1. routeros-7.0beta1-arm.npk
2. RB4011iGS+5HacQ2HnD-IN
3. Just enable 5 GHz, set frequency to 5180 ceee, no secondary frequency, scan list to 5180
result: On status tab it tells me "initializing". It never starts sending any SSID.
MMM MMM KKK TTTTTTTTTTT KKK
MMMM MMMM KKK TTTTTTTTTTT KKK
MMM MMMM MMM III KKK KKK RRRRRR OOOOOO TTT III KKK KKK
MMM MM MMM III KKKKK RRR RRR OOO OOO TTT III KKKKK
MMM MMM III KKK KKK RRRRRR OOO OOO TTT III KKK KKK
MMM MMM III KKK KKK RRR RRR OOOOOO TTT III KKK KKK
MikroTik RouterOS 7.0beta3 (c) 1999-2019 http://www.mikrotik.com/
[?] Gives the list of available commands
command [?] Gives help on the command and list of arguments
[Tab] Completes the command/word. If the input is ambiguous,
a second [Tab] gives possible options
/ Move up to base level
.. Move up one level
/command Use command at the base level
[XXXXXXXX@MikroTik] > /export hide-sensitive
# oct/31/2019 14:10:02 by RouterOS 7.0beta3
# software id = YPJS-5AHL
#
# model = RB4011iGS+5HacQ2HnD
# serial number = B8E20ADDB8AD
/interface bridge
add arp=reply-only name=Guest_Bridge
add admin-mac=74:4D:28:XX:XX:XX auto-mac=no comment=defconf name=bridge
/interface wireless
set [ find default-name=wlan2 ] antenna-gain=3 band=2ghz-onlyn channel-width=20/40mhz-XX country="united kingdom" disabled=no distance=indoors frequency=auto frequency-mode=regulatory-domain installation=indoor mode=ap-bridge name=2.4Ghz ssid=\
Net_2 wireless-protocol=802.11 wps-mode=disabled
set [ find default-name=wlan1 ] antenna-gain=3 band=5ghz-n/ac channel-width=20/40/80mhz-Ceee country="united kingdom" disabled=no distance=indoors frequency=auto frequency-mode=regulatory-domain installation=indoor mode=ap-bridge name=5Ghz \
secondary-channel=auto ssid=Net_5 wireless-protocol=802.11 wps-mode=disabled
/interface ethernet switch port
set 0 default-vlan-id=0
set 1 default-vlan-id=0
set 2 default-vlan-id=0
set 3 default-vlan-id=0
set 4 default-vlan-id=0
set 5 default-vlan-id=0
set 6 default-vlan-id=0
set 7 default-vlan-id=0
set 8 default-vlan-id=0
set 9 default-vlan-id=0
set 10 default-vlan-id=0
set 11 default-vlan-id=0
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=dynamic-keys supplicant-identity=MikroTik
add authentication-types=wpa2-psk eap-methods="" mode=dynamic-keys name=Guests supplicant-identity=MikroTik
/interface wireless
add default-forwarding=no disabled=no mac-address=76:4D:28:XX:XX:XX master-interface=2.4Ghz name=2.4Ghz_Guests security-profile=Guests ssid=Net_G wps-mode=disabled
add default-forwarding=no disabled=no mac-address=76:4D:28:XX:XX:XX master-interface=5Ghz name=5Ghz_Guests security-profile=Guests ssid=Net_G wps-mode=disabled
/ip ipsec mode-config
add name=NordVPN responder=no src-address-list=local
/ip ipsec policy group
add name=NordVPN
/ip ipsec profile
add name=NordVPN
/ip ipsec peer
add address=uk1394.nordvpn.com disabled=yes exchange-mode=ike2 name=NordVPN profile=NordVPN
/ip ipsec proposal
add disabled=yes name=NordVPN pfs-group=none
/ip pool
add name=dhcp_lan ranges=192.168.10.10-192.168.10.35
add name=dhcp_guests ranges=10.1.1.2-10.1.1.25
/ip dhcp-server
add address-pool=dhcp_lan disabled=no interface=bridge lease-time=12h name=LAN
add add-arp=yes address-pool=dhcp_guests disabled=no interface=Guest_Bridge lease-time=12h name=Guests
