHz is still present (around 5% of them). Do you have any ideas?

Thanks in advance.

PS. This configuration has been exported from RB450G and it works without any issues with ip tunnels, but RB450G doesn’t have any local wifi interfaces :confused:

Not without seeing complete (or most of) setup of RB4011.

Hi.
Here you go.

# jan/22/2021 12:17:49 by RouterOS 6.48
# software id = VGUM-JIWC

/caps-man channel
add band=5ghz-n/ac name=5_auto
add band=2ghz-g/n extension-channel=Ce name=2.4_auto
add band=5ghz-n/ac extension-channel=eeeC frequency=5320 name=channel56
add band=2ghz-g/n extension-channel=Ce frequency=2412 name=channel1
add band=2ghz-g/n extension-channel=eC frequency=2462 name=channel11
add band=5ghz-n/ac extension-channel=eCee frequency=5200 name=channel40
add band=5ghz-n/ac extension-channel=Ceee frequency=5520 name=channel104
add band=5ghz-n/ac extension-channel=eeCe frequency=5785 name=channel157
add band=5ghz-n/ac extension-channel=eeeCeeee frequency=5600 name=\
    channel64-160MHz
add band=5ghz-n/ac extension-channel=Ceee frequency=5600 name=channel120
/interface wireless
# managed by CAPsMAN
# channel: 2462/20-eC/gn(24dBm), SSID: ssid2, CAPsMAN forwarding
set [ find default-name=wlan2 ] antenna-gain=0 band=2ghz-g/n channel-width=\
    20/40mhz-eC country=no_country_set frequency=2462 frequency-mode=\
    manual-txpower mode=ap-bridge name=wlan-2.4 ssid=\
    "MT" \
    station-roaming=enabled wireless-protocol=802.11
# managed by CAPsMAN
# channel: 5320/20-eeeC/ac/DP(23dBm)+5775/80(30dBm), SSID: ssid3, CAPsMAN forwarding
set [ find default-name=wlan1 ] antenna-gain=0 band=5ghz-n/ac channel-width=\
    20/40/80mhz-eeeC country=no_country_set frame-lifetime=1 frequency=5320 \
    frequency-mode=manual-txpower mode=ap-bridge name=wlan-5 rx-chains=0,1 \
    ssid="MT" station-roaming=enabled \
    tx-chains=0,1 wireless-protocol=802.11
/interface bridge
add name=LAN
add name=VPN
add admin-mac=00:0C:42:5C:4A:0F auto-mac=no name=WAN
/interface ethernet
set [ find default-name=ether1 ] name=eth1
set [ find default-name=ether2 ] name=eth2
set [ find default-name=ether3 ] name=eth3
set [ find default-name=ether4 ] name=eth4
set [ find default-name=ether5 ] name=eth5
set [ find default-name=ether6 ] name=eth6
set [ find default-name=ether7 ] name=eth7
set [ find default-name=ether8 ] name=eth8
set [ find default-name=ether9 ] name=eth9
set [ find default-name=ether10 ] name=eth10
set [ find default-name=sfp-sfpplus1 ] advertise=1000M-half,1000M-full \
    disabled=yes name=sfp
/interface pptp-client
add comment="to name4" connect-to=name4.domain.com name=pptp-name4 \
    password=t3m6qhws user=ts-name5
add comment="to name3 " connect-to=name3.domain.com disabled=no \
    name=pptp-name3 password=some_password user=ts-name5
/interface ipip
add allow-fast-path=no name=ip-tunnel-name2 remote-address=name2.domain.com
add allow-fast-path=no comment="to name1" ipsec-secret=\
    some_password name=ip-tunnel-name1 remote-address=\
    name1.domain.com
add comment="to name3" disabled=yes name=ip-tunnel-name3 remote-address=\
    name3.domain.com
/caps-man datapath
add bridge=LAN client-to-client-forwarding=yes local-forwarding=no name=\
    datapath-LAN
add bridge=VPN client-to-client-forwarding=yes local-forwarding=no name=\
    datapath-VPN
/caps-man security
add authentication-types=wpa-psk,wpa2-psk encryption=aes-ccm \
    group-encryption=aes-ccm name=security1 passphrase=some_password
/caps-man configuration
add channel=5_auto country="united kingdom" datapath=datapath-LAN mode=ap \
    name=cfg-5auto security=security1 ssid=\
    "MT"
add channel=2.4_auto datapath=datapath-LAN mode=ap name=cfg-2.4auto security=\
    security1 ssid=\
    "MT"
add channel=channel1 datapath=datapath-LAN mode=ap name=cfg1 security=\
    security1 ssid=\
    "MT"
add channel=channel11 datapath=datapath-LAN mode=ap name=cfg11 security=\
