Access points with KERNEL FAILURE - I'm going crazy

About the first part, previously there used to be a sure way to cause kernel panic: start a fast multi threaded download, like opensuse update, but that is no longer the case.
About the second part, I thought about that, but I couldn't find the "offender" yet, also it is happening at multiple locations so it would be a class of devices causing the failure. I am currently in process of collecting debug logs with client connections and CAP disconnects from CAPsMAN, to try to find some regularity...

What does it cost to try ?
That one device where I have it applied, didn't cause me a single problem anymore since I applied that proces (roughly 2 years ago ?).
Maybe it isn't needed anymore (can't tell) but it certainly shouldn't hurt.

Historically, I've had this configuration on the APs and since the release of the wifi-qcom-ac drivers for the cAP ac, I haven't had a single problem with the APs.

# 2026-06-06 22:48:02 by RouterOS 7.20.8
# software id = XXXX
#
# model = RBcAPGi-5acD2nD
# serial number = XXXX
/interface bridge
add admin-mac=2C:C8:1B:xx:xx:xx ageing-time=10s auto-mac=no name=bridge1 \
    protocol-mode=none vlan-filtering=yes
/interface ethernet
set [ find default-name=ether1 ] comment="!Uplink!"
set [ find default-name=ether2 ] comment="VOLNO" disabled=yes
/interface ethernet switch
set 0 cpu-flow-control=no
/interface list
add comment="Veskera rozhrani s povolenou spravou pres MAC a discovery" name=\
    MAC_mgmt
add comment="Vsechna \"nebezpecna\" WiFi rozhrani pro bridge filters" name=\
    WiFi_unsecure_all
/interface wifi configuration
add channel.frequency=2412-2472:25 .width=20mhz country=Czech disabled=no \
    dtim-period=1 hide-ssid=no manager=capsman-or-local mode=ap \
    multicast-enhance=enabled name=Local_AP-2G qos-classifier=priority \
    security.authentication-types=wpa2-psk .connect-priority=0/1 \
    .disable-pmkid=no .group-key-update=1d .passphrase=xxxxxxxx .wps=disable \
    ssid=cAP_Local steering.rrm=yes .wnm=no tx-power=14
add channel.frequency=5180-5240:20 .skip-dfs-channels=all .width=20mhz \
    country=Czech disabled=no dtim-period=1 hide-ssid=no manager=\
    capsman-or-local mode=ap multicast-enhance=enabled name=Local_AP-5G \
    qos-classifier=priority security.authentication-types=wpa2-psk \
    .connect-priority=0/1 .disable-pmkid=no .group-key-update=1d .passphrase=\
    xxxxxxxx .wps=disable ssid=cAP_Local steering.rrm=yes .wnm=no tx-power=17
/interface wifi datapath
add client-isolation=yes comment=\
    "Vsechna \"nebezpecna\" WiFi rozhrani pro bridge filters" disabled=no \
    interface-list=WiFi_unsecure_all name=datapath_IL-unsecureWiFi
/interface wifi
# managed by CAPsMAN 10.20.0.1, traffic processing on CAP
# mode: AP, SSID: XXXXXXXX, channel: 2462/n
set [ find default-name=wifi1 ] comment="Access VLAN 36 (2.4 GHz, 802.11n)" \
    configuration=Local_AP-2G configuration.mode=ap datapath=\
    datapath_IL-unsecureWiFi disable-running-check=yes disabled=no
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi1 name=wifi1_VAP1
# managed by CAPsMAN 10.20.0.1, traffic processing on CAP
# mode: AP, SSID: XXXXXXXX
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi1 name=wifi1_VAP2
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi1 name=wifi1_VAP3
# managed by CAPsMAN 10.20.0.1, traffic processing on CAP
# mode: AP, SSID: XXXXXXXX, channel: 5180/ac/Ce
set [ find default-name=wifi2 ] comment="Access VLAN 36 (5 GHz, 802.11ac)" \
    configuration=Local_AP-5G configuration.mode=ap datapath=\
    datapath_IL-unsecureWiFi disable-running-check=yes disabled=no
# managed by CAPsMAN 10.20.0.1, traffic processing on CAP
# mode: AP, SSID: XXXXXXXX
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi2 name=wifi2_VAP1
# managed by CAPsMAN 10.20.0.1, traffic processing on CAP
# mode: AP, SSID: XXXXXXXX
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi2 name=wifi2_VAP2
add configuration.mode=ap datapath=datapath_IL-unsecureWiFi \
    disable-running-check=yes disabled=no mac-address=2E:C8:1B:XX:XX:XX \
    master-interface=wifi2 name=wifi2_VAP3
/queue type
set 2 kind=none
/snmp community
set [ find default=yes ] disabled=yes
add addresses=::/0,0.0.0.0/0 comment="XXXXXXXX" name=\
    XXXXXXXX
/interface bridge filter
add action=drop chain=input comment=\
    "Zahodit input z IL \"WiFi_unsecure_all\" (Ochrana pred utocniky)" \
    in-interface-list=WiFi_unsecure_all
add action=accept chain=forward comment="Povolit komunikaci z IL \"WiFi_unsecu\
    re_all\" na router s MAC \"2C:C8:1B:XX:XX:XX\"" dst-mac-address=\
    2C:C8:1B:XX:XX:XX/FF:FF:FF:FF:FF:FF in-interface-list=WiFi_unsecure_all
add action=accept chain=forward comment=\
    "Povolit broadcast z IL \"WiFi_unsecure_all\" (20 za vterinu, burst 50)" \
    dst-mac-address=FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF in-interface-list=\
    WiFi_unsecure_all limit=20,50
add action=accept chain=forward comment=\
    "Povolit DHCP offer do IL \"WiFi_unsecure_all\"" dst-port=68 ip-protocol=\
    udp mac-protocol=ip out-interface-list=WiFi_unsecure_all src-port=67
add action=drop chain=forward comment=\
    "Zakazat broadcast do IL \"WiFi_unsecure_all\"" dst-mac-address=\
    FF:FF:FF:FF:FF:FF/FF:FF:FF:FF:FF:FF out-interface-list=WiFi_unsecure_all
add action=accept chain=forward comment="Povolit Router Solicitation z IL \"Wi\
    Fi_unsecure_all\" (Pokud neprichazi ohlaseni smerovace, muze o ne uzel tou\
    to zpravou pozadat) (10 za vterinu, burst 20)" dst-mac-address=\
    33:33:00:00:00:02/FF:FF:FF:FF:FF:FF in-interface-list=WiFi_unsecure_all \
    limit=10,20
add action=accept chain=forward comment="Povolit Neighbor Solicitation z IL \"\
    WiFi_unsecure_all\" (Zada souseda o jeho ohlaseni; pouziva se ke zjistovan\
    i linkovych adres a detekci dosazitelnosti) (20 za vterinu, burst 50)" \
    dst-mac-address=33:33:FF:00:00:00/FF:FF:FF:00:00:00 in-interface-list=\
    WiFi_unsecure_all limit=20,50
add action=drop chain=forward comment=\
    "Zahodit zbytek z IL \"WiFi_unsecure_all\" (Ochrana pred utocniky)" \
    in-interface-list=WiFi_unsecure_all
/interface bridge port
add bridge=bridge1 comment="Trusted port, edge-port=no; PVID 1" edge=no hw=no \
    interface=ether1 internal-path-cost=10 path-cost=10 trusted=yes
add bridge=bridge1 comment="PVID 1" hw=no interface=ether2 \
    internal-path-cost=10 path-cost=10
add bridge=bridge1 comment="PVID 36; Horizon 36" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged horizon=36 interface=wifi1 pvid=\
    36
add bridge=bridge1 comment="PVID 30" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged interface=wifi1_VAP1 pvid=30
add bridge=bridge1 comment="PVID 36; Horizon 36" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged horizon=36 interface=wifi1_VAP2 \
    pvid=36
add bridge=bridge1 comment="PVID 35" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged interface=wifi1_VAP3 pvid=35
add bridge=bridge1 comment="PVID 36; Horizon 36" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged horizon=36 interface=wifi2 pvid=\
    36
add bridge=bridge1 comment="PVID 30" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged interface=wifi2_VAP1 pvid=30
add bridge=bridge1 comment="PVID 36; Horizon 36" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged horizon=36 interface=wifi2_VAP2 \
