Liked the video? Not yet subscribed? Please consider subscribing to the channel to help this channel reach more people. Feel free to let me know what you thought about it in the comments as well as any other MT content you would like to see!
1st time viewer and I sub'd. Very interesting video: I'm using an Asus RT-AX89X but just ordered a hAP 3 ... Seems like there's a lot more that can be done with it than with the OS my Router uses (virtual machines!?). Very cool. I found this trying to figure out when I should consider a more powerful router and just using my WiFi device as an AP ... Also seems like where the hAP 3 can work with both the DD-WRT and OpenWRT ...and apparently (from watching your video) ... can run VIRTUAL MACHINES within their RouterOS !?? (Uh SUPER cool). I'm assuming their "flagship product" ... the CCR2216-1G-12XS-2XQ ... can also then, yes ...? I'm going to look and see if you've done a video on that device, and if not, perhaps you will in the future. Very cool. Alas, am I wrong to think the hAP 3 - vs - RT-AX89X - vs - Mikrotik's Chateau 5G ax ..... will all yield equivalent WiFi performance to one another ..? And where the "Chateau" is a more "prefabbed" appliance with Cell WAN access, the hAP 3 is [equally] capable with the right add-on modules ... but has the added benefit of being more flexible..? Thanks again, really liked your video and information. Keep it up.
I love MikroTik. I've been working with them for 10yrs at this point. Process is King. I always drill it into my Jr. Admins. "If you upgrade the ROS, do the FW right after. It is ALWAYS a 2-step process." If someone makes an upgrade it is announced and then someone doublechecks. It saves time when you don't have todo "rabbit hole" troubleshooting. Fix the simple things and worry about the big stuff. My only gripe is they have been shipping new units with ROS7 without a "long-term" OS version available, but Stable works fine for now.
I just received mine a few days ago. I am still playing with the configuration before I deploy it to replace my existing setup. I am looking forward to more content on this. Thanks.
I was a big fan of MT. In august 2022 I bought HAP AC3. Having 11 years of experience I still struggled for 3 months. Wifi clients were reconnecting every 10-60 mins. That was 3 months of grabbing suspicious log entry, googling it, reading through forum threads, applying suggested work arounds. After 3 months of "fun" it finally stopped pissing me off. I do love MT, but wifi in them is just junk. Any tplink just works out of the box. My next setup will be some MT + tplink access points.
Yeah, to be honest I will most likely replace this hAP ax3 with something like an RB5009 and also just install a different vendor's APs because I also personally feel like their Wifi access is not the best.
@@TheNetworkBerg I also got a hAP AX3 and 1 GB internet, ethernet cannot go above 700 Mbps and wifi 5GHz no interference never got above 400 Mbps. Do you think RB5009 would give better result?
I have a rb5009 and 3 unifi access points. Works very well. Used chat.gpt to help me optimize and set up the 5009. Worked amazingly well with only a few corrections needed.
Good to see you back. Comments: A wifi tutorial providing a methodical process to configure the wifi from scratch would be invaluable. There are many new settings which are hard to understand. The whole concept of how to deal with Radar DFS is probably a video in of itself. For real world testing did you try OOKLA, curious to see what speeds you get from your laptop. Finally do you recommend running a container such as either Adguard or zerotrust cloudflare tunnel, on a USB stick and if so what size??
I literally returned one of these to Scoop this morning. Everything on this worked flawlessly, except for the wireless. Using the default wireless config I had an incredible amount of wireless instability. I tried several things, including switching wireless bands from ax to ac, separate 2G and 5G SSIDs, different combinations of authentication and encryption, and in every case I kept seeing the same thing - the device would drop off the wireless network at seemingly random times. Sometimes it would happen every 30 seconds, other times I could get a solid 10 minutes of use. In the end I simply got too frustrated, gave up, boxed it up and returned it to Scoop. I've switched back to my old combination of a Fortunate and Unified AP and it's been rock solid.
You are not the only person I have seen having issues with wireless instability, in this video alone there are other comments with people not being happy with the wireless performance. There are also multiple threads on Reddit and the MT forums regarding the wireless. Hopefully it is something that MT can iron out, I don't know if my small tweaks I did to the wireless, or the firmware upgrade I did enhanced my experience. But I can totally see why you would take the device back, I probably would have done the same thing too if the firmware upgrade didn't fix that weird bug I was having when connecting an external drive dropping the entire band.
@@TheNetworkBergMikrotik has made absolutely terrible wifi access points for nearly 6 years now. Their AC products were a proprietary driver and could not deal with interference at all. Hard to set up. Poor performance. Unfixable glitches... Mikrotik can route... But plug in someone else's wireless access points.
