Community discussions

MikroTik App
 
Jorbu
just joined
Topic Author
Posts: 23
Joined: Sun Apr 01, 2012 4:23 am

SGI w/CapsMan

Fri Jan 06, 2017 10:55 am

Hello,
Recently upgraded all my units (RB1100 & 3x hAP AC) from 6.37 to 6.38. After the upgrade I noticed some slowness, so I started to troubleshoot. Noticed that no 5Ghz radios were advertising the use of more than on chain :( . Eventually, I ended up fixing the issue by recreating my CapsMan profile and all underlying object dependencies (security, datapath, channel, etc). I assume somehow, with the upgrade the chain value might have become corrupt. Anyways....

With all this troubleshooting, I noticed that even thought I'm using "any" in the "Guard Interval" setting in my CapsMan profiles, I'm unable to see any Clients associate using SGI. This is true for both AC 5Ghz and N 2.4Ghz wireless. Is this a limitation of CapsMan? or am I missing something?
 
donny007x
just joined
Posts: 1
Joined: Sat Jan 07, 2017 12:21 am

Re: SGI w/CapsMan

Sat Jan 07, 2017 1:02 am

I'm seeing the same thing: clients are not connecting with SGI to any radio that is controlled by CAPsMAN.

Tested with the following boards/radio's (all running v6.37.3):
  • wAP ac
  • wAP 2n
  • RB2011-UAS-2HnD
iw wlan0 scan on a Linux client shows that any radio controlled by CAPsMAN does not advertise SGI.

I tried changing the guard interval in CAPsMAN from unset to "any", that didn't change anything.
 
Mazutti
newbie
Posts: 27
Joined: Sat Jun 21, 2014 4:12 am

Re: SGI w/CapsMan

Tue Jan 10, 2017 3:07 pm

Have also seen this and posted a while back, anyway got no response. My scenarios are below, and in none of them clients connect with SGI (makes no difference to leave SGI unchecked or marked as "all" on the CAPsMAN configuration).

CAPsMAN (6.36.4): RB2011UiAS-2HnD
CAPs (6.36.4 or 6.37.3): wAP, mAP-2n, RB952, RB941 and RB2011UiAS-2HnD (CAPsMAN and CAP).

Recently replaced the RB2011 with a hEXr3 (on 6.38), to no effect, nobody connects using SGI while CAP mode is enabled, although disabling it and creating the interfaces on the routers makes SGI work flawlessly.
 
uldis
MikroTik Support
MikroTik Support
Posts: 3446
Joined: Mon May 31, 2004 2:55 pm

Re: SGI w/CapsMan

Tue Jan 10, 2017 5:12 pm

Thank you for the report, we will try to check why the CAPsMAN isn't advertising the SGI flag.
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 3007
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: SGI w/CapsMan

Tue Jan 10, 2017 8:35 pm

i can confirm this issue with capsman on 6.37.1, in fact i have disabled capsman because this and the group key update setting absence (Supposedly fixed on 6.38 i have not tried)
 
Jorbu
just joined
Topic Author
Posts: 23
Joined: Sun Apr 01, 2012 4:23 am

Re: SGI w/CapsMan

Tue Jan 10, 2017 10:48 pm

I didn't get to test the group key timeout setting as I rolled back, but I did notice it's not exposed via the Winbox GUI; nor was the online manual updated to show it's existence. However, the "group-key-update" setting is now available under the "capsman -> security" object:
 /caps-man security> add 
Creates new item with specified property values.

authentication-types -- 
comment -- Short description of the item
copy-from -- Item number
eap-methods -- 
eap-radius-accounting -- 
encryption -- 
group-encryption -- 
group-key-update -- 
name -- 
passphrase -- 
tls-certificate -- 
tls-mode -- 
@chechito - When modifying this setting, what have you found to work best with iOS devices?
 
Marino
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Sun Jun 14, 2015 7:26 pm

Re: SGI w/CapsMan

Wed Jan 11, 2017 12:57 pm

i can confirm this issue with capsman on 6.37.1, in fact i have disabled capsman because this and the group key update setting absence (Supposedly fixed on 6.38 i have not tried)
I've never seen this work (sgi and capsman). Did you?
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 3007
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: SGI w/CapsMan

Thu Jan 12, 2017 7:38 pm

i can confirm this issue with capsman on 6.37.1, in fact i have disabled capsman because this and the group key update setting absence (Supposedly fixed on 6.38 i have not tried)
I've never seen this work (sgi and capsman). Did you?
i dont know, i droped capsman long time ago because of the absence of data-rate/MCS configuration, i give capsman a try on 6.37.1 because data-rate/MCS configuration was added and i want to test it but knock with sgi and group key interval issue just to drop capsman again.

I dont understand why its so difficult to just synchronize all the wireless existent settings on capsman
 
User avatar
nz_monkey
Forum Guru
Forum Guru
Posts: 2104
Joined: Mon Jan 14, 2008 1:53 pm
Location: Over the Rainbow
Contact:

Re: SGI w/CapsMan

Fri Jan 13, 2017 12:51 am

We have seen "synchronisation" issues with the "Client to Client Forwarding" option between CAPSMAN and the CAP's. e.g. using the default option in CAPSMAN which should be "enabled", we found some CAP's would not allow forwarding between clients. We changed the setting to "enabled" on CAPSMAN and re-provisioned the affected CAP's and clients were then able to forward to each other.

So it seems the sync problem is wider than just this one setting :(
 
eternal0
Frequent Visitor
Frequent Visitor
Posts: 50
Joined: Fri Jun 20, 2014 5:56 pm

Re: SGI w/CapsMan

Fri Jan 13, 2017 8:50 am

Same issue.
It seems like this issue exist for a long time:
http://forum.mikrotik.com/viewtopic.php?t=103679
 
Marino
Frequent Visitor
Frequent Visitor
Posts: 65
Joined: Sun Jun 14, 2015 7:26 pm

Re: SGI w/CapsMan

Fri Jan 13, 2017 3:34 pm

i can confirm this issue with capsman on 6.37.1, in fact i have disabled capsman because this and the group key update setting absence (Supposedly fixed on 6.38 i have not tried)
I've never seen this work (sgi and capsman). Did you?
i dont know, i droped capsman long time ago because of the absence of data-rate/MCS configuration, i give capsman a try on 6.37.1 because data-rate/MCS configuration was added and i want to test it but knock with sgi and group key interval issue just to drop capsman again.

I dont understand why its so difficult to just synchronize all the wireless existent settings on capsman
Thanks, good to know. I thought it might be a configuration setting I overlooked or the routeros version.
 
uldis
MikroTik Support
MikroTik Support
Posts: 3446
Joined: Mon May 31, 2004 2:55 pm

Re: SGI w/CapsMan

Fri Jan 13, 2017 3:39 pm

we will try to fix this problem in RouterOS v6.39rc13
 
User avatar
chechito
Forum Guru
Forum Guru
Posts: 3007
Joined: Sun Aug 24, 2014 3:14 am
Location: Bogota Colombia
Contact:

Re: SGI w/CapsMan

Sat Jan 14, 2017 3:51 pm

we will try to fix this problem in RouterOS v6.39rc13

i want to seize de opportunity to request the possibility to see ccq of clients on capsman registration table
 
Jorbu
just joined
Topic Author
Posts: 23
Joined: Sun Apr 01, 2012 4:23 am

Re: SGI w/CapsMan

Tue Jan 17, 2017 9:42 pm

Just saw RC13 is out, with the SGI fix. I'll test now and report back.
 
Jorbu
just joined
Topic Author
Posts: 23
Joined: Sun Apr 01, 2012 4:23 am

Re: SGI w/CapsMan

Tue Jan 17, 2017 9:54 pm

SGI is now working with CAPSMAN!!
Before RC13:
BeforeRC13.PNG
After RC13:
AfterRC13.PNG
You do not have the required permissions to view the files attached to this post.
 
Mazutti
newbie
Posts: 27
Joined: Sat Jun 21, 2014 4:12 am

Re: SGI w/CapsMan

Tue Jan 17, 2017 9:58 pm

SGI is now working with CAPSMAN!!
Before RC13:
BeforeRC13.PNG

After RC13:
AfterRC13.PNG
Was going to test it, but since you already did, just clarify it to me, you tested it with CAPsMAN and CAP on RC or just CAPsMAN?
 
Jorbu
just joined
Topic Author
Posts: 23
Joined: Sun Apr 01, 2012 4:23 am

Re: SGI w/CapsMan

Tue Jan 17, 2017 10:06 pm

I didn't try updating one or the other. I updated CAP first, then the CAPsMAN, so they are both on the same version. Sorry...
 
Mazutti
newbie
Posts: 27
Joined: Sat Jun 21, 2014 4:12 am

Re: SGI w/CapsMan

Tue Jan 17, 2017 10:36 pm

I didn't try updating one or the other. I updated CAP first, then the CAPsMAN, so they are both on the same version. Sorry...
No problem, anyway it's working, which is already great news. Thanks for the report.

Who is online

Users browsing this forum: Amazon [Bot] and 34 guests