The cAP ax (product code cAPGi-5HaxD2HaxD) is made for a ceiling or a wall, fed over the network cable, with a router or switch doing the real work. You hang two or five of them with the same SSID and the same passphrase, and people walk through the building without their phone noticing. It is not a router and it does not want to be one.
The ports
ether1— gigabit, with PoE-in. This is the cable to your switch or router: data and power at once. It is also the port where your VLANs arrive tagged.ether2— gigabit, with PoE-out. You can hang a next device off it and power it at the same time: a second cAP, a phone, a camera.
Two ports is exactly enough and not one port more. That has consequences for which roles the tool offers, see below. PoE-out is switched on in advanced; more about it in PoE-out.
Wi-Fi
The catalogue lists two radios on this model:
wifi1— 5 GHz. The band your speed comes from and where your clients belong.wifi2— 2.4 GHz. For reach, old devices and IoT gear that knows nothing else.
The Wi-Fi package for this model is wifi, the newer of the two Wi-Fi packages in RouterOS v7. So the configurator writes the wireless side as /interface wifi, not as /interface wireless. That is not a choice you have to make: the tool reads it from the catalogue record and writes the right one. What you do choose is the SSIDs, the security and the country, and the country decides which channels and power levels are allowed. See Wi-Fi settings and Channels.
What is inside
From the catalogue: a 64-bit ARM processor, 1 GB of RAM, an IPQ-6010 as the switch chip and a level 4 RouterOS licence. The data has been checked against real hardware. 1 GB is generous for an access point; level 4 is enough for the role you give it, but it does cap the number of tunnels. See RouterOS licences.
What it is good at, and where it runs out
Good at: delivering clean Wi-Fi somewhere a cable already runs, broadcasting several SSIDs on different VLANs, and powering both itself and the next device.
Where it runs out:
- Two wired ports. Roles that need at least three wired ports, such as Office router with VLANs, Router + CAPsMAN and Hotspot, are blocked by the tool with "Needs at least 3 wired ports". That is not fussiness: you need a WAN, a LAN and a trunk, and they do not fit here side by side.
- No LTE, no SFP. The uplink is copper or nothing.
- An access point is not a router. It can be one, with the Home router role, but then ether1 is your WAN and you are left with a single LAN port. That is rarely what you want.
Which roles fit
- Access point — the normal choice. Everything bridged, SSIDs optionally per VLAN, management address by DHCP or static. No DHCP server, no NAT.
- CAP (managed by CAPsMAN) — when you want SSIDs and security set centrally on a controller instead of on every device separately. See CAPsMAN.
- Wi-Fi repeater / extender — for a spot without a cable. Because this model has two radios, the uplink radio does not have to rebroadcast as well. Still expect a serious drop in throughput.
- Wireless CPE / point-to-point — as the station end of a wireless link.
The quickest route to a working configuration
If it hangs on its own, pick the model, pick the Access point role and walk through the wizard: country, SSIDs, management address, password. Done.
If there are several of them and a router with VLANs, use Multiple devices instead. Every access point then gets the same SSID, the same security and the same passphrase, which is the condition for roaming, and the site checks tell you whether the management VLAN reaches each device. A worked case is in Example: an office.
What trips people up
- Forgetting the management VLAN. Put the access point on a management VLAN that does not arrive tagged over the trunk and it is unreachable the moment you paste. The site checks catch this when you work with several devices.
- Different Wi-Fi settings per access point. For roaming the name, security and passphrase have to match. That is why they live in the shared settings.
- Turning PoE-out on without looking at the supply. The cAP is itself powered over ether1. If it also has to power something on ether2, the far end of that first cable has to have the headroom for both.
- Setting the country wrong. It changes the allowed channels and power, and with them your coverage. See Channels.
- Wanting a wide channel on 2.4 GHz. There is no room there; on that band you win with a narrow channel and a quiet neighbourhood.