/interface bridge filter
add action=drop chain=forward in-interface=5Ghz_Guests
add action=drop chain=forward out-interface=5Ghz_Guests
add action=drop chain=forward in-interface=2.4Ghz_Guests
add action=drop chain=forward out-interface=2.4Ghz_Guests
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=ether6
add bridge=bridge comment=defconf interface=ether7
add bridge=bridge comment=defconf interface=ether8
add bridge=bridge comment=defconf interface=ether9
add bridge=bridge comment=defconf interface=ether10
add bridge=bridge comment=defconf interface=sfp-sfpplus1
add bridge=bridge comment=defconf interface=5Ghz
add bridge=bridge comment=defconf interface=2.4Ghz
add bridge=Guest_Bridge interface=5Ghz_Guests
add bridge=Guest_Bridge interface=2.4Ghz_Guests
/ip neighbor discovery-settings
set discover-interface-list=LAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=Guest_Bridge list=LAN
/ip address
add address=192.168.10.1/24 comment=defconf interface=bridge network=192.168.10.0
add address=10.1.1.1/24 interface=Guest_Bridge network=10.1.1.0
/ip dhcp-client
add comment=defconf dhcp-options=hostname,clientid disabled=no interface=ether1 use-peer-dns=no use-peer-ntp=no
/ip dhcp-server lease
add address=192.168.10.12 client-id=XXXXXXXXXXX comment="Nvidia Shield" mac-address=00:04:4B:XX:XX:XXX server=LAN
add address=192.168.10.101 client-id=XXXXXXXXXXXX comment=Synology mac-address=00:11:32:XX:XX:XX server=LAN
add address=10.1.1.4 mac-address=XXXXXXXXXXXXXXX server=Guests
/ip dhcp-server network
add address=10.1.1.0/24 dns-server=10.1.1.1 gateway=10.1.1.1 netmask=24
add address=192.168.10.0/24 comment=defconf dns-server=192.168.10.1 gateway=192.168.10.1 netmask=24
/ip dns
set allow-remote-requests=yes servers=1.1.1.1,1.0.0.1
/ip dns static
add address=192.168.10.1 comment=defconf name=router.lan
/ip firewall address-list
add address=192.168.10.0/24 list=local
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=forward dst-address=192.168.10.101 dst-port=16881 in-interface-list=WAN protocol=tcp
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat disabled=yes dst-port=8883 in-interface-list=WAN protocol=tcp to-addresses=10.1.1.4 to-ports=0
/ip ipsec identity
add auth-method=eap certificate="" disabled=yes eap-methods=eap-mschapv2 generate-policy=port-strict mode-config=NordVPN peer=NordVPN policy-template-group=NordVPN username=XXXXXXXXXXX
/ip ipsec policy
set 0 disabled=yes
add disabled=yes dst-address=0.0.0.0/0 group=NordVPN proposal=NordVPN src-address=0.0.0.0/0 template=yes
/ip service
set telnet disabled=yes
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
#error exporting /ipv6/route/rule
#error exporting /routing/policy/selection
/system clock
set time-zone-name=Europe/London
/system leds
add interface=2.4Ghz leds=2.4Ghz_signal1-led,2.4Ghz_signal2-led,2.4Ghz_signal3-led,2.4Ghz_signal4-led,2.4Ghz_signal5-led type=wireless-signal-strength
add interface=2.4Ghz leds=2.4Ghz_tx-led type=interface-transmit
add interface=2.4Ghz leds=2.4Ghz_rx-led type=interface-receive
/system package update
set channel=development
/system resource irq rps
set sfp-sfpplus1 disabled=no
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN