Dear MIKROTIK Team,
i am a fan of your products - but i am very unhappy with your Default config.
IF i connect a new access-Point with only ETH1 to my Network i do have an OPEN ACCESS-POINT for everybody and i have no Chance to configure it via CABLE.
Because of the Firewall Settings i even dont see it at all.
Optimum would be:
If a CAPS-MAN Server is online - then use this and open the INTERNAL Firewall AT LEAST for the CAPSMAN-Server.
Usefull would be:
Show the new device on ETH-Interfaces in WINBOX - open the FIREWALL on ETH's and SECURE OR DISABLE the WLAN