How to outperform TP-Link Deco

I do not want spill any emotions and just want to ask for kindly help.

We are using Mikrotik devices for years and still strugling with wifi APs (XL, AC, AX no metter). Every time that Mikrotik release new Wifi HW we are excited that this is the day when Mikrotik Wifi starts working properly.

In our scenario we use

  • always latest ROS
  • always latest HW (now WAP AX, CAP AX)
  • always read all docs and forums to try understand how squeze max from Mikrotik Wifi

Now we are use 3 WAP Ax connected to our network (based on mikrotik switches) and we need to get stable wifi for as much as possible clients (what is the maximum real world client of clients on mikrotik wifi AP?)

Now we are testing TP-Link deco becase we are a bit tired to twak every single setting in winbox to “get something that can perform good at least”.

TP-Link Deco out of the box just out perform Mikrotik wifi (on default settings) like a beast. No issues at all, superior stable speedy wifi. But why?

  • is Mikrotik wifi just bad OR we dont understand how setup it properly and we are dumb?
  • why “default out of box” capsman settings just do not set mikrotik to their “best performed settings” to reach “max juice” from Mikrotik Wifi?
  • qos? wmm? roaming? old ipad wont connect? crowded enviroment and mikrotik just hang up?


    Is there anybody who can “help us” to get maximum performance from mikrotik WAP ax before we just pull the trigger on Decos and forgot about mikrotik wifi?

Thank you!

I hesitate to say it, but to be honest: it is what it is. There are no secret tweaks or hidden settings that provide a hidden performance boost. As a hobby, you can experiment with it, but in a commercial or professional environment, I’d clearly say: Use what works well for you and meets your needs.

TP-Link Deco out of the box just out perform Mikrotik wifi (on default settings) like a beast. No issues at all, superior stable speedy wifi. But why?

But maybe you get better quality responses when you elaborate on this (what issues with Mikrotik wifi? What is unstable? How did you perform speed test? How do speeds compare with Deco?).

Thank you for quick answer!

Yes this was intial message to see if there is somebody who can tell “Yes your settings can make huge differences!” So if the default settings is “the best” for what Mikrotik can do with their radios, i can say thats not good news.

We are small church, and we do lot of streaming and we very rely on Wifi. Many smartphones which control something, smartphones who receinve NDI streams as monitoring some stuff.

For now i cant tell what exactly is worse.

Yesterday i set up WAP Ax with hope. All on 7.17.2 to be sure thats is latest.

I need to say that we experimenting with wifi APs for long time now, before Wave2 and ax was mikrotik AP useless for us because many devices is “moving” smarpthones with Video NDI streams on int, so any roaming from one AP to another AP was just dealbreaker.

We tried had jus one AP in middle of the room (CAP AX)… same non stable wifi.

I descibe not stable as “ping from device to router goes from 7ms to 3000ms and then drop… and again and again”

Specially when 300 people come in with theirs smarphones it their pocket :slight_smile: (i think)

Swap to DECO and ping is rock solid in same enviroment.

And now i got thinking that default setiings is not good enoug to overperform Deco, and strart twaking things according to the forum, docs, chatgpt, and so on.

There i no progress.

Now we have 3 wap ax precisely placed to get good coverage of area (against the wall) with FT enabled to get seamless roaming. I can see roaming in logs, but just the ping can stil go wrong …

So what you recommend to do?

Reset? Start over? What settings can improve situation… or just ? I m lost in this situation for sure… and i do not like to get TP-link as our main Wifi APs.

There are several discussions in the forum, especially http://forum.mikrotik.com/t/not-responding-f-k-a-sa-query-timeout/168864/1 As far as I know, there is no simple solution - or even a solution at all to this problem until today. Especially in a church setting, where many different and unknown wireless clients are in use. However, maybe just post your wifi configuration here as an export. Probably someone here has some useful tips how to reach broader compatibility.