@TheNetworkBerg fast forward 1 year... I actually had these issues but it is not firmware related from my experience. I tested the antennas in a lab environment and they only resonate properly on certain parts of the 5 ghz band. Once I switched to a frequency that had preferable return loss, stability was great. Another option is to put on some known good antennas from a reputable manufacturer.
Yeah that is really what sets MT apart from most vendors. All their gear can do the same stuff for the most part (Just newer things like ZeroTier or Containers need ARM/ARM64) Just don't expect to run an IXP BGP router learning 800k+ routes on a hAP or to be a VPN concentrator. But if you want to do BGP on a hAP you can which is sooo cool
@TheNetworkBerg, can you show us how to setup this unit to work with 2 different ISP's on port 4 and 5. The idea is to create a load balancing solution. I am going to connect port 1 to my switch.
Hi @TheNetworkBerg can you make a video tutorial how to install Webserver into hAP AX3? I tryed but have a trouble in order how go setup properly. Thanks
@SuperCharlesPeter if you watch some of my older videos you will hear me say rooter, but as my channel continued to grow I noticed that a large portion of my demographics are in North America and people have the opposite question asking why I say rooter instead of "router" So I just decided that when I am on YT land I try and pronounce things the way most of my viewers will understand it.
@@TheNetworkBerg I ask because here in Australia, a "rooter" is something other than this hardware. I am thinking of buying a ax3 but read some bad reviews. I have 1Gbps from my ISP and need a router that can deliver close to that via wi-fi. Thanks for your video. I can't believe that the firmware was the issue with the USB and 2.4!
I have seen a few people have issues like this with the ax series routers. It seems like poor Wifi is common thing. If you google "MikroTik AX Poor Wifi" there are many threads on Reddit or even on MikroTik's forums. There is a good chance that I don't really experience this much myself as I am mainly sitting right next to the router in my office space and I did have to do a firmware upgrade before my Wifi worked as I believe it should've.
I bought one of these for my parents with LHG LTE18, because it has external antennas and PoE out. I compared it with my Orbi Pro(SXK80) and the 2.4 GHz had around the same signal strength as Orbi’s main router(internal antenna) but the 5GHz seemed a bit weak. My parents are using it at a villa, reaching ~90-100m distance on 2.4GHz.
Thanks for your awesome vids! If you have to choose, in a home setup, would you go for Pfsense or a mikrotik router e.g. the ax3 or another mikrotik, and if so, which one?
That depends completely on your requirements, if you need certain firewall functions like IDS/IPS or web filtering then I would look at either pfSense or Opnsense. If you are looking at a device that natively supports wifi6 with Zerotier and a lot of different Mcguyver functions then an ax3 is perfect for any home. Though you could always mix and match components to get the BEST out of everything. Where I could suggest the RB5009 as your router with a pfSenee behind it to do the firewall functions and connecting something like Ubiquity APs for wireless coverage.
Good video. I'm always asking myself what would I gain by adding extra router, except maybe better wifi signal range, cause I live in 100 years old brick house with 50-60cm think walls in the city center, 2.4GHz band is congested and 5GHz is bad at penetrating walls (plus on docsys modem/router/ap 5Ghz is not stable and usually stops working after two days). I already have some "server" running a few podman containers. Other than that, current modem needs factory reset twice a year and port forwarding configuration has terrible ui in which it's not clear which port are on wan side and which are local. And it does not provide DNS. Just a bridge mode or NAT, port forwarding, DHCP and option to turn on/off wifi. And time-based MAC filtering.
looks like a great device but it has one really big flaw - PoE in/out is on the same port and what is even worse that it is on the speediest one. no chance to daisy chain any other device if the router is far from power outlet and already uses port 1 for powering itself...
@TheNetworkBerg How well does the vlan-filtering bridge work on the hAP ax³? It doesn't appear that the switch chip allows hardware assist, at least with current ROS. You are probably not configuring different ports in different vlans on the hAP ax³ since you probably have a dedicated external managed switch, but if you have played with vlans, your observations would be interesting. (especially testing two ports in the same vlan, one tagged and one untagged, if this was hardware assisted, it should be wirespeed and not use the CPU since there is no routing involved).
Please can you do a tutorial with full config for hap ax3 ?! (multiple vlans, common vlans for LAN and WLAN, trunk concept for mikrotik (using one of ports to connect to a mikrotik switch to expand ports number and span vlans on that sw), firewall rules etc). It seems so dificult to gather all this scattered informations from all videos - in order to achive a full config of this mikrotik hap devices. Thanks
I have a question about hap ax3. Is hardware support only on one bridge or is it provided for more than one bridge? What's better - as many bridges as there are vlans, or one bridge with vlans and then bridge filtering?
I think the hap ax3 uses the cpu regardless looking at the specifications where the CPU and Switch both uses IPQ-6010. Can also see more on the block diagram at i.mt.lv/cdn/product_files/C53UiG5HPaxD2HPaxD_221052.png, it is best practice to use a single bridge with vlan filtering enabled in general so that would be my recommended setup.
Hello, I have this same router, do you use the integrated Wi-Fi? We are having very frequent disconnection problems with wireless clients and I wanted to know your opinion. Thanks
No, since I don't use it. But I have seen people having issues with it in general. I know MikroTik is working on some fixes to WiFiwave2 and possibly Capsman in 7.11, the test channel is already available if you want to test for yourself
I got one a while back and set up. License Level 6 was a shocker at the price point. As for issues I have had, the only one I can state is the wifi backwards compatibility of AX on the 2ghz band. I don't have any wifi 1 or 2 devices, but have wifi 3 and 4 2ghz and wifi 5 and 6 5ghz. N, AC and AX devices connect fine on 2.4 and 5, wpa2/3 when band set to AX. Some G devices failed to connect unless 1. Disabled wpa2/3 (no security) 2. Swap AX band to N band. Is super weird, and proven with trying to connect a hAP AC in station mode when it was locked to G band... Have put in a ticket, but anyone having issues with legacy devices could drop the band down. I had a Spare ap from my old setup so just made a new wifi on that for old devices. Otherwise fantastic router - only other thing I'd ask for is PoE out on another port as well as the in/out on ether1 (replaced a edgerouter x which had an in and an out)
@@johnck435 Mikrotik may have found the cause and are looking at a fix... According to the team that got in touch via the bug report ticket. Maybe 7.10 or 7.11, they gave me no timeframe.
I faced lot of wifi issues and adguard problesm when i upgraded from 7.8 to 7.9...after struggeling and trying a lot (even firmware upgrade), it did not work. So i downgrade again everyting to 7.8 and wifi + adguard are doing fine. I'll stay there to 7.8 as long as nobody will break my device.
Did you mean in a container? I personally dont have time to look at dashboards and thus one can install adguard via DOH right on the Mikrotik. It works great! Choose between add blocker DNS or plus family friendly etc....
hey man, i wish you could do a video on Mikrotik user management through microsoft Active Directoyr. I've searched everywhere, but I'm not sure how I can limit access to the MT router through Active Directory Radius. it will be a great help if you could do this and other PPP AAA authentications through Windows Server. Thank you in advance
I am still running off the ax3, even after immigrating to another country, unfortunately we've had to start using repeaters due to some signal quality issues for multi storey houses .
@@TheNetworkBerg Interesting to know. I was hoping you would say you found some way to improve wifi on it. I ended up moving to an RB5009 with Unifi APs. Anyway, thanks for your content. You've helped me immeasurably.
I've never used the ac2 so I couldn't really say. Although I do not have any issues with overheating on the ax3. The temperature runs constantly at around 52 Celsius which is a fairly normal temp for a router. Especially one where I have a ton of additional features running.
Thank you for your Videos, it is helping me a lot. I got hap az3 and I am facing a bit of issue on configuring the Wi-Fi interface as the design have changed. Can you give me a hand on this matter, please?
Glad to see you back.. I am also currently using mikrotik hAP ac3 at my home, ZT is working fine but due to CG NAT configured on my ISP side could not use Wireguard on it. As far as i know Wireguard needs a static IP or DNS name to reach to your router wan but in my case where my router is hosted on back of ISP Gpon it wasn't possible. Moreover ISP isn't allowing me to change MAC binding which is currently binded with GPON supplied by ISP. please illustrate if i can create a Wireguard Server on my mikrotik and connect my roaming devices my phone and external computers to it. that will be really helpful. Thanks in advance.
Yes CG NAT prevents hosting VPN, you really get a private IP and usually there is no port forwarding option from the ISP. Sometimes an LTE cgnat via a configured APN can provide a private IP ( isp specific ). Hence zerotier really provides the solution for that scenario still correct in that one is relying on a third party.
Thank you for the awesome content as always. I'm still new to Mikrotik using containers, but it's so interesting. Do you think that it's possible to install Portainer or Zamaad helpdesk as a container on a Mikrotik device?
Dear Network Berg, first thx for your great videos. They helped me a lot in the past. Regarding the new ax3 devices, I have two questions. First: Is is possible to deacitvate the LEDs on the ax3 so that the device is completely dark? Looks like this is not working with the ax2... Second: Could you consider making a video on using capsman with the new ax devices? Mikrotik changed a lot on this topic since they introduced wifiwave2. Thx for your help!
The main issue - Berg - is that quite frankly, Mikrotik's software quality control is very poor. It feels as though their software is always written by young people who don't know what they're doing. I would like to see Mikrotik improve itself by releasing less bugs and provide higher quality software in the future. If they continue to screw this up, it will only hurt them.
That is a very fair assumption to make as there is a decades old joke about MikroTik and their version releases where the beta builds are early alpha. The stable builds are beta builds and the long-term release (not even available on ROSv7 yet) are "stable". So I definitely agree that they need to get more resources involved in their software releases. I would also recommend that they fix issues before working on new features. As cool as having some of the new features are it really sucks when there are some old features not working as they should :/
Nice vid Berg and it's funny as I've just been fighting with the AX3 for the last few days. I love the routing functionality but the wifi part I just had to disable. My older wifi devices don't want to connect and the worst is, my AX compatible laptop has a weird RDP lagging issue every few minutes when connected to the hAP AX3. Moved back to my OpenWRT AX capable router and all issues vanished. Yes, I know, should open ticket etc. but at this point I'm thinking Mikrotik just doesn't has its AX3 and backwards compatibility ready and I rather stick to the stuff that works.
Completely understandable and I think you did the right thing since I would do exactly the same thing. Many people seem to struggle with the AC and AX products, hopefully it's something with the software that MT can iron out.
Maybe (requested just out of respect) You do a video, where you explain your Firewall ruels! It would be nice, to compare and to improve our Firewall :)
@@TheNetworkBerg ❤ You have no idea how happy I am now simply because you are responding to my comment. Thank you very much. Waiting for more videos like this. Sorry for my English is bad.
@@TheNetworkBerg disappeared prefix/name-format (were in regular CAPSMAN), very strange behavior if you provisioning yourself (same device where CAPSMAN) - looks like regular config. Even you have renamed interfaces after provisioning it goes back wifiXX etc.
Super cool dude! I really like the addition of the external antennas. The Mikrotik Cube 60Ghz wireless stuff also comes with a random password on the sticker. Personally I don't like it much, but it is for the better.
That sinking feeling when youhave to roll back changes because the wife lost internet🤣🤣🤣🤣🙈🙈. Some content on wifiwave2 will be great had to roll back that update as an old iPad did not connect. Love my hAP ax³
🤦♂ you have got to be kidding me... 😅 even with a much newer firmware (7.12.1), and a flash drive without any cable (mini format), my 2.4GHz didn't work remove the flash drive, and the network comes up 🤦♂
@@TheNetworkBergnah... I'll contact support about it, of course... and thank you for your content, I don't think I'd try to unplug the flash drive (which I added for containers 😆) not sure what I'd do had I not stumbled upon this video 👍
Liked the video? Not yet subscribed? Please consider subscribing to the channel to help this channel reach more people. Feel free to let me know what you thought about it in the comments as well as any other MT content you would like to see!
I liked, I was waiting
1st time viewer and I sub'd. Very interesting video:
I'm using an Asus RT-AX89X but just ordered a hAP 3 ... Seems like there's a lot more that can be done with it than with the OS my Router uses (virtual machines!?). Very cool. I found this trying to figure out when I should consider a more powerful router and just using my WiFi device as an AP ...
Also seems like where the hAP 3 can work with both the DD-WRT and OpenWRT ...and apparently (from watching your video) ... can run VIRTUAL MACHINES within their RouterOS !?? (Uh SUPER cool).
I'm assuming their "flagship product" ... the CCR2216-1G-12XS-2XQ ... can also then, yes ...? I'm going to look and see if you've done a video on that device, and if not, perhaps you will in the future. Very cool.
Alas, am I wrong to think the
hAP 3 - vs - RT-AX89X - vs - Mikrotik's Chateau 5G ax .....
will all yield equivalent WiFi performance to one another ..?
And where the "Chateau" is a more "prefabbed" appliance with Cell WAN access, the hAP 3 is [equally] capable with the right add-on modules ... but has the added benefit of being more flexible..?
Thanks again, really liked your video and information. Keep it up.
Nothing will make you realize your network is messed up more than your wife telling you the internet is down.
or your son 😂
Haha. Give her a Roaming vlan. Play on your own roaming vlan. :) Have a spare ssid that you can enable to test on her /your/both VLANs.
The ultimate shame
I love MikroTik. I've been working with them for 10yrs at this point. Process is King. I always drill it into my Jr. Admins. "If you upgrade the ROS, do the FW right after. It is ALWAYS a 2-step process." If someone makes an upgrade it is announced and then someone doublechecks. It saves time when you don't have todo "rabbit hole" troubleshooting. Fix the simple things and worry about the big stuff. My only gripe is they have been shipping new units with ROS7 without a "long-term" OS version available, but Stable works fine for now.
I just received mine a few days ago. I am still playing with the configuration before I deploy it to replace my existing setup. I am looking forward to more content on this. Thanks.
