dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -69
dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -68
dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -47
dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -74
dec/03 20:38:22 wireless,info *mac*@wifi-24g disconnected, connection lost, signal strength -59
dec/03 20:38:22 wireless,info *mac*@wifi-24g disconnected, connection lost, signal strength -50
dec/03 20:38:22 wireless,info *mac*@wifi-24g disconnected, connection lost, signal strength -46
dec/03 20:38:22 wireless,info *mac*@wifi-24g disconnected, connection lost, signal strength -49
dec/03 20:38:22 wireless,info *mac*@wifi-24g disconnected, connection lost, signal strength -48
dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -70
dec/03 20:38:22 wireless,info *mac*@wifi-5g disconnected, connection lost, signal strength -53
sid123 can you make a separate topic for your issue? this topic is about a specific issue.
everyone else - we are seeing something like this too. we are working on a fix in the internal betas right now, so next major v7 release should hopefully resolve the problem.
security.authentication-types=wpa-psk,wpa2-psk
# dec/10/2022 23:40:36 by RouterOS 7.6
# software id = JAMW-UMX1
#
# model = C52iG-5HaxD2HaxD
/interface wifiwave2
set [ find default-name=wifi2 ] configuration.mode=ap .ssid=MyWiFi2G
/interface wifiwave2 channel
add frequency=2412,2432,2472 name=ch-2ghz width=20mhz
add frequency=5180,5260,5500 name=ch-5ghz width=20/40/80mhz
/interface wifiwave2 security
add authentication-types=wpa2-psk,wpa3-psk name=MyWiFi
add authentication-types=wpa2-psk,wpa3-psk name=MyWiFiGuest
/interface wifiwave2 configuration
add channel=ch-5ghz country=Guatemala name=MyWiFi security=MyWiFi ssid=MyWiFi
add channel=ch-5ghz country=Guatemala name=MyWiFiGuest security=MyWiFiGuest ssid=MyWiFiGuest
/interface wifiwave2
set [ find default-name=wifi1 ] channel.frequency=5180,5260,5500 configuration=MyWiFi configuration.mode=ap disabled=no
# failed to create interface
add channel.frequency=5180,5260,5500 configuration=MyWiFiGuest configuration.mode=ap disabled=no mac-address=AA:BB:CC:AA:BB:CC master-interface=wifi1 name=wifi3-guest
I don't think it's related. The hAP ax2 is accessible via LAN. It just stops broadcasting BSSID beacons and you can't connect anymore...... connect to AC3 with LAN cable via Winbox without sucess.
Not sure whats exactly was his issue. I will give 7.7rc2 a shot.The 7.7rc2 release has fixed my issue with the hAP ax2 radios.
With the countries field now populated, the wifi radios start up and devices associate just fine. Thanks to the Mikrotik team for getting that taken care of!
#
# Unstable configuration
#
# Configuration
/interface wifiwave2 configuration add name=wifi2 mode=ap country=Poland channel.band=2ghz-ax channel.width=20/40mhz
/interface wifiwave2 configuration add name=wifi6 mode=ap country=Poland channel.band=5ghz-ax channel.width=20/40/80mhz
# Home SSID
/interface wifiwave2 security add name=main authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 set [ find default-name=wifi1 ] configuration=wifi6 configuration.ssid=BLUE channel.skip-dfs-channels=disabled security=main disabled=no
/interface wifiwave2 set [ find default-name=wifi2 ] configuration=wifi2 configuration.ssid=BLUE security=main disabled=no
# Guest SSID
/interface wifiwave2 security add name=guest authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 add name="guest1" master-interface=wifi1 configuration=wifi6 configuration.ssid=GREEN security=guest disabled=no
/interface wifiwave2 add name="guest2" master-interface=wifi2 configuration=wifi2 configuration.ssid=GREEN security=guest disabled=no
# IoT SSID
/interface wifiwave2 security add name=iot authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 add name="iot1" master-interface=wifi1 configuration=wifi6 configuration.ssid=RED security=iot disabled=no