    pvid=36
add bridge=bridge1 comment="PVID 35" edge=yes frame-types=\
    admit-only-untagged-and-priority-tagged interface=wifi2_VAP3 pvid=35
/interface bridge settings
set allow-fast-path=no use-ip-firewall=yes use-ip-firewall-for-vlan=yes
/ip firewall connection tracking
set enabled=no
/ip neighbor discovery-settings
set discover-interface-list=MAC_mgmt discover-interval=15s
/ip settings
set ip-forward=no
/ipv6 settings
set accept-redirects=no accept-router-advertisements=no forward=no
/interface bridge vlan
add bridge=bridge1 comment="Wi-Fi VLANy" tagged=bridge1,ether1,ether2 \
    vlan-ids=30,35-36
/interface list member
add interface=bridge1 list=MAC_mgmt
/interface wifi cap
set caps-man-addresses=10.20.0.1 certificate=none enabled=yes \
    lock-to-caps-man=no slaves-static=yes
/ip address
add address=10.20.0.50/24 interface=bridge1 network=10.20.0.0
/ip dns
set cache-max-ttl=10m max-udp-packet-size=512 servers=2a02:xxxx:xxx::1,10.20.0.1
/ip firewall filter
add action=accept chain=input comment="===== OCHRANA ROUTERU =====" disabled=\
    yes
# connection state matcher not possible when connection tracking is disabled
add action=accept chain=input comment=\
    "Povol established, related, untracked spojeni" connection-state=\
    established,related,untracked
add action=accept chain=input comment="Povol vse z I \"bridge1\"" \
    in-interface=bridge1
add action=drop chain=input comment="Zahod vse ostatni"
/ip firewall mangle
add action=set-priority chain=postrouting comment=\
    "pro WiFi: Nastaveni priority z DSCP pro WMM" new-priority=\
    from-dscp-high-3-bits
/ip firewall service-port
set sip disabled=yes
/ip hotspot profile
set [ find default=yes ] html-directory=hotspot
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=10.20.0.1
/ipv6 route
add disabled=no dst-address=::/0 gateway=2a02:xxxx:xxx::1
/ip service
set ftp disabled=yes
set telnet disabled=yes
set api disabled=yes
set api-ssl disabled=yes
/ip ssh
set strong-crypto=yes
/ipv6 address
add address=2a02:xxxx:xxx::50 advertise=no interface=bridge1
/ipv6 firewall filter
add action=accept chain=input comment="===== OCHRANA ROUTERU =====" disabled=\
    yes
# connection state matcher not possible when connection tracking is disabled
add action=accept chain=input comment=\
    "Povol established, related, untracked spojeni" connection-state=\
    established,related,untracked
add action=accept chain=input comment="Povol vse z I \"bridge1\"" \
    in-interface=bridge1
add action=drop chain=input comment="Zahod vse ostatni"
/ipv6 firewall mangle
add action=set-priority chain=postrouting comment=\
    "pro WiFi: Nastaveni priority z DSCP pro WMM" new-priority=\
    from-dscp-high-3-bits
/ipv6 nd
set [ find default=yes ] disabled=yes
/snmp
set contact=xxxxxx.cz enabled=yes location=\
    "xxxx" trap-community=xxx \
    trap-generators=start-trap,interfaces,temp-exception trap-target=\
    x.x.x.x trap-version=2
/system clock
set time-zone-autodetect=no time-zone-name=Europe/Prague
/system identity
set name=cAP_xx
/system logging
add topics=caps
/system ntp client
set enabled=yes
/system ntp client servers
add address=ntp.nic.cz
add address=time.cloudflare.com
add address=time.google.com
/system routerboard settings
set auto-upgrade=yes boot-device=nand-only
/system scheduler
add comment="Smaze historii konzole - uvolni misto na disku" interval=4w \
    name=4tydenni_mazani_konzole on-event="#Smazeme historii konzole - uvolni \
    misto na disku\r\
    \n/console/clear-history\r\
    \n" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=1970-01-01 start-time=03:20:00
add comment="Povoli disable running check pro vsechna WiFi rozhrani" \
    interval=14w1d name=wifi_disable_running_check on-event="#Povoli disable r\
    unning check pro vsechna WiFi rozhrani - pro jistotu, kdyby nekdo zapomnel\
    \_nastavit\r\
    \n/interface/wifi/set disable-running-check=yes [find]" policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=1970-01-01 start-time=03:10:00
add comment="Provede planovane 28denni zalohovani na FTP v 03:05:00" \
    interval=4w name=28denni_zalohy_ftp on-event=vytvorit_zalohy_ftp policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=1970-01-01 start-time=03:00:00
/system script
add comment="Vytvori backup a rsc soubory pojmenovane jako identita s aktualni\
    m datem" dont-require-permissions=no name=vytvorit_zalohy owner=user1 \
    policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    source="#Informujeme do logu\r\
    \n:log/info message=\"Zahajuji zalohovani konfigurace.\";\r\
    \n\r\
    \n#Nastavime si promenne\r\
    \n:local NazevSouboru;\r\
    \n\r\
    \n:local Datum [/system/clock/get date];\r\
    \n:local Identita [/system/identity/get name];\r\
    \n\r\
    \n:set NazevSouboru (\$Identita. \" - \" .\$Datum);\r\
    \n\r\
    \n#Vytvorime .backup\r\
    \n/system/backup/save dont-encrypt=yes name=\$NazevSouboru;\r\
    \n\r\
    \n#Pockame 3 vteriny\r\
    \n:delay delay-time=3s;\r\
    \n\r\
    \n#Vytvorime .rsc\r\
    \n/export show-sensitive file=\$NazevSouboru;\r\
    \n\r\
    \n#Informujeme do logu\r\
    \n:log/info message=\"Zaloha konfigurace dokoncena.\";"
add comment="Vytvori backup a rsc soubory pojmenovane jako identita s aktualni\
    m datem a nahraje je na FTP" dont-require-permissions=no name=\
    vytvorit_zalohy_ftp owner=user1 policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="#\
    Informujeme do logu\
    \n:log/info message=\"Zahajuji zalohovani konfigurace.\";\
    \n\
    \n#Nastavime si promenne\
    \n:local NazevSouboru;\
    \n\
    \n:local Datum [/system/clock/get date];\
    \n:local Identita [/system/identity/get name];\
    \n\
    \n:set NazevSouboru (\$Identita. \" - \" .\$Datum);\
    \n\
    \n#Vytvorime .backup\
    \n/system/backup/save dont-encrypt=yes name=\$NazevSouboru;\
    \n\
    \n#Pockame 3 vteriny\
    \n:delay delay-time=3s;\
    \n\
    \n#Vytvorime .rsc\
    \n/export show-sensitive file=\$NazevSouboru;\
    \n\
    \n#Pockame 3 vteriny\
    \n:delay delay-time=3s;\
    \n\
    \n#Informujeme do logu\
    \n:log/info message=\"Zahajuji nahravani zaloh na FTP.\";\
    \n\
    \n#Nahrajeme soubory na hlavni router\
    \n{\
    \n    :do {/tool/fetch address=xxxx src-path=\"\$NazevSouboru.backu\
    p\" mode=ftp user=\"xxxx\" password=\"xxxx\" upload=\
    yes dst-path=\"/MT_Zalohy/WiFi-AP/\$NazevSouboru.backup\"} on-error={:log/\
    warning \"Nastala chyba pri uploadu .backup zalohy!\"}\
    \n};\
    \n{\
    \n    :do {/tool/fetch address=xxxx src-path=\"\$NazevSouboru.rsc\"\
    \_mode=ftp user=\"xxxx\" password=\"xxxx\" upload=ye\
    s dst-path=\"/MT_Zalohy/WiFi-AP/\$NazevSouboru.rsc\"} on-error={:log/warni\
    ng \"Nastala chyba pri uploadu .rsc zalohy!\"}\
    \n};\
    \n\
    \n#Pockame 3 vteriny\
    \n:delay delay-time=3s;\
    \n\
    \n#Smazeme soubory\
    \n/file/remove \"\$NazevSouboru.backup\"\
    \n/file/remove \"\$NazevSouboru.rsc\"\
    \n\
    \n#Informujeme do logu\
    \n:log/info message=\"Zaloha konfigurace dokoncena.\";"
/system watchdog
set automatic-supout=no
/tool graphing
set store-every=hour
/tool mac-server
set allowed-interface-list=MAC_mgmt
/tool mac-server mac-winbox
set allowed-interface-list=MAC_mgmt

