Skip to content

60 GHz Radios — MTU & Recovery (Wireless Wire / Cube Pro)

Related pages

Design-phase doc. Operational reference: Wireless 60 GHz.

Version: 1.0 — 2026-07-06 Operations notes for the MikroTik 60 GHz backup links: Wireless Wire (60 GHz only, e.g. RBwAPG-60ad / nRAY pairs) and Wireless Wire Cube Pro (60 GHz + 5 GHz failover, CubeG-5ac60ad pairs). These are the metro's backup paths (DESIGN.md §2.3) and — being wireless — the MTU bottleneck for the whole MPLS/VPLS overlay (CONFIG-GUIDE §6). Both run RouterOS (ROS6 or ROS7), so everything below is per-RouterBOARD.


1. What they are, and why the difference matters

Product Radios Failover Notes
Wireless Wire (RBwAPG-60ad, nRAY) 60 GHz only (802.11ad, /interface w60g) None — link drops in heavy rain/fog Cheapest, shortest range; a wet-weather single point of failure
Wireless Wire Cube Pro (CubeG-5ac60ad) 60 GHz primary + 5 GHz (802.11ac) Automatic to 5 GHz when 60 GHz fades Longer range, rain-resilient; the right choice for any link that must survive weather

60 GHz (V-band, 57–66 GHz) is high-capacity but rain/foliage-attenuated — a 60 GHz-only hop can disappear in a downpour exactly when you least want a backup to fail. The Cube Pro's 5 GHz keeps the link up (at lower capacity) through rain fade, which is why it's preferred on any path that is someone's only backup (e.g. Seel↔Holmes if built, Old Bank).

2. MTU — the design-critical part

The overlay needs L2 MTU ≥ 1596 on every infra link for MPLS labels, and more (~1620) for VPLS + RFC 4638 PPPoE (CONFIG-GUIDE §6). Fibre does 9000 trivially; these radios are where MTU is tight and must be verified per model.

2.1 60 GHz (w60g)

  • Check and raise: /interface w60g set wlan60-1 l2mtu=<n> then /interface w60g print to confirm what actually took. The hardware caps L2MTU — it silently won't exceed its max, so always read it back.
  • Typical w60g L2MTU default is ~1600; newer nRAY/Cube generations support more. Do not assume — measure. A link that reports 1600 L2MTU can carry basic MPLS but is marginal for VPLS and cannot do RFC 4638 clean-1500 PPPoE.
  • Validate end-to-end after setting, don't trust the number: from one side, /ping <far-loopback> size=1580 do-not-fragment (and step up). If DF pings at your target size fail across the hop, the pseudowire will silently blackhole — this test is mandatory before enabling any VPLS over the radio.

2.2 Cube Pro — match 60 GHz and 5 GHz, or failover breaks pseudowires

The Cube bridges the w60g and the 5 GHz wlan (or wifiwave2) interface; traffic prefers 60 GHz and fails to 5 GHz automatically. The bridge's usable L2MTU is the minimum of its member interfaces. So: - Set the same L2MTU on both radios and the bridge. 5 GHz (802.11ac) can carry large frames (L2MTU up to ~2290), so the 60 GHz side is the limit — set 5 GHz to match it. - If they differ, a 60 GHz→5 GHz failover changes the path MTU mid-session and silently drops oversized MPLS/VPLS frames — the link "works" for ping but pseudowires break only when it's raining. Nightmare to diagnose. Matching MTU on both radios makes failover MTU-transparent.

2.3 When a radio can't reach the target MTU

If a given radio maxes below ~1596, that hop cannot carry the full overlay. Options, per link: - Let it carry plain IP backup only (OSPF/BGP still fail over) but exclude it from VPLS paths — guest/ISP-POP simply don't fail over across that hop (acceptable: during a fibre outage, guest degrading is fine; §7 QoS already deprioritises it). - Or drop PPPoE MTU to 1492 on any POP circuit whose backup crosses that radio (WAN-DESIGN notes this fallback). - Record each radio's verified max L2MTU in the registry (network.yaml / NetBox) next to the link — it's a first-class attribute of the link, like OSPF cost.

3. Password recovery / factory reset

Losing the password on a roof radio is the scenario to plan for. Three tiers, worst-case last.

3.1 If you have physical access (roof)

  • Reset button (hold during power-up — behaviour by how long you hold, watch the LED):
  • Release when the LED starts flashing (~5 s) → reset configuration to defaults.
  • Keep holding until the LED goes solid/stops (~10 s) then release → Etherboot / netinstall mode (BOOTP — waits for a netinstall server).
  • Exact timings vary by model — the LED transition is the reliable signal, not a stopwatch.
  • Reset jumper hole on models without an accessible button — short during power-up, same effect.
  • This is identical on ROS6 and ROS7 — reset behaviour lives in RouterBOOT (firmware), below the OS.

3.2 Netinstall (wipes config, reinstalls RouterOS) — ROS6 & ROS7

  • Run Netinstall (Windows tool, or netinstall-cli on Linux) on a machine with an L2 path to the radio's ethernet (i.e. on the roof switch / the feeding router's segment).
  • The radio must be in Etherboot mode — normally via the reset button (§3.1), or remotely via §3.3.
  • Use a Netinstall version ≥ the RouterOS you're flashing; it can install either 6.x or 7.x (pick the package you want). This is how you'd also downgrade/upgrade a bricked radio.
  • After netinstall the config is empty → push your saved config (Oxidized/Terraform) back. For a paired link this includes re-creating the w60g pairing (SSID, frequency, connect-list/peer MAC) — a reset loses the pairing, so both ends' radio settings must be reapplied. Keep the pairing parameters in the config backup so recovery is copy-paste, not guesswork.

3.3 If you CANNOT get to the roof — the only remote path, and it must be pre-armed

You cannot press a button remotely. The only way to netinstall a roof radio without touching it is to have prepared it in advance:

Pre-arm every roof radio NOW (before you ever lose access): 1. Set it to try netboot on every power-cycle: /system routerboard settings set boot-device=try-ethernet-once-then-nand (exists on both ROS6 and ROS7). On each boot it briefly looks for a Netinstall/BOOTP server on ethernet, then boots normally from NAND if none answers — harmless in normal operation. 2. Ensure the radio's PoE is remotely power-cyclable — it's fed from a switch/router port you can reach (the neighbour hub router or roof switch). /interface ethernet poe set <port> poe-out=off then on power-cycles it.

Recovery when locked out (roof unreachable): 1. Stand up a Netinstall server on the L2 segment feeding the radio (a laptop on the roof-switch's management VLAN, or netinstall-cli on the neighbour device's network) with the desired RouterOS package and a default/target config queued. 2. Remotely toggle the radio's PoE off/on (from the feeding router you can reach). 3. On boot the radio (via try-ethernet-once) finds the waiting Netinstall server → flashes → comes up on default config → push your saved config.

Without step 1 of the pre-arm done ahead of time, there is no remote recovery — it's a roof visit. So this pre-arm is a one-time task to do on every 60 GHz radio at install/next-touch.

Caveat — the paired-link chicken-and-egg: if the lost-password radio is the far end of the only path to itself (you reach it only over its own 60 GHz link), netinstall drops that link the moment it reboots. Mitigations: reach the radio's ethernet from the local (roof-switch) side where the Netinstall server sits, not across the radio link; and on Cube Pro, the 5 GHz side may keep a management path up during 60 GHz reflash. For a genuinely single-homed roof radio reachable only over itself, roof access is unavoidable — which is an argument for the §3.3 pre-arm and for not single-homing critical roof kit.

4. Pre-arm checklist (do once per radio, at install or next maintenance)

  • [ ] boot-device=try-ethernet-once-then-nand set (enables remote netinstall)
  • [ ] Radio PoE fed from a remotely reachable switch/router port (enables remote power-cycle)
  • [ ] Verified max L2MTU recorded in the registry; both radios matched on Cube Pro
  • [ ] DF-ping MTU test passed at the overlay's target size before any VPLS uses the hop
  • [ ] Full /export in Oxidized/Terraform including w60g pairing params (so a reset is recoverable)
  • [ ] Emergency local credential stored in the vault (these radios may not reach RADIUS over a backup path — don't rely on RADIUS-only auth on roof kit)
  • [ ] RoMON enabled on the radio + its neighbour (reaches it by MAC if it loses its IP — note: RoMON still needs valid credentials, so it helps "lost IP", not "lost password")

4b. Known radio inventory (as-built)

Discovered/confirmed 60 GHz links, to seed the registry. Radio credentials must all be cycled; the interim credentials are recorded in discovery/credentials.md (gitignored — not published), not here.