/interface wifiwave2 add name="iot2" master-interface=wifi2 configuration=wifi2 configuration.ssid=RED security=iot disabled=no
#
# Stable (so far) configuration:
#
# Configuration
/interface wifiwave2 configuration add name=wifi2 mode=ap country="Poland" channel.band=2ghz-ax channel.width=20/40mhz
/interface wifiwave2 configuration add name=wifi6 mode=ap country="Poland" channel.band=5ghz-ax channel.width=20/40/80mhz
# Home SSID
/interface wifiwave2 security add name=main authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 set [ find default-name=wifi1 ] configuration=wifi6 configuration.ssid=BLUE channel.skip-dfs-channels=disabled security=main disabled=no
/interface wifiwave2 set [ find default-name=wifi2 ] configuration=wifi2 configuration.ssid=BLUE security=main disabled=no
# Guest SSID
/interface wifiwave2 security add name=guest authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 add name="guest1" master-interface=wifi1 configuration=wifi6 configuration.ssid=GREEN security=guest disabled=no
/interface wifiwave2 add name="guest2" master-interface=wifi2 configuration=wifi2 configuration.ssid=GREEN security=guest disabled=no
# IoT SSID
/interface wifiwave2 security add name=iot authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase"
/interface wifiwave2 add name="iot1" master-interface=wifi1 configuration=wifi6 configuration.ssid=RED security=iot disabled=no
/interface wifiwave2 add name="iot2" master-interface=wifi2 configuration=wifi2 configuration.ssid=RED security=iot disabled=no
Did you solve the disconnection problem? I have the same problem with a hap ax2 and I can't find the solution. I didn't find any solution from Mikrotik support either.Hi!
I have recently bought a Mikrotik hAP ax2 router, running routerOS v7.6 but I am facing a few issues already...
One (which is being the most serious) that sometimes all of a sudden the wifi networks stop working, the SSIDs are not visible when searching for WiFi networks from devices. Of course connected devices also lose the connection. This happens for the second time in 3days. The networks do not come back (not even half an hour or an hour later). The only thing that restart the transmission is when I open the wifi network from winbox (double click on the network in Wireless menu) then push the Scan button (at this stage is still nothing happens) and then Close that window with the particular wifi interface. After closing the window the transmission restarts immediately and I see the following in the log:
22:14:17 wireless,info BC:DD:C2:0E:11:97@wifi2 connected, signal strength -57
22:14:18 wireless,info 78:0F:77:FD:7D:28@wifi2 connected, signal strength -54
22:14:18 wireless,info BC:DD:C2:0F:10:84@wifi2 connected, signal strength -73
22:14:18 dns,packet --- got query from 192.168.1.25:41708:
22:14:18 dns,packet id:85de rd:1 tc:0 aa:0 qr:0 ra:0 QUERY 'no error'
...
...
nothing else remarkable can be seen in the logs. I am attaching the whole debug log from around that time when transmission from wifi2 restarted (at that time I have already restarted wifi1 transmission with the same method).
Can you help me solve this serious issue?
Thank you!
Best regards,
Krisztián Barassevich
Please explain to me, step by step, how to enter "" before and after the name of the country. I'm a beginner, I'm not that good at it.I have a setup where I have 3 WLANs 5GHz and 3 WLANs 2.4GHz paired (2.4 + 5) into 3 wifi endpoints. I was trying to prepare nice config file, which I could gradually improve with better firewall setup or VLAN configuration... AND it was pissing me off(!) because my WLANs were unstable, some were visible, others not. Sometimes it was 5GHz that was working, sometimes 2.4GHz - it was changing after reboot or something? But it looks like I've finally solved the puzzle!
