Ty klientské routery v objektech 2 a 3 sou nastaveny jako "AP kleint bridge" - čili mají adresu v síti 192.168.1.x, vypnutý DHCP server. O vše se tak stará hlavní MikroTik. AP-čka připojená k těmto dvěma klientským routerům jsou v režimu AP bridge (čili opět adresa v síti 192.168.1.x, vypnuté DHCP).
Ještě přikládám části konfigurace hlavního routereu (Mikrotik RB433 - MikroTik RouterOS 5.23):
[admin@MikroTik] /interface> print
Flags: D - dynamic, X - disabled, R - running, S - slave
# NAME TYPE MTU L2MTU MAX-L2MTU
0 R ether1_WAN ether 1500 1526 1526
1 R ether2_LAN1 ether 1500 1522 1522
2 R ether3_LAN2 ether 1500 1522 1522
3 wlan1 wlan 1500 2290
4 R bridge_LAN+WiFi bridge 1500 1522
[admin@MikroTik] /interface bridge> print
Flags: X - disabled, R - running
0 R name="bridge_LAN+WiFi" mtu=1500 l2mtu=1522 arp=enabled mac-address=xx:xx:xx:xx:xx:xx protocol-mode=none
priority=0x8000 auto-mac=yes admin-mac=00:00:00:00:00:00 max-message-age=20s forward-delay=15s
transmit-hold-count=6 ageing-time=5m
[admin@MikroTik] /interface bridge>
Bridge interface is accessible through any interface with bridging functionality enabled.
[admin@MikroTik] /interface bridge port> print
Flags: X - disabled, I - inactive, D - dynamic
# INTERFACE BRIDGE PRIORITY PATH-COST HORIZON
0 ether2_LAN1 bridge_LAN+WiFi 0x80 10 none
1 I wlan1 bridge_LAN+WiFi 0x80 10 none
2 ether3_LAN2 bridge_LAN+WiFi 0x80 10 none
[admin@MikroTik] /ip address> print
Flags: X - disabled, I - invalid, D - dynamic
# ADDRESS NETWORK INTERFACE
0 192.168.1.1/24 192.168.1.0 bridge_LAN+WiFi
1 D 10.0.0.100/24 10.0.0.0 ether1_WAN
[admin@MikroTik] /ip address>
[admin@MikroTik] /ip route> print
Flags: X - disabled, A - active, D - dynamic, C - connect, S - static, r - rip, b - bgp, o - ospf, m - mme,
B - blackhole, U - unreachable, P - prohibit
# DST-ADDRESS PREF-SRC GATEWAY DISTANCE
0 ADS 0.0.0.0/0 10.0.0.138 0
1 ADC 10.0.0.0/24 10.0.0.100 ether1_WAN 0
2 ADC 192.168.1.0/24 192.168.1.1 bridge_LAN+WiFi 0
[admin@MikroTik] /interface wireless> print
Flags: X - disabled, R - running
0 name="wlan1" mtu=1500 mac-address=xx:xx:xx:xx:xx:xx arp=enabled interface-type=Atheros AR5413 mode=ap-bridge
ssid="SSID" frequency=xxxx band=2ghz-onlyg channel-width=20mhz scan-list=default
wireless-protocol=unspecified antenna-mode=ant-a wds-mode=disabled wds-default-bridge=bridge_LAN+WiFi
wds-ignore-ssid=no bridge-mode=enabled default-authentication=yes default-forwarding=yes default-ap-tx-limit=0
default-client-tx-limit=0 hide-ssid=yes security-profile=WPA_pater compression=no
[admin@MikroTik] /interface wireless security-profiles> print
Flags: * - default
0 name="WPA_pater" mode=dynamic-keys authentication-types=wpa-psk,wpa2-psk unicast-ciphers=aes-ccm group-ciphers=aes-ccm
wpa-pre-shared-key="xxxxxxxxxxxxxx" wpa2-pre-shared-key="xxxxxxxxxxxxxx" supplicant-identity="" eap-methods="" tls-mode=no-certificates
tls-certificate=none static-algo-0=none static-key-0="" static-algo-1=none static-key-1="" static-algo-2=none static-key-2=""
static-algo-3=none static-key-3="" static-transmit-key=key-0 static-sta-private-algo=none static-sta-private-key=""
radius-mac-authentication=no radius-mac-accounting=no radius-eap-accounting=no interim-update=0s
radius-mac-format=XX:XX:XX:XX:XX:XX radius-mac-mode=as-username radius-mac-caching=disabled group-key-update=5m
management-protection=allowed management-protection-key=""
[admin@MikroTik] /interface wireless security-profiles>
[admin@MikroTik] >> ip firewall nat print
Flags: X - disabled, I - invalid, D - dynamic
0 chain=srcnat action=masquerade out-interface=ether1_WAN
[admin@MikroTik] >> queue simple print
Flags: X - disabled, I - invalid, D - dynamic
[admin@MikroTik] >> queue interface print
Flags: D - dynamic
# INTERFACE QUEUE DEFAULT-QUEUE
0 ether1_WAN only-hardware-queue only-hardware-queue
1 ether2_LAN1 only-hardware-queue only-hardware-queue
2 ether3_LAN2 only-hardware-queue only-hardware-queue
3 wlan1 wireless-default wireless-default
[admin@MikroTik] >> ip firewall filter print
Flags: X - disabled, I - invalid, D - dynamic