    security1 ssid=\
    "MT"
add channel=channel56 datapath=datapath-LAN mode=ap name=cfg56 rx-chains=0,1 \
    security=security1 ssid="MT" \
    tx-chains=0,1
add channel=channel40 country=bulgaria datapath=datapath-LAN mode=ap name=\
    cfg40 security=security1 ssid=\
    "MT"
add channel=channel104 datapath=datapath-LAN mode=ap name=cfg104 security=\
    security1 ssid="MT"
add channel=channel157 country=no_country_set datapath=datapath-LAN mode=ap \
    name=cfg157 security=security1 ssid=\
    "MT"
add channel=channel1 datapath=datapath-VPN mode=ap name=cfg1-vpn security=\
    security1 ssid=ssid
add channel=channel11 datapath=datapath-VPN mode=ap name=cfg11-vpn security=\
    security1 ssid=ssid
add channel=channel56 datapath=datapath-VPN mode=ap name=cfg56-vpn security=\
    security1 ssid=ssidiA
add channel=channel120 country="united kingdom" datapath=datapath-LAN \
    installation=indoor mode=ap name=cfg120 security=security1 ssid=\
    "MT"
add channel=channel64-160MHz country=no_country_set datapath=datapath-LAN \
    mode=ap name=cfg64-160MHz security=security1 ssid=\
    "MT"
/caps-man interface
add channel.tx-power=24 configuration=cfg11 configuration.installation=indoor \
    configuration.rx-chains=0,1 configuration.tx-chains=0,1 disabled=no \
    l2mtu=1600 mac-address=48:8F:5A:C8:9A:29 master-interface=none name=\
    "cap 4011 - 2.4GHz" radio-mac=48:8F:5A:C8:9A:29 radio-name=488F5AC89A29
add configuration=cfg56 configuration.frame-lifetime=10ms \
    datapath.local-forwarding=no disabled=no l2mtu=1600 mac-address=\
    08:55:31:1F:AF:C7 master-interface=none name="cap 4011 - 5GHz" radio-mac=\
    08:55:31:1F:AF:C7 radio-name=0855311FAFC7
add configuration=cfg1 disabled=no l2mtu=1600 mac-address=4C:5E:0C:84:79:DE \
    master-interface=none name="cap Metal AP" radio-mac=4C:5E:0C:84:79:DE \
    radio-name=4C5E0C8479DE
/interface ethernet switch port
set 0 default-vlan-id=0
set 1 default-vlan-id=0
set 2 default-vlan-id=0
set 3 default-vlan-id=0
set 4 default-vlan-id=0
set 5 default-vlan-id=0
set 6 default-vlan-id=0
set 7 default-vlan-id=0
set 8 default-vlan-id=0
set 9 default-vlan-id=0
set 10 default-vlan-id=0
set 11 default-vlan-id=0
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk eap-methods="" \
    mode=dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=\
    some_password wpa2-pre-shared-key=some_password
/ip pool
add name=dhcp_pool0 ranges=192.168.89.100-192.168.89.254
add name=dhcp_pool1 ranges=192.168.88.50-192.168.88.254
/ip dhcp-server
add address-pool=dhcp_pool1 disabled=no interface=LAN name=dhcp1
/ppp profile
add bridge=LAN dns-server=8.8.8.8,1.1.1.1 local-address=192.168.89.1 name=\
    VPN-LAN remote-address=dhcp_pool0
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes
/caps-man manager interface
add disabled=no forbid=yes interface=ip-tunnel-name1
add disabled=no forbid=yes interface=ip-tunnel-name3
add disabled=no forbid=yes interface=l2tp-name3
add disabled=no forbid=yes interface=pptp-name4
add disabled=no forbid=yes interface=pptp-name3
add disabled=no forbid=yes interface=ip-tunnel-name2
/caps-man provisioname2ng
add action=create-dynamic-enabled master-configuration=cfg-2.4auto
add action=create-dynamic-enabled master-configuration=cfg-5auto
/interface bridge port
add bridge=LAN interface=eth1
add bridge=LAN interface=eth2
add bridge=LAN interface=eth3
add bridge=LAN interface=eth4
add bridge=LAN interface=eth5
add bridge=LAN interface=eth6
add bridge=LAN interface=eth7
add bridge=LAN interface=eth8
add bridge=WAN interface=eth9
add bridge=LAN interface=eth10
add bridge=LAN interface=wlan-5
add bridge=LAN interface=wlan-2.4
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ip settings
set accept-redirects=yes accept-source-route=yes
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set default-profile=VPN-LAN enabled=yes ipsec-secret=some_password use-ipsec=yes
/interface pptp-server server
set authentication=chap,mschap1,mschap2 default-profile=VPN-LAN enabled=yes
/interface wireless cap
# 
set discovery-interfaces=LAN enabled=yes interfaces=wlan-2.4,wlan-5
/ip address
add address=192.168.89.1/24 interface=VPN network=192.168.89.0
add address=192.168.88.1/24 interface=LAN network=192.168.88.0
add address=10.0.0.1/30 interface=ip-tunnel-name1 network=10.0.0.0
add address=10.0.0.5/30 interface=ip-tunnel-name2 network=10.0.0.4
add address=10.0.0.9/30 interface=ip-tunnel-name3 network=10.0.0.8
/ip cloud
set ddns-enabled=yes ddns-update-interval=10m
/ip dhcp-client
add disabled=no interface=WAN
/ip dhcp-server network
add address=192.168.88.0/24 dns-server=1.1.1.1,8.8.8.8,80.80.80.80 gateway=\
    192.168.88.1
add address=192.168.99.0/24 dns-server=1.1.1.1,8.8.8.8,80.80.80.80 gateway=\
    192.168.99.1
/ip dns
set allow-remote-requests=yes servers=1.1.1.1,8.8.8.8,80.80.80.80
/ip firewall address-list
add address=123.456.789.123 list=WAN
add address=domain.com list=domain.com
add address=beaconcomms.domain.com list=domain.com
add address=site.net list=site-vpn
add address=192.168.0.0/23 list=site-vpn
add address=192.168.100.0/24 list=site-vpn
add address=reports.domain.com list=domain.com
add address=122.51.240.0/24 list=blocked
add address=195.54.160.0/24 list=blocked
add address=1.180.0.0/16 list=blocked
add address=138.99.6.0/24 list=blocked
add address=129.158.122.65 list=blocked
add address=193.174.89.19 list=blocked
add address=89.248.174.0/24 list=blocked
add address=121.54.0.0/16 list=blocked
add address=130.61.48.0/24 list=blocked
add address=103.30.92.0/24 list=blocked
add address=189.223.233.0/24 list=blocked
add address=94.66.77.0/24 list=blocked
add address=109.64.162.0/24 list=blocked
add address=83.97.20.0/24 list=blocked
add address=112.201.78.0/24 list=blocked
add address=179.33.226.0/24 list=blocked
add address=179.186.38.0/24 list=blocked
add address=180.183.4.0/24 list=blocked
add address=45.248.57.0/24 list=blocked
add address=87.10.94.0/24 list=blocked
add address=195.154.61.0/24 list=blocked
add address=209.212.202.0/24 list=blocked
add address=10.0.1.0/24 list=site-vpn
add address=212.129.33.0/24 list=blocked
add address=129.204.0.0/16 list=blocked
add address=49.235.0.0/16 list=blocked
add address=5.182.210.0/24 list=blocked
add address=47.52.0.0/16 list=blocked
add address=140.143.0.0/16 list=blocked
add address=62.210.185.0/24 list=blocked
add address=104.248.224.0/24 list=blocked
add address=84.38.0.0/16 list=blocked
add address=35.203.155.0/24 list=blocked
add address=106.53.0.0/16 list=blocked
add address=13.75.157.0/24 list=blocked
add address=106.52.0.0/16 list=blocked
add address=148.72.31.0/24 list=blocked
add address=122.51.0.0/16 list=blocked
add address=51.15.147.0/24 list=blocked
add address=91.247.36.0/24 list=blocked
add address=91.32.238.0/24 list=blocked
add address=54.86.0.0/16 list=blocked
add address=183.56.0.0/16 list=blocked
add address=94.111.43.0/24 list=blocked
add address=132.232.0.0/16 list=blocked
add address=5.188.0.0/16 list=blocked
add address=45.145.0.0/16 list=blocked
add address=93.174.93.0/24 list=blocked
add address=41.192.0.0/16 list=blocked
add address=185.100.0.0/16 list=blocked
add address=arenabg.ch list=site-vpn
add address=siteb.com list=siteb
/ip firewall filter
add action=fasttrack-connection chain=forward
add action=drop chain=input dst-port=53 in-interface=WAN protocol=udp
add action=drop chain=input dst-port=161-162 in-interface=WAN protocol=udp
add action=drop chain=input in-interface=WAN src-address-list=blocked
add action=drop chain=forward in-interface=WAN src-address-list=blocked
add action=drop chain=forward connection-state=invalid
add action=drop chain=forward connection-nat-state=!dstnat connection-state=\
    new in-interface=WAN
/ip firewall mangle
add action=mark-routing chain=prerouting new-routing-mark=vpn-name3 \
