Mikrotik Wifi

Some time after I purchased by Mikrotik Router I wanted to see if I could change my access points to Mikrotik as well and use them via CapsMan so they are managed from my main router.

I purchased a CAP AC and started to play with after a lot of swearing I finally got it connected to my main router through CapsMan. Later I purchased a used WAP AC for a good price – right now it is not connected through CapsMan but that is the plan.

What is important about wifi is that default settings are not nescessarily those that are the best for your environment at home, so you should expect to do some tweaking. One of the most important things is to find set wifi to a channel with no or little use in the neighbourhood.

I have below configuration below which gives me between 350 and 400 Mbit/s

/interface bridge
add name=BR1 protocol-mode=none vlan-filtering=yes
/interface wireless
set [ find default-name=wlan2 ] band=5ghz-n/ac basic-rates-a/g=12Mbps \
channel-width=20/40/80mhz-XXXX country=denmark disabled=no installation=\
indoor mode=ap-bridge name=Wifi1 ssid=Wifi1 supported-rates-a/g=\
12Mbps,18Mbps,24Mbps,36Mbps,48Mbps,54Mbps wps-mode=disabled
set [ find default-name=wlan1 ] band=2ghz-g/n disabled=no frequency=2462 mode=\
ap-bridge ssid=wifi-slow
/interface list
add name=BASE
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk eap-methods=”” mode=\
dynamic-keys supplicant-identity=MikroTik wpa2-pre-shared-key=Password1
add authentication-types=wpa2-psk eap-methods=”” mode=dynamic-keys name=Guest \
supplicant-identity=MikroTik wpa2-pre-shared-key=password2
add authentication-types=wpa2-psk eap-methods=”” management-protection=allowed \
mode=dynamic-keys name=IOT supplicant-identity=”” wpa2-pre-shared-key=\
/interface wireless
add disabled=no keepalive-frames=disabled mac-address=E6:8D:8C:72:A1:57 \
master-interface=wifi1 multicast-buffering=disabled name=IOT \
security-profile=IOT ssid=IOT wds-cost-range=0 wds-default-cost=0 wps-mode=\
add disabled=no keepalive-frames=disabled mac-address=E6:8D:8C:72:A1:58 \
master-interface=Wifi1 multicast-buffering=disabled name=guests \
security-profile=Guest ssid=WiFi_GUEST wds-cost-range=0 wds-default-cost=0 \
/interface bridge port
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged \
ingress-filtering=yes interface=wlan1
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged \
ingress-filtering=yes interface=Wifi1
add bridge=BR1 frame-types=admit-only-vlan-tagged ingress-filtering=yes \
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged \
ingress-filtering=yes interface=IOT pvid=80
add bridge=BR1 frame-types=admit-only-untagged-and-priority-tagged \
ingress-filtering=yes interface=guests pvid=20
/ip neighbor discovery-settings
set discover-interface-list=BASE
/interface bridge vlan
add bridge=BR1 tagged=ether1 untagged=Wifi1,wlan1 vlan-ids=1
add bridge=BR1 tagged=ether1 untagged=A vlan-ids=20 add bridge=BR1 tagged=BR1,ether1 vlan-ids=99 add bridge=BR1 tagged=ether1 untagged=A vlan-ids=80
/ip dhcp-client
add disabled=no interface=BR1
/system clock
set time-zone-name=Europe/Copenhagen
/system identity
set name=AccessPoint