I was a big fan of MT. In august 2022 I bought HAP AC3. Having 11 years of experience I still struggled for 3 months. Wifi clients were reconnecting every 10-60 mins. That was 3 months of grabbing suspicious log entry, googling it, reading through forum threads, applying suggested work arounds. After 3 months of "fun" it finally stopped pissing me off. I do love MT, but wifi in them is just junk. Any tplink just works out of the box. My next setup will be some MT + tplink access points.
Yeah, to be honest I will most likely replace this hAP ax3 with something like an RB5009 and also just install a different vendor's APs because I also personally feel like their Wifi access is not the best.
I think input my money on the wrong device. 😢
@@TheNetworkBerg I also got a hAP AX3 and 1 GB internet, ethernet cannot go above 700 Mbps and wifi 5GHz no interference never got above 400 Mbps. Do you think RB5009 would give better result?
I have a rb5009 and 3 unifi access points. Works very well. Used chat.gpt to help me optimize and set up the 5009. Worked amazingly well with only a few corrections needed.
i was thinking where did you "lost" and i show in the channel you had 2 months to upload a video. Great that you are back
I would love to see some wifiwave2 capsman content. Especially managing multiple SSIDs with separated VLANs.
Same here!!
Yes great ideea
i tested it and it's not fully implemented yet
Good to see you back. Comments: A wifi tutorial providing a methodical process to configure the wifi from scratch would be invaluable. There are many new settings which are hard to understand. The whole concept of how to deal with Radar DFS is probably a video in of itself. For real world testing did you try OOKLA, curious to see what speeds you get from your laptop. Finally do you recommend running a container such as either Adguard or zerotrust cloudflare tunnel, on a USB stick and if so what size??
I agree radar DFS need better understand
Another great video. Thank you for that. I just got the ax3 and am also really happy with it.
I would love to see walkthroughs and demonstrations of the coolest uses of Mikrotik devices.
I literally returned one of these to Scoop this morning. Everything on this worked flawlessly, except for the wireless. Using the default wireless config I had an incredible amount of wireless instability. I tried several things, including switching wireless bands from ax to ac, separate 2G and 5G SSIDs, different combinations of authentication and encryption, and in every case I kept seeing the same thing - the device would drop off the wireless network at seemingly random times. Sometimes it would happen every 30 seconds, other times I could get a solid 10 minutes of use.
In the end I simply got too frustrated, gave up, boxed it up and returned it to Scoop. I've switched back to my old combination of a Fortunate and Unified AP and it's been rock solid.
You are not the only person I have seen having issues with wireless instability, in this video alone there are other comments with people not being happy with the wireless performance. There are also multiple threads on Reddit and the MT forums regarding the wireless. Hopefully it is something that MT can iron out, I don't know if my small tweaks I did to the wireless, or the firmware upgrade I did enhanced my experience. But I can totally see why you would take the device back, I probably would have done the same thing too if the firmware upgrade didn't fix that weird bug I was having when connecting an external drive dropping the entire band.
@@TheNetworkBergMikrotik has made absolutely terrible wifi access points for nearly 6 years now.
Their AC products were a proprietary driver and could not deal with interference at all.
Hard to set up. Poor performance. Unfixable glitches... Mikrotik can route... But plug in someone else's wireless access points.
@TheNetworkBerg fast forward 1 year... I actually had these issues but it is not firmware related from my experience. I tested the antennas in a lab environment and they only resonate properly on certain parts of the 5 ghz band. Once I switched to a frequency that had preferable return loss, stability was great. Another option is to put on some known good antennas from a reputable manufacturer.
mikrotik is fully open. You can do anything, but you need to know what are you doing. For that $ it is incredible machine.
Yeah that is really what sets MT apart from most vendors. All their gear can do the same stuff for the most part (Just newer things like ZeroTier or Containers need ARM/ARM64) Just don't expect to run an IXP BGP router learning 800k+ routes on a hAP or to be a VPN concentrator. But if you want to do BGP on a hAP you can which is sooo cool
@TheNetworkBerg, can you show us how to setup this unit to work with 2 different ISP's on port 4 and 5. The idea is to create a load balancing solution. I am going to connect port 1 to my switch.
Also please explain about chains in wifi settings. On ax2 there are 6 chains but I can configure 2
Wireless chains are basically physical channels that your antennas are getting the signal out, so there's only a pair of them
how to install tailscale?
Glad to see you back at it! Maybe a tutorial on CAPsMAN with come CAPs? May help out those that want to use it to manage all their AP's.
Please teach us how to install open wrt on mikrotik
Point to Point wireless would be great, how to optimise the link and get the best speeds...🥰
Hi @TheNetworkBerg can you make a video tutorial how to install Webserver into hAP AX3? I tryed but have a trouble in order how go setup properly. Thanks
My wifi interface is not detected any videos on how to solve it... thanks
My home phone line that is connected on Hs300 Router can connected to this router? Also can I use vpn through container app?