Can you spot the difference?Code: Select all# # Unstable configuration # # Configuration /interface wifiwave2 configuration add name=wifi2 mode=ap country=Poland channel.band=2ghz-ax channel.width=20/40mhz /interface wifiwave2 configuration add name=wifi6 mode=ap country=Poland channel.band=5ghz-ax channel.width=20/40/80mhz # Home SSID /interface wifiwave2 security add name=main authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 set [ find default-name=wifi1 ] configuration=wifi6 configuration.ssid=BLUE channel.skip-dfs-channels=disabled security=main disabled=no /interface wifiwave2 set [ find default-name=wifi2 ] configuration=wifi2 configuration.ssid=BLUE security=main disabled=no # Guest SSID /interface wifiwave2 security add name=guest authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 add name="guest1" master-interface=wifi1 configuration=wifi6 configuration.ssid=GREEN security=guest disabled=no /interface wifiwave2 add name="guest2" master-interface=wifi2 configuration=wifi2 configuration.ssid=GREEN security=guest disabled=no # IoT SSID /interface wifiwave2 security add name=iot authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 add name="iot1" master-interface=wifi1 configuration=wifi6 configuration.ssid=RED security=iot disabled=no /interface wifiwave2 add name="iot2" master-interface=wifi2 configuration=wifi2 configuration.ssid=RED security=iot disabled=no # # Stable (so far) configuration: # # Configuration /interface wifiwave2 configuration add name=wifi2 mode=ap country="Poland" channel.band=2ghz-ax channel.width=20/40mhz /interface wifiwave2 configuration add name=wifi6 mode=ap country="Poland" channel.band=5ghz-ax channel.width=20/40/80mhz # Home SSID /interface wifiwave2 security add name=main authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 set [ find default-name=wifi1 ] configuration=wifi6 configuration.ssid=BLUE channel.skip-dfs-channels=disabled security=main disabled=no /interface wifiwave2 set [ find default-name=wifi2 ] configuration=wifi2 configuration.ssid=BLUE security=main disabled=no # Guest SSID /interface wifiwave2 security add name=guest authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 add name="guest1" master-interface=wifi1 configuration=wifi6 configuration.ssid=GREEN security=guest disabled=no /interface wifiwave2 add name="guest2" master-interface=wifi2 configuration=wifi2 configuration.ssid=GREEN security=guest disabled=no # IoT SSID /interface wifiwave2 security add name=iot authentication-types=wpa2-psk,wpa3-psk passphrase="passphrase" /interface wifiwave2 add name="iot1" master-interface=wifi1 configuration=wifi6 configuration.ssid=RED security=iot disabled=no /interface wifiwave2 add name="iot2" master-interface=wifi2 configuration=wifi2 configuration.ssid=RED security=iot disabled=no
it's the "" around the name of the country in wifiwave2 configuration. For some reason if the "" was missing the config loading was unstable and country was not setup in configuration properly. Because of that ie. only one group of networks was working, sometimes the other one and sometimes none... The country seems to be required to be set for the wifi to work stable. Not sure if that would help you with your issues, but looks like setting country with "" solved my issues. Wifi is stable over last 3 days.
Can you also send me the configuration of the hap ax2 router?Mine hap ax2 and ax3 works fine...
What problem, exactly?with 7.9 i still get the same problem!
However, I only see it in the logs. In my client side, I never see a disconnection, which is weird. I even leave SSH sessions open for more than 5 days on my clients, they never closed, so that means the Wi-Fi never disconnected.
security.authentication-types=wpa2-psk
I had a similar issue on ax3, starting after sw upgrade to rc2 or rc3, can't recall. After the stable 7.9 upgrade, it remained and was very annoying.Mine is configured withfor both interfaces, so I don't think the problem is WPA3-related.Code: Select allsecurity.authentication-types=wpa2-psk
Update: it just happened again. Router uptime is less than 24h. Disabling/enabling wifi interfaces does not work. Tried changing some settings, but there seems to be no way to make it work except for rebooting. Sent supout.rif to support@mikrotik.com.
