Thanks for the quick response, first of all, which is the menu for the centralized common management WIFI or Wireless (capsman or wireless)???What needs to be done:
- Move everything to 7.13
- Upgrade wifi on all arm-ac devices to wifi-qcom-ac (first remove wireless, then drop wifi-qcom-ac, enable caps mode)
- Enjoy centralized capsman wave2-style in wifi menu-section
[admin@MikroTik2] > interface/wifi/cap print
enabled: no
discovery-interfaces: home-bridge
requested-certificate: CAP-D49D31594FFA
[admin@MikroTik2] >
[admin@MikroTik2] > interface/wifi/configuration print
Flags: X - disabled
0 name="cfg1" mode=ap ssid="TestLan" country=Germany manager=capsman-or-local
security.authentication-types=wpa2-psk,wpa3-psk .passphrase="xxxxxxxx"
datapath.bridge=home-bridge .interface-list=all
[admin@MikroTik2] >
[admin@MikroTik2] > interface/wifi/provisioning/ print
Columns: RADIO-MAC, ACTION, MASTER-CONFIGURATION
# RADIO-MAC ACTION MASTER-CONFIGURATION
0 00:00:00:00:00:00 create-dynamic-enabled cfg1
[admin@MikroTik2] >
###########################################################
# This is the CHR Master Router, attached are 7 cap ac and 1 cap ax
###########################################################
# 2024-01-11 15:23:43 by RouterOS 7.13.1
# software id =
#
/interface bridge
add name=guest-bridge port-cost-mode=short
add name=home-bridge port-cost-mode=short
add name=test-bridge port-cost-mode=short
/interface ethernet
set [ find default-name=ether1 ] disable-running-check=no name=\
"ether1 (HomeLAN)"
set [ find default-name=ether2 ] disable-running-check=no disabled=yes name=\
"ether2 (GuestLAN)"
/disk
set sata1 type=hardware
set sata2 type=hardware
set sata3 type=hardware
add parent=sata3 partition-number=1 partition-offset=512 partition-size=\
"10 737 417 728" type=partition
set slot1 type=hardware
set slot2 slot=slot2 type=hardware
set slot3 slot=slot3 type=hardware
set slot4 slot=slot4 type=hardware
set slot5 slot=slot5 type=hardware
set slot6 slot=slot6 type=hardware
set slot7 slot=slot7 type=hardware
set slot8 slot=slot8 type=hardware
set slot9 slot=slot9 type=hardware
set slot10 slot=slot10 type=hardware
set slot11 slot=slot11 type=hardware
set slot12 slot=slot12 type=hardware
set slot13 slot=slot13 type=hardware
set slot14 slot=slot14 type=hardware
set slot15 slot=slot15 type=hardware
set slot16 slot=slot16 type=hardware
set slot17 slot=slot17 type=hardware
set slot18 slot=slot18 type=hardware
set slot19 slot=slot19 type=hardware
set slot20 slot=slot20 type=hardware
set slot21 slot=slot21 type=hardware
set slot22 slot=slot22 type=hardware
set slot23 slot=slot23 type=hardware
set slot24 slot=slot24 type=hardware
set slot25 slot=slot25 type=hardware
set slot26 slot=slot26 type=hardware
set slot27 slot=slot27 type=hardware
set slot28 slot=slot28 type=hardware
set slot29 slot=slot29 type=hardware
set slot30 slot=slot30 type=hardware
set slot31 slot=slot31 type=hardware
set slot32 slot=slot32 type=hardware
set slot33 slot=slot33 type=hardware
set slot34 slot=slot34 type=hardware
set slot35 slot=slot35 type=hardware
set slot36 slot=slot36 type=hardware
set slot37 slot=slot37 type=hardware
set slot38 slot=slot38 type=hardware
set slot39 slot=slot39 type=hardware
set slot40 slot=slot40 type=hardware
set slot41 slot=slot41 type=hardware
set slot42 slot=slot42 type=hardware
set slot43 slot=slot43 type=hardware
set slot44 slot=slot44 type=hardware
set slot45 slot=slot45 type=hardware
set slot46 slot=slot46 type=hardware
set slot47 slot=slot47 type=hardware
set slot48 slot=slot48 type=hardware
set slot49 slot=slot49 type=hardware
set slot50 slot=slot50 type=hardware
set slot51 slot=slot51 type=hardware
set slot52 slot=slot52 type=hardware
set slot53 slot=slot53 type=hardware
set slot54 slot=slot54 type=hardware
set slot55 slot=slot55 type=hardware
set slot56 slot=slot56 type=hardware
set slot57 slot=slot57 type=hardware
set slot58 slot=slot58 type=hardware
set slot59 slot=slot59 type=hardware
set slot60 slot=slot60 type=hardware
set slot61 slot=slot61 type=hardware
set slot62 slot=slot62 type=hardware
set slot63 slot=slot63 type=hardware
set slot64 slot=slot64 type=hardware
set slot65 slot=slot65 type=hardware
set slot66 slot=slot66 type=hardware
set slot67 slot=slot67 type=hardware
/interface list
add name=WAN
add name=LAN
/caps-man configuration
add channel.skip-dfs-channels=yes country=germany datapath.bridge=home-bridge \
.interface-list=all .vlan-mode=no-tag distance=indoors installation=\
indoor mode=ap name="HomeNET Configuration" \
security.authentication-types=wpa-psk,wpa2-psk .encryption=aes-ccm \
.group-encryption=aes-ccm ssid=HomeNET
add channel.skip-dfs-channels=yes country=germany datapath.bridge=\
guest-bridge .interface-list=all .vlan-mode=no-tag distance=indoors \
installation=indoor mode=ap name="GuestLAN Configuration" \
security.authentication-types=wpa-psk,wpa2-psk .encryption=aes-ccm \
.group-encryption=aes-ccm ssid=GuestLAN
add country=germany datapath.bridge=test-bridge .interface-list=all \
.vlan-mode=no-tag distance=indoors installation=indoor mode=ap name=Test \
security.authentication-types=wpa-psk,wpa2-psk .encryption=aes-ccm ssid=\
Test-AP
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wifi configuration
add country=Germany datapath.bridge=home-bridge .interface-list=all disabled=\
no manager=capsman-or-local mode=ap name=cfg1 \
security.authentication-types=wpa2-psk,wpa3-psk ssid=TestLan
/interface wifi
# no connection to CAPsMAN, managed locally
add configuration=cfg1 configuration.mode=ap disabled=no name=cap-wifi1 \
radio-mac=48:A9:8A:9B:09:16
# no connection to CAPsMAN, managed locally
add configuration=cfg1 configuration.mode=ap disabled=no name=cap-wifi2 \
radio-mac=48:A9:8A:9B:09:17
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip dhcp-server option
add code=66 name=DigiumPhones value="'http://192.168.1.103/phones/'"
/ip pool
add name=home_pool ranges=192.168.1.2-192.168.1.200
add name=guest_pool ranges=192.168.10.2-192.168.10.20
/ip dhcp-server
add address-pool=home_pool interface=home-bridge lease-time=2h name=home_dhcp
add address-pool=guest_pool interface=guest-bridge lease-time=2h name=\
guest_dhcp
/port
set 0 name=serial0
/routing bgp template
set default disabled=yes output.network=bgp-networks
/caps-man manager
set ca-certificate=CAPsMAN-CA-7D0641D5B3AF certificate=CAPsMAN-7D0641D5B3AF \
enabled=yes package-path=/ require-peer-certificate=yes upgrade-policy=\
suggest-same-version
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=\
"HomeNET Configuration" name-format=identity slave-configurations=\
"GuestLAN Configuration"
/dude
set data-directory=sata3-part1/dude
/interface bridge port
add bridge=home-bridge interface="ether1 (HomeLAN)" internal-path-cost=10 \
path-cost=10
add bridge=test-bridge disabled=yes interface="ether2 (GuestLAN)" \
internal-path-cost=10 path-cost=10
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set disable-ipv6=yes max-neighbor-entries=8192
/interface detect-internet
set detect-interface-list=all wan-interface-list=all
/interface list member
add interface="ether1 (HomeLAN)" list=WAN
add interface=guest-bridge list=LAN
add interface="ether2 (GuestLAN)" list=WAN
add interface=home-bridge list=LAN
/interface ovpn-server server
set auth=sha1,md5
/interface wifi cap
set discovery-interfaces=home-bridge
/interface wifi capsman
set ca-certificate=auto certificate=auto enabled=yes interfaces=all \
package-path="\\" require-peer-certificate=no upgrade-policy=none
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=cfg1 \
name-format=prefix-identify radio-mac=00:00:00:00:00:00
/ip address
add address=192.168.1.3/24 interface=home-bridge network=192.168.1.0
add address=192.168.10.1/24 interface=guest-bridge network=192.168.10.0
/ip dhcp-client
add interface=test-bridge
/ip dhcp-server lease
/ip dhcp-server network
add address=192.168.1.0/24 dhcp-option=DigiumPhones dns-server=192.168.1.1 \
domain=fritz.box gateway=192.168.1.1 netmask=24
add address=192.168.10.0/24 dns-server=192.168.1.1 domain=guest.net gateway=\
192.168.10.1
/ip dns
set allow-remote-requests=yes servers=192.168.1.1
/ip firewall address-list
add address=192.168.1.2-192.168.1.255 list=DropList
/ip firewall filter
add action=reject chain=forward dst-address=66.254.114.41 log=yes log-prefix=\
PornHub reject-with=icmp-host-prohibited
add action=reject chain=forward in-interface=home-bridge log-prefix=in \
out-interface=guest-bridge reject-with=icmp-network-unreachable \
src-address-list=DropList
add action=reject chain=forward dst-address-list=DropList in-interface=\
guest-bridge log-prefix=out out-interface=home-bridge reject-with=\
icmp-network-unreachable
add action=accept chain=forward dst-address-list=DropList in-interface=\
guest-bridge out-interface=home-bridge
/system clock
set time-zone-name=Europe/Berlin
/system identity
set name=MikroTik2
/system note
set note="\r\
\n\r\
\n\r\
\n\r\
\n\r\
\n Unauthorized login is prohibited"
/system ntp client
set enabled=yes
/system ntp client servers
add address=192.168.1.1
/tool e-mail
set from="<MikroTik Virtual Router>" port=465 server=mail.o2mail.de tls=\
starttls user=xxxx.yyy
#############################################################
# This i the cap ax with no manual changes, just the capsman reboot
#############################################################
# 2024-01-11 15:24:24 by RouterOS 7.13.1
# software id = NYAP-3PWD
#
# model = cAPGi-5HaxD2HaxD
# serial number = xxxxxxxxx
/interface bridge
add admin-mac=48:A9:8A:9B:09:14 auto-mac=no comment=defconf name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN
# mode: AP, SSID: TestLan, channel: 5680/ax/eCee
set [ find default-name=wifi1 ] configuration.manager=capsman datapath=capdp \
disabled=no
# managed by CAPsMAN
# mode: AP, SSID: TestLan, channel: 2412/ax/Ce
set [ find default-name=wifi2 ] configuration.manager=capsman datapath=capdp \
disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
/interface wifi cap
set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal
/system clock
set time-zone-name=Europe/Berlin
/system identity
set name=HomeLAN-DG1
/system note
set show-at-login=no
/interface wifi
# no connection to CAPsMAN, managed locally
add configuration=cfg1 configuration.mode=ap disabled=no name=cap-wifi1 \
radio-mac=48:A9:8A:9B:09:16
# no connection to CAPsMAN, managed locally
add configuration=cfg1 configuration.mode=ap disabled=no name=cap-wifi2 \
radio-mac=48:A9:8A:9B:09:17
YesCan you connect to testlan ?
The counters does not see any movements, always on "0"I'll rephrase my question: what does not work which you expect that should ?
Which local Interfaces you mean, the cap-wifi?Those local interfaces on CHR: maybe some leftover from conversion script towards 7.13.
Make a binary backup to be sure, then delete those 2 interfaces. They are not needed there.
Thanks for your supportI may have to pull out my hex, a map and a spare ax2 to make a test setup so I can play... errrm, test with that combination of both capsman environments too
Action to take if rule matches are specified by the following settings:
create-disabled - create disabled static interfaces for radio. I.e., the interfaces will be bound to the radio, but the radio will not be operational until the interface is manually enabled;
create-enabled - create enabled static interfaces. I.e., the interfaces will be bound to the radio and the radio will be operational;
create-dynamic-enabled - create enabled dynamic interfaces. I.e., the interfaces will be bound to the radio, and the radio will be operational;
none - do nothing, leaves radio in the non-provisioned state;
What a joy, you finaly have a good reason for properly configuring your network!But now the CAP does not send the data anymore to the GuestBridge, so it does not get an GuestLAN IP address, will i get forced now to use VLAN ID in the whole network instead?
Tried you suggestion, still not working...Thanks, this was the solution, unselecting instead of "00:00:00:00:00:00".
Now i have another problem, in old CAPSman i assigned allmy GuestLAN's into a GuestBridge and attached the DHCP Server to it, so the devices got a GuestLan IP address.
But now the CAP does not send the data anymore to the GuestBridge, so it does not get an GuestLAN IP address, will i get forced now to use VLAN ID in the whole network instead?