Can you set up it as a wifi repeater?
can you post a video on wifiwave2? am also using the AX3 but cannot connect wireless devices, whereas they all work with the AC3.
Thanks for that. Just wondering why you don't pronounce it "rooter" instead of "router" like my old South African colleague?
@SuperCharlesPeter if you watch some of my older videos you will hear me say rooter, but as my channel continued to grow I noticed that a large portion of my demographics are in North America and people have the opposite question asking why I say rooter instead of "router"
So I just decided that when I am on YT land I try and pronounce things the way most of my viewers will understand it.
@@TheNetworkBerg I ask because here in Australia, a "rooter" is something other than this hardware. I am thinking of buying a ax3 but read some bad reviews. I have 1Gbps from my ISP and need a router that can deliver close to that via wi-fi. Thanks for your video. I can't believe that the firmware was the issue with the USB and 2.4!
You have an extremely similar skill set to my own as regards networking.
On mine, wifi deactivates itself when no equipment is connected, so I have to reboot the router for the ssid to reappear.
I have seen a few people have issues like this with the ax series routers. It seems like poor Wifi is common thing. If you google "MikroTik AX Poor Wifi" there are many threads on Reddit or even on MikroTik's forums. There is a good chance that I don't really experience this much myself as I am mainly sitting right next to the router in my office space and I did have to do a firmware upgrade before my Wifi worked as I believe it should've.
Can you rate limit the speeds of the WAN with this router? Like if I wanted to cap it to only being able to pull 100mb down ..
I bought one of these for my parents with LHG LTE18, because it has external antennas and PoE out. I compared it with my Orbi Pro(SXK80) and the 2.4 GHz had around the same signal strength as Orbi’s main router(internal antenna) but the 5GHz seemed a bit weak. My parents are using it at a villa, reaching ~90-100m distance on 2.4GHz.
Thanks for your awesome vids! If you have to choose, in a home setup, would you go for Pfsense or a mikrotik router e.g. the ax3 or another mikrotik, and if so, which one?
That depends completely on your requirements, if you need certain firewall functions like IDS/IPS or web filtering then I would look at either pfSense or Opnsense. If you are looking at a device that natively supports wifi6 with Zerotier and a lot of different Mcguyver functions then an ax3 is perfect for any home. Though you could always mix and match components to get the BEST out of everything. Where I could suggest the RB5009 as your router with a pfSenee behind it to do the firewall functions and connecting something like Ubiquity APs for wireless coverage.
Good video. I'm always asking myself what would I gain by adding extra router, except maybe better wifi signal range, cause I live in 100 years old brick house with 50-60cm think walls in the city center, 2.4GHz band is congested and 5GHz is bad at penetrating walls (plus on docsys modem/router/ap 5Ghz is not stable and usually stops working after two days). I already have some "server" running a few podman containers. Other than that, current modem needs factory reset twice a year and port forwarding configuration has terrible ui in which it's not clear which port are on wan side and which are local. And it does not provide DNS. Just a bridge mode or NAT, port forwarding, DHCP and option to turn on/off wifi. And time-based MAC filtering.
After that big CaP ax dissapointment, ax3 is still the best Mikrotik WiFi6 device. Have fun with it!
looks like a great device but it has one really big flaw - PoE in/out is on the same port and what is even worse that it is on the speediest one. no chance to daisy chain any other device if the router is far from power outlet and already uses port 1 for powering itself...
@TheNetworkBerg How well does the vlan-filtering bridge work on the hAP ax³? It doesn't appear that the switch chip allows hardware assist, at least with current ROS. You are probably not configuring different ports in different vlans on the hAP ax³ since you probably have a dedicated external managed switch, but if you have played with vlans, your observations would be interesting. (especially testing two ports in the same vlan, one tagged and one untagged, if this was hardware assisted, it should be wirespeed and not use the CPU since there is no routing involved).
I assume that the USB power is shared or inline with the 2.4G radio's power ?
That was an assumption I also had to be honest, but weird that a firmware upgrade fixed that
Can you make video for Wifi Wave 2 config .
Please can you do a tutorial with full config for hap ax3 ?! (multiple vlans, common vlans for LAN and WLAN, trunk concept for mikrotik (using one of ports to connect to a mikrotik switch to expand ports number and span vlans on that sw), firewall rules etc). It seems so dificult to gather all this scattered informations from all videos - in order to achive a full config of this mikrotik hap devices. Thanks
I have a question about hap ax3. Is hardware support only on one bridge or is it provided for more than one bridge? What's better - as many bridges as there are vlans, or one bridge with vlans and then bridge filtering?
I think the hap ax3 uses the cpu regardless looking at the specifications where the CPU and Switch both uses IPQ-6010. Can also see more on the block diagram at i.mt.lv/cdn/product_files/C53UiG5HPaxD2HPaxD_221052.png, it is best practice to use a single bridge with vlan filtering enabled in general so that would be my recommended setup.
