2 APs - Windows Laptop won't roam or reconnect

I spent the better part of today trying to solve this issue, to no avail so far.

In an office with two floors, I have one Hap Ax S on each floor. Capsman is used on one of the APs to manage both of them. One SSID for both 2GHh/5GHz, one security profile.

I'm having huge issues with Windows laptops. As long as they are stationary, they work perfectly fine. This goes for both floors. But as soon one laptop moves away from AP1 into the sending zone of AP2, it sticks to AP1 until it loses connection and does not reestablish connection with AP2 even once the connection to AP1 is entirely lost. The same the other way around.

What's worse, I can't even connect manually once the connection was dropped, it simply won't connect to the new AP, and it won't even reconnect to the original AP if I move back to it. I have to wait several minutes close to the other AP and only then it will let me connect. Or, alternatively, switch off Wifi entirely for about 20-30 seconds, turn it back on again, then connecting will work.

Interestingly enough, I don't have these issues with my Android phone. It roams not only between the two APs but also switches back and forth between 2Ghz and 5GHz.

I understand that the client is supposed to make this decision and there is only so much one can influence from the AP. But several Windows laptops of various brands and with various drivers act the same. And even if it does not seamlessly roam, I would expect to at least build up a new connection once the previous one was lost.

Here are some of things I tried on the APs:

  • Turning FT on and off
  • Turning RMM on and off
  • Turning WNM on and off
  • Reducing transition threshold
  • Skipping DFS channels for 5GHz
  • Turning off all auth types and ciphers except "WPA2 PSK" with CCMP

And on the windows client:

  • Updating to newest intel drivers (current)
  • Changing preferred band from none to 2ghz and also to 5ghz
  • Changing roaming aggressiveness from medium to low to highest
  • Turning off power management for the wifi nic
  • Reinstalling wifi nic
  • Deleting and recreating connection

Nothing I do makes a difference. Even though the second AP can clearly be seen from my Windows laptop with a good RSI value, it won't connect to it after being connected to the other AP.

I've been walking around the office for hours on end, changing settings several times. No problem with Android, but with Windows laptops, it just won't budge. And even though I understand how the responsibilities are divided between the AP and the client, I just don't think this behaviour is normal. After having tested this much without things getting better, I wonder if this is a firmware issue.

Having said that, I had 7.20 on it and then upgraded to 7.23 (current stable), no improvement.

For reference, my Wifi settings:

[admin@PD1] > /interface wifi print detail  
count-only     from         proplist           where            
file           interval     show-sensitive     without-paging   
[admin@PD1] > /interface wifi print detail 
Flags: M - MASTER; D - DYNAMIC, N - NETWORK; B - BOUND; 
X - DISABLED, I - INACTIVE, R - RUNNING 
 0 MDBR default-name="wifi1" name="PD1-2g" mac-address=D0:EA:11:3F:AE:88 
        arp-timeout=auto radio-mac=D0:EA:11:3F:AE:88 configuration=2ghz 
        configuration.country=Switzerland .ssid="MySSID" .mode=ap 
        security.authentication-types=wpa2-psk .encryption=ccmp .ft=no 
        .ft-over-ds=no 
        datapath.bridge=bridgeLocal 
        channel.band=2ghz-ax .width=20mhz 
        steering.rrm=yes .wnm=yes .transition-threshold=-75 
        .transition-threshold-time=5s 

 1 MDBR default-name="wifi2" name="PD1-5g" mac-address=D0:EA:11:3F:AE:89 
        arp-timeout=auto radio-mac=D0:EA:11:3F:AE:89 configuration=5ghz 
        configuration.country=Switzerland .ssid="MySSID" .mode=ap 
        security.authentication-types=wpa2-psk .encryption=ccmp .ft=no 
        .ft-over-ds=no 
        datapath.bridge=bridgeLocal 
        channel.band=5ghz-ax .width=20/40mhz .skip-dfs-channels=all 
        steering.rrm=yes .wnm=yes .transition-threshold=-72 
        .transition-threshold-time=5s 

 2 MDB  ;;; operated by CAP D0:EA:11:3F:A3:2A%bridgeLocal, traffic processing on 
P
        cap="PD2@D0:EA:11:3F:A3:2A%*b" name="PD2-2g" 
        mac-address=D0:EA:11:3F:A3:30 arp-timeout=auto 
        radio-mac=D0:EA:11:3F:A3:30 configuration=2ghz 
        configuration.country=Switzerland .ssid="MySSID" .mode=ap 
        security.authentication-types=wpa2-psk .encryption=ccmp .ft=no 
        .ft-over-ds=no 
        datapath.bridge=bridgeLocal 
        channel.band=2ghz-ax .width=20mhz 
        steering.rrm=yes .wnm=yes .transition-threshold=-75 
        .transition-threshold-time=5s 

 3 MDB  ;;; operated by CAP D0:EA:11:3F:A3:2A%bridgeLocal, traffic processing on 
P
        cap="PD2@D0:EA:11:3F:A3:2A%*b" name="PD2-5g" 
        mac-address=D0:EA:11:3F:A3:31 arp-timeout=auto 
        radio-mac=D0:EA:11:3F:A3:31 configuration=5ghz 
        configuration.country=Switzerland .ssid="MySSID" .mode=ap 
        security.authentication-types=wpa2-psk .encryption=ccmp .ft=no 
        .ft-over-ds=no 
        datapath.bridge=bridgeLocal 
        channel.band=5ghz-ax .width=20/40mhz .skip-dfs-channels=all 
        steering.rrm=yes .wnm=yes .transition-threshold=-72 
        .transition-threshold-time=5s 

As far as I remember, to do real ft-roaming in Windows you have to use WPA2/3-EAP, I've seen many of those which under windows fail to roam, but under ubuntu/debian they connect as "ft-wpa3-psk" and roams fast.