    passthrough=no src-address=192.168.88.59
add action=mark-routing chain=prerouting disabled=yes new-routing-mark=\
    vpn-name3 passthrough=no src-address=192.168.88.244
add action=mark-routing chain=prerouting dst-address=192.168.88.0/24 \
    new-routing-mark=lan passthrough=no src-address=192.168.88.0/24
add action=mark-routing chain=prerouting dst-address-list=site-vpn \
    new-routing-mark=vpn passthrough=no src-address=192.168.88.0/24
add action=mark-routing chain=prerouting dst-address-list=!site-vpn \
    new-routing-mark=lan-r passthrough=no src-address=192.168.88.0/24
/ip firewall nat
add action=masquerade chain=srcnat dst-address=!192.168.88.0/24 src-address=\
    192.168.88.0/24
add action=masquerade chain=srcnat dst-address=!192.168.99.0/24 src-address=\
    192.168.99.0/24
add action=src-nat chain=srcnat dst-address=192.168.88.10 out-interface=LAN \
    src-address=192.168.88.0/24 to-addresses=192.168.88.1
add action=dst-nat chain=dstnat dst-address-list=domain.com dst-port=80 \
    protocol=tcp to-addresses=192.168.88.10 to-ports=80
add action=dst-nat chain=dstnat disabled=yes dst-address-list=domain.com \
    dst-port=22 protocol=tcp to-addresses=192.168.88.10 to-ports=22
add action=dst-nat chain=dstnat disabled=yes dst-address-list=domain.com \
    dst-port=21 protocol=tcp to-addresses=192.168.88.10 to-ports=21
add action=masquerade chain=srcnat dst-address=192.168.88.0/24
/ip route
add distance=1 gateway=pptp-name3 routing-mark=vpn-name3
add distance=1 gateway=LAN routing-mark=lan
add distance=1 gateway=192.168.100.1 routing-mark=vpn
add distance=1 dst-address=192.168.95.0/24 gateway=10.0.0.2
add distance=1 dst-address=192.168.99.0/24 gateway=10.0.0.6
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=LAN type=internal
add interface=WAN type=external
/ppp secret
add local-address=192.168.89.1 name=user1 password=some_password profile=VPN-LAN
add local-address=192.168.89.1 name=user2 password=some_password profile=VPN-LAN
add local-address=192.168.89.1 name=user3 password=some_password profile=VPN-LAN
/snmp
set enabled=yes trap-generators=interfaces
/system clock
set time-zone-name=Europe/London
/system identity
set name=RB4011
/system leds
add interface=wlan-2.4 leds="wlan-2.4_signal1-led,wlan-2.4_signal2-led,wlan-2.\
    4_signal3-led,wlan-2.4_signal4-led,wlan-2.4_signal5-led" type=\
    wireless-signal-strength
add interface=wlan-2.4 leds=wlan-2.4_tx-led type=interface-transmit
add interface=wlan-2.4 leds=wlan-2.4_rx-led type=interface-receive
/system logging
add action=disk topics=info
/system note
set show-at-login=no
/system routerboard settings
set auto-upgrade=yes
/tool graphing
set store-every=hour
/tool graphing interface
add store-on-disk=no
/tool graphing resource
add store-on-disk=no
/tool romon
set enabled=yes



Packets drop for 5GHz is still present (around 5% of them).

UPDATE:
I removed Frame-Lifetime value (setting to default) and there is no packet loss.
ping.png

Hi.

The problem above with the caps gone when I remove the ip-tunnels.
However I must use several VPN connections and I tried with PPTP.
Connection have been successfully established, but the performance was awful (slow connection), until disabling/removing default Fasttrack connection rule.

The 4011 is powered by PoE+ Switch (TL-SF1005P V2) and once in a week the router shutdown itself. I need to restart it from the power source to make it run again.
The switch can deliver up to 30 W per port and 67 W for all PoE ports.
I have only one more PoE Camera connected to this switch.
Camera’s power consumption is 48V PoE( IEEE 802.3af),<8W
The power should be more than enough.

There is no attachments connected to 4011 (no PoE devices, no SFP).
I doubt that the issue comes from the switch, because 4011 is connected on the first port and if the power is not enough it going to disable other devices first.