I read almost all forums related to the mikrotik wifi performance. (This is why i start to be a bit sceptic about performance).

I do start over with just default bare minimum without any FT settings.

And we will see.

Please provide some information (preferably share your config) to provide information. Every situation is different, there is a lot of tweaking on MikroTik that can be done. But it depends on requirements.For instance, what do you exactly mean by outperform?

In my experience, you can get MikroTik (wifi) super stable. It is just not plug and play.

I will glad to share my config. But this is the point.

If i set bare minimum (like wpa2, ssdi, pass) why mikrotik just do not fall into the best common settings? If so, the overal performance is poor?

This is my config for next sunday. It is bare minimum with disabled FT entireliy

[gavo@MAIN_Router_SNV] > interface/wifi/configuration/ print
Flags: X - disabled 
 0   name="2g_nl_iot" mode=ap ssid="iot.newlevel.media" 
     security.authentication-types=wpa2-psk .encryption=ccmp 
     .group-encryption=ccmp .passphrase="" .connect-group="nl_iot" 
     .connect-priority=0/1 
     steering.neighbor-group=nl_iot .rrm=yes .wnm=no 

 1   name="5ghz_nl_master" mode=ap ssid="newlevel.media" country=Slovakia 
     dtim-period=3 
     security.authentication-types=wpa2-psk .encryption=ccmp 
     .group-encryption=ccmp .passphrase="" .wps=disable .ft=no 
     .ft-over-ds=no .connect-group="nl_connect" .connect-priority=0/1 
     channel.frequency=5150-5350 .width=20/40/80mhz .skip-dfs-channels=all 
     steering.neighbor-group=nl_steering .rrm=yes .wnm=no 

 2   name="2ghz_nl_master" mode=ap ssid="newlevel.media" country=Slovakia 
     tx-power=8 dtim-period=3 
     security.authentication-types=wpa2-psk .encryption=ccmp 
     .group-encryption=ccmp .passphrase="" .ft=no .ft-over-ds=no 
     .connect-group="nl_connect" .connect-priority=0/1 
     channel.frequency=2412-2462:25 .width=20mhz 
     steering.neighbor-group=nl_steering .rrm=yes .wnm=no 

 3 X name="2ghz_nl_guest" mode=ap ssid="GUEST newlevel.media" country=Slovakia 
     security.authentication-types="" .encryption=ccmp .group-encryption=ccmp 
     .disable-pmkid=yes .wps=disable .ft=yes .ft-over-ds=yes 
     .connect-group="nl_connect" .connect-priority=0/1 
     channel.skip-dfs-channels=all 
     steering.rrm=yes .wnm=yes 
[gavo@MAIN_Router_SNV] > 

[gavo@MAIN_Router_SNV] >

Sorry for my rude tone, i was just frustrated. But i get new breath. So THANK YOU! for helping me!


Just overall stability, like NDI video monitoring streams (at lowest possible bandwidth settings) ist just glitching.
Continuous ping from my laptop to router (just to test the connection) can vary from 4ms to 4000ms+++ or just drop for a while (this is reason why others services like NDI streams, or touchOSC, is just not responsive)
Audio over IP intercom has very poor quality (like endless jitter, bad codec because of network stabilty...)


So you are right guy for me ! i do everything what you tell me with my configuraton!

Note: Seamless transitioning from AP to AP is saginificant feature for use because all our volunteers is constantly mooving (with all needed services in pocket like interkom).

This is what TP-link deco just done quite nice. (Yes in outdoors we experience some serious bircking with tplink.. but mostly works more then perfect). But we have mikrotik established in our topology so we will try to stick with Mikrotik AP too (if you can help me to reach stable ping at least)

Note2: We are Mikrotik AP users since dinousaurs. But now when we grow in size and technlogoy needs more a more bandwidth we struggling with Mikrotik APs and we do not how to solve this.

FWIW I have capsman setup at home (personal test lab before I use things elsewhere) and e.g. medium sized one in warehouse with customer (16 APs, all AX devices). Some smaller ones too.

Roaming simply works and ping times are rather low (or those warehouse scanners would disconnect all the time from their connection with Azure Terminal server).

In my view brands like TP Link use some generic settings but they also do quite some “If this, then that” kind of stuff when auto-configuring their devices. Sometimes rather clever, sometimes not so.

Mikrotik doesn’t do that at all. You can change a TON of things but you have to do so yourself.
Default config is usually very sub-par meaning it will work for most cases but far from optimal sometimes.
Like AX radios preferring UNII-4 bands when left to auto setting where definitely not all client devices support it. And then complains come in 5GHz is invisible …
It’s like driving a sports car on a corn field then. It will move (MAYBE !) but certainly not fast.

I know that i can change TON of things.

But nobody (like just you also) do not tell what exactly has to be changed/tweaked to get good performance.

So what you are suggest to do?

I can do call one by one. I can share my rustdesk… i really wan to see that mikrotik can perform well in crowded enviroment.

And kindly ask everybody who can tell that the their network pefrom well to help sort out TONs of settings what have to be set up to get those results.

I really do not like the fact that we will need to go for TPLINK just because we can not set Mikrotik properly.

And TPLINK X50 mesh cost 130 Euro per device. CAP ax cost 120 Euro per device.

So there is no sagnificant price diff. But it is about “130e per device which boot up in default mode and works, even in hard conditions” and “120e per device which boot up in caps mode and works, until we really start using it just like tplink”

Hi @gavopp! Sorry to disappoint you, but I can’t really give you an advice how to make MT Wifi working great. I was trying mysefl many times and have spent countless hours changing all the little bits of config, you can play with on the CAPac, WAPac, CAPax, HAPax3, HAPac2, HAPac3 etc. I had 3 sites (just private flats) running with or without Capsman, on old drivers, on new drivers, ac and ax hardware. I love the versatility, compactness, cheapness, longevity & great features, but it’s just not worth it . On 2 sites I went for TPLink Omada. Don’t like the management web gui, it’s slowness and quirks. For security considerations I don’t recommend using a TP router (except with Openwrt) and I avoid using the cloud part. But man I have saved so much time and nerves! It’s fire and forget. Sometimes there are updates, but the APs just deliver the same high performace as ever. No chasing bugs and strange disconnects. Just browse the forums.

Ps. I’ m talking only about MT WIFI and I very much hope (since many years I do this) that it will improve!

Maybe if you would start to show actual config ?
Then we can have a look at it. Help us to help you.

Terminal
/export file=anynameyouwish
Move file to PC, remove serial, private stuff, serial, …
Post back between code quotes.

The answer to your question is very simple … For wireless place your FOCUS on TP-Link Wireless and you will never look back. The reason that TP-Link does a far better Job on wireless is due to the fact that the OEM drives TP-Link uses in their wireless devices are far more EXPERTLY exploited.

At some point in time MikroTik will learn how to BETTER exploit the OEM drivers – so far their wireless work has been a massive disappointment IMO … if you persist in wasting your time and effort on MikroTik Wireless its on YOU …
:smiley: :smiley:

Export of what?

I post above my Wifi configuration used on capsman. Everything is just default. WAP/CAP is on CAPS mode, DHCP client.., no fw rules, just default CAPS mode. Even the identity i set over capsman.

So what exactly you are looking for? Router? Which does not make any sens because all trafic what i m talking about happening localy? Do not reach router at all.

If i move capsman to switch (CRS310-8G+2S+IN, in default configuration - all porrs in bridge… )

So what exactly you want to export? Whole router? All switches?

Basic topology attached
Snimka_obrazovky_2025-02-21_o_16.59.34.png

It might help if you first learn that when using capsman, everything basically starts with the controller.
CAPs devices are simply getting their config from that controller.

So config from controller and one of the caps, yes.

We are trying to help but it does not help if you block requests for more info in case you want to proceed here.

