Hi guys, thank you so much for everyone’s replies. I hope I’m providing better info with my 2nd post 
@erlinden, I hope I understood your requirements. Please find below. I’m hoping that the config shows something that might be useful.
Problem: When connected to the WiFi, 5ghz in this case, the response time of web sites, web sites take long to load, remote servers that I log into, seems to be “sluggish” and slow to respond upon commands given. It’s not as quick to open and respond when I’m connected with an ethernet cable for instance. Some of the laptops will be collected to the 5Ghz network and almost all personal mobile devices are connected to the 2.4Ghz network. Sometimes, the WiFi would be doing great, but most of the time, you’ll feel a BIG difference between being connected with an ethernet cable compared to the WiFi.
I’ve also attached a screenshot of the channels for 2.4Ghz and 5Ghz.
Also added speedtest. Which seems to be okay, but user still experience a “slow/sluggish” connection when connected to the WiFi.
Would it be better then to replace the hAP ac2 with theRB5009UG+S+IN that gigabyte09 suggested?
# aug/12/2024 16:11:41 by RouterOS 6.49.17
# software id = Y22R-I3EW
#
# model = RBD52G-5HacD2HnD
# serial number = Serial Number
/caps-man channel
add band=5ghz-n/ac control-channel-width=20mhz extension-channel=XX name=5Ghz \
reselect-interval=1h save-selected=no skip-dfs-channels=no tx-power=20
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=disabled \
frequency=2412 name=2412 reselect-interval=1h secondary-frequency=\
disabled tx-power=14
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=disabled \
frequency=2437 name=2437 reselect-interval=1h secondary-frequency=\
disabled tx-power=14
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=disabled \
frequency=2462 name=2462 reselect-interval=1h secondary-frequency=\
disabled tx-power=14
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=disabled \
name=2.4Ghz reselect-interval=1h save-selected=no tx-power=14
/interface bridge
add arp=proxy-arp name=bridge-lan
/interface ethernet
set [ find default-name=ether1 ] name=ether1-WAN
set [ find default-name=ether5 ] l2mtu=1596 mac-address=48:8F:5A:2C:2F:08 \
name=ether2-mtnlte
set [ find default-name=ether4 ] l2mtu=1596 mac-address=48:8F:5A:2C:2F:09 \
name=ether3-LAN
set [ find default-name=ether3 ] l2mtu=1596 mac-address=48:8F:5A:2C:2F:0A \
name=ether4-LAN
set [ find default-name=ether2 ] l2mtu=1596 mac-address=48:8F:5A:2C:2F:0B \
name=ether5
/interface pppoe-client
add add-default-route=yes disabled=no interface=ether1-WAN name="ISP Name" \
password=***** user=user@user
/interface l2tp-server
add name=l2tp-in1 user=vpn
add name=l2tp-in2-user1 user=user1
add name=l2tp-in3-user2 user=user2
/interface wireless
set [ find default-name=wlan1 ] ssid=MikroTik
set [ find default-name=wlan2 ] ssid=MikroTik
/caps-man datapath
add bridge=bridge-lan local-forwarding=yes name=Internet
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
group-key-update=40m name="WiFi Security" passphrase=********
/caps-man configuration
add channel=5Ghz country="south africa" datapath=Internet datapath.bridge=\
bridge-lan installation=indoor mode=ap name="Config 5G" rx-chains=0,1 \
security="WiFi Security" ssid="Pepla 5G" tx-chains=0,1
add channel=2.4Ghz country="south africa" datapath=Internet datapath.bridge=\
bridge-lan installation=indoor mode=ap name="Config 2.4Ghz" rx-chains=0,1 \
security="WiFi Security" ssid=Pepla tx-chains=0,1
/interface ethernet switch port
set 0 default-vlan-id=1 vlan-mode=fallback
set 1 default-vlan-id=1 vlan-mode=fallback
set 2 default-vlan-id=1 vlan-mode=fallback
set 3 default-vlan-id=1 vlan-mode=fallback
set 5 default-vlan-id=1 vlan-mode=fallback
/interface list
add name=WAN
add name=LAN
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip ipsec profile
set [ find default=yes ] enc-algorithm=aes-256,aes-128,3des
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha256,sha1
/ip pool
add name=dhcp ranges=192.168.0.11-192.168.0.239
add name=vpn ranges=192.168.89.2-192.168.89.255
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge-lan lease-time=4w name=\
dhcp
/ppp profile
add change-tcp-mss=yes local-address=192.168.89.1 name=RAS remote-address=vpn \
use-encryption=yes
/queue simple
add disabled=yes limit-at=100M/100M max-limit=100M/100M name=VPN target=\
154.73.32.0/32
add disabled=yes limit-at=80M/80M max-limit=80M/80M name=Rest queue=\
default/default target="" total-queue=default
/snmp community
set [ find default=yes ] addresses=154.73.32.1/32,154.73.32.2/32
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/caps-man access-list
add action=accept allow-signal-out-of-range=10s disabled=yes signal-range=\
-70..120 ssid-regexp=""
add action=reject allow-signal-out-of-range=10s disabled=yes signal-range=\
-120..-71 ssid-regexp=""
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes
/caps-man manager interface
set [ find default=yes ] forbid=yes
add disabled=no interface=bridge-lan
/caps-man provisioning
add action=create-dynamic-enabled hw-supported-modes=gn,b \
master-configuration="Config 2.4Ghz" name-format=identity
add action=create-dynamic-enabled hw-supported-modes=ac,an \
master-configuration="Config 5G" name-format=identity
