ax series lineup WiFi issues

I see quite a lot issues reported in forums about ax lineup WiFi issues, lets collect them here whit possible workarounds and fixes.

I have notices these issues:

  1. The mostly known “rejected, can’t find PMKSA”. It affects my Samsung S22 the most, but I have also seen it affecting S10+ and my laptop whit Intel AX210 WNIC. This should be WPA3 related, if you disable it and use WPA2 only this issue should go away.

  2. “association SA Query timed out” - it is 802.11w Protected Management Frame related. Looks like it started when i turned on FT (Fast BSS Transition (802.11r)).


    Please don’t post about slow WiFi speeds, that’s another story, post only issues that make WiFi unstable or otherwise are software or hardware related.

Here’s mine. Been meaning to send support an email and supout but keep forgetting to generate it. Gonna do that the next time it dies.

I have had very few “can’t find PMKSA” errors. It’s always “key handshake timeout” when the wifi hangs.

hAP ax3 v7.9
13 May 3:50am. ax3 7.9. Wifi uptime: 7 days 2hrs.

hAP ax3 v7.10beta
14 May 5:00pm. ax3 7.10beta5. Wifi uptime: 1 days 12hrs.
15 May 12:20pm. ax3 7.10beta5. Wifi uptime: 7 hrs 20 mins.
(I had FT turned on. Maybe shouldn’t have done that. Back to off.)
18 May 8:00am. ax3 7.10beta5. Wifi uptime: 3 days 6 hrs.
19 May 9:16am. ax3 7.10beta5. Wifi uptime: 1 days 1 hr.


My current config (since May 5 or 6)

# may/09/2023 04:15:47 by RouterOS 7.9
# model = C53UiG+5HPaxD2HPaxD
/interface wifiwave2
set [ find default-name=wifi1 ] channel.band=5ghz-ax .skip-dfs-channels=disabled .width=20/40/80mhz \
    configuration.country=Malaysia .mode=ap .ssid=mtk disabled=no security.authentication-types=wpa2-psk,wpa3-psk \
    .disable-pmkid=no .encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button
set [ find default-name=wifi2 ] channel.band=2ghz-ax .skip-dfs-channels=disabled .width=20mhz configuration.country=\
    Malaysia .mode=ap .ssid=mtk disabled=no mtu=1500 security.authentication-types=wpa-psk,wpa2-psk .disable-pmkid=no \
    .encryption=ccmp,gcmp,ccmp-256,gcmp-256 .wps=push-button

I disabled WPA2 and for now I’m only using WPA3 on ax2, and for now it’s working without any problem, uptime 5d 6h. I was getting PMKSA errors only when WPA2/WPA3 was selected. I’m running 7.10beta5

Still going strong here, wpa2/wpa3 enabled no PMKSA errors.

uptime: 6d11h29m2s
version: 7.10beta5 (development)
build-time: May/09/2023 10:38:53
factory-software: 7.7
free-memory: 619.1MiB
total-memory: 928.0MiB
cpu: ARM64
cpu-count: 4
cpu-frequency: 864MHz
cpu-load: 0%
free-hdd-space: 95.2MiB
total-hdd-space: 128.5MiB
write-sect-since-reboot: 382
write-sect-total: 71514
bad-blocks: 0%
architecture-name: arm64
board-name: cAP ax
platform: MikroTik

I bought my routers before cap ax was released… So now there is no chance to explain my wife that we need yet another APs…

I was thinking about setting up capsman but i don’t have third device that should act as controller… And that is just another layer of complexity… And just for roaming…

AX, AX2, AX3 and cAP AX can all be used as controller, even for their own radios.

 ___________________ 
< ax3 crashed again >
 ------------------- 
        \   ^__^
         \  (oo)\_______
            (__)\       )\/\
                ||----w |
                ||     ||

18 May 8:00am. ax3 7.10beta5. Wifi uptime: 3 days 6 hrs.
…and I forgot to supout.rif again… :frowning:

Is it worth the trouble for just 2 AP ?

Topic related, two PMKSA errors for 2.4 GHz on ax2 after almost 6 days but wifi is still working, it didn’t crash or anything.

Certainly not. :smiley:

Interfaces crashed? Like ax2 reported? Or device itself? autosup should be created if device crashes.

I do use capsman at home for 2 APs, its a learning opportunity.

Oh but for learning there is no problem.
It’s just not needed. I have AX2 and AX3 at home, no capsman.

I have toyed with it too (briefly) to see differences with legacy capsman (I used to have a setup with that for another place) but some of the quirks need to be ironed out before I will try it again.
Or is VLAN handling for ether-ports now sorted out properly ?
Last time I tried it, all VLAN handling needed to be disabled on AP-bridge, hence also for ether-ports.

Yea, i was thinking about that, just to try it, I saw some default configutations on Mikrotik wiki.

Sooo… I ordered two cAP ax… you know… for when drivers get even better…

Hahahahahahahaha too funny!

I never had issues whit VLANs in general, but I did had issue whit interface dynamic add to bridge (so I did it manually). As I revisited config its now working as it should, but system is not perfect. Maybe I don’t know how to do it the right way, but now, afaik, I have to tag interface in capsman interface list and on AP datapath. By logic I understand that server does not know APs datapaths, so this have to be set manually per AP, but vlan tagging should be passed from server, only server side configuration required.

Sorry, double post.

@maigonis

So we can expect some CAPsMAN tutorial from you ? :smiley: :smiley:

I am planning to do tutorials, but not right now. For that I need time and be sure my knowledge is solid, so I’m not spreading false information.

When its wifi dies, the ax3 is still running. Switch, ethernet and containers all ok. Just that nothing connects to the wifi anymore. Logs show “handshake key timeout” whenever any device tries to connect. Nothing in the registration table. For both 2.4 and 5Ghz.

Does enable/disable of the interfaces helps ? Or you have to reboot the router ?