I do not block anythink.

You can be highly specific, i m not a rookie in network. I did some stuff with mikrotik. We just talking about the wifi performance here.

So i asked you what difference is when i put my capsman controller on any of device. so why config of any device matters? Capsman controller is just placeholder for setting isnt? Wthich is pushed into CAPs itself after provisioning.

You ask me for config for CAPs. I wrote above that all my caps is on DEFAULT CAPS MODE (restored by holding reset button for entering CAPS mode).
My controler (capsman) running on the router right now, but you try to tell me that i move capsman to other device it will be different? No tnik so. Settings for “caps” in “manager” will be the same. So is no difference where capsman runs itself… because all traffic is procesed on cAP not on controller (like it was before when you dont set local forwarding option..)

But i prepare it and post it here.

BTW: My config printed from “interface/wifi/configuration” is printed above + caps in default.

I do not try to be blocking anything, but i want to know any detail - why you are asking for “MY” settings, when i ask YOU GUYS for YOURS settings what i can implement into my enviroment. Because my settings (defaults) does not do the job, so why is even relevant..

I maybe expect somethink like step by step: Do this this this and this, to to 20 , this to -5, this on, this off, this how enable QOS, aaaand you are ready to handle bunch of heavy traffic with no single drop.

So i was wondering what you will se from “my settings” shich is not different from what i posted above. Only what you get is whole export for whole device with all stuff WHICH i ASK you if IT IS RELEVANT. - because if so, i will be really suprised.

So let me prepare what you want to see :slight_smile:

cAP

# 2025-02-21 20:06:47 by RouterOS 7.17.2
# software id = VSAL-8E4U
#
# model = wAPG-5HaxD2HaxD
# serial number = 
/interface bridge
add admin-mac=F4:1E:57:69:07:E4 auto-mac=no comment=defconf name=bridgeLocal
/interface wifi datapath
add bridge=bridgeLocal comment=defconf disabled=no name=capdp
/interface wifi
# managed by CAPsMAN 74:4D:28:88:E0:4D%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: newlevel.media, channel: 2412/ax
set [ find default-name=wifi1 ] configuration.manager=capsman datapath=capdp \
    disabled=no
# managed by CAPsMAN 74:4D:28:88:E0:4D%bridgeLocal, traffic processing on CAP
# mode: AP, SSID: newlevel.media, channel: 5180/ax/Ceee/I
set [ find default-name=wifi2 ] configuration.manager=capsman datapath=capdp \
    disabled=no
/interface bridge port
add bridge=bridgeLocal comment=defconf interface=ether1
add bridge=bridgeLocal comment=defconf interface=ether2
/ipv6 settings
set disable-ipv6=yes
/interface ovpn-server server
add mac-address=FE:EF:90:0A:B8:4C name=ovpn-server1
/interface wifi cap
set discovery-interfaces=bridgeLocal enabled=yes slaves-datapath=capdp
/ip dhcp-client
add comment=defconf interface=bridgeLocal
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/system clock
set time-zone-name=Europe/Bratislava
/system identity
set name=SG-WAX-1
/system note
set show-at-login=no
/system routerboard settings
set auto-upgrade=yes
/tool romon
set enabled=yes
/tool romon port
add interface=ether1

Router (with capsman)

# 2025-02-21 20:31:23 by RouterOS 7.17.2
# software id = X99A-5RX6
#
# model = RB4011iGS+
# serial number = 
/interface bridge
add admin-mac=74:4D:28:88:E0:4D auto-mac=no comment=defconf name=bridge \
    port-cost-mode=short
/interface ethernet
set [ find default-name=ether1 ] comment=WAN
set [ find default-name=ether2 ] comment=DANTE
set [ find default-name=ether3 ] comment="Ableton REC"
set [ find default-name=ether4 ] comment="QNAP 2.5G"
set [ find default-name=ether9 ] comment="PP NET !!!"
set [ find default-name=ether10 ] comment="Wifi POE"
/interface wireguard
add comment=back-to-home-vpn listen-port= mtu= name=back-to-home-vpn
add comment=Proton disabled=yes listen-port= mtu= name=\
    wireguard-inet
/interface list
add comment=defconf name=WAN
add comment=defconf name=LAN
/interface lte apn
set [ find default=yes ] ip-type=ipv4 use-network-apn=no
/interface wifi configuration
add disabled=no mode=ap name=2g_nl_iot security.authentication-types=wpa2-psk \
    .connect-group=nl_iot .connect-priority=0/1 .encryption=ccmp \
    .group-encryption=ccmp ssid=iot.newlevel.media steering.neighbor-group=\
    nl_iot .rrm=yes .wnm=no
add channel.skip-dfs-channels=all .width=20/40/80mhz country=Slovakia \
    disabled=no dtim-period=3 mode=ap name=5ghz_nl_master \
    security.authentication-types=wpa2-psk .connect-group=nl_connect \
    .connect-priority=0/1 .encryption=ccmp .ft=no .ft-over-ds=no \
    .group-encryption=ccmp .wps=disable ssid=newlevel.media \
    steering.neighbor-group=nl_steering .rrm=yes .wnm=no
add channel.frequency=2412,2437,2462 .width=20mhz country=Slovakia disabled=\
    no dtim-period=3 mode=ap name=2ghz_nl_master \
    security.authentication-types=wpa2-psk .connect-group=nl_connect \
    .connect-priority=0/1 .encryption=ccmp .ft=no .ft-over-ds=no \
    .group-encryption=ccmp ssid=newlevel.media steering.neighbor-group=\
    nl_steering .rrm=yes .wnm=no tx-power=8
add channel.skip-dfs-channels=all country=Slovakia disabled=yes mode=ap name=\
    2ghz_nl_guest security.authentication-types="" .connect-group=nl_connect \
    .connect-priority=0/1 .disable-pmkid=yes .encryption=ccmp .ft=yes \
    .ft-over-ds=yes .group-encryption=ccmp .wps=disable ssid=\
    "GUEST newlevel.media" steering.rrm=yes .wnm=yes
/ip kid-control
add name="Ucta k Bohu" sun=13h30m-21h thu=7h-17h
/ip pool
add name=dhcp ranges=10.77.9.100-10.77.9.200
/ip dhcp-server
add address-pool=dhcp interface=bridge lease-time=10h name=dhcp
/ip smb users
set [ find default=yes ] disabled=yes
/port
set 0 name=serial0
set 1 name=serial1
/interface bridge port
add bridge=bridge comment=defconf ingress-filtering=no interface=ether2 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether3 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether4 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether5 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether6 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether7 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether8 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf disabled=yes ingress-filtering=no \
    interface=ether9 internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=ether10 \
    internal-path-cost=10 path-cost=10
add bridge=bridge comment=defconf ingress-filtering=no interface=sfp-sfpplus1 \
    internal-path-cost=10 path-cost=10
/ipv6 settings
set disable-ipv6=yes
/interface bridge vlan
add bridge=bridge tagged=ether10,bridge vlan-ids=50
/interface list member
add comment=defconf interface=bridge list=LAN
add comment=defconf interface=ether1 list=WAN
/interface ovpn-server server
add auth=sha1,md5 mac-address=FE:74:A8:24:2B:D3 name=ovpn-server1
/interface wifi access-list
add action=reject disabled=yes interface=any mac-address=B8:27:EB:39:DA:DF \
    mac-address-mask=FF:FF:FF:FF:FF:FF
/interface wifi capsman
set enabled=yes package-path="" require-peer-certificate=no upgrade-policy=\
    none
/interface wifi provisioning
add action=create-dynamic-enabled disabled=no master-configuration=\
    5ghz_nl_master name-format=%I_5ghz supported-bands=5ghz-ax
add action=create-dynamic-enabled disabled=no master-configuration=\
    2ghz_nl_master name-format=%I_2ghz slave-configurations=2g_nl_iot \
    supported-bands=2ghz-ax
/interface wireguard peers
add allowed-address=0.0.0.0/0 disabled=yes endpoint-address= \
    endpoint-port=interface=wireguard-inet name=peer4 \
    persistent-keepalive=25s public-key=\
    ""
/ip address
add address=10.77.8.1/23 interface=bridge network=10.77.8.0
add address=/27 disabled=yes interface=ether1 network=\
add address=10.2.0.2/30 interface=wireguard-inet network=10.2.0.0
/ip cloud
set back-to-home-vpn=enabled ddns-enabled=yes ddns-update-interval=10m
/ip cloud back-to-home-users
add allow-lan=yes comment=" OnePlus KB2003" name=NLSNV private-key=\
    "" public-key=\
    ""
add name=gavo private-key="" \
    public-key=""
/ip dhcp-client
add comment=defconf interface=ether1 use-peer-dns=no
/ip dhcp-server lease
add address=10.77.8.208 comment="PP: knxrpi" mac-address=B8:27:EB:BC:6D:C9 \
    server=dhcp
add address=10.77.8.211 comment="PP: procesor-led-pp" mac-address=\
    54:B5:6C:0A:6A:C9 server=dhcp
add address=10.77.9.2 comment="SNV: STAGERACK_Router_SNV" mac-address=\
    48:8F:5A:73:A8:CF server=dhcp
add address=10.77.9.210 comment="SNV: Sennheizer Peta mic" mac-address=\
    00:1B:66:30:EA:DF server=dhcp
add address=10.77.9.211 comment="SNV: Senheizer Pastor" mac-address=\
    00:1B:66:7A:28:F2 server=dhcp
add address=10.77.9.3 comment="SNV: FOH_Switch_SNV" mac-address=\
    78:9A:18:3F:EA:8D server=dhcp
add address=10.77.9.4 comment="SNV: STAGE_Switch_SNV" mac-address=\
    78:9A:18:3F:EA:78 server=dhcp
add address=10.77.9.1 comment="SNV: MAIN_Router_SNV" mac-address=\
    74:4D:28:88:E0:55 server=dhcp
add address=10.77.9.55 comment="SNV: tapo-sg telka" mac-address=\
    50:91:E3:F1:A9:08 server=dhcp
add address=10.77.9.50 comment="SNV: tapo-telky" mac-address=\
    A8:42:A1:EC:54:44 server=dhcp
add address=10.77.9.51 comment="SNV: tapo-stagerack" mac-address=\
    A8:42:A1:EC:5B:EA server=dhcp
add address=10.77.9.52 comment="SNV: tapo-teradeks" mac-address=\
    E4:FA:C4:EB:4F:CE server=dhcp
add address=10.77.9.42 client-id=1:12:54:80:2b:66:74 comment="sd2 wireless" \
    mac-address=12:54:80:2B:66:74 server=dhcp
add address=10.77.9.32 client-id=1:64:d8:1b:20:c9:17 comment="sd2 lan" \
    mac-address=64:D8:1B:20:C9:17 server=dhcp
add address=10.77.9.31 client-id=1:6c:c2:42:f3:c8:48 comment="sd1 lan" \
    mac-address=6C:C2:42:F3:C8:48 server=dhcp
add address=10.77.9.43 client-id=1:c6:3b:43:46:13:4e comment="sd3 wireless" \
    mac-address=C6:3B:43:46:13:4E server=dhcp
add address=10.77.9.33 client-id=1:64:d8:1b:20:c6:e2 comment=sd3.lan \
    mac-address=64:D8:1B:20:C6:E2 server=dhcp
add address=10.77.9.229 client-id=1:0:1d:c1:1a:44:30 comment="Tascam ML-32D" \
    mac-address=00:1D:C1:1A:44:30 server=dhcp
add address=10.77.9.44 client-id=1:86:be:7e:52:c2:8d comment="sd4 wireless" \
    mac-address=86:BE:7E:52:C2:8D server=dhcp
add address=10.77.9.34 client-id=1:64:d8:1b:20:c1:8 comment=sd4.lan \
    mac-address=64:D8:1B:20:C1:08 server=dhcp
add address=10.77.9.56 client-id=1:a8:6e:84:cf:9c:e3 mac-address=\
    A8:6E:84:CF:9C:E3 server=dhcp
add address=10.77.8.230 client-id=1:e0:d5:5e:f6:aa:d3 comment="PP: LV1" \
    mac-address=E0:D5:5E:F6:AA:D3 server=dhcp
/ip dhcp-server network
add address=10.77.8.0/23 comment=defconf dns-server=10.77.8.1 gateway=\
    10.77.8.1 netmask=23
/ip dns
set allow-remote-requests=yes servers=10.77.8.1,8.8.8.8
/ip dns static
add cname=interkom-snv.lan comment=Dynamicke name=sonobus.lan ttl=30s type=\
    CNAME
add cname=companion-snv.lan name=companion.lan ttl=30s type=CNAME
add cname=propresenter-snv.lan name=propresenter.lan ttl=30s type=CNAME
add cname=strih-snv.lan name=interkom.lan ttl=30s type=CNAME
add cname=strih-snv.lan name=tally.lan ttl=30s type=CNAME
add cname=resolume-snv.lan name=cg.lan ttl=30s type=CNAME
add cname=resolume-snv.lan name=resolume.lan ttl=30s type=CNAME
add cname=companion-snv.lan name=cg-resolume.lan ttl=30s type=CNAME
add cname=stream-snv.lan name=stream.lan ttl=30s type=CNAME
add cname=stream_audio-snv.lan name=stream_audio.lan ttl=30s type=CNAME
add cname=strih-snv.lan name=strih.lan ttl=30s type=CNAME
add cname=propresenter-snv.lan name=lightkey.lan ttl=30s type=CNAME
add cname=companion-snv.lan name=vestibul.lan ttl=30s type=CNAME
add cname=ha-snv.lan name=ha.lan ttl=30s type=CNAME
add cname=moderatori-snv.lan name=moderatori.lan ttl=30s type=CNAME
add cname=songs-snv.lan name=songs.lan ttl=30s type=CNAME
add address=10.77.9.201 comment=Staticke name=resolume-snv.lan ttl=30s type=A
add address=10.77.8.201 name=resolume-pp.lan ttl=30s type=A
add address=10.77.9.202 name=strih-snv.lan ttl=30s type=A
add address=10.77.8.202 name=strih-pp.lan ttl=30s type=A
add address=10.77.9.203 name=propresenter-snv.lan ttl=30s type=A
add address=10.77.8.203 name=propresenter-pp.lan ttl=30s type=A
add address=10.77.9.204 name=stream-snv.lan ttl=30s type=A
add address=10.77.8.204 name=stream-pp.lan ttl=30s type=A
add address=10.77.9.205 name=companion-snv.lan ttl=30s type=A
add address=10.77.8.202 name=companion-pp.lan ttl=30s type=A
add address=10.77.9.206 name=cg-resolume-snv.lan ttl=30s type=A
add address=10.77.8.206 name=cg-pp.lan ttl=30s type=A
add address=10.77.8.207 name=lightkey-pp.lan ttl=30s type=A
add address=10.77.9.208 name=ha-snv.lan ttl=30s type=A
add address=10.77.9.209 name=marek-nb.lan ttl=30s type=A
add address=10.77.9.212 disabled=yes name=songs-snv.lan ttl=30s type=A
add address=10.77.9.220 name=artnet-snv.lan ttl=30s type=A
add address=10.77.9.221 name=vestibul-snv.lan ttl=30s type=A
add address=10.77.9.222 disabled=yes name=besiedka.lan ttl=30s type=A
add address=10.77.9.230 name=fohabl.lan ttl=30s type=A
add address=10.77.8.230 name=lv1.lan ttl=30s type=A