Thanks a lot for your reply. Greetings and I'm waiting for new videos about MT.@@TheNetworkBerg
nice video, keep it up mate
Does it run pfSense???
I.m considering to buy this router. But i wonder can it do full 1gb over an PPPOE on VLAN-connection with my ISP. Is the proc fast enough?
I do that. No issues at all. Easy
When will be working capsman?
Dunno, MikroTik is still working on it.
Hello,
I have this same router, do you use the integrated Wi-Fi? We are having very frequent disconnection problems with wireless clients and I wanted to know your opinion.
Thanks
Thanks for this video! Thinking about picking up this router. Any idea how much power it consumes?
Mikrotik AX with capsman? Did you test it?
No, since I don't use it. But I have seen people having issues with it in general. I know MikroTik is working on some fixes to WiFiwave2 and possibly Capsman in 7.11, the test channel is already available if you want to test for yourself
I'd love to see some WifiWave2 tests, I don't have any hardware that can run it
I got one a while back and set up. License Level 6 was a shocker at the price point.
As for issues I have had, the only one I can state is the wifi backwards compatibility of AX on the 2ghz band.
I don't have any wifi 1 or 2 devices, but have wifi 3 and 4 2ghz and wifi 5 and 6 5ghz.
N, AC and AX devices connect fine on 2.4 and 5, wpa2/3 when band set to AX. Some G devices failed to connect unless
1. Disabled wpa2/3 (no security)
2. Swap AX band to N band.
Is super weird, and proven with trying to connect a hAP AC in station mode when it was locked to G band... Have put in a ticket, but anyone having issues with legacy devices could drop the band down.
I had a Spare ap from my old setup so just made a new wifi on that for old devices.
Otherwise fantastic router - only other thing I'd ask for is PoE out on another port as well as the in/out on ether1 (replaced a edgerouter x which had an in and an out)
I have the same issue!!! Have you found any solution yet?
@@johnck435 Mikrotik may have found the cause and are looking at a fix... According to the team that got in touch via the bug report ticket.
Maybe 7.10 or 7.11, they gave me no timeframe.
I faced lot of wifi issues and adguard problesm when i upgraded from 7.8 to 7.9...after struggeling and trying a lot (even firmware upgrade), it did not work. So i downgrade again everyting to 7.8 and wifi + adguard are doing fine. I'll stay there to 7.8 as long as nobody will break my device.
please give instructions how to install adguard
Did you mean in a container? I personally dont have time to look at dashboards and thus one can install adguard via DOH right on the Mikrotik. It works great! Choose between add blocker DNS or plus family friendly etc....
@@Anavllama yes
hey man, i wish you could do a video on Mikrotik user management through microsoft Active Directoyr. I've searched everywhere, but I'm not sure how I can limit access to the MT router through Active Directory Radius. it will be a great help if you could do this and other PPP AAA authentications through Windows Server.
Thank you in advance
Curious if you're still running the ax3.
I am still running off the ax3, even after immigrating to another country, unfortunately we've had to start using repeaters due to some signal quality issues for multi storey houses .
@@TheNetworkBerg Interesting to know. I was hoping you would say you found some way to improve wifi on it. I ended up moving to an RB5009 with Unifi APs. Anyway, thanks for your content. You've helped me immeasurably.
Please make a wireless bridge between two wifi routers
Is this one better than the mikrotik hap ac2 I feel like I get so much jitter and it overheats.
I've never used the ac2 so I couldn't really say. Although I do not have any issues with overheating on the ax3. The temperature runs constantly at around 52 Celsius which is a fairly normal temp for a router. Especially one where I have a ton of additional features running.
Mr Berg do you aim to get a certificate in Mikrotik ..? or you already have one..?
I already passed the MTCNA, MTCRE and MTCINE, why do you ask?
Thank you for your Videos, it is helping me a lot.
I got hap az3 and I am facing a bit of issue on configuring the Wi-Fi interface as the design have changed.
Can you give me a hand on this matter, please?
Glad to see you back..
I am also currently using mikrotik hAP ac3 at my home, ZT is working fine but due to CG NAT configured on my ISP side could not use Wireguard on it. As far as i know Wireguard needs a static IP or DNS name to reach to your router wan but in my case where my router is hosted on back of ISP Gpon it wasn't possible. Moreover ISP isn't allowing me to change MAC binding which is currently binded with GPON supplied by ISP.
please illustrate if i can create a Wireguard Server on my mikrotik and connect my roaming devices my phone and external computers to it. that will be really helpful.
Thanks in advance.
Yes CG NAT prevents hosting VPN, you really get a private IP and usually there is no port forwarding option from the ISP. Sometimes an LTE cgnat via a configured APN can provide a private IP ( isp specific ). Hence zerotier really provides the solution for that scenario still correct in that one is relying on a third party.
wow dude i love u, it works!
