Finally success - 802.11r/k/v fast roaming works reliably with WifiWave2

I apologize: I separated the SSIDs of the two channels. So I have this issue while roaming from the 2.4GHz band of the hap ax3 to the 2.4GHz band of the hap ax lite. The phone roams from ax3 to ax lite → after 10s, it disconnects from the hap ax lite → after 2-3s it connects to the hap ax lite

Example:

 15:33:32 wireless,info E4:XX@wifi2 roamed to E4:XX@wifihapaxlite, signal strength -47
 15:33:42 wireless,info E4:XX@wifihapaxlite disconnected, connection lost, signal strength -39
 15:33:45 wireless,info E4:XX@wifihapaxlite connected, signal strength -44

In some cases I also have:

 15:33:45 dhcp,info dhcp deassigned 192.168.1.20 for E4:XX HUAWEI_P20
 15:33:45 dhcp,info dhcp assigned 192.168.1.20 for E4:XX HUAWEI_P20

The same happens also in the other way (from hapaxlite to hapax3)

oh i’m sorry too, overlooked the different ssids. But this is indeed very strange. It may be because of your “connect-priority=0/1” setting that causes the “disconnect” entries. Try to unset and use the default (accept/hold equal)

/interface/wifi/security/unset value-name=connect-priority wifisec_FT

That was the original setting. Nonetheless, I tried to disable connect-priority, without any change. It still disconnect after 10s and it reconnects in a couple of seconds.
Does anybody know how to debug/collect additional information of what happen in those seconds?

When phone roams is purely client’s decision. The 10s number is quite good. The NetworkManager in Linux configures wpa_supplicant to quite bad values - to initiate roaming possibility discovery only when signal is very very bad.

The fact, that phone roamed successfully, but then disconnects and reconnects indicates, that you have L2 or L3 issues in your network.

Do you have RSTP enabled on all your routers and switches?

One device should have high bridge priority - I choose main/central/edge router to have the highest bridge priority (the lowest value = the highest priority) to ensure it becomes the root bridge.

As this requires troubleshooting your network/setup/devices, it’s better to open a new thread than to hijack existing thread. It may be completely off topic. And, if it’s resolved successful and there’s something missing in this thread, then just add results to this thread.

Yes, you are right. I’ll open a new thread and I will have a look at those points in the meanwhile.
Thanks.

I come back here to report of what happen when FT is disabled: basically roaming now works perfectly for different clients.
Another user reported that roaming works also when FT is disabled (and that disabling FT fixed a problem of one of her/his iPhones).

For details: http://forum.mikrotik.com/t/roaming-ft-unexpected-behaviour-on-7-13-3/173221/1

I would like to see the hostname as it was in the legacy wireless registration table. This is a pita.

Wondering why these parameters exist at two places - configuration and security. When enabled in security it works great, but when enabled in configuration then it makes troubles in stability and roaming does not work at all. Can anyone explain?

Interface > Configuration > security profile

You can configure the parameters anywhere you like. Interface parameters overwrite everything else, if you are using a configuration profile you can overwrite specific settings of the referred security profile.

Contrary to your observations, the result will be the same in any case. It’s only a matter of how you want to organize your configuration.

Concur, the setup process and menu selections are not intuitive and its easy to get lost, ( especially how there are hidden defaults etc. )
I am not a fan of how they have chosen to give flexibility, or more accurately how clear it is to the admin, what is actually configured.
Dont feel bad, you are not alone, all these so called wifi experts dont have a clue about proper MMI.

easy, /interface/wifi/actual-configuration print

Well, using capsman, when I enable FT on configuration (which there is not shown under security at least in webfig not) while having selected in security some already predefined security profile, it does not work. However, when I go in the security profile and define FT there then it works.

Maybe it is just unintuitive and maybe FT in configuration should be under security, and probably once you have security profile defined there in configuration then whet is under FT in configuration is not taken in account, it is rewritten by the security profile chosen.

But of course I am not alone on this one, just found this:

http://forum.mikrotik.com/t/support-for-802-11r/165416/41

time to show off…your configuration. all speculation

let me rephrase that: The result should be the same.
It it isn’t, you may want to report a bug to Mikrotik support.

Does the Cap AX support 802.11v? Thought it did only 802.11k/r

See Help pages.
https://help.mikrotik.com/docs/display/ROS/WiFi

Benefits
WPA3 authentication and OWE (opportunistic wireless encryption)
802.11w standard management frame protection
802.11r/k/v
MU-MIMO and beamforming
400Mb/s maximum data rate in the 2.4GHz band for IPQ4019 interfaces
These benefits apply both to the wifi-qcom and wifi-qcom-ac packages.

So not only AX, also for AC devices capable of using wave2 package.

Guys i really deeply read this post again and again.

I have all set properly i think using this post and also check it in docs…

BUT my main issue with APs is switching clients from AP to another AP.

There is about 20 metters between my 2 APs.

And my goal is use maximum speed possible so i want to have “closest AP connected”

But when i connect my laptop (macbook pro m2) at one position and “walk towards” the second AP i slowly getting worse bandwidth and when i m 1m from second AP i still have 48mbit bandwidt so i think i m still connected to the first AP.

Why?

I can see roaming messages in my logs just from 2g and 5g bands at the same AP (same MAC address in log).. so i disabled 2g entirely to “force” and test this behavior on 5G…

So my laptop is locked to the first AP and no way to du “seamless” transition between to APs.

Note:
In OLD Wireless package i have achieved this by disabling som MCS codes (like disablin all MCS bellow 80mbit for 5g) and leave antena gain and access via signal power untouched and this works perfectly for my old wireless package. Now i m on Wifi (7.14.2 …not wifiWave2 anymore) but i can get this done.

All my CAPs are capsman managed from one of the APs.

THANK YOUI for help.

The design and implementation is a bug.
When I look at capsman configuration, it looks like a nuclear explosion and completely consumes any config, like japanese knotweed.

Ah yes, you explained it earlier … you don’t move away from your chair so you don’t need it :confused:
In all seriousness … what’s the added value of your comment here ?
Have you ever used capsman ? Legacy and wave2 versions ?

@gavopp:
best to open new topic, describe your setup and provide exports of controller and 2 APs.

Is fast roaming (ft=yes) supposed to work between 2.4 and 5GHz with different SSIDs and different vlans ?