# may/09/2023 04:15:47 by RouterOS 7.9
# model = C53UiG+5HPaxD2HPaxD
/interface wifiwave2
set [ find default-name=wifi1 ] channel.band=5ghz-ax .skip-dfs-channels=disabled .width=20/40/80mhz \
configuration.country=Malaysia .mode=ap .ssid=mtk disabled=no security.authentication-types=wpa2-psk,wpa3-psk \
.disable-pmkid=no .encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button
set [ find default-name=wifi2 ] channel.band=2ghz-ax .skip-dfs-channels=disabled .width=20mhz configuration.country=\
Malaysia .mode=ap .ssid=mtk disabled=no mtu=1500 security.authentication-types=wpa-psk,wpa2-psk .disable-pmkid=no \
.encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button
/interface bridge
add admin-mac=48:A9:8A:xx:xx:xx auto-mac=no name=bridge1
/interface ethernet
set [ find default-name=ether1 ] poe-out=off
set [ find default-name=ether2 ] name=ether2-uplink
/interface bridge port
add bridge=bridge1 interface=ether1
add bridge=bridge1 interface=ether2-uplink
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=ether4
add bridge=bridge1 interface=ether5
add bridge=bridge1 interface=wifi1
add bridge=bridge1 interface=wifi2
add bridge=bridge1 interface=veth1-adguard
add bridge=bridge1 interface=veth2-uptimekuma
add bridge=bridge1 interface=veth3-lego
/ip dhcp-client
add interface=bridge1
Tried setting group key update to something higher?I wasn't able to do so before since I was busy IRL and was mucking around with containers on the ax3. Now that has passed, I've started keeping track of the ax3's wifi and any correlation with its config.
The last time I rebooted was 6 May around 1am. Current wifi uptime is 4 days 2 hours.
Before the 6th, I would have hangs from every few hours to every 2-3 days. This happened on 7.9rc1-5 and 7.9. If and when the wifi hangs, I get tons of "disconnected, key handshake timeout" for both 2.4 and 5Ghz. Shouts from wife and kids follow suit.
Clients include:
1. iPhones (4) (ax, ac)
2. Macs (2) (ax, ac)
3. PCs (3) (ax, ac)
3. 1 lonely Android phone (ac)
4. iPads (3) (ac)
5. AppleTV (1) (ax)
6. HomePods (2) (ax)
7. Apple Watches (2) (5Ghz n)
8. Aqara Hub (1) and Wifi Cameras (4) (2.4Ghz n)
FWIW, I'll post my latest config below in case you all need to compare. For this latest config, the 2 things I've changed are:
1. .disable-pmkid=no (I've had this at yes or no previously. Didn't seem to make a difference.)
2. .wps=push-button (This is the first time I've enabled it. I always had WPS disabled.)
Code: Select all# may/09/2023 04:15:47 by RouterOS 7.9 # model = C53UiG+5HPaxD2HPaxD /interface wifiwave2 set [ find default-name=wifi1 ] channel.band=5ghz-ax .skip-dfs-channels=disabled .width=20/40/80mhz \ configuration.country=Malaysia .mode=ap .ssid=mtk disabled=no security.authentication-types=wpa2-psk,wpa3-psk \ .disable-pmkid=no .encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button set [ find default-name=wifi2 ] channel.band=2ghz-ax .skip-dfs-channels=disabled .width=20mhz configuration.country=\ Malaysia .mode=ap .ssid=mtk disabled=no mtu=1500 security.authentication-types=wpa-psk,wpa2-psk .disable-pmkid=no \ .encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button /interface bridge add admin-mac=48:A9:8A:xx:xx:xx auto-mac=no name=bridge1 /interface ethernet set [ find default-name=ether1 ] poe-out=off set [ find default-name=ether2 ] name=ether2-uplink /interface bridge port add bridge=bridge1 interface=ether1 add bridge=bridge1 interface=ether2-uplink add bridge=bridge1 interface=ether3 add bridge=bridge1 interface=ether4 add bridge=bridge1 interface=ether5 add bridge=bridge1 interface=wifi1 add bridge=bridge1 interface=wifi2 add bridge=bridge1 interface=veth1-adguard add bridge=bridge1 interface=veth2-uptimekuma add bridge=bridge1 interface=veth3-lego /ip dhcp-client add interface=bridge1
Already had required packages downloaded to Files but was hesitating.Needless to say I downgraded it to 7.8.
On my macOS client if wireless interface is disconnected, it also loses IP addressing, macOS immediately terminates all network sockets. So I digress.The beauty of TCP (which ssh uses as session layer) is that it can survive intermittent disruptions in connectivity of underlying layers. Duration of "intermittent" can be anything from seconds (in the middle of active data exchange, depends on TCP retransmission timeouts) and hours (when ssh is idle and ssh isn't configured to send keep-alives).