Thank you for the awesome content as always. I'm still new to Mikrotik using containers, but it's so interesting. Do you think that it's possible to install Portainer or Zamaad helpdesk as a container on a Mikrotik device?
Thanks for the video!
Awesome video. Does MikroTik make any Wifi mesh products?
Audience
Dear Network Berg,
first thx for your great videos. They helped me a lot in the past.
Regarding the new ax3 devices, I have two questions.
First: Is is possible to deacitvate the LEDs on the ax3 so that the device is completely dark? Looks like this is not working with the ax2...
Second: Could you consider making a video on using capsman with the new ax devices? Mikrotik changed a lot on this topic since they introduced wifiwave2.
Thx for your help!
The main issue - Berg - is that quite frankly, Mikrotik's software quality control is very poor. It feels as though their software is always written by young people who don't know what they're doing. I would like to see Mikrotik improve itself by releasing less bugs and provide higher quality software in the future. If they continue to screw this up, it will only hurt them.
That is a very fair assumption to make as there is a decades old joke about MikroTik and their version releases where the beta builds are early alpha. The stable builds are beta builds and the long-term release (not even available on ROSv7 yet) are "stable". So I definitely agree that they need to get more resources involved in their software releases. I would also recommend that they fix issues before working on new features. As cool as having some of the new features are it really sucks when there are some old features not working as they should :/
Nice vid Berg and it's funny as I've just been fighting with the AX3 for the last few days. I love the routing functionality but the wifi part I just had to disable. My older wifi devices don't want to connect and the worst is, my AX compatible laptop has a weird RDP lagging issue every few minutes when connected to the hAP AX3. Moved back to my OpenWRT AX capable router and all issues vanished. Yes, I know, should open ticket etc. but at this point I'm thinking Mikrotik just doesn't has its AX3 and backwards compatibility ready and I rather stick to the stuff that works.
Completely understandable and I think you did the right thing since I would do exactly the same thing. Many people seem to struggle with the AC and AX products, hopefully it's something with the software that MT can iron out.
Maybe (requested just out of respect) You do a video, where you explain your Firewall ruels! It would be nice, to compare and to improve our Firewall :)
HELP ME CONFIGURE MikroTik hAP ax³ REMOTE TEAMVIWER ?
Hey
Hi! The Network Berg. I love all your videos your number 1 fan. Please make video on fq-codel.
Definitely in the pipeline and is something I need to make a vid on :D!
@@TheNetworkBerg ❤
You have no idea how happy I am now simply because you are responding to my comment. Thank you very much. Waiting for more videos like this. Sorry for my English is bad.
indeed..long time no see
Great Video
I'm not happy with ax3, especially CAPSMAN on wave2
Need to test this out, mind saying exactly what you are unhappy with?
@@TheNetworkBerg disappeared prefix/name-format (were in regular CAPSMAN), very strange behavior if you provisioning yourself (same device where CAPSMAN) - looks like regular config. Even you have renamed interfaces after provisioning it goes back wifiXX etc.
Regarding usb interference, Synology router, for instance, even has explicit option to downgrade usb speed in case it makes interference
Super cool dude! I really like the addition of the external antennas. The Mikrotik Cube 60Ghz wireless stuff also comes with a random password on the sticker. Personally I don't like it much, but it is for the better.
The external antennas and design of box means the CPu will run cooler and the wifi should be better than the ax2.
Great review. Would the AX3 with a USB SSD and pi-hole container run off a 12V DC UPS , or would it need 19V?
That sinking feeling when youhave to roll back changes because the wife lost internet🤣🤣🤣🤣🙈🙈. Some content on wifiwave2 will be great had to roll back that update as an old iPad did not connect.
Love my hAP ax³
Hell has no fury like a wife that no longer has access to their scrolling feeds
I fan sir😊
Great. I was waiting
🤦♂ you have got to be kidding me... 😅
even with a much newer firmware (7.12.1), and a flash drive without any cable (mini format), my 2.4GHz didn't work
remove the flash drive, and the network comes up 🤦♂
Oof, maybe certain firmware is just wonky with the wifi and external devices. For me that is not a good design from MikroTik :(
@@TheNetworkBergnah... I'll contact support about it, of course...
and thank you for your content, I don't think I'd try to unplug the flash drive (which I added for containers 😆)
not sure what I'd do had I not stumbled upon this video 👍
Same poblem for me in 2.4ghz. i will upgrade the firware like you .Same device ax3👍
Weird accest for a South African, but thnx for the review.
Thumbs down because of music while speaking!
can you post a video on wifiwave2? am also using the AX3 but cannot connect wireless devices, whereas they all work with the AC3.