/interface bridge
add admin-mac=CA:D7:EC:B6:EC:B2 auto-mac=no name=Bridge-LAN port-cost-mode=\
short
/interface wifi channel
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2G
add band=5ghz-ax disabled=no name=5G skip-dfs-channels=10min-cac
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
/interface wifi security
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes group-key-update=20m \
name=Security passphrase=10203040
/interface wifi configuration
add channel=2G datapath=Datapath disabled=no mode=ap name=2G security=\
Security ssid=nastrojka-mikrotik.ukr
add channel=5G datapath=Datapath disabled=no mode=ap name=5G \
security=Security ssid=nastrojka-mikrotik.ukr
/interface bridge port
add bridge=Bridge-LAN interface=ether1 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether2 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether3 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether4 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether5 internal-path-cost=10 path-cost=10
/interface wifi cap
set caps-man-addresses=127.0.0.1 enabled=yes
/interface wifi capsman
set enabled=yes interfaces="" package-path="" require-peer-certificate=no \
upgrade-policy=require-same-version
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=2G \
name-format=2G-%I supported-bands=2ghz-ax
add action=create-dynamic-enabled disabled=no master-configuration=5G \
name-format=5G-%I supported-bands=5ghz-ax
/ip dhcp-client
add interface=Bridge-LAN
/system clock
set time-zone-name=Europe/Kiev
/system identity
set name=MikroTik-CAPsMAN
/system note
set show-at-login=no
/interface bridge
add admin-mac=16:0A:05:A2:6A:A5 auto-mac=no name=Bridge-LAN
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
/interface wifi
# managed by CAPsMAN
# mode: AP, SSID: nastrojka-mikrotik.ukr, channel: 5500/ax/Ceee
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap \
datapath=Datapath disabled=no
# managed by CAPsMAN
# mode: AP, SSID: nastrojka-mikrotik.ukr, channel: 2412/ax/Ce
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap \
datapath=Datapath disabled=no
/interface bridge port
add bridge=Bridge-LAN interface=ether1
add bridge=Bridge-LAN interface=ether2
/interface wifi cap
set discovery-interfaces=Bridge-LAN enabled=yes
/ip dhcp-client
add interface=Bridge-LAN
/system clock
set time-zone-name=Europe/Kiev
/system identity
set name=MikroTik-cAP-ax
/system note
set show-at-login=no
/interface bridge
add admin-mac=CA:D7:EC:B6:EC:B2 auto-mac=no name=Bridge-LAN port-cost-mode=\
short
/interface wifi channel
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2G
add band=5ghz-ax disabled=no name=5G skip-dfs-channels=10min-cac
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
/interface wifi security
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes group-key-update=20m \
name=Security passphrase=10203040
/interface wifi configuration
add channel=2G datapath=Datapath disabled=no mode=ap name=2G security=\
Security ssid=nastrojka-mikrotik.ukr
add channel=5G country=Latvia datapath=Datapath disabled=no mode=ap name=5G \
security=Security ssid=nastrojka-mikrotik.ukr
/interface bridge port
add bridge=Bridge-LAN interface=ether1 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether2 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether3 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether4 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether5 internal-path-cost=10 path-cost=10
/interface wifi cap
set caps-man-addresses=127.0.0.1 enabled=yes
/interface wifi capsman
set enabled=yes interfaces="" package-path="" require-peer-certificate=no \
upgrade-policy=require-same-version
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=2G \
name-format=2G-%I supported-bands=2ghz-ax
add action=create-dynamic-enabled disabled=no master-configuration=5G \
name-format=5G-%I supported-bands=5ghz-ax
/ip dhcp-client
add interface=Bridge-LAN
/system clock
set time-zone-name=Europe/Kiev
/system identity
set name=MikroTik-CAPsMAN
/system note
set show-at-login=no
/interface bridge
add admin-mac=CA:D7:EC:B6:EC:B2 auto-mac=no name=Bridge-LAN port-cost-mode=\
short vlan-filtering=yes
/interface vlan