/interface bridge port
add bridge=bridge-lan interface=ether3-LAN
add bridge=bridge-lan interface=ether4-LAN
add bridge=bridge-lan interface=ether5
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/interface l2tp-server server
set default-profile=RAS enabled=yes ipsec-secret="*********" \
use-ipsec=yes
/interface list member
add list=WAN
add interface=bridge-lan list=LAN
/interface pptp-server server
set default-profile=RAS enabled=yes
/interface sstp-server server
set default-profile=RAS enabled=yes
/ip address
add address=192.168.0.1/24 interface=bridge-lan network=192.168.0.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add default-route-distance=255 disabled=no interface=ether2-mtnlte
/ip dhcp-server lease
add address=192.168.0.27 client-id=1:0:14:fd:19:21:4d mac-address=\
00:14:FD:19:21:4D server=dhcp
/ip dhcp-server network
add address=192.168.0.0/24 dns-server=192.168.0.1 gateway=192.168.0.1 \
ntp-server=154.73.32.1,154.73.32.2
/ip dns
set allow-remote-requests=yes servers=\
8.8.8.8,154.73.32.2,2c0f:f720::1,2c0f:f720::2
/ip firewall address-list
add address=154.73.32.0/22 list=iewc-ip4s
add address=165.16.200.0/21 list=iewc-ip4s
add address=154.73.34.4/30 list=iewc-voice
add address=154.73.34.8/30 list=iewc-voice
add address=197.96.209.0/24 list=iewc-voice
add address=154.73.35.0/24 list=iewc-voice
/ip firewall filter
add action=accept chain=input connection-state=established,related
add action=accept chain=input protocol=ipsec-esp
add action=accept chain=input comment="allow IPsec NAT" dst-port=4500 \
protocol=udp
add action=accept chain=input comment="allow IKE" dst-port=500 protocol=udp
add action=accept chain=input comment="allow l2tp" dst-port=1701 protocol=udp
add action=accept chain=input comment="allow pptp" dst-port=1723 protocol=tcp
add action=accept chain=input comment="allow sstp" dst-port=443 protocol=tcp
add action=drop chain=input connection-state=invalid
add action=accept chain=input dst-port=22,2000,8291 protocol=tcp \
src-address-list=iewc-ip4s tcp-flags=syn,!fin,!rst,!ack
add action=accept chain=input icmp-options=8:0-255 protocol=icmp
add action=accept chain=input dst-port=53,123 in-interface=bridge-lan \
protocol=udp
add action=accept chain=input dst-port=22,8291 in-interface=bridge-lan \
protocol=tcp tcp-flags=syn,!fin,!rst,!ack
add action=accept chain=forward dst-port=19001 protocol=tcp
add action=drop chain=input
/ip firewall mangle
add action=accept chain=prerouting dst-address=192.168.0.0/24
/ip firewall nat
add action=masquerade chain=srcnat disabled=yes log=yes log-prefix=MARK \
out-interface=bridge-lan
add action=masquerade chain=srcnat
/ip firewall service-port
set tftp disabled=yes
set h323 disabled=yes
set sip disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip route
add distance=10 gateway=192.168.0.10
add comment=briisk-dev-collections.database.windows.net disabled=yes \
distance=1 dst-address=102.133.120.2/32 gateway=*B
add comment=2_briisk-dev-collections.database.windows.net disabled=yes \
distance=1 dst-address=102.133.152.32/32 gateway=*B
add comment=lecroc.dedicated.co.za disabled=yes distance=1 dst-address=\
165.73.81.148/32 gateway=*A
add comment=lecroc.dedicated.co.za disabled=yes distance=1 dst-address=\
165.73.81.148/32 gateway=*B
add comment=pepladev2.dedicated.co.za disabled=yes distance=1 dst-address=\
197.242.150.92/32 gateway=*A
add comment=pepladev2.dedicated.co.za disabled=yes distance=1 dst-address=\
197.242.150.92/32 gateway=*B
add comment=stimulusmaksima.dedicated.co.za disabled=yes distance=1 \
dst-address=197.242.159.114/32 gateway=*A
add comment=stimulusmaksima.dedicated.co.za disabled=yes distance=1 \
dst-address=197.242.159.114/32 gateway=*B
/ppp secret
add name=vpn password="*****"
add name=user1 password=********
add name=user2 password=******
add name=user3 password=********* profile=RAS
/radius
add address=154.73.34.18 secret=eevohch5mie0ou1P service=login
add address=154.73.34.19 secret=eevohch5mie0ou1P service=login
add address=154.73.34.18 secret=eevohch5mie0ou1P service=login
add address=154.73.34.19 secret=eevohch5mie0ou1P service=login
/system clock
set time-zone-name=Africa/Johannesburg
/system identity
set name=iewc-cpe-pepla
/system ntp client
set enabled=yes server-dns-names=kerberos.iewc.co.za,cerberus.iewc.co.za
/system scheduler
add interval=1d name=backup_daily on-event=backup_email policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=may/18/2018 start-time=00:30:00
add interval=1w name=auto_upgrade on-event="/system package update\r\
\ncheck-for-updates once\r\
\n:delay 30s\r\
\n:if ([ get status ] = \"New version is available\") do { install }" \
policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-date=mar/01/2023 start-time=00:30:00
/system script
add dont-require-permissions=no name=backup_email owner=admin policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive source="/export\
\_file=email;\r\
\n/tool e-mail send to=\"mikrotik@uls.co.za\" subject=(\"[CPE BACKUP] \".[\
/system identity get name]) body=(\"Note that this is an export.rsc file a\
nd not a backup.backup file for mikrotik.\") file=email.rsc;\r\
\n:log info \"Export email sent.\";"
/tool e-mail
set address=mail.iewc.co.za from=mikrotik@uls.co.za start-tls=yes
/user aaa
set use-radius=yes