So what you see doesn't mean that stations didn't disconnect. They might have and then reconnected - to same wireless interface of same AP (or another AP in same L2 network). The two conditions are: station reconnects soon enough for TCP to handle it gracefully (not too hard in normal conditions) and station keeps IP address (even if DHCP doing gets triggered for any reason).
Why these specific two changes ?FWIW, I'll post my latest config below in case you all need to compare. For this latest config, the 2 things I've changed are:
1. .disable-pmkid=no (I've had this at yes or no previously. Didn't seem to make a difference.)
2. .wps=push-button (This is the first time I've enabled it. I always had WPS disabled.)
I was out of ideas. Nothing seemed to work.Why these specific two changes ?FWIW, I'll post my latest config below in case you all need to compare. For this latest config, the 2 things I've changed are:
1. .disable-pmkid=no (I've had this at yes or no previously. Didn't seem to make a difference.)
2. .wps=push-button (This is the first time I've enabled it. I always had WPS disabled.)
Nah, no change with this, am on v7.10rc6Adding a +1 to this. Have been running 7.10rc1 for 8 days and the fault occurred again. Will update now to 7.10rc4
No. 8hours after 7.10 installation. 40+ devices and 4 AX caps. Mikrotik AX is a money waste!Has 7.10 solved the problem of wireless networks dropping? Has anyone tried?
[admin@MikroTik] > /system/resource/print
uptime: 2d19h20m51s
version: 7.10 (stable)
build-time: Jun/15/2023 05:17:29
factory-software: 7.5
free-memory: 659.1MiB
total-memory: 960.0MiB
cpu: ARM64
cpu-count: 4
cpu-frequency: 864MHz
cpu-load: 0%
free-hdd-space: 94.9MiB
total-hdd-space: 128.5MiB
write-sect-since-reboot: 3375
write-sect-total: 64668
bad-blocks: 0%
architecture-name: arm64
board-name: hAP ax^2
platform: MikroTik
I was struggling with the same issue for a month (since I have bought hAP ax2). The issue occurred 1-2 times per day! Every single day! The only thing which worked was a reboot (tried to disable/enable wifi and dhcp server).
Three days ago I have upgraded firmware to 7.10 stable and so far the issue is gone. Keeping fingers crossed!
Code: Select all[admin@MikroTik] > /system/resource/print uptime: 2d19h20m51s version: 7.10 (stable) build-time: Jun/15/2023 05:17:29 factory-software: 7.5 free-memory: 659.1MiB total-memory: 960.0MiB cpu: ARM64 cpu-count: 4 cpu-frequency: 864MHz cpu-load: 0% free-hdd-space: 94.9MiB total-hdd-space: 128.5MiB write-sect-since-reboot: 3375 write-sect-total: 64668 bad-blocks: 0% architecture-name: arm64 board-name: hAP ax^2 platform: MikroTik
TBH I haven't checked the signal strength so I don't know what was the impact (unfortunately I have updated to 7.9 just after I got the device). Now I have downgraded it to 7.6 to see whether it helps (uptime 1d+ now).But what can you say about the signal strength for each frequency band? After the update to 7.10 did it decrease drastically? For me, after the update from 7.6 to 7.10, it dropped from -40db to -55-56 db!! Likewise the download speed!
https://download.mikrotik.com/routeros/[ver]/routeros-[ver]-arm64.npk
It seems that since I updated to 7.10 or 7.10.1, the network drops disappeared. Only the weak signal strength remained on both bands.I've got the same problem with WiFi drops with Chateau LTE18 - only reset helps
I had lots of problems with 7.9 and 7.10 dropping the 5GHz radio. With the 7.11 beta 4 and later RouterOS and firmware (which has the IPQ-6010 hang fix), the 5Ghz radio has not dropped yet. (hAP ax2)Has the latest firmware resolved the issues? Anyone have any comments?
We have bed test and we have protocol before deploying but i see so many reports here and in redit about problems in radio or signal strength drops. Its must be an known issue its over a year know the problem.No problems for me on AX3, AX2, cAP AX nor AX Lite using 7.11b6 (apart from 7.9, I didn't see too many wifi issues with earlier versions on those devices).