Link Radio Ports (as-built) Failover Notes
Colo (LEVEL-01) ↔ Old Bank roof MikroTik nRAY (60 GHz) CR-LEVEL-01 sfp11 ↔ CR-OLDBANK-01 ether3 (10.254.5.28/30) none (60 GHz only) Port comment says "5 GHz" — wrong; it's nRAY 60 GHz. Migrates to CR-COLOROOF-01 in MOVE-PLAN D1.
CR-LEVEL-01 → Lord St Wireless Wire (60 GHz pair) CR-LEVEL-01 sfpplus1.4 (to Lord St, RTR-LOR-001) none (60 GHz only) A radio link, not a Vive-provider L2 VLAN as FIBRE-PATCH first assumed — reconcile the fibre count. Pair MACs + password in discovery/credentials.md.
Colo roof (LEVEL-03) ↔ Charlotte roof MikroTik 60 GHz (type TBC) CR-LEVEL-03 ether1 ↔ CR-CHARLOTTESTREET-01 ether1 (10.254.8.20/30) TBC The colo-roof↔Charlotte-roof backup (DESIGN §2.2). LEVEL-03 → CR-COLOROOF-01 (MOVE-PLAN D1); radio stays. Pair MACs + password in discovery/credentials.md.
Colo roof (LEVEL-03) ↔ Irish House MikroTik 60 GHz (type TBC) CR-LEVEL-03 ether5 ↔ Irish House venue ether5 TBC The Irish House 60 GHz (DESIGN §5.1). LEVEL-03 → CR-COLOROOF-01 (MOVE-PLAN D1); radio stays. Pair MACs + password in discovery/credentials.md.
Colo roof (LEVEL-03) ↔ Old Bank roof MikroTik 60 GHz (type TBC) CR-LEVEL-03 ether6 ↔ Old Bank roof ether6 (10.254.8.24/30) TBC 2nd of Old Bank's 2×60 GHz to colo (1st = nRAY on LEVEL-01 sfp11). ⚠ both land on CR-COLOROOF-01 after D1 — split for diversity. Creds in discovery/credentials.md.
Old Bank roof ↔ Castle St (hotel) vendor TBC — MAC OUI may not be MikroTik CR-OLDBANK-01 ether6 ↔ Castle St (RTR-CAS-001, 10.254.23.4/30) TBC ⚠ If not MikroTik (e.g. Ubiquiti), the recovery in this doc does not apply — different vendor process. Creds in discovery/credentials.md.
Old Bank roof ↔ Lord St roof MikroTik 60 GHz (type TBC) CR-OLDBANK-01 ether2 ↔ CR-LORDSTREETROOF-01 (offline) TBC Feed to the offline Lord St roof — explains its discovery no-show. Lord St venue is on the LEVEL-01 Wireless Wire, so removal (MOVE-PLAN §E) doesn't strand it. Creds in discovery/credentials.md.
Charlotte roof ↔ (undocumented roof router) LHGG-60ad (60 GHz) CR-CHARLOTTESTREET-01 ether2 ↔ ugly static-route roof segment none (60 GHz only) ⚠ Leads to an undocumented static-route-managed roof router (Temple Tavern, Reiss, 10.246.100.0/29) — needs its own discovery + untangle. Creds in discovery/credentials.md.
Charlotte roof ↔ Irish House (2nd link) MikroTik 60 GHz (type TBC) CR-CHARLOTTESTREET-01 ether8 ↔ Irish House (RTR-IRH-001, 10.254.4.78) TBC Irish House dual-homed (also colo roof via LEVEL-03 ether5). Creds in discovery/credentials.md.
Temple Court roof ↔ Shiraz 2 MikroTik 60 GHz (type TBC) Temple Court roof ↔ Shiraz 2 TBC → PPPoE VPLS (ISP business, WAN-DESIGN.md) — Shiraz 2 becomes an ISP POP; radio is its access hop. Creds in discovery/credentials.md.
Temple Court roof ↔ Cumberland Hotel MikroTik 60 GHz (type TBC) Temple Court roof ↔ Cumberland Hotel TBC → PPPoE VPLS (ISP business) — ISP POP. Far-end OUI 04:F4:1C — confirm MikroTik. Creds in discovery/credentials.md.
Boston (Holmes) ↔ Moloko venue MikroTik 60 GHz (type TBC) CR-BOSTON-01 ether1 ↔ Moloko (RTR-MOL-001) TBC Moloko re-homes to Seel; then this radio = spare/reserve, documented & not used (maybe a future metro link). Creds in discovery/credentials.md.
Boston (Holmes) ↔ Seel St metro MikroTik 60 GHz (OFFLINE) CR-BOSTON-01 ↔ CR-SEELST-01 (metro↔metro) n/a ⭐ The Seel↔Holmes ring-closure link already exists as dormant hardware (DESIGN §2.4) — reviving it gives Seel its backup with no new kit. Find why it's offline. Creds in discovery/credentials.md.

(Add rows as other radios are confirmed — the roof antennas we couldn't auth into during discovery: LEVEL_, ANT-, LEVEL-IRISH-, LEVEL_TO_RUBY_.)

Both are 60 GHz-only (no 5 GHz failover) — they drop in heavy rain. If either is a sole path that must survive weather, swap to a Cube Pro (§1). MACs are recorded because they're the re-pairing key after a reset (§3.2).

5. Design implications (summary)

  • Prefer Cube Pro over plain Wireless Wire on any link that is a sole backup — the 5 GHz keeps routing (and, if MTU matches, the overlay) alive through rain.
  • 60 GHz L2MTU is a per-link registry attribute — verify it, match both radios on Cube Pro, and exclude sub-1596 hops from VPLS paths.
  • Remote recovery is only possible if pre-armed (§3.3) — bake the boot-device + remote-PoE setup into the standard radio build, and keep pairing params in config backups. Untouched, a locked-out roof radio is a climb.