add interface=Bridge-LAN name=Vlan-100 vlan-id=100
/interface wifi channel
add band=2ghz-ax disabled=no frequency=2412,2437,2462 name=2G
add band=5ghz-ax disabled=no name=5G
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
add bridge=Bridge-LAN client-isolation=yes disabled=no name=Datapath-Guest \
vlan-id=100
/interface wifi security
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes \
group-key-update=20m name=Security passphrase=10203040
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes \
group-key-update=20m name=Security-Guest passphrase=10203040
/interface wifi configuration
add channel=2G datapath=Datapath disabled=no mode=ap name=2G security=\
Security ssid=nastrojka-mikrotik.ukr
add channel=5G country=Latvia datapath=Datapath disabled=no mode=ap name=5G \
security=Security ssid=nastrojka-mikrotik.ukr
add datapath=Datapath-Guest disabled=no name=Guest security=Security-Guest \
ssid=nastrojka-mikrotik.ukr-Guest
/ip pool
add name=Ip-Pool-Guest ranges=192.168.254.2-192.168.254.254
/ip dhcp-server
add address-pool=Ip-Pool-Guest interface=Vlan-100 name=DHCP-Guest
/interface bridge port
add bridge=Bridge-LAN interface=ether1 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether2 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether3 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether4 internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=ether5 internal-path-cost=10 path-cost=10
/interface bridge vlan
add bridge=Bridge-LAN tagged=ether1,ether2,ether3,ether4,ether5,Bridge-LAN \
vlan-ids=100
/interface wifi cap
set caps-man-addresses=127.0.0.1 enabled=yes slaves-datapath=Datapath
/interface wifi capsman
set enabled=yes interfaces="" package-path="" require-peer-certificate=no \
upgrade-policy=require-same-version
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=2G \
name-format=2G-%I slave-configurations=Guest supported-bands=2ghz-ax
add action=create-dynamic-enabled disabled=no master-configuration=5G \
name-format=5G-%I slave-configurations=Guest supported-bands=5ghz-ax
/ip address
add address=192.168.254.1/24 interface=Vlan-100 network=192.168.254.0
/ip dhcp-client
add interface=Bridge-LAN
/ip dhcp-server network
add address=192.168.254.0/24 dns-server=192.168.254.1 gateway=192.168.254.1
/ip dns
set allow-remote-requests=yes
/ip firewall filter
add action=drop chain=forward dst-address=175.10.0.0/24 src-address=\
192.168.254.0/24
add action=accept chain=forward dst-address=!175.10.0.0/24 src-address=\
192.168.254.0/24
add action=accept chain=input dst-port=53 in-interface=Vlan-100 protocol=udp
add action=drop chain=forward in-interface=Vlan-100
add action=drop chain=input in-interface=Vlan-100
/ip firewall nat
add action=masquerade chain=srcnat out-interface=Bridge-LAN src-address=\
192.168.254.0/24
/system clock
set time-zone-name=Europe/Kiev
/system identity
set name=MikroTik-CAPsMAN
/system note
set show-at-login=no
/interface bridge
add admin-mac=46:C6:C2:80:80:39 auto-mac=no name=Bridge-LAN vlan-filtering=\
yes
/interface vlan
add interface=Bridge-LAN name=Vlan-100 vlan-id=100
/interface wifi channel
add band=2ghz-n disabled=no name=2G-N
add band=5ghz-ac disabled=no name=5G-AC skip-dfs-channels=10min-cac
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
add bridge=Bridge-LAN client-isolation=yes disabled=no name=Datapath-Guest-AC
/interface wifi security
add authentication-types=wpa2-psk disabled=no ft=yes ft-over-ds=yes \
group-key-update=20m name=Security
/interface wifi configuration
add channel=2G-N datapath=Datapath disabled=no mode=ap name=2G security=\
Security ssid=nastrojka-mikrotik.ukr
add datapath=Datapath-Guest-AC disabled=no mode=ap name=Guest-AC security=\
Security ssid=nastrojka-mikrotik.ukr-Guest
add channel=5G-AC datapath=Datapath disabled=no mode=ap name=5G security=\
Security ssid=nastrojka-mikrotik.ukr
/interface bridge port
add bridge=Bridge-LAN interface=ether3
add bridge=Bridge-LAN interface=ether1
add bridge=Bridge-LAN interface=ether2
add bridge=Bridge-LAN interface=ether4
add bridge=Bridge-LAN interface=ether5
/interface bridge vlan
add bridge=Bridge-LAN tagged=Bridge-LAN,ether3 vlan-ids=100
/interface wifi capsman
