Capsman низкая скорость wi-fi 2.4
Добавлено: 20 май 2024, 06:14
ни как не удаётся выжать из wi-fi скорость выше 20Mbps
частный дом, в 30 км от города. эфир чистый
3 микротика, RB951G-2Hnd(capsman), RB951Ui-2nD, RB951Ui-2HnD

между точками переключает по правилу, всё норм

но скорость низкая, максимум 20Mbps, тариф провайдера 100Mbps, при подключению проводом speedtest выдаёт 100Mbps
подскажите в чём может быть дело?
# may/20/2024 12:26:34 by RouterOS 6.49.10
# software id = 1YE8-BWYZ
#
# model = 951G-2HnD
# serial number = 4184026AE9C6
/caps-man channel
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=XX \
frequency=2437 name=2G
/caps-man datapath
add client-to-client-forwarding=yes local-forwarding=yes name=datapath1
/interface bridge
add admin-mac=D4:CA:6D:6C:BE:C9 auto-mac=no comment=defconf igmp-snooping=yes \
name=bridge
/interface wireless
# managed by CAPsMAN
# channel: 2437/20-Ce/gn(6dBm), SSID: 13, local forwarding
set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode \
antenna-gain=0 band=2ghz-b/g/n country=russia3 default-forwarding=no \
disabled=no frequency=auto frequency-mode=manual-txpower \
hw-protection-mode=rts-cts installation=indoor mode=ap-bridge ssid=13 \
station-roaming=enabled wireless-protocol=802.11 wmm-support=enabled \
wps-mode=disabled
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-key-update=20m \
name=security passphrase=12128506
/caps-man configuration
add channel=2G channel.band=2ghz-b/g/n channel.control-channel-width=20mhz \
channel.extension-channel=XX channel.frequency=2437 channel.tx-power=6 \
country=russia4 datapath=datapath1 installation=indoor mode=ap name=2G \
rx-chains=0,1,2,3 security=security ssid=13 tx-chains=0,1,2,3
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=\
dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=12128506 \
wpa2-pre-shared-key=12128506
add authentication-types=wpa-psk,wpa2-psk eap-methods="" \
management-protection=allowed mode=dynamic-keys name=CAM_profile \
supplicant-identity="" wpa-pre-shared-key=12345679846632798 \
wpa2-pre-shared-key=12345679846632798
/ip pool
add name=dhcp2 ranges=192.168.77.101-192.168.77.254
add name=vpnpool ranges=192.168.99.10-192.168.99.100
add name=dhcp next-pool=dhcp2 ranges=192.168.77.10-192.168.77.79
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge name=defconf
/ppp profile
add change-tcp-mss=yes dns-server=192.168.99.1 local-address=192.168.99.1 \
name=PPTPprofile only-one=no remote-address=vpnpool use-compression=yes \
use-encryption=required use-mpls=no use-upnp=no
set *FFFFFFFE dns-server=192.168.99.1 local-address=192.168.99.1 \
remote-address=vpnpool
/system logging action
set 1 disk-file-name=flash/log
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/caps-man access-list
add action=accept allow-signal-out-of-range=10s disabled=no signal-range=\
-79..120 ssid-regexp=""
add action=reject allow-signal-out-of-range=10s disabled=no signal-range=\
-120..80 ssid-regexp=""
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
2G name-format=prefix-identity name-prefix=2G
add action=create-dynamic-enabled disabled=yes hw-supported-modes=an \
name-format=prefix-identity name-prefix=5G
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
/ip neighbor discovery-settings
set discover-interface-list=WAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface pptp-server server
set authentication=mschap2 default-profile=PPTPprofile
/interface wireless access-list
add comment="samsung s8+" interface=wlan1 mac-address=6C:C7:EC:ED:44:D8 \
vlan-mode=no-tag
add comment="\ED\EE\F3\F2 \ED\F0" interface=wlan1 mac-address=\
00:1D:E0:4C:C9:45 vlan-mode=no-tag
add comment="\F0\EE\E1\EE\F2" interface=wlan1 mac-address=24:18:C6:13:C8:A8 \
vlan-mode=no-tag