You might better wait for stable 7.11 release if it is for field deployment and already do some extensive testing using latest 7.11b6 version.
First some facts:We have bed test and we have protocol before deploying but i see so many reports here and in redit about problems in radio or signal strength drops. Its must be an known issue its over a year know the problem.
Okay, so if you have means to test it and you have protocols in place why do you rely on things seen on the Internet ? Test it yourself then and if it's satisfy your needs then deploy it.We have bed test and we have protocol before deploying but i see so many reports here and in redit about problems in radio or signal strength drops. Its must be an known issue its over a year know the problem.
Process is streamlined enough.Take notice that you have to download and install the wifiwave2 npk file separately - when we were upgrading, we did not copy the wifiwave2 file, and then both the wifi interfaces "disappeared" when the device was rebooted/upgraded.
Maybe we did it in the wrong way - but it was scary to see the interfaces disappeared when upgraded - we assumed it was failed hardware. But only missing drivers etc.
Probably MT should make this process bit more streamlined - like in v6 we never had such issue when upgrading.
hi, yes, ax2 router + AP same timeI was trying something out that made no sense. Basicly instead of having 1 single mikrotik device (ax2) I turned it into 3 - Router done by a 5009, ax ap by an ax2 and ac ap by an ac2.
Since I did this the AX2 has not dropped the wifi, not even once. I was wondering if this was coincidental or not so i tried reverting it back to do routing and ap functions and it dropped the wifi in 5 days more or less.
When I had an ax2 as a router and ap and it froze once I decided to make it router and station instead because that wireless was only used for a bridge and that also made the wifi stop dropping
This seems to me more like an interaction problem between routing and wifi running at the same time, making wifi fail. This is such a Byzantine error.
Just out of curiosity are any of you having issues using the device as a router and an AP at the same time?
# 2023-10-05 19:15:55 by RouterOS 7.11.2
# software id = P275-LLI5
#
# model = C52iG-5HaxD2HaxD
# serial number = XXXXXXXXXXXXX
/interface bridge
add admin-mac=XXXXXXXXXXX auto-mac=no comment=defconf name=bridge
/interface wifiwave2
set [ find default-name=wifi1 ] channel.skip-dfs-channels=all configuration.country=Australia .mode=ap .ssid=JCMNet5.0 disabled=no security.authentication-types=wpa2-psk
set [ find default-name=wifi2 ] channel.skip-dfs-channels=all configuration.country=Australia .mode=ap .ssid=JCMNet2.4 disabled=no security.authentication-types=wpa2-psk
/interface pppoe-client
add add-default-route=yes disabled=no interface=ether1 name=pppoe-out1 use-peer-dns=yes user=XXXXXXXXXX
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/ip pool
add name=dhcp ranges=192.168.1.1-192.168.1.150
/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=23h59m59s name=defconf
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wifi1
add bridge=bridge comment=defconf interface=wifi2
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ip settings
set tcp-syncookies=yes
/ipv6 settings
set max-neighbor-entries=15360
/interface detect-internet
set detect-interface-list=all
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
add interface=pppoe-out1 list=WAN
/ip address
add address=192.168.1.254/24 comment=defconf interface=bridge network=192.168.1.0
/ip dhcp-client
add comment=defconf disabled=yes interface=ether1
/ip dhcp-server network
add address=192.168.1.0/24 comment=defconf dns-server=1.1.1.1,1.0.0.1,192.168.1.254 domain=JCMNET gateway=192.168.1.254 netmask=24
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.1.254 comment=defconf name=router.lan
/ip firewall address-list
add address=0.0.0.0/8 comment=RFC6890 list=not_in_internet
add address=172.16.0.0/12 comment=RFC6890 list=not_in_internet
add address=192.168.0.0/16 comment=RFC6890 list=not_in_internet
add address=10.0.0.0/8 comment=RFC6890 list=not_in_internet
add address=169.254.0.0/16 comment=RFC6890 list=not_in_internet
add address=127.0.0.0/8 comment=RFC6890 list=not_in_internet
add address=224.0.0.0/4 comment=Multicast list=not_in_internet
add address=198.18.0.0/15 comment=RFC6890 list=not_in_internet
add address=192.0.0.0/24 comment=RFC6890 list=not_in_internet
add address=192.0.2.0/24 comment=RFC6890 list=not_in_internet
add address=198.51.100.0/24 comment=RFC6890 list=not_in_internet