I have been experiencing the kernel failure issue with a Mantbox L22UGS-5HaxD2HaxD that has 13 SXT CPEs connected to it. I have already Netinstalled it and disabled neighbor discovery. So far, it seems stable after reading through this topic.

I have also contacted MikroTik Support, but I have not received a solution yet.

I really hope we can identify the root cause of this issue and get it resolved.

Hi,

I wanted to share my experience with a similar setup as OP:

CAPsMAN controller - LMT-LTE18 (RBD53G-5HacD2HnD&EG18-EA) ROS 7.21.4

cAPs - 2x cAP ac, 1x wAP ac LTE Kit, ROS 7.21.4 all devices have wifi-qcom-ac drivers.

Recently (last month) I installed another cAP ac (/system/reset-configuration skip-backup=yes no-defaults=yes) and added it as a CAPsMAN client. The location is a small workshop. about 5-10 wireless devices are connected to the AP.

cAP ac Configuiration
# software id = SJW9-MTWF
#
# model = RBcAPGi-5acD2nD
# serial number = DEADBEEF
/interface bridge
add admin-mac=6E:D4:9F:D2:F3:31 ageing-time=5m arp=enabled arp-timeout=auto \
    auto-mac=no dhcp-snooping=no disabled=no fast-forward=yes forward-delay=\
    15s igmp-snooping=no max-learned-entries=auto max-message-age=20s mtu=\
    auto mvrp=no name=bridge01 port-cost-mode=long priority=0x8000 \
    protocol-mode=rstp transmit-hold-count=6 vlan-filtering=no
/interface wifi
# managed by CAPsMAN 02:7E:31:47:4A:6C%bridge01, traffic processing on CAP
# mode: AP, SSID: Company, channel: 2427/n
set [ find default-name=wifi1 ] arp-timeout=auto configuration.manager=\
    capsman .mode=ap disabled=no l2mtu=1560 mac-address=D0:EA:11:3F:45:0A \
    name=wifi1 radio-mac=D0:EA:11:3F:45:0A
# managed by CAPsMAN 02:7E:31:47:4A:6C%bridge01, traffic processing on CAP
# mode: AP, SSID: Company, channel: 5180/ac/Ceee/I
set [ find default-name=wifi2 ] arp-timeout=auto configuration.manager=\
    capsman .mode=ap disabled=no l2mtu=1560 mac-address=D0:EA:11:3F:45:0B \
    name=wifi2 radio-mac=D0:EA:11:3F:45:0B
/interface ethernet
set [ find default-name=ether1 ] advertise="10M-baseT-half,10M-baseT-full,100M\
    -baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full" arp=enabled \
    arp-timeout=auto auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no l2mtu=1598 loop-protect=default loop-protect-disable-time=5m \
    loop-protect-send-interval=5s mac-address=D0:EA:11:3F:45:08 mtu=1500 \
    name=ether1 orig-mac-address=D0:EA:11:3F:45:08 rx-flow-control=off \
    tx-flow-control=off
set [ find default-name=ether2 ] advertise="10M-baseT-half,10M-baseT-full,100M\
    -baseT-half,100M-baseT-full,1G-baseT-half,1G-baseT-full" arp=enabled \
    arp-timeout=auto auto-negotiation=yes bandwidth=unlimited/unlimited \
    disabled=no l2mtu=1598 loop-protect=default loop-protect-disable-time=5m \
    loop-protect-send-interval=5s mac-address=D0:EA:11:3F:45:09 mtu=1500 \
    name=ether2 orig-mac-address=D0:EA:11:3F:45:09 poe-out=auto-on \
    poe-priority=10 power-cycle-interval=none !power-cycle-ping-address \
    power-cycle-ping-enabled=no !power-cycle-ping-timeout rx-flow-control=off \
    tx-flow-control=off
/queue interface
set bridge01 queue=no-queue
/interface ethernet switch
set 0 cpu-flow-control=yes mirror-source=none mirror-target=none name=switch1
/interface ethernet switch port
set 0 default-vlan-id=auto vlan-header=leave-as-is vlan-mode=disabled
set 1 default-vlan-id=auto vlan-header=leave-as-is vlan-mode=disabled
set 2 default-vlan-id=auto vlan-header=leave-as-is vlan-mode=disabled
/interface ethernet switch port-isolation
set 0 !forwarding-override
set 1 !forwarding-override
set 2 !forwarding-override
/interface list
set [ find name=all ] comment="contains all interfaces" exclude="" include="" \
    name=all
set [ find name=none ] comment="contains no interfaces" exclude="" include="" \
    name=none
set [ find name=dynamic ] comment="contains dynamic interfaces" exclude="" \
    include="" name=dynamic
set [ find name=static ] comment="contains static interfaces" exclude="" \
    include="" name=static
/interface lte apn
set [ find default=yes ] add-default-route=yes apn=internet authentication=\
    none default-route-distance=2 ip-type=auto name=default use-network-apn=\
    yes use-peer-dns=yes
/interface macsec profile
set [ find default-name=default ] name=default server-priority=10
/ip dhcp-client option
set clientid_duid code=61 name=clientid_duid value="0xff\$(CLIENT_DUID)"
set clientid code=61 name=clientid value="0x01\$(CLIENT_MAC)"
set hostname code=12 name=hostname value="\$(HOSTNAME)"
/ip hotspot profile
set [ find default=yes ] dns-name="" hotspot-address=0.0.0.0 html-directory=\
    flash/hotspot html-directory-override="" http-cookie-lifetime=3d \
    http-proxy=0.0.0.0:0 install-hotspot-queue=no login-by=cookie,http-chap \
    name=default smtp-server=0.0.0.0 split-user-domain=no use-radius=no
/ip hotspot user profile
set [ find default=yes ] add-mac-cookie=yes address-list="" idle-timeout=none \
    !insert-queue-before keepalive-timeout=2m mac-cookie-timeout=3d name=\
    default !parent-queue !queue-type shared-users=1 status-autorefresh=1m \
    transparent-proxy=no
/ip ipsec mode-config
set [ find default=yes ] name=request-only responder=no use-responder-dns=\
    exclusively
/ip ipsec policy group
set [ find default=yes ] name=default
/ip ipsec profile
set [ find default=yes ] dh-group=modp2048,modp1024 dpd-interval=2m \
    dpd-maximum-failures=5 enc-algorithm=aes-128,3des hash-algorithm=sha1 \
    lifetime=1d name=default nat-traversal=yes ppk=no proposal-check=obey
/ip ipsec proposal
set [ find default=yes ] auth-algorithms=sha1 disabled=no enc-algorithms=\
    aes-256-cbc,aes-192-cbc,aes-128-cbc lifetime=30m name=default pfs-group=\
    modp1024
/ip smb users
set [ find default=yes ] disabled=no name=guest read-only=yes
/ipv6 dhcp-relay option
set client_mac code=79 name=client_mac only-if-mac-available=yes value=\
    "\$(CLIENT_MAC)"
/ppp profile
set *0 address-list="" !bridge !bridge-horizon bridge-learning=default \
    !bridge-path-cost !bridge-port-priority !bridge-port-trusted \
    !bridge-port-vid change-tcp-mss=yes !dhcpv6-lease-time !dhcpv6-use-radius \
    !dns-server !idle-timeout !incoming-filter !insert-queue-before \
    !interface-list !local-address name=default on-down="" on-up="" only-one=\
    default !outgoing-filter !parent-queue !queue-type !rate-limit \
    !remote-address !remote-ipv6-prefix-reuse !session-timeout \
    use-compression=default use-encryption=default use-ipv6=yes use-mpls=\
    default use-upnp=default !wins-server
set *FFFFFFFE address-list="" !bridge !bridge-horizon bridge-learning=default \
    !bridge-path-cost !bridge-port-priority !bridge-port-trusted \
    !bridge-port-vid change-tcp-mss=yes !dhcpv6-lease-time !dhcpv6-use-radius \
    !dns-server !idle-timeout !incoming-filter !insert-queue-before \
    !interface-list !local-address name=default-encryption on-down="" on-up=\
    "" only-one=default !outgoing-filter !parent-queue !queue-type \
    !rate-limit !remote-address !remote-ipv6-prefix-reuse !session-timeout \
    use-compression=default use-encryption=yes use-ipv6=yes use-mpls=default \
    use-upnp=default !wins-server
/queue type
set 0 kind=pfifo name=default pfifo-limit=50
set 1 kind=pfifo name=ethernet-default pfifo-limit=50
set 2 kind=sfq name=wireless-default sfq-allot=1514 sfq-perturb=5
set 3 kind=red name=synchronous-default red-avg-packet=1000 red-burst=20 \
    red-limit=60 red-max-threshold=50 red-min-threshold=10
set 4 kind=sfq name=hotspot-default sfq-allot=1514 sfq-perturb=5
set 5 kind=pcq name=pcq-upload-default pcq-burst-rate=0 pcq-burst-threshold=0 \
    pcq-burst-time=10s pcq-classifier=src-address pcq-dst-address-mask=32 \
    pcq-dst-address6-mask=128 pcq-limit=50KiB pcq-rate=0 \
    pcq-src-address-mask=32 pcq-src-address6-mask=128 pcq-total-limit=2000KiB
set 6 kind=pcq name=pcq-download-default pcq-burst-rate=0 \
    pcq-burst-threshold=0 pcq-burst-time=10s pcq-classifier=dst-address \
    pcq-dst-address-mask=32 pcq-dst-address6-mask=128 pcq-limit=50KiB \
    pcq-rate=0 pcq-src-address-mask=32 pcq-src-address6-mask=128 \
    pcq-total-limit=2000KiB
set 7 kind=none name=only-hardware-queue
set 8 kind=mq-pfifo mq-pfifo-limit=50 name=multi-queue-ethernet-default
set 9 kind=pfifo name=default-small pfifo-limit=10
/queue interface
set ether1 queue=only-hardware-queue
set ether2 queue=only-hardware-queue
# managed by CAPsMAN 02:7E:31:47:4A:6C%bridge01, traffic processing on CAP
# mode: AP, SSID: Company, channel: 2427/n
set wifi1 queue=wireless-default
# managed by CAPsMAN 02:7E:31:47:4A:6C%bridge01, traffic processing on CAP
# mode: AP, SSID: Company, channel: 5180/ac/Ceee/I
set wifi2 queue=wireless-default
/routing bgp template
set default name=default
/snmp community
set [ find default=yes ] addresses=::/0 authentication-protocol=MD5 disabled=\
    no encryption-protocol=DES name=public read-access=yes security=none \
    write-access=no
/system logging action
set 0 memory-lines=1280 memory-stop-on-full=no name=memory target=memory
set 1 disk-file-count=2 disk-file-name=flash/log disk-lines-per-file=1000 \
    disk-stop-on-full=no name=disk target=disk
set 2 name=echo remember=yes target=echo
set 3 name=remote remote=0.0.0.0 remote-log-format=default remote-port=514 \
    remote-protocol=udp src-address=0.0.0.0 target=remote vrf=main
/user group
set read name=read policy="local,telnet,ssh,reboot,read,test,winbox,password,w\
    eb,sniff,sensitive,api,romon,rest-api,!ftp,!write,!policy" skin=default
set write name=write policy="local,telnet,ssh,reboot,read,write,test,winbox,pa\
    ssword,web,sniff,sensitive,api,romon,rest-api,!ftp,!policy" skin=default
set full name=full policy="local,telnet,ssh,ftp,reboot,read,write,policy,test,\
    winbox,password,web,sniff,sensitive,api,romon,rest-api" skin=default
/certificate settings
set builtin-trust-store=all crl-download=no crl-store=ram crl-use=no
/console settings
set log-script-errors=yes sanitize-names=no tab-width=4
/disk settings
set auto-media-interface=none auto-media-sharing=no auto-smb-sharing=no \
    auto-smb-user=guest default-mount-point-template="[slot]"
/ip smb
set comment=MikrotikSMB domain=MSHOME enabled=auto interfaces=all
/interface bridge port
add auto-isolate=no bpdu-guard=no bridge=bridge01 broadcast-flood=yes \
    disabled=no edge=auto fast-leave=no frame-types=admit-all horizon=none \
    hw=yes ingress-filtering=yes interface=ether1 !internal-path-cost learn=\
    auto multicast-router=temporary-query mvrp-applicant-state=\
    normal-participant mvrp-registrar-state=normal !path-cost point-to-point=\
    auto priority=0x80 pvid=1 restricted-role=no restricted-tcn=no \
    tag-stacking=no trusted=no unknown-multicast-flood=yes \
    unknown-unicast-flood=yes
add auto-isolate=no bpdu-guard=no bridge=bridge01 broadcast-flood=yes \
    disabled=no edge=auto fast-leave=no frame-types=admit-all horizon=none \
    hw=yes ingress-filtering=yes interface=ether2 !internal-path-cost learn=\
    auto multicast-router=temporary-query mvrp-applicant-state=\
    normal-participant mvrp-registrar-state=normal !path-cost point-to-point=\
    auto priority=0x80 pvid=1 restricted-role=no restricted-tcn=no \
    tag-stacking=no trusted=no unknown-multicast-flood=yes \
    unknown-unicast-flood=yes
add auto-isolate=no bpdu-guard=no bridge=bridge01 broadcast-flood=yes \
    disabled=no edge=auto fast-leave=no frame-types=admit-all horizon=none \
    ingress-filtering=yes interface=wifi1 !internal-path-cost learn=auto \
    multicast-router=temporary-query mvrp-applicant-state=normal-participant \
    mvrp-registrar-state=normal !path-cost point-to-point=auto priority=0x80 \
    pvid=1 restricted-role=no restricted-tcn=no tag-stacking=no trusted=no \
    unknown-multicast-flood=yes unknown-unicast-flood=yes
add auto-isolate=no bpdu-guard=no bridge=bridge01 broadcast-flood=yes \
    disabled=no edge=auto fast-leave=no frame-types=admit-all horizon=none \
    ingress-filtering=yes interface=wifi2 !internal-path-cost learn=auto \
    multicast-router=temporary-query mvrp-applicant-state=normal-participant \
    mvrp-registrar-state=normal !path-cost point-to-point=auto priority=0x80 \
    pvid=1 restricted-role=no restricted-tcn=no tag-stacking=no trusted=no \
    unknown-multicast-flood=yes unknown-unicast-flood=yes
/interface bridge settings
set allow-fast-path=yes use-ip-firewall=no use-ip-firewall-for-pppoe=no \
    use-ip-firewall-for-vlan=no
/ip firewall connection tracking
set enabled=auto generic-timeout=10m icmp-timeout=10s liberal-tcp-tracking=no \
    loose-tcp-tracking=yes tcp-close-timeout=10s tcp-close-wait-timeout=10s \
    tcp-established-timeout=1d tcp-fin-wait-timeout=10s tcp-last-ack-timeout=\
    10s tcp-max-retrans-timeout=5m tcp-syn-received-timeout=5s \
    tcp-syn-sent-timeout=5s tcp-time-wait-timeout=10s tcp-unacked-timeout=5m \
    udp-stream-timeout=3m udp-timeout=30s
/ip neighbor discovery-settings
set discover-interface-list=none discover-interval=30s lldp-mac-phy-config=no \
    lldp-max-frame-size=no lldp-med-net-policy-vlan=disabled lldp-poe-power=\
    yes lldp-vlan-info=no mode=tx-and-rx protocol=cdp,lldp,mndp
/ip settings
set accept-redirects=no accept-source-route=no allow-fast-path=yes \
    arp-timeout=30s icmp-errors-use-inbound-interface-address=no \
    icmp-rate-limit=10 icmp-rate-mask=0x1818 ip-forward=yes \
    ipv4-multipath-hash-policy=l3 max-neighbor-entries=4096 rp-filter=no \
    secure-redirects=yes send-redirects=yes tcp-syncookies=no tcp-timestamps=\
    random-offset
/ipv6 settings
set accept-redirects=yes-if-forwarding-disabled accept-router-advertisements=\
    yes-if-forwarding-disabled accept-router-advertisements-on=all \
    allow-fast-path=yes disable-ipv6=yes disable-link-local-address=no \
    forward=yes max-neighbor-entries=2048 min-neighbor-entries=512 \
    multipath-hash-policy=l3 soft-max-neighbor-entries=1024 \
    stale-neighbor-detect-interval=30 stale-neighbor-timeout=60
/interface detect-internet
set detect-interface-list=none internet-interface-list=none \
    lan-interface-list=none wan-interface-list=none
/interface l2tp-server server
set accept-proto-version=all accept-pseudowire-type=all allow-fast-path=no \
    authentication=pap,chap,mschap1,mschap2 caller-id-type=ip-address \
    default-profile=default-encryption enabled=no keepalive-timeout=30 \
    l2tpv3-circuit-id="" l2tpv3-cookie-length=0 l2tpv3-digest-hash=md5 \
    !l2tpv3-ether-interface-list max-mru=1450 max-mtu=1450 max-sessions=\
    unlimited mrru=disabled one-session-per-host=no use-ipsec=no
/interface lte settings
set esim-channel=auto firmware-path=firmware link-recovery-timer=120 mode=\
    auto
/interface ovpn-server server
add auth=sha1,md5,sha256,sha512 certificate=*0 cipher=blowfish128,aes128-cbc \
    default-profile=default disabled=yes enable-tun-ipv6=no ipv6-prefix-len=\
    64 keepalive-timeout=60 mac-address=FE:DC:AF:D7:FA:CC max-mtu=1500 mode=\
    ip name=ovpn-server1 netmask=24 port=1194 protocol=tcp push-routes="" \
    push-routes-ipv6="" redirect-gateway=disabled reneg-sec=3600 \
    require-client-certificate=no tls-version=any tun-server-ipv6=:: \
    user-auth-method=pap vrf=main
/interface pptp-server server
# PPTP connections are considered unsafe, it is suggested to use a more modern VPN protocol instead
set authentication=mschap1,mschap2 default-profile=default-encryption \
    enabled=no keepalive-timeout=30 max-mru=1450 max-mtu=1450 mrru=disabled
/interface sstp-server server
set authentication=pap,chap,mschap1,mschap2 certificate=none ciphers=\
    aes256-sha,aes256-gcm-sha384 default-profile=default enabled=no \
    keepalive-timeout=60 max-mru=1500 max-mtu=1500 mrru=disabled pfs=no port=\
    443 tls-version=any verify-client-certificate=no
/interface wifi cap
set certificate=request discovery-interfaces=bridge01 enabled=yes \
    lock-to-caps-man=yes
/interface wifi capsman
set enabled=no
/ip cloud
set back-to-home-vpn=revoked-and-disabled ddns-enabled=auto \
    ddns-update-interval=none update-time=no
/ip cloud advanced
set use-local-address=no
/ip dhcp-client
add add-default-route=yes allow-reconfigure=no check-gateway=none \
    default-route-distance=1 default-route-tables=default dhcp-options=\
    hostname,clientid disabled=no interface=bridge01 use-broadcast=both \
    use-peer-dns=yes use-peer-ntp=no
/ip dhcp-server config
set accounting=yes interim-update=0s radius-password=empty store-leases-disk=\
    5m
/ip dns
set address-list-extra-time=0s allow-remote-requests=no cache-max-ttl=1w \
    cache-size=2048KiB doh-max-concurrent-queries=50 \
    doh-max-server-connections=5 doh-timeout=5s max-concurrent-queries=100 \
    max-concurrent-tcp-sessions=20 max-udp-packet-size=4096 \
    mdns-repeat-ifaces="" query-server-timeout=2s query-total-timeout=10s \
    servers="" use-doh-server="" verify-doh-cert=no vrf=main
/ip firewall service-port
set ftp disabled=no ports=21
set tftp disabled=no ports=69
set irc disabled=yes ports=6667
set h323 disabled=no
set sip disabled=no ports=5060,5061 sip-direct-media=yes sip-timeout=1h
set pptp disabled=no
set rtsp disabled=yes ports=554
set udplite disabled=no
set dccp disabled=no
set sctp disabled=no
/ip hotspot service-port
set ftp disabled=no ports=21
/ip hotspot user
set [ find default=yes ] comment="counters and limits for trial users" \
    disabled=no name=default-trial server=all
/ip ipsec key qkd
set address="" cache-size=2 certificate=*FFFFFFFF enabled=no key-size=128 \
    kme-id="" peer-sae-id=""
/ip ipsec settings
set accounting=yes interim-update=0s xauth-use-radius=no
/ip ipsec policy
set 0 disabled=no dst-address=::/0 group=default proposal=default protocol=\
    all src-address=::/0 template=yes
/ip media settings
set thumbnails=""
/ip nat-pmp
set enabled=no
/ip proxy
# inactivated, not allowed by device-mode
set always-from-cache=no anonymous=no cache-administrator=webmaster \
    cache-hit-dscp=4 cache-on-disk=no cache-path=web-proxy enabled=no \
    max-cache-object-size=2048KiB max-cache-size=unlimited \
    max-client-connections=600 max-fresh-time=3d max-server-connections=600 \
    parent-proxy=:: parent-proxy-port=0 port=8080 serialize-connections=no \
    src-address=::
/ip service
set ftp address="" disabled=yes max-sessions=20 port=21 vrf=main
set ssh address="" disabled=no max-sessions=20 port=22 vrf=main
set telnet address="" disabled=yes max-sessions=20 port=23 vrf=main
set www address="" disabled=yes max-sessions=20 port=80 vrf=main
set www-ssl address="" certificate=none disabled=yes max-sessions=20 port=443 \
    tls-version=any vrf=main
set winbox address="" disabled=no max-sessions=20 port=8291 vrf=main
set api address="" disabled=yes max-sessions=20 port=8728 vrf=main
set api-ssl address="" certificate=none disabled=yes max-sessions=20 port=\
    8729 tls-version=any vrf=main
/ip smb shares
set [ find default=yes ] directory=/flash/pub disabled=yes invalid-users="" \
    name=pub read-only=no require-encryption=no valid-users=""
/ip socks
# inactivated, not allowed by device-mode
set auth-method=none connection-idle-timeout=2m enabled=no max-connections=\
    200 port=1080 version=4 vrf=main
/ip ssh
set ciphers=auto forwarding-enabled=no host-key-size=2048 host-key-type=rsa \
    password-authentication=yes-if-no-key publickey-authentication-options=\
    none strong-crypto=yes
/ip tftp settings
set max-block-size=4096
/ip traffic-flow
set active-flow-timeout=30m cache-entries=32k enabled=no \
    inactive-flow-timeout=15s interfaces=all packet-sampling=no \
    sampling-interval=0 sampling-space=0
/ip traffic-flow ipfix
set bytes=yes dst-address=yes dst-address-mask=yes dst-mac-address=yes \
    dst-port=yes first-forwarded=yes gateway=yes icmp-code=yes icmp-type=yes \
    igmp-type=yes in-interface=yes ip-header-length=yes ip-total-length=yes \
    ipv6-flow-label=yes is-multicast=yes last-forwarded=yes nat-dst-address=\
    yes nat-dst-port=yes nat-events=no nat-src-address=yes nat-src-port=yes \
    out-interface=yes packets=yes protocol=yes src-address=yes \
    src-address-mask=yes src-mac-address=yes src-port=yes sys-init-time=yes \
    tcp-ack-num=yes tcp-flags=yes tcp-seq-num=yes tcp-window-size=yes tos=yes \
    ttl=yes udp-length=yes
/ip upnp
set allow-disable-external-interface=no enabled=no show-dummy-rule=yes
/ipv6 nd
set [ find default=yes ] advertise-dns=no advertise-mac-address=yes disabled=\
    no hop-limit=unspecified interface=all managed-address-configuration=no \
    mtu=unspecified other-configuration=no ra-delay=3s ra-interval=3m20s-10m \
    ra-lifetime=30m ra-preference=medium reachable-time=unspecified \
    retransmit-interval=unspecified
/ipv6 nd prefix default
set autonomous=yes preferred-lifetime=1w valid-lifetime=4w2d
/mpls settings
set allow-fast-path=yes dynamic-label-range=16-1048575 propagate-ttl=yes
/ppp aaa
set accounting=yes enable-ipv6-accounting=no interim-update=0s \
    use-circuit-id-in-nas-port-id=no use-radius=no
/radius incoming
set accept=no port=3799 vrf=main
/routing igmp-proxy
set query-interval=2m5s query-response-interval=10s quick-leave=no
/routing settings
set check-gateway-ping-count=2 check-gateway-ping-interval=10s \
    check-gateway-ping-timeout=1s single-process=no
/snmp
set contact="" enabled=no engine-id-suffix="" location="" src-address=:: \
    trap-community=public trap-generators=temp-exception trap-target="" \
    trap-version=1 vrf=main
/system clock
set time-zone-autodetect=no time-zone-name=Europe/Riga
/system clock manual
set dst-delta=+00:00 dst-end="1970-01-01 00:00:00" dst-start=\
    "1970-01-01 00:00:00" time-zone=+00:00
/system identity
set name="cAP ac (Vestibils)"
/system leds settings
set all-leds-off=never
/system logging
set 0 action=memory disabled=no prefix="" regex="" topics=info
set 1 action=memory disabled=no prefix="" regex="" topics=error
set 2 action=memory disabled=no prefix="" regex="" topics=warning
set 3 action=echo disabled=no prefix="" regex="" topics=critical
/system note
set note="" show-at-cli-login=no show-at-login=yes
/system ntp client
set enabled=yes mode=unicast servers=\
    0.pool.ntp.org,1.pool.ntp.org,2.pool.ntp.org,3.pool.ntp.org vrf=main
/system ntp server
set auth-key=none broadcast=no broadcast-addresses="" enabled=no \
    local-clock-stratum=5 manycast=no multicast=no use-local-clock=no vrf=\
    main
/system ntp client servers
add address=0.pool.ntp.org auth-key=none disabled=no iburst=yes max-poll=10 \
    min-poll=6
add address=1.pool.ntp.org auth-key=none disabled=no iburst=yes max-poll=10 \
    min-poll=6
add address=2.pool.ntp.org auth-key=none disabled=no iburst=yes max-poll=10 \
    min-poll=6
add address=3.pool.ntp.org auth-key=none disabled=no iburst=yes max-poll=10 \
    min-poll=6
/system package local-update mirror
set check-interval=1d enabled=no primary-server=0.0.0.0 secondary-server=\
    0.0.0.0 user=""
/system package update
set channel=long-term
/system resource hardware usb-settings
set authorization=no
/system resource irq
set 0 cpu=auto
set 1 cpu=auto
set 2 cpu=auto
set 3 cpu=auto
set 4 cpu=auto
set 5 cpu=auto
/system routerboard mode-button
set enabled=no hold-time=0s..1m on-event=""
/system routerboard reset-button
set enabled=no hold-time=0s..1m on-event=""
/system routerboard settings
set auto-upgrade=yes boot-device=nand-if-fail-then-ethernet boot-protocol=\
    bootp force-backup-booter=no preboot-etherboot=disabled \
    preboot-etherboot-server=any protected-routerboot=disabled \
    reformat-hold-button=20s reformat-hold-button-max=10m silent-boot=no
/system scheduler
add disabled=no interval=1d name=auto-reboot on-event=/system/reboot policy=\
    reboot,read start-date=2026-05-10 start-time=01:00:00
/system watchdog
set auto-send-supout=no automatic-supout=yes ping-start-after-boot=5m \
    ping-timeout=1m watch-address=none watchdog-timer=yes
/tool bandwidth-server
set allocate-udp-ports-from=2000 allowed-addresses4="" allowed-addresses6="" \
    authenticate=yes enabled=no max-sessions=100
/tool e-mail
set certificate-verification=no from=<> port=25 server=0.0.0.0 tls=no user="" \
    vrf=main
/tool graphing
set page-refresh=300 store-every=5min
/tool mac-server
set allowed-interface-list=none
/tool mac-server mac-winbox
set allowed-interface-list=none
/tool mac-server ping
set enabled=no
/tool romon
set enabled=no id=00:00:00:00:00:00
/tool romon port
set [ find default=yes ] cost=100 disabled=no forbid=no interface=all
/tool sms
set allowed-number="" channel=0 polling=no port=none receive-enabled=no \
    remove-sent-sms-after-send=no sms-storage=sim
/tool sniffer
set file-limit=1000KiB file-name="" filter-cpu="" filter-direction=any \
    filter-dst-ip-address="" filter-dst-ipv6-address="" \
    filter-dst-mac-address="" filter-dst-port="" filter-interface="" \
    filter-ip-address="" filter-ip-protocol="" filter-ipv6-address="" \
    filter-mac-address="" filter-mac-protocol="" \
    filter-operator-between-entries=or filter-port="" filter-size="" \
    filter-src-ip-address="" filter-src-ipv6-address="" \
    filter-src-mac-address="" filter-src-port="" filter-stream=no \
    filter-vlan="" max-packet-size=2048 memory-limit=100KiB memory-scroll=yes \
    only-headers=no quick-rows=20 quick-show-frame=no streaming-enabled=no \
    streaming-server=0.0.0.0:37008
/tool traffic-generator
set latency-distribution-max=100us measure-out-of-order=no \
    stats-samples-to-keep=100 test-id=0
/user aaa
set accounting=yes default-group=read exclude-groups="" interim-update=0s \
    use-radius=no
/user settings
set minimum-categories=0 minimum-password-length=0

The unit started to reboot on its own and after rebooting log shows that "router was rebooted without proper shutdown, probably kernel failure".
I've opened a Mikrotik support ticket (SUP-217768). First and obvious statement is that the device was shipped with "wireless" driver package, and that "wifi-qcom-ac" is not suitable for it. Now I have to test the device as a standalone AP, but the question still is open - why some devices work fine with the "wifi-qcom-ac" driver and some don't.

I have returned to this after about 2 months. In the meantime APs were rebooting multiple times per day, some of them more often than others, but none of them could last for more than a few days. My guess is that some of the clients (mostly phones) were doing something strange, but I couldn't catch the offender(s).

Some 2 weeks ago I have returned to this problem and started to turn on/off different settings. My latest result is that if I set this:

/interface wifi security
add authentication-types=wpa2-psk disable-pmkid=yes management-protection=disabled connect-priority=0/1 ft=yes ft-over-ds=no ft-preserve-vlanid=no name=mysec

there were no kernel failures for more than 10 days!!!

"New" (non-default for me) settings are marked in bold. After setting those there were no reboots. Btw, someone posted these settings in this thread around March, but I have skipped over that because that was standalone AP (without CAPsMAN) and I wasn't really paying attention :frowning:

Important hing to notice: WPA3 requires management protection, so it had to go, leaving only WPA2, but that is good enough for those locations with "wifi-qcom-ac" based devices. If you need WPA3, go for AX devices with "wifi-qcom".

After more than 10 days of working OK, today I have started to turn back on SNMP and other things that I have disabled in my search (first on the devices that were rebooting most), to see if I can have some monitoring. Later I'll reset to default CAP some of the devices to check if I can leave everything at default as it is supposed to work (security settings come from CAPsMAN so they would apply automatically)... will get back with results.

Default setting for "management-protection" is being unset ... which means "allowed" for WPA2 clients and "required" for WPA3 clients ... yes, according to documentation it's up to authentication type negotiated by each individual client. Since most WPA2 clients don't support management-protection, this actually allows for mixed WPA2/WPA3 SSID.

So you may want to try to unset this setting and keep authentication-types to wpa2-psk only.

Other than that, I'm surprised that these two settings would cause kernel panic ... unless there's a client which manages to construct a combination which makes ROS kernel (more probably wifi driver) to flip over.

Just wondering: when those devices reboot due to kernel panic, do they create auto supout files? If yes, then you should pass them to MT support so that they could analyze what in particular caused those kernel panics.

@mkx Did you read the WHOLE thread? This has been going on for many moons, at least since May last year for me. YES, Mikrotik is aware of this, YES many of us have sent the .rif multiple times, and NO, there has been no useful answer from them, only "we gave you advanced driver, downgrade to old wireless if it doesn't work for you". They were mostly "pointing finger" at small RAM, but I couldn't accept that because hap ac3 has got plenty and is using just over half of it.

That is exactly why I am still on this, trying to make the hardware I bought useful. Old wireless is not an option (no FT/roaming). Those affected by this problem will know what I am talking about. Others probably don't care. If I can help someone else - even better.

Important thing is to set both "disable-pmkid=yes" and "management-protection=disabled", any single of these are not enough and reboots (kernel failures) still happen if you don't set both. I'd say that there is a bug in wifi-com-ac, but since this is now Qualcom's driver, and not Mikrotik's, I don't think that it will get fixed any time soon, if ever.

A software bug would affect everyone. But I never experienced any instability.

@infabo I think that many of those affected would disagree with you. Ask @dwnldr :slight_smile: You not experiencing the bug only means that you maybe didn't have the same clientèle. I also have many hap ac2/ac3/cap ac based networks which have never experienced this problem, and then there are three networks with identical configs which used to have problems for the past year, until 10 days ago.

The only difference between them is that in those affected there are many phone models (basically whatever people bring with them - semi public, you only have to ask for password and it shall be given to you). And it is not related to number of clients per AP, because problem used to happen with only a few (less than 3) clients being connected at the moment...

Do you have the possibility for an experiment?

Exchange one cap ac which never experienced these issues with a problematic cap ac.

Already done so. APs are from 6 different batches (one of them is even hap ac2 with 256MB RAM!), 4 different models (hap ac2/ac3, cap ac, wap ac), all netinstalled and reset to default many times. They are hardly available here since AX appeared, and anyway I would go for AX when buying new, so I got some of those, and they are rock solid.

The problem first appeared about March 2025, can't really pinpoint ROS version because at first I suspected bad PoE/cabling/even users rebooting AP for some reason, reported to Mikrotik in May (conversation lasted till Jan 2026, with suggestion to buy "stronger" equipment), in the meantime tried downgrading and upgrading, resetting, netinstalling... changing different related and unrelated options, just didn't think of changing those two security options together... and now all those AC devices have been stable too for the past 11 days.

Then it's not the "clientèle".

Did you also reply this to Mikrotik support?

Yes, I just waited a few more days to be sure enough.