add comment="\E0\EB\E8\F1\E0" interface=wlan1 mac-address=B8:87:6E:18:3D:A7 \
vlan-mode=no-tag
/interface wireless cap
#
set bridge=bridge discovery-interfaces=bridge enabled=yes interfaces=wlan1
/ip address
add address=192.168.77.1/24 comment=defconf interface=bridge network=\
192.168.77.0
/ip cloud
set ddns-update-interval=1m
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server lease
add address=192.168.77.111 client-id=1:0:80:48:3a:b3:c8 mac-address=\
00:80:48:3A:B3:C8 server=defconf
add address=192.168.77.78 client-id=1:90:e6:ba:a3:95:a8 mac-address=\
90:E6:BA:A3:95:A8 server=defconf
add address=192.168.77.37 client-id=1:7c:fd:6b:e8:d:9c mac-address=\
7C:FD:6B:E8:0D:9C server=defconf
add address=192.168.77.99 client-id=1:44:19:b6:22:6:17 comment=\
"Hikivision ZAL" mac-address=44:19:B6:22:06:17 server=defconf
add address=192.168.77.222 mac-address=00:E0:8B:01:15:B4
add address=192.168.77.11 comment="izba tech poliv" mac-address=\
A8:80:55:12:3A:F7 server=defconf
add address=192.168.77.10 comment="Smart Switch Relay poliv2" mac-address=\
C8:47:8C:01:29:47 server=defconf
add address=192.168.77.90 comment="Camera Hikivision" mac-address=\
28:57:BE:6E:60:9E
add address=192.168.77.15 client-id=1:74:15:75:fa:f9:19 comment="Lilya Redmi" \
mac-address=74:15:75:FA:F9:19 server=defconf
add address=192.168.77.89 comment=Hikivision mac-address=44:19:B6:22:06:02
add address=192.168.77.35 client-id=1:d4:3d:7e:32:fd:c9 mac-address=\
D4:3D:7E:32:FD:C9 server=defconf
add address=192.168.77.88 mac-address=44:19:B6:22:06:16
/ip dhcp-server network
add address=192.168.77.0/24 gateway=192.168.77.1 netmask=24
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.77.1 name=router.lan
add address=108.157.4.61 name=themoviedb.org
add address=65.9.49.79 name=www.themoviedb.org
add address=108.157.4.61 name=api.themoviedb.org
add address=89.187.169.39 name=image.tmdb.org
/ip firewall address-list
add address=wildberries.ru list=wildberries.ru
/ip firewall filter
add action=accept chain=input connection-state="" dst-port=1723 protocol=tcp
add action=accept chain=input connection-state="" protocol=gre
add action=drop chain=forward comment="Cameras Block" src-address=\
192.168.77.88-192.168.77.100
add action=accept chain=input comment=UnblockCapsman dst-address-type=local \
src-address-type=local
add action=reject chain=forward comment="Block wildberries.ru" \
dst-address-list=wildberries.ru protocol=tcp reject-with=\
icmp-network-unreachable
add action=drop chain=forward disabled=yes src-address=192.168.77.35
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=forward disabled=yes dst-port=888 protocol=tcp
add action=drop chain=input disabled=yes dst-port=8291,80 in-interface-list=\
!LAN protocol=tcp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat dst-port=888 in-interface=ether1 protocol=tcp \
to-addresses=192.168.77.35 to-ports=81
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip route
add distance=1 dst-address=192.168.4.0/24 gateway=bridge
/ip service
set telnet disabled=yes
set ftp disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ppp secret
add disabled=yes local-address=192.168.99.1 name=tr0y password=t121285067+ \
profile=PPTPprofile remote-address=192.168.99.99 service=pptp
/system clock
set time-zone-name=Asia/Yekaterinburg
/system ntp server
set enabled=yes
/system package update
set channel=long-term
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN
частный дом, в 30 км от города. эфир чистый
3 микротика, RB951G-2Hnd(capsman), RB951Ui-2nD, RB951Ui-2HnD

между точками переключает по правилу, всё норм

но скорость низкая, максимум 20Mbps, тариф провайдера 100Mbps, при подключению проводом speedtest выдаёт 100Mbps
подскажите в чём может быть дело?
