MikroTik CAPsMAN setup: manage many access points from one router
Last updated: 11 October 2026
With CAPsMAN, one router (the manager) holds the Wi-Fi settings and every MikroTik access point (a CAP) takes them from it. You change the password once, and every access point has it. As with single access points, there are two systems: one for the older wireless package and one for the newer wifi package.
Before you change a live router: take a backup (how) and turn on Safe Mode in Winbox, so a mistake that locks you out is undone by itself.
Which CAPsMAN?
The access points decide. Check their Wi-Fi interfaces (see Wi-Fi setup): wlan interfaces need the old CAPsMAN, wifi interfaces the new one. The two do not manage each other's access points.
In both cases the access points must reach the manager over your network, the manager should be the router where the LAN bridge lives, and Wi-Fi traffic goes from each access point straight into its own LAN port.
New: wifi CAPsMAN
On the manager:
/interface wifi security add name=sec1 authentication-types=wpa2-psk,wpa3-psk passphrase=AtLeast8Characters
/interface wifi configuration add name=cfg1 ssid=ShopWiFi security=sec1
/interface wifi provisioning add action=create-dynamic-enabled master-configuration=cfg1
/interface wifi capsman set enabled=yes ca-certificate=autoOn each access point (its LAN port in a bridge named bridge, getting an address by DHCP):
/interface wifi datapath add name=capdp bridge=bridge
/interface wifi cap set enabled=yes discovery-interfaces=bridge slaves-datapath=capdp
/interface wifi set [find default-name=wifi1] configuration.manager=capsman datapath=capdp disabled=no
/interface wifi set [find default-name=wifi2] configuration.manager=capsman datapath=capdp disabled=no(A single-radio access point has no wifi2; skip that line.)
Old: wireless CAPsMAN
On the manager:
/caps-man security add name=sec1 authentication-types=wpa2-psk encryption=aes-ccm passphrase=AtLeast8Characters
/caps-man datapath add name=dp1 bridge=bridge local-forwarding=yes
/caps-man configuration add name=cfg1 ssid=ShopWiFi security=sec1 datapath=dp1
/caps-man provisioning add action=create-dynamic-enabled master-configuration=cfg1
/caps-man manager set enabled=yesOn each access point:
/interface wireless cap set enabled=yes interfaces=wlan1,wlan2 discovery-interfaces=bridge bridge=bridgelocal-forwarding=yes lets each access point put client traffic straight into its own LAN instead of sending it all through the manager.
Check
/interface wifi capsman remote-cap print
/caps-man remote-cap print(The first for the wifi system, the second for the old one.) Each access point should be listed, and its radios appear as interfaces on the manager.
An access point does not appear
- It cannot reach the manager: check its cable, its address, and that
discovery-interfacesnames the interface that leads to the manager. - Wrong system: a
wlanaccess point will never show up in wifi CAPsMAN, or the other way round. - Firewall on the manager: CAPsMAN uses UDP 5246 and 5247. The default firewall allows them from the LAN.
- Very different RouterOS versions: upgrade the manager and the access points to the same version.
Tips
- Same name and password on every access point lets phones move between them.
- Turn the power down on access points that are close together; too strong is as bad as too weak.
- For paid access, run the hotspot on the manager's bridge. All access points then share one login page and one list of users.
Questions and answers
What is MikroTik CAPsMAN?
Controlled Access Point system Manager: one MikroTik router holds the Wi-Fi settings and every MikroTik access point takes them from it.
Can wifi CAPsMAN manage old wireless access points?
No. Access points with wlan interfaces need the old CAPsMAN; those with wifi interfaces need the new wifi CAPsMAN.
Does CAPsMAN work with a hotspot?
Yes. Run the hotspot on the manager's LAN bridge and every access point leads to the same login page.