The hAPac runs capsman as well as being a caps.
/interface wireless cap
set bridge=bridge caps-man-names=tnshap1 certificate=CAP-E48D8C492F1B discovery-interfaces=vlan-lan enabled=yes interfaces=wlan1,wlan2
/caps-man datapath
add client-to-client-forwarding=yes local-forwarding=yes name=gjest vlan-id=1 vlan-mode=use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=tns vlan-id=5 vlan-mode=use-tag
add client-to-client-forwarding=yes local-forwarding=yes name=ves vlan-id=6 vlan-mode=use-tag
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm name=gjest passphrase=xxx
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm name=tns passphrase=xxx
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm name=ves passphrase=xxx
/caps-man configuration
add country=france datapath=gjest mode=ap name=gjest security=gjest ssid=gjest
add country=france datapath=tns mode=ap name=tns security=tns ssid=tns
add country=france datapath=ves mode=ap name=ves security=ves ssid=ves
/caps-man access-list
add action=accept disabled=no interface=all signal-range=-80..120 ssid-regexp=""
add action=reject disabled=no interface=all signal-range=-120..-81 ssid-regexp=""
/caps-man manager
set ca-certificate=CAPsMAN-CA-E48D8C492F1B certificate=CAPsMAN-E48D8C492F1B enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled identity-regexp="^tns[h|w]ap[0-9]*" master-configuration=tns name-format=prefix-identity \
name-prefix=cap slave-configurations=gjest,ves