# may/20/2024 12:26:34 by RouterOS 6.49.10
# software id = 1YE8-BWYZ
#
# model = 951G-2HnD
# serial number = 4184026AE9C6
/caps-man channel
add band=2ghz-b/g/n control-channel-width=20mhz extension-channel=XX \
frequency=2437 name=2G
/caps-man datapath
add client-to-client-forwarding=yes local-forwarding=yes name=datapath1
/interface bridge
add admin-mac=D4:CA:6D:6C:BE:C9 auto-mac=no comment=defconf igmp-snooping=yes \
name=bridge
/interface wireless
# managed by CAPsMAN
# channel: 2437/20-Ce/gn(6dBm), SSID: 13, local forwarding
set [ find default-name=wlan1 ] adaptive-noise-immunity=ap-and-client-mode \
antenna-gain=0 band=2ghz-b/g/n country=russia3 default-forwarding=no \
disabled=no frequency=auto frequency-mode=manual-txpower \
hw-protection-mode=rts-cts installation=indoor mode=ap-bridge ssid=13 \
station-roaming=enabled wireless-protocol=802.11 wmm-support=enabled \
wps-mode=disabled
/caps-man security
add authentication-types=wpa2-psk encryption=aes-ccm group-key-update=20m \
name=security passphrase=12128506
/caps-man configuration
add channel=2G channel.band=2ghz-b/g/n channel.control-channel-width=20mhz \
channel.extension-channel=XX channel.frequency=2437 channel.tx-power=6 \
country=russia4 datapath=datapath1 installation=indoor mode=ap name=2G \
rx-chains=0,1,2,3 security=security ssid=13 tx-chains=0,1,2,3
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa-psk,wpa2-psk mode=\
dynamic-keys supplicant-identity=MikroTik wpa-pre-shared-key=12128506 \
wpa2-pre-shared-key=12128506
add authentication-types=wpa-psk,wpa2-psk eap-methods="" \
management-protection=allowed mode=dynamic-keys name=CAM_profile \
supplicant-identity="" wpa-pre-shared-key=12345679846632798 \
wpa2-pre-shared-key=12345679846632798
/ip pool
add name=dhcp2 ranges=192.168.77.101-192.168.77.254
add name=vpnpool ranges=192.168.99.10-192.168.99.100
add name=dhcp next-pool=dhcp2 ranges=192.168.77.10-192.168.77.79
/ip dhcp-server
add address-pool=dhcp disabled=no interface=bridge name=defconf
/ppp profile
add change-tcp-mss=yes dns-server=192.168.99.1 local-address=192.168.99.1 \
name=PPTPprofile only-one=no remote-address=vpnpool use-compression=yes \
use-encryption=required use-mpls=no use-upnp=no
set *FFFFFFFE dns-server=192.168.99.1 local-address=192.168.99.1 \
remote-address=vpnpool
/system logging action
set 1 disk-file-name=flash/log
/user group
set full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,winbox,pas\
sword,web,sniff,sensitive,api,romon,dude,tikapp"
/caps-man access-list
add action=accept allow-signal-out-of-range=10s disabled=no signal-range=\
-79..120 ssid-regexp=""
add action=reject allow-signal-out-of-range=10s disabled=no signal-range=\
-120..80 ssid-regexp=""
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled hw-supported-modes=gn master-configuration=\
2G name-format=prefix-identity name-prefix=2G
add action=create-dynamic-enabled disabled=yes hw-supported-modes=an \
name-format=prefix-identity name-prefix=5G
/interface bridge port
add bridge=bridge comment=defconf interface=ether2
add bridge=bridge comment=defconf interface=ether3
add bridge=bridge comment=defconf interface=ether4
add bridge=bridge comment=defconf interface=ether5
add bridge=bridge comment=defconf interface=wlan1
/ip neighbor discovery-settings
set discover-interface-list=WAN
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface pptp-server server
set authentication=mschap2 default-profile=PPTPprofile
/interface wireless access-list
add comment="samsung s8+" interface=wlan1 mac-address=6C:C7:EC:ED:44:D8 \
vlan-mode=no-tag
add comment="\ED\EE\F3\F2 \ED\F0" interface=wlan1 mac-address=\
00:1D:E0:4C:C9:45 vlan-mode=no-tag
add comment="\F0\EE\E1\EE\F2" interface=wlan1 mac-address=24:18:C6:13:C8:A8 \
vlan-mode=no-tag
add comment="\E0\EB\E8\F1\E0" interface=wlan1 mac-address=B8:87:6E:18:3D:A7 \
vlan-mode=no-tag
/interface wireless cap
#
set bridge=bridge discovery-interfaces=bridge enabled=yes interfaces=wlan1
/ip address
add address=192.168.77.1/24 comment=defconf interface=bridge network=\
192.168.77.0