add address=203.0.113.0/24 comment=RFC6890 list=not_in_internet
add address=100.64.0.0/10 comment=RFC6890 list=not_in_internet
add address=240.0.0.0/4 comment=RFC6890 list=not_in_internet
add address=192.88.99.0/24 comment="6to4 relay Anycast [RFC 3068]" list=not_in_internet
/ip firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMP" disabled=yes protocol=icmp
add action=accept chain=input comment="defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=drop chain=input comment="defconf: drop all not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" disabled=yes ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" ipsec-policy=out,ipsec
add action=drop chain=forward comment="Animaljam Block" content=animaljam protocol=tcp time=0s-1d,sun,mon,tue,wed,thu,fri
add action=drop chain=forward comment="Roblox block" content=roblox.com protocol=tcp time=0s-1d,sun,mon,tue,wed,thu,fri
add action=drop chain=forward comment="Snapchat block" content=snapchat.com protocol=tcp time=0s-1d,sun,mon,tue,wed,thu,fri
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" connection-state=established,related hw-offload=yes
add action=accept chain=forward comment="defconf: accept established,related, untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat connection-state=new in-interface-list=WAN
add action=drop chain=forward comment="Drop incoming from internet which is not public IP" in-interface-list=WAN src-address-list=not_in_internet
add action=drop chain=forward comment="Drop packets from LAN that do not have LAN IP" in-interface=bridge src-address=!192.168.1.0/24
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" ipsec-policy=out,none out-interface-list=WAN
/ipv6 firewall address-list
add address=::/128 comment="defconf: unspecified address" list=bad_ipv6
add address=::1/128 comment="defconf: lo" list=bad_ipv6
add address=fec0::/10 comment="defconf: site-local" list=bad_ipv6
add address=::ffff:0.0.0.0/96 comment="defconf: ipv4-mapped" list=bad_ipv6
add address=::/96 comment="defconf: ipv4 compat" list=bad_ipv6
add address=100::/64 comment="defconf: discard only " list=bad_ipv6
add address=2001:db8::/32 comment="defconf: documentation" list=bad_ipv6
add address=2001:10::/28 comment="defconf: ORCHID" list=bad_ipv6
add address=3ffe::/16 comment="defconf: 6bone" list=bad_ipv6
/ipv6 firewall filter
add action=accept chain=input comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=invalid
add action=accept chain=input comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=input comment="defconf: accept UDP traceroute" port=33434-33534 protocol=udp
add action=accept chain=input comment="defconf: accept DHCPv6-Client prefix delegation." dst-port=546 protocol=udp src-address=fe80::/10
add action=accept chain=input comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=input comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=input comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=input comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=input comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept established,related,untracked" connection-state=established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" connection-state=invalid
add action=drop chain=forward comment="defconf: drop packets with bad src ipv6" src-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: drop packets with bad dst ipv6" dst-address-list=bad_ipv6
add action=drop chain=forward comment="defconf: rfc4890 drop hop-limit=1" hop-limit=equal:1 protocol=icmpv6
add action=accept chain=forward comment="defconf: accept ICMPv6" protocol=icmpv6
add action=accept chain=forward comment="defconf: accept HIP" protocol=139
add action=accept chain=forward comment="defconf: accept IKE" dst-port=500,4500 protocol=udp
add action=accept chain=forward comment="defconf: accept ipsec AH" protocol=ipsec-ah
add action=accept chain=forward comment="defconf: accept ipsec ESP" protocol=ipsec-esp
add action=accept chain=forward comment="defconf: accept all that matches ipsec policy" ipsec-policy=in,ipsec
add action=drop chain=forward comment="defconf: drop everything else not coming from LAN" in-interface-list=!LAN
/system clock
set time-zone-name=Australia/Melbourne
/system identity
set name=JCM-RTR
/system note
set show-at-login=no
/system package update
set channel=testing
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
OK. Any particular setting to improve range? Maybe 20mhz channels on both 2.4 and 5.0?Why ? leave it untouched so it defaults to default antenna gain...