set enabled=yes package-path="" require-peer-certificate=no upgrade-policy=\
require-same-version
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=2G \
name-format=2G-%I slave-configurations=Guest-AC supported-bands=2ghz-n
add action=create-dynamic-enabled disabled=no master-configuration=5G \
name-format=5G-%I slave-configurations=Guest-AC supported-bands=5ghz-ac
/interface bridge
add admin-mac=D2:E0:4D:D6:1F:93 auto-mac=no ingress-filtering=no name=\
Bridge-LAN port-cost-mode=short vlan-filtering=yes
/interface wifi datapath
add bridge=Bridge-LAN disabled=no name=Datapath
/interface wifi
# managed by CAPsMAN
# mode: AP, SSID: nastrojka-mikrotik.ukr, channel: 2412/n/Ce
set [ find default-name=wifi1 ] configuration.manager=capsman .mode=ap \
datapath=Datapath disabled=no
# managed by CAPsMAN
# mode: AP, SSID: nastrojka-mikrotik.ukr, channel: 5500/ac/Ceee
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap \
datapath=Datapath disabled=no
# managed by CAPsMAN
# mode: AP, SSID: nastrojka-mikrotik.ukr-Guest
add configuration.mode=ap disabled=no mac-address=4A:A9:8A:F2:9A:D0 \
master-interface=wifi1 name=wifi12
add configuration.mode=ap disabled=no mac-address=4A:A9:8A:F2:9A:D1 \
master-interface=wifi2 name=wifi22
/interface bridge port
add bridge=Bridge-LAN ingress-filtering=no interface=ether1 \
internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN ingress-filtering=no interface=ether2 \
internal-path-cost=10 path-cost=10
add bridge=Bridge-LAN interface=wifi12 pvid=100
add bridge=Bridge-LAN interface=wifi22 pvid=100
/interface bridge vlan
add bridge=Bridge-LAN tagged=ether1 untagged=wifi12,wifi22 vlan-ids=100
/interface wifi cap
set discovery-interfaces=Bridge-LAN enabled=yes slaves-static=yes
/ip dhcp-client
add interface=Bridge-LAN
/caps-man channel
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=XX \
frequency=2412,2437,2462 name=2G
add band=5ghz-a/n/ac control-channel-width=20mhz extension-channel=XXXX name=\
5G skip-dfs-channels=yes
/caps-man datapath
add client-to-client-forwarding=yes local-forwarding=yes name=Datapath
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-encryption=aes-ccm \
group-key-update=20m name=Security passphrase=11223344
/caps-man configuration
add channel=2G country=no_country_set datapath=Datapath installation=any \
mode=ap name=2G rx-chains=0,1,2,3 security=Security ssid=Home tx-chains=\
0,1,2,3
add channel=5G country=no_country_set datapath=Datapath installation=any \
mode=ap name=5G rx-chains=0,1,2,3 security=Security ssid=Home tx-chains=\
0,1,2,3
/caps-man manager set enabled=yes upgrade-policy=require-same-version
/caps-man provisioning
add action=create-dynamic-enabled hw-supported-modes=ac master-configuration=\
5G name-format=prefix-identity name-prefix=5G
add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
2G name-format=prefix-identity name-prefix=2G
/interface bridge
add admin-mac=02:F1:41:46:46:E2 auto-mac=no name=Bridge-LAN
/interface wireless
# managed by CAPsMAN
# channel: 2462/20-eC/gn(28dBm), SSID: Home, CAPsMAN forwarding
set [ find default-name=wlan1 ] ssid=MikroTik station-roaming=enabled
# managed by CAPsMAN
# channel: 5200/20-eCee/ac(14dBm), SSID: Home, CAPsMAN forwarding
set [ find default-name=wlan2 ] ssid=MikroTik station-roaming=enabled
/interface wireless security-profiles
set [ find default=yes ] supplicant-identity=MikroTik
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/interface bridge port
add bridge=Bridge-LAN interface=ether1
add bridge=Bridge-LAN interface=ether2
/interface wireless cap
set bridge=Bridge-LAN discovery-interfaces=Bridge-LAN enabled=yes interfaces=\
wlan1,wlan2
/ip dhcp-client
add disabled=no interface=Bridge-LAN
/system identity
set name=MikroTik-AP-3
/system scheduler
add name=Auto-Upgrade-Firmware on-event="if ([/system routerboard get current-\
firmware] != [/system routerboard get upgrade-firmware]) do={\r\
\n/system routerboard upgrade\r\
\n:delay 15s\r\
\n/system reboot\r\
\n}" policy=\
ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
start-time=startup
/tool romon
set enabled=yes
add action=reject allow-signal-out-of-range=10s disabled=no interface=all \
signal-range=-120..-85 ssid-regexp=""