/ip cloud
set ddns-update-interval=1m
/ip dhcp-client
add comment=defconf disabled=no interface=ether1
/ip dhcp-server lease
add address=192.168.77.111 client-id=1:0:80:48:3a:b3:c8 mac-address=\
00:80:48:3A:B3:C8 server=defconf
add address=192.168.77.78 client-id=1:90:e6:ba:a3:95:a8 mac-address=\
90:E6:BA:A3:95:A8 server=defconf
add address=192.168.77.37 client-id=1:7c:fd:6b:e8:d:9c mac-address=\
7C:FD:6B:E8:0D:9C server=defconf
add address=192.168.77.99 client-id=1:44:19:b6:22:6:17 comment=\
"Hikivision ZAL" mac-address=44:19:B6:22:06:17 server=defconf
add address=192.168.77.222 mac-address=00:E0:8B:01:15:B4
add address=192.168.77.11 comment="izba tech poliv" mac-address=\
A8:80:55:12:3A:F7 server=defconf
add address=192.168.77.10 comment="Smart Switch Relay poliv2" mac-address=\
C8:47:8C:01:29:47 server=defconf
add address=192.168.77.90 comment="Camera Hikivision" mac-address=\
28:57:BE:6E:60:9E
add address=192.168.77.15 client-id=1:74:15:75:fa:f9:19 comment="Lilya Redmi" \
mac-address=74:15:75:FA:F9:19 server=defconf
add address=192.168.77.89 comment=Hikivision mac-address=44:19:B6:22:06:02
add address=192.168.77.35 client-id=1:d4:3d:7e:32:fd:c9 mac-address=\
D4:3D:7E:32:FD:C9 server=defconf
add address=192.168.77.88 mac-address=44:19:B6:22:06:16
/ip dhcp-server network
add address=192.168.77.0/24 gateway=192.168.77.1 netmask=24
/ip dns
set allow-remote-requests=yes
/ip dns static
add address=192.168.77.1 name=router.lan
add address=108.157.4.61 name=themoviedb.org
add address=65.9.49.79 name=www.themoviedb.org
add address=108.157.4.61 name=api.themoviedb.org
add address=89.187.169.39 name=image.tmdb.org
/ip firewall address-list
add address=wildberries.ru list=wildberries.ru
/ip firewall filter
add action=accept chain=input connection-state="" dst-port=1723 protocol=tcp
add action=accept chain=input connection-state="" protocol=gre
add action=drop chain=forward comment="Cameras Block" src-address=\
192.168.77.88-192.168.77.100
add action=accept chain=input comment=UnblockCapsman dst-address-type=local \
src-address-type=local
add action=reject chain=forward comment="Block wildberries.ru" \
dst-address-list=wildberries.ru protocol=tcp reject-with=\
icmp-network-unreachable
add action=drop chain=forward disabled=yes src-address=192.168.77.35
add action=accept chain=input comment=\
"defconf: accept established,related,untracked" connection-state=\
established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=forward disabled=yes dst-port=888 protocol=tcp
add action=drop chain=input disabled=yes dst-port=8291,80 in-interface-list=\
!LAN protocol=tcp
add action=drop chain=input comment="defconf: drop all not coming from LAN" \
in-interface-list=!LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
connection-state=established,related
add action=accept chain=forward comment=\
"defconf: accept established,related, untracked" connection-state=\
established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
connection-state=invalid
add action=drop chain=forward comment=\
"defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
ipsec-policy=out,none out-interface-list=WAN
add action=dst-nat chain=dstnat dst-port=888 in-interface=ether1 protocol=tcp \
to-addresses=192.168.77.35 to-ports=81
/ip firewall service-port
set ftp disabled=yes
set tftp disabled=yes
set irc disabled=yes
set h323 disabled=yes
set sip disabled=yes
set pptp disabled=yes
set udplite disabled=yes
set dccp disabled=yes
set sctp disabled=yes
/ip route
add distance=1 dst-address=192.168.4.0/24 gateway=bridge
/ip service
set telnet disabled=yes
set ftp disabled=yes
set ssh disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip ssh
set allow-none-crypto=yes forwarding-enabled=remote
/ppp secret
add disabled=yes local-address=192.168.99.1 name=tr0y password=t121285067+ \
profile=PPTPprofile remote-address=192.168.99.99 service=pptp
/system clock
set time-zone-name=Asia/Yekaterinburg
/system ntp server
set enabled=yes
/system package update
set channel=long-term
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN