CAPsMAN reassociating

Hello, I would like to ask for your advice. In my home network, I have a CRS125-24G-1S-2HnD-IN set up in CAPsMAN mode, and to it are connected CAPs (RBwAP2nDr2, RBcAPL-2nD, RB952Ui-5ac2nD). The network works fine over LAN. However, I have trouble connecting other devices to the Wi-Fi. The RB952Ui-5ac2nD serves as the main Wi-Fi in the apartment, and everything works basically normally. Other devices in the apartment can connect to the Wi-Fi. The problem arises when, for example, I move around with my phone, and it should switch to another CAP, like the RBwAP2nDr2 (cap8) that I have in the garden. The phone connects to the Wi-Fi, but the internet does not work, and I cannot access the internal network. Same in the garage (CAP RBcAPL-2nD)
The log repeatedly shows

44:..:..:..:6G@cap8 reassociating.

It is strange, though, that the IP camera, which is permanently in the garage, connects to the Wi-Fi without any issues, using the RBcAPL-2nD as its CAP.
Can someone please help me identify the problem and what I might be missing in the configuration?
Thank you very much.

Here is my config:

# 2024-10-13 19:58:24 by RouterOS 7.16.1
# software id = JVZ3-7613
#
# model = CRS125-24G-1S-2HnD
# serial number = 944B0CCF7629
/interface bridge
add admin-mac=48:8F:5A:1A:04:EB auto-mac=no comment=defconf name=bridge \
    port-cost-mode=short
/interface wireless
set [ find default-name=wlan1 ] band=2ghz-b/g/n channel-width=20/40mhz-XX \
    country="czech republic" distance=indoors frequency=auto installation=\
    indoor mode=ap-bridge ssid=JoinTheDarkSide station-roaming=enabled \
    wireless-protocol=802.11
/interface ethernet
set [ find default-name=ether2 ] comment="Predsin 4 (WallBox)"
set [ find default-name=ether3 ] comment="garaz nahore (WallBox)"
set [ find default-name=ether4 ] comment="zahrada 2 (prav\FD)" name=\
    ether4_zahrada_2_prava
set [ find default-name=ether5 ] name=ether5_garaz_nahore
set [ find default-name=ether6 ] comment="zahrada 1 (lev\FD)" name=\
    ether6_zahrada_1_leva
set [ find default-name=ether7 ] comment="predsin 3" name=ether7_predsin_3
set [ find default-name=ether8 ] comment="kuchyne 1" name=ether8_kuchyne_1
set [ find default-name=ether9 ] comment="predsin 2" name=ether9_predsin_2
set [ find default-name=ether10 ] comment="lo\9Enice 2"
set [ find default-name=ether11 ] comment="obyv\E1k 3"
set [ find default-name=ether13 ] comment="lo\9Enice 1"
set [ find default-name=ether14 ] comment="gara\9E 1 (nad stolem)"
set [ find default-name=ether15 ] comment="pokoj 1"
set [ find default-name=ether16 ] comment="obyv\E1k 2"
set [ find default-name=ether18 ] comment="pokoj 2"
set [ find default-name=ether19 ] comment="p\F8ed domem"
set [ find default-name=ether21 ] comment="obyv\E1k 4"
set [ find default-name=ether22 ] comment="p\F8eds\ED\F2 1"
set [ find default-name=ether23 ] comment="obyv\E1k 1"
/caps-man interface
add disabled=no l2mtu=1600 mac-address=64:D1:54:A3:58:45 master-interface=\
    none name=cap1 radio-mac=64:D1:54:A3:58:45 radio-name=64D154A35845
/interface wireguard
add listen-port=13231 mtu=1420 name="Platanov\E1"
/interface vlan
add interface=bridge name=GuestWiFi vlan-id=2
/caps-man security
add authentication-types=wpa2-psk eap-radius-accounting=no encryption=aes-ccm \
    group-encryption=aes-ccm group-key-update=1d name=security
add authentication-types=wpa2-psk eap-radius-accounting=no encryption=aes-ccm \
    group-encryption=aes-ccm group-key-update=1d name=security1
add authentication-types=wpa2-psk encryption=aes-ccm name=MainWiFi
add authentication-types=wpa2-psk encryption=aes-ccm name=GuestWiFi
/caps-man configuration
add channel.band=2ghz-g/n .control-channel-width=20mhz .extension-channel=\
    disabled .skip-dfs-channels=yes country="czech republic" \
    datapath.client-to-client-forwarding=yes .local-forwarding=yes name=\
    cfg-2ghz security=security ssid=JoinTheDarkSide
add channel.band=5ghz-a/n/ac .control-channel-width=20mhz .extension-channel=\
    disabled country="czech republic" datapath.client-to-client-forwarding=\
    yes .local-forwarding=yes name=cfg-5ghz-ac security=security ssid=\
    JoinTheDarkSide
add channel.band=5ghz-a/n/ac .control-channel-width=20mhz .extension-channel=\
    disabled country="czech republic" datapath.client-to-client-forwarding=\
    yes .local-forwarding=yes name=cfg-5ghz-an security=security ssid=\
    JoinTheDarkSide
add country="czech republic" datapath.client-to-client-forwarding=no \
    .local-forwarding=yes .vlan-id=2 .vlan-mode=use-tag distance=indoors \
    installation=indoor mode=ap name=GuestWiFiIndoor security=GuestWiFi ssid=\
    WeHaveCookies
add country="czech republic" datapath.client-to-client-forwarding=no \
    .local-forwarding=yes .vlan-id=2 .vlan-mode=use-tag distance=dynamic \
    installation=outdoor mode=ap name=GuestWiFiOutdoor security=GuestWiFi \
    ssid=WeHaveCookies
add country="czech republic" datapath.client-to-client-forwarding=yes \
    .local-forwarding=yes distance=indoors installation=indoor mode=ap name=\
    MainWiFiIndoor security=MainWiFi ssid=JoinTheDarkSide
add country="czech republic" datapath.client-to-client-forwarding=yes \
    .local-forwarding=yes distance=dynamic installation=outdoor mode=ap name=\
    MainWiFiOutdoor security=MainWiFi ssid=JoinTheDarkSide
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wireless security-profiles
set [ find default=yes ] authentication-types=wpa2-psk mode=dynamic-keys \
    supplicant-identity=MikroTik
/ip ipsec policy group
add name=ProtonVPN
/ip pool
add name=dhcp ranges=192.168.88.2-192.168.88.254
add name=vpn ranges=192.168.89.2-192.168.89.255
add name=dhcp_pool2 ranges=10.60.0.2-10.60.0.254
/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=10m name=defconf
add address-pool=dhcp_pool2 interface=GuestWiFi name=dhcp1
/ip smb users
set [ find default=yes ] disabled=yes
/port
set 0 name=serial0
/ppp profile
set *FFFFFFFE dns-server=192.168.88.1 local-address=192.168.89.1 \
    remote-address=vpn
/routing bgp template
set default disabled=no output.network=bgp-networks
/caps-man manager
set enabled=yes
/caps-man provisioning
add action=create-dynamic-enabled disabled=yes hw-supported-modes=gn \
    master-configuration=cfg-2ghz name-format=prefix-identity name-prefix=\
    2ghz
add action=create-dynamic-enabled disabled=yes hw-supported-modes=ac \
    master-configuration=cfg-5ghz-ac name-format=prefix-identity name-prefix=\
    5ghz-ac
add action=create-dynamic-enabled disabled=yes hw-supported-modes=an \
    master-configuration=cfg-5ghz-an name-format=prefix-identity name-prefix=\
    5ghz-an
add action=create-dynamic-enabled comment="cAP Lite (garaz)" \
    master-configuration=MainWiFiIndoor radio-mac=2C:C8:1B:1D:16:82 \
    slave-configurations=GuestWiFiIndoor
add action=create-dynamic-enabled comment="wAP (zahrada)" \
    master-configuration=MainWiFiOutdoor radio-mac=08:55:31:36:50:88 \
    slave-configurations=GuestWiFiOutdoor
add action=create-dynamic-enabled comment="hAP AC Lite" master-configuration=\
    MainWiFiIndoor radio-mac=64:D1:54:A3:58:44 slave-configurations=\
    GuestWiFiIndoor
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether2 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether3 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether4_zahrada_2_prava internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether5_garaz_nahore internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether6_zahrada_1_leva internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether7_predsin_3 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether8_kuchyne_1 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=\
    ether9_predsin_2 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether10 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether11 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether12 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether13 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether14 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether15 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether16 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether17 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether18 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether19 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether20 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether21 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether22 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether23 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether24 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=sfp1 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=wlan1 \
    internal-path-cost=10 path-cost=10
/ip firewall connection tracking
set udp-timeout=10s
/ip neighbor discovery-settings
set discover-interface-list=LAN
/ip settings
set max-neighbor-entries=8192
/ipv6 settings
set max-neighbor-entries=8192
/interface detect-internet
set detect-interface-list=all
/interface l2tp-server server
set enabled=yes use-ipsec=yes
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface ovpn-server server
set auth=sha1,md5
/interface sstp-server server
set default-profile=default-encryption
/interface wireguard peers
add allowed-address=192.168.216.2/32 comment="Michal iPhone12" disabled=yes \
    interface="Platanov\E1" name=peer8 public-key=\
    "N4KjIEEYJXQrS4ITeHx5H1H7MrPwb4H3sPSE5akE/So="
add allowed-address=192.168.216.3/32 comment="Michal MBP" interface=\
    "Platanov\E1" name=peer10 public-key=\
    "PPNvlwbx5C/zewDOuGYjIuMiA2J06BH8w9brjiOcAmo="
add allowed-address=192.168.216.4/32 comment="Niki iPhone 14" interface=\
    "Platanov\E1" name=peer11 public-key=\
    "3am54R6p5FyGJ7ve0a6LRkOdI/cjaE/NkmoYX95vR1Q="
/interface wireless cap
set bridge=bridge discovery-interfaces=bridge interfaces=wlan1
/ip address
add address=192.168.88.1/24 comment=defconf interface=bridge network=\
    192.168.88.0
add address=10.9.32.10/30 interface=ether1 network=10.9.32.8
add address=192.168.216.1/24 interface="Platanov\E1" network=192.168.216.0
add address=10.60.0.1/24 interface=GuestWiFi network=10.60.0.0
/ip cloud
set ddns-enabled=yes
/ip dhcp-client
add comment=defconf disabled=yes interface=ether1
/ip dhcp-server lease
add address=192.168.88.11 comment="Philips HUE br\E1na" mac-address=\
    EC:B5:FA:15:B0:54 server=defconf
add address=192.168.88.3 client-id=1:8:55:31:36:50:87 comment=\
    "MikroTik wAP (venkovn\ED)" mac-address=08:55:31:36:50:87 server=defconf
add address=192.168.88.22 client-id=1:4c:20:b8:de:56:1a comment=\
    "HomePod Mini - koupelna" mac-address=4C:20:B8:DE:56:1A server=defconf
add address=192.168.88.12 comment="IKEA br\E1na" mac-address=\
    74:7A:90:A1:D2:19 server=defconf
add address=192.168.88.10 client-id=1:c4:a8:1d:81:f6:c7 comment="NAS D-Link" \
    mac-address=C4:A8:1D:81:F6:C7 server=defconf
add address=192.168.88.20 client-id=1:98:6:3c:78:5b:2c comment=\
    "TV Frame Samsung" mac-address=98:06:3C:78:5B:2C server=defconf
add address=192.168.88.4 client-id=1:2c:c8:1b:1d:16:81 comment=\
    "Mikrotik cAP Lite (gar\E1\9E)" mac-address=2C:C8:1B:1D:16:81 server=\
    defconf
add address=192.168.88.5 client-id=1:8:55:31:9f:c0:55 comment=\
    "Mikrotik hAP AC Lite (kuchyne- byt)" mac-address=08:55:31:9F:C0:55 \
    server=defconf
add address=192.168.88.41 client-id=1:a6:36:ab:ac:72:96 comment=\
    "Michal iPhone 7" mac-address=A6:36:AB:AC:72:96 server=defconf
add address=192.168.88.30 client-id=1:b8:e8:56:4a:1b:54 comment="Michal MBP" \
    mac-address=B8:E8:56:4A:1B:54 server=defconf
add address=192.168.88.42 client-id=1:56:ac:37:e7:5b:10 comment=\
    "Niki iPhone 11" mac-address=56:AC:37:E7:5B:10 server=defconf
add address=192.168.88.51 client-id=1:2c:a5:9c:ef:0:b8 comment=\
    "Kamera pred domem" mac-address=2C:A5:9C:EF:00:B8 server=defconf
add address=192.168.88.52 client-id=1:f8:4d:fc:be:cd:c3 comment=\
    Kamera_ZAHRADA mac-address=F8:4D:FC:BE:CD:C3 server=defconf
add address=192.168.88.50 client-id=1:24:28:fd:2d:c3:4a comment=NVR \
    mac-address=24:28:FD:2D:C3:4A server=defconf
add address=192.168.88.43 client-id=1:8c:fa:ba:71:8c:ee comment="Michal iPad" \
    mac-address=8C:FA:BA:71:8C:EE server=defconf
add address=192.168.88.23 client-id=1:84:57:33:4c:bb:8f comment=Xbox \
    mac-address=84:57:33:4C:BB:8F server=defconf
add address=192.168.88.14 client-id=1:e4:5f:1:5f:55:be comment=HomeAssistant \
    mac-address=E4:5F:01:5F:55:BE server=defconf
add address=192.168.88.54 client-id=1:80:91:33:46:1f:59 comment=\
    "Kamera chodba" mac-address=80:91:33:46:1F:59 server=defconf
add address=192.168.88.17 client-id=1:bc:d0:74:65:25:a2 mac-address=\
    BC:D0:74:65:25:A2 server=defconf
add address=192.168.88.16 client-id=\
    ff:8f:c1:49:a9:0:2:0:0:ab:11:de:6:29:49:38:a3:e3:ba mac-address=\
    B8:27:EB:07:E0:84 server=defconf
add address=192.168.88.19 client-id=ff:50:81:83:76:0:3:0:1:30:49:50:81:83:76 \
    comment="Ernesto - vysavac" mac-address=30:49:50:81:83:76 server=defconf
add address=192.168.88.9 client-id=1:e4:5f:1:55:92:49 comment="RbPi Zero2" \
    mac-address=E4:5F:01:55:92:49 server=defconf
add address=192.168.88.24 client-id=1:0:41:e:e4:2e:ce comment=\
    Tiskarna_Brother mac-address=00:41:0E:E4:2E:CE server=defconf
add address=192.168.88.2 client-id=1:64:d1:54:a3:58:3f comment=\
    "Mikrotik hAP AC Lite (skrin - byt)" mac-address=64:D1:54:A3:58:3F \
    server=defconf
add address=192.168.88.55 client-id=1:4c:f5:dc:8b:d4:aa comment=Kamera_SUD \
    mac-address=4C:F5:DC:8B:D4:AA server=defconf
/ip dhcp-server network
add address=10.60.0.0/24 dns-server=1.1.1.1 gateway=10.60.0.1
add address=192.168.88.0/24 comment=defconf gateway=192.168.88.1
/ip dns
set allow-remote-requests=yes use-doh-server=https://dns.nextdns.io/be3c3b \
    verify-doh-cert=yes
/ip dns static
add address=192.168.88.1 name=router.lan type=A
add address=45.90.28.0 name=dns.nextdns.io type=A
add address=45.90.30.0 name=dns.nextdns.io type=A
add address=2a07:a8c0:: name=dns.nextdns.io type=AAAA
add address=2a07:a8c1:: name=dns.nextdns.io type=AAAA
/ip firewall address-list
add address=192.168.88.11 comment="HUE Br\E1na" list="Block - Users"
add address=192.168.88.50 comment=NVR list="Block - Users"
add address=192.168.88.51 comment="IP Kamera - vstup" list="Block - Users"
add address=192.168.88.53 comment="IP Kamera - gar\E1\9E" list=\
    "Block - Users"
add address=192.168.88.52 comment="IP Kamera - zahrada" list="Block - Users"
add address=192.168.88.0/24 list=under_protonvpn
/ip firewall filter
add action=drop chain=forward comment="IoT + kamery" disabled=yes \
    src-address-list="Block - Users"
add action=accept chain=input protocol=icmp
add action=accept chain=input connection-state=established
add action=accept chain=input connection-state=related
add action=accept chain=input dst-port=13231 protocol=udp
add action=accept chain=input dst-port=13231 protocol=udp src-address=\
    192.168.216.0/24
add action=accept chain=input comment="allow IPsec NAT" dst-port=4500 \
    protocol=udp
add action=accept chain=input comment="allow IKE" dst-port=500 protocol=udp
add action=accept chain=input comment="allow l2tp" dst-port=1701 protocol=udp
add action=drop chain=input comment="toto zapni" in-interface-list=!LAN
add action=drop chain=forward dst-address=192.168.88.0/24 src-address=\
    10.60.0.0/24
/ip firewall mangle
add action=mark-connection chain=prerouting new-connection-mark=\
    under_protonvpn passthrough=yes src-address-list=under_protonvpn
/ip firewall nat
add action=masquerade chain=srcnat comment="defconf: masquerade" \
    ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment="masq. vpn traffic" src-address=\
    192.168.89.0/24
add action=masquerade chain=srcnat dst-address=192.168.216.0/24
add action=redirect chain=dstnat dst-port=53 protocol=tcp
add action=redirect chain=dstnat dst-port=53 protocol=udp
/ip ipsec policy
add dst-address=0.0.0.0/0 group=ProtonVPN proposal=*1 src-address=0.0.0.0/0 \
    template=yes
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=10.9.32.9
/ip service
set ftp disabled=yes
/ip smb shares
set [ find default=yes ] directory=/pub
/ip upnp
set enabled=yes
/ip upnp interfaces
add interface=bridge type=internal
add interface=ether1 type=external
/lcd
set time-interval=weekly
/lcd interface pages
set 2 interfaces=sfp1
/ppp secret
add name=vpn profile=default-encryption
/system clock
set time-zone-name=Europe/Prague
/system identity
set name="Switch (basement)"
/system note
set show-at-login=no
/tool mac-server
set allowed-interface-list=LAN
/tool mac-server mac-winbox
set allowed-interface-list=LAN