/interface wifiwave2 channel
add band=5ghz-ax disabled=no frequency=5260,5300,5500,5540,5580,5620,5660 name=CH5G width=20/40mhz-Ce
add band=2ghz-ax disabled=no frequency=2412,2437,2460 name=CH2.4G width=20mhz
/interface wifiwave2 security
add authentication-types=wpa2-psk,wpa3-psk disabled=no group-encryption=ccmp name=SSID1
/interface wifiwave2
set [ find default-name=wifi2 ] channel=CH2.4G configuration.country=Netherlands .dtim-period=3 .mode=ap .ssid=SSID1 disabled=no security=SSID1
set [ find default-name=wifi1 ] channel=CH5G configuration.country=Netherlands .dtim-period=3 .mode=ap .ssid=SSID1 disabled=no security=SSID1
/interface wifiwave2 access-list
add action=accept allow-signal-out-of-range=10s disabled=no signal-range=-80..120
add action=reject allow-signal-out-of-range=10s disabled=no signal-range=-120..-81
If you restart the radio by disabling and enabling... does that fix it?After 1 week of stability, HAP AX2 is dropping SSID again on both 5ghz and 2.4ghz. Switched to my old router HAP AC2 and no issues at all. Looks like the HAP AX2 is not a stable product. Mikrotik support has not been able to provide any help and don't see any issues with my config. I am giving up on Mikrotik and getting a Mesh router soon!!!
Please check which frequency your wifi1 interface chose.Neither my hAP ax2 nor my cAP ax, which I received today, show the 5 GHz SSID. Is this the same problem as what's being discussed here?
Thanks, I just checked and the frequency field was empty. For the 2 GHz interface the frequency field was empty too, but that interface was working. When I click the down arrow button it populates the field with "2300-7300", which appears to be the greatest range allowed. How should I know what values I'm supposed to type in this field?Please check which frequency your wifi1 interface chose.Neither my hAP ax2 nor my cAP ax, which I received today, show the 5 GHz SSID. Is this the same problem as what's being discussed here?
Must be higher than your equipment see. Maybe 5805 or 5785 MHz.
Please choose manually comfort frequency. For example 5180-5240.
For some reason now it works but I haven't put anything in the frequency field yet. In the Status tab it says Channel: "5220/ax/eeCe"Just try 5180 and see if it works.
For some reason now it works but I haven't put anything in the frequency field yet. In the Status tab it says Channel: "5220/ax/eeCe"Just try 5180 and see if it works.
[30748.735993] iwlwifi 0000:02:00.0: missed beacons exceeds threshold, but receiving data. Stay connected, Expect bugs.
[30748.736006] iwlwifi 0000:02:00.0: missed_beacons:19, missed_beacons_since_rx:1
[30748.838365] iwlwifi 0000:02:00.0: missed beacons exceeds threshold, but receiving data. Stay connected, Expect bugs.
[30748.838379] iwlwifi 0000:02:00.0: missed_beacons:20, missed_beacons_since_rx:1
...
[30750.374253] wlp2s0: Connection to AP d4:01:c3:48:94:7c lost
[31018.668312] iwlwifi 0000:02:00.0: missed beacons exceeds threshold, but receiving data. Stay connected, Expect bugs.
[31018.668325] iwlwifi 0000:02:00.0: missed_beacons:19, missed_beacons_since_rx:3
[31018.770724] wlp2s0: Connection to AP d4:01:c3:48:94:7c lost
[31018.901736] wlp2s0: Connection to AP 00:00:00:00:00:00 lost
00:03:38 wireless,info C6:6D:48:21:CE:81@ap-library-2-5ghz disconnected, SA Query timeout, signal strength -37
00:03:40 wireless,info C6:6D:48:21:CE:81@ap-library-2-5ghz connected, signal strength -36