I'd be even willing to accept if the wifi link was reestablished with existing connections being dropped. I just don't understand why it won't connect again within a short amount of time, no matter how close I get to the ap. It keeps trying to reconnect to the ap that is out of reach for at least a minute and only then connects to the ap close by.

its a windows thing ™️

Some Intel NICs have options under advanced settings called "Roaming Aggressiveness", maybe try there.

Tried everything from low to aggressive, no notable difference.

@vic666

From WiFi - RouterOS - MikroTik Documentation

For a client device to successfully roam between 2 APs, the APs need to be managed by the same instance of RouterOS. For information on how to centrally manage multiple APs, see CAPsMAN

| ft (no | yes: default: no) | |
|----|----|

Whether to enable 802.11r fast BSS transitions ( roaming).

ft-mobility-domain (integer 0..65535; default: 44484 (0xADC4))

The fast BSS transition mobility domain ID.

ft-nas-identifier (string of 2..96 hex characters)

Fast BSS transition PMK-R0 key holder identifier. Default: MAC address of the interface.

| ft-over-ds (no | yes; default: no) | |
|----|----|

Whether to enable fast BSS transitions over DS (distributed system).

Check your config once again, manage both APs by Capsman, and turn on roaming.

@pmastal you must have missed the following sentence in my post

Capsman is used on one of the APs to manage both of them.

Also, I tried it with FT on and off. I left domain and identifier unchanged.

Do these two APs overlap in their reach or are they so far apart that these are basically two separate cells?

You might want to give V7.24RC2 a try. There are lots of improvements introduced for this device.

I did not miss that. You think both APs are under CapsMan's control, but that is not true. Also, from your output, neither AP has set roaming.

You're wrong here. If the remote AP wasn't controlled by CAPsMAN, it wouldn't be shown as CAP in output, provided by @vic666 in opening post.

You are right, though, saying that FT is disabled. But I tend to believe that @vic666 vic tried with FT enabled and disabled, it's just that posted status was taken while FT was disabled.

And I'm with others saying that most likely it's Windows problem ... FT or no FT, roaming/mobility is always handled by wireless station, APs will only provide additional information if FT is enabled (and handle requests from stations in appropriate manner).

Take a look at this config which works for me:

/interface/wifi print detail

Flags: M - MASTER; D - DYNAMIC, N - NETWORK; B - BOUND; X - DISABLED, I - INACTIVE, R - RUNNING
0 MDB ;;; operated by CAP XX:XX:XX:XX:XX:XX%VLAN_MGMT, traffic processing on CAP
cap="AP Floor -1@....." name="AP Floor -1 (2G)" mac-address=XX:XX:XX:XX:XX:XX arp-timeout=auto radio-mac=XX:XX:XX:XX:XX:XX configuration=cfg24-priv
configuration.country=Luxembourg .ssid="MySSID"
security.authentication-types=wpa3-psk .management-protection=required .wps=disable .ft=yes .ft-mobility-domain=0x1001 .ft-over-ds=yes .ft-preserve-vlanid=yes
datapath.bridge=bridge .traffic-processing=on-cap .vlan-id=10
channel.frequency=2412,2437,2462 .width=20/40mhz
steering.rrm=yes .wnm=yes

Settings from WIFI->Configuration:

They overlap quite considerably.

Thanks for sharing your configuration. The only notable difference between your config and mine is that you're using wpa3-psk instead of wpa2-psk, and that you set fixed channel frequencies instead of letting RouterOS make that decision.

So, you are using that configuration on HAP AX S with Windows clients and it works for you? What firmware version are you on?

That solved it. As soon as I installed this version on both APs, roaming with my Windows laptop went like a charm. Thanks a lot for bringing this to my attention.

I'm happy it works now, of course. But it turns out I spent a day figuring out what I'm doing wrong when the issue clearly was on the part of Mikrotik. And this pi**es me off.

Microsoft Windows has a market share of at least 65%, in the business space it's likely a lot higher than that, how can Mikrotik not test this? I don't even expect Mikrotik to absolutely make sure that Windows is supported (for roaming) but at least inform your customers that it's not so that I can take this into account when selecting the hardware!

I've been using Mikrotik for more than 10 years at home and for my customers (SMB). I'm a big fan but this experience dented my impression considerably.

You do have a new device. After the introduction of the ax devices, it took some time to get it completely stable. Now it is rock solid, at least for me.

In regards to Windows, that runs on most (exotic) devices. Let alone Linux. Not everything can be tested upfront.

Glad the 7.24 version solved your problem.

I am on 7.23.2. With my config I can roam with Windows between a "hap ax s" and a "wap ax" without problems. I have only one "hap ax s" though generally.

Maybe it's, as often said in this forum, that the mediatek driver is still crappy, but apparently has improved in 7.24. I hope so since I also find my "hap ax s" to be slow often. Rarely I can reach 500 Mbit/s, but often for no apparent reason, it maxes out at 200 MBit/s, sometimes even less.

Well, with the issue (with Winbox 3) of "interworking.realms-raw" they recently managed to have all Apple devices not connect, so the good thing is that they are not "racist" :wink:.