add address=10.77.9.231 name=iem-snv.lan ttl=30s type=A
add address=10.77.9.232 name=mbc.lan ttl=30s type=A
add address=10.77.9.234 name=stream_audio-snv.lan ttl=30s type=A
add address=10.77.9.235 name=moderatori-snv.lan ttl=30s type=A
add address=10.77.9.31 name=sd1l.lan ttl=30s type=A
add address=10.77.9.32 name=sd2l.lan ttl=30s type=A
add address=10.77.9.33 name=sd3l.lan ttl=30s type=A
add address=10.77.9.34 name=sd4l.lan ttl=30s type=A
add address=10.77.9.41 name=sd1w.lan ttl=30s type=A
add address=10.77.9.42 name=sd2w.lan ttl=30s type=A
add address=10.77.9.43 name=sd3w.lan ttl=30s type=A
add address=10.77.9.44 name=sd4w.lan ttl=30s type=A
add address=10.77.9.203 name=vdo.newlevel.media ttl=30s type=A
add address=10.77.9.203 name=stagedisp.newlevel.church ttl=10s type=A
/ip firewall address-list
add address=192.168.0.0/16 disabled=yes list=rfc1918_private
add address=10.0.0.0/8 disabled=yes list=rfc1918_private
add address=172.16.0.0/12 disabled=yes list=rfc1918_private
add address=192.168.90.0/24 disabled=yes list=guest
add address=192.168.88.0/24 disabled=yes list=dns_allow
add address=192.168.90.0/24 disabled=yes list=dns_allow
add address=10.32.121.0/24 disabled=yes list=milostpp-lan
add address=192.168.88.0/24 disabled=yes list=newlevel-lan
/ip firewall filter
add action=drop chain=input comment="Block DNS requests from WAN" dst-port=53 \
    in-interface-list=WAN protocol=udp
add action=drop chain=input comment="Block DNS requests from WAN" dst-port=53 \
    in-interface-list=WAN protocol=tcp
add action=jump chain=forward comment="jump to kid-control rules" disabled=\
    yes jump-target=kid-control
add action=accept chain=input comment=\
    "defconf: accept established,related,untracked" connection-state=\
    established,related,untracked
add action=drop chain=input comment="defconf: drop invalid" connection-state=\
    invalid
add action=accept chain=input comment="defconf: accept ICMP" protocol=icmp
add action=accept chain=input comment=\
    "defconf: accept to local loopback (for CAPsMAN)" dst-address=127.0.0.1
add action=add-src-to-address-list address-list=\
    "drop all not coming from LAN" address-list-timeout=none-dynamic chain=\
    input comment="defconf: drop all not coming from LAN" in-interface-list=\
    !LAN
add action=accept chain=forward comment="defconf: accept in ipsec policy" \
    ipsec-policy=in,ipsec
add action=accept chain=forward comment="defconf: accept out ipsec policy" \
    ipsec-policy=out,ipsec
add action=fasttrack-connection chain=forward comment="defconf: fasttrack" \
    connection-state=established,related hw-offload=yes
add action=accept chain=forward comment=\
    "defconf: accept established,related, untracked" connection-state=\
    established,related,untracked
add action=drop chain=forward comment="defconf: drop invalid" \
    connection-state=invalid
add action=drop chain=forward comment=\
    "defconf: drop all from WAN not DSTNATed" connection-nat-state=!dstnat \
    connection-state=new in-interface-list=WAN
/ip firewall nat
add action=masquerade chain=srcnat out-interface=wireguard-inet src-address=\
    10.77.8.0/23
add action=masquerade chain=srcnat comment=masquerade ipsec-policy=out,none \
    out-interface-list=WAN
add action=dst-nat chain=dstnat comment="NDI Bridge" disabled=