Hi all, here is my config.
# oct/15/2020 18:29:49 by RouterOS 6.47.4
# software id
#
# model = RB962UiGS-5HacT2HnT
# serial number =xxx
/caps-man channel
add band=5ghz-onlyac control-channel-width=20mhz extension-channel=Ce \
frequency=5180,5220,5260 name="channel 36-44-52" tx-power=30
/interface bridge
add disabled=yes name=bridge-Guest
add name=bridge/Router protocol-mode=stp
/interface ethernet
set [ find default-name=ether1 ] comment=WAN
set [ find default-name=ether2 ] comment=AP241
set [ find default-name=ether3 ] comment=AP242
/interface wireless
# managed by CAPsMAN
# channel: 2412/20/gn(17dBm), SSID: HYPERKSJ24, local forwarding
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
disabled=no distance=indoors frequency=auto installation=indoor mode=\
ap-bridge ssid=MikroTik-166E3F station-roaming=enabled wireless-protocol=\
802.11
# managed by CAPsMAN
# channel: 5260/20-Ce/ac/DP(18dBm), SSID: HYPERKSJ5, local forwarding
set [ find default-name=wlan2 ] band=5ghz-a/n/ac channel-width=\
20/40/80mhz-XXXX disabled=no distance=indoors frequency=auto \
installation=indoor mode=ap-bridge ssid=MikroTik-166E3E station-roaming=\
enabled wireless-protocol=802.11
/caps-man security
add authentication-types=wpa2-psk disable-pmkid=yes encryption=aes-ccm name=\
wpaowner
add authentication-types=wpa2-psk encryption=aes-ccm name=wpaguest
/caps-man configuration
add channel.band=2ghz-g/n channel.control-channel-width=20mhz \
channel.extension-channel=disabled channel.frequency=2412,2437,2462 \
channel.save-selected=yes country=denmark \
datapath.client-to-client-forwarding=yes datapath.local-forwarding=yes \
hw-retries=7 mode=ap multicast-helper=full name=2.4Ghz-WPA-Owner \
rx-chains=0,1,2 security=wpaowner security.disable-pmkid=yes ssid=\
HYPERKSJ24 tx-chains=0,1,2
add channel="channel 36-44-52" channel.save-selected=no country=denmark \
datapath.client-to-client-forwarding=yes datapath.local-forwarding=yes \
distance=indoors hw-retries=7 installation=indoor mode=ap \
multicast-helper=full name=5Ghz-WPA-Owner rx-chains=0,1,2 security=\
wpaowner ssid=HYPERKSJ5 tx-chains=0,1,2
/caps-man interface
add configuration=5Ghz-WPA-Owner disabled=no l2mtu=1600 mac-address=\
64:D1:54:87:6D:28 master-interface=none name="Klaus AP1-2" radio-mac=\
64:D1:54:87:6D:28 radio-name=64D154876D28
add configuration=5Ghz-WPA-Owner disabled=no l2mtu=1600 mac-address=\
64:D1:54:88:BA:B9 master-interface=none name="Klaus AP2-2" radio-mac=\
64:D1:54:88:BA:B9 radio-name=64D15488BAB9
add configuration=2.4Ghz-WPA-Owner disabled=no l2mtu=1600 mac-address=\
48:8F:5A:16:6E:3F master-interface=none name="WIXX hAPac 254-1" \
radio-mac=48:8F:5A:16:6E:3F radio-name=488F5A166E3F
add configuration=5Ghz-WPA-Owner disabled=no l2mtu=1600 mac-address=\
48:8F:5A:16:6E:3E master-interface=none name="WIXX hAPac 254-2" \
radio-mac=48:8F:5A:16:6E:3E radio-name=488F5A166E3E
/interface list
add name=WAN
add include=dynamic name=No-Discover
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/ip pool
add name=dhcp_pool0 ranges=10.1.0.1-10.1.0.175
add name=dhcp_pool1 ranges=172.16.15.1-172.16.15.175
/ip dhcp-server
add address-pool=dhcp_pool0 always-broadcast=yes disabled=no interface=\
bridge/Router lease-time=3d name=dhcp1
add address-pool=dhcp_pool1 always-broadcast=yes interface=bridge-Guest \
lease-time=3h name=dhcp2
/interface sstp-client
add connect-to=xxx disabled=no name=sstp-out1 \
profile=default-encryption user=xxx
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/caps-man manager
set ca-certificate=auto certificate=auto enabled=yes upgrade-policy=\
suggest-same-version
/caps-man manager interface
add disabled=no forbid=yes interface=ether1
add disabled=no interface=bridge/Router
add disabled=no forbid=yes interface=bridge-Guest
/caps-man provisioning
add action=create-dynamic-enabled master-configuration=2.4Ghz-WPA-Owner \
name-format=prefix-identity
add action=create-dynamic-enabled master-configuration=5Ghz-WPA-Owner \
name-format=prefix-identity
/interface bridge port
add bridge=bridge/Router interface=ether2
add bridge=bridge/Router interface=ether3
add bridge=bridge/Router interface=ether4
add bridge=bridge/Router interface=ether5
add bridge=bridge/Router interface=sfp1
add bridge=bridge/Router interface=wlan1
add bridge=bridge/Router interface=wlan2
/ip neighbor discovery-settings
set discover-interface-list=all
/interface list member
add interface=bridge-Guest list=No-Discover
add interface=ether1 list=WAN
add interface=wlan1 list=No-Discover
/interface wireless cap
#
set bridge=bridge/Router discovery-interfaces=bridge/Router enabled=yes \
interfaces=wlan1,wlan2
/ip address
add address=10.1.0.254/24 interface=bridge/Router network=10.1.0.0
add address=172.16.15.254/24 interface=bridge-Guest network=172.16.15.0
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server network
add address=10.1.0.0/24 dns-server=8.8.8.8 domain=8.8.4.4 gateway=10.1.0.254
add address=172.16.15.0/24 dns-server=8.8.8.8 domain=8.8.4.4 gateway=\
172.16.15.254
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.88.1 comment=defconf name=router.lan
/ip firewall address-list
add address=783d07cbf9d4.sn.mynetname.net list=whitelist
/ip firewall filter
add action=accept chain=forward comment="Allow forwards on these ports" \
in-interface-list=WAN protocol=tcp
add action=accept chain=forward comment="Allow forwards on these ports" \
in-interface-list=WAN protocol=udp
add action=drop chain=forward comment="Drop all forwarded traffic from WAN" \
connection-state=new in-interface-list=WAN
add action=accept chain=input comment="PCB-01-Whitelist allowed TCP-Ports" \
connection-state=new dst-port=443,1723,2121,8291,2222 in-interface-list=\
WAN protocol=tcp
add action=jump chain=input comment="PCB-02-Whitelist allowed UDP-Ports" \
connection-state=new dst-port=161,500,4500,1701 in-interface-list=WAN \
jump-target="Public Connection Block" log-prefix=PCB-02-UDP-Jump \
protocol=udp src-address-list=whitelist
add action=accept chain="Public Connection Block" comment=\
"PCB-04-Allow Whitelisted Connection on PCB ports" in-interface-list=WAN \
log-prefix="PCB-04-Allowed Whitelisted" src-address-list=whitelist
add action=accept chain=input comment=\
"PCB-04-Allow Whitelisted Connection on PCB ports" log-prefix=PCB-04-ICMP \
protocol=icmp src-address-list=whitelist
add action=accept chain=input comment=\
"PCB-05 - Allow Established Connections" connection-state=\
established,related in-interface-list=WAN log-prefix=PCB-05-Established
add action=drop chain=input comment="PCB-06 Drop all trafic" \
in-interface-list=WAN
/ip firewall mangle
add action=set-priority chain=postrouting comment="Set priority for WMM" \
new-priority=from-dscp-high-3-bits passthrough=yes
/ip firewall nat
add action=masquerade chain=srcnat ipsec-policy=out,none out-interface=ether1 \
src-address=172.16.15.0/24
add action=masquerade chain=srcnat out-interface=ether1 src-address=\
10.1.0.0/24
/ip service
set telnet port=xx
set ftp disabled=yes
set www disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ppp secret
add name=admin profile=default-encryption
/system clock
set time-zone-name=Europe/Copenhagen
/system identity
set name=xxx
/system watchdog
set watchdog-timer=no
/tool mac-server
set allowed-interface-list=No-Discover
/tool mac-server mac-winbox
set allowed-interface-list=No-Discover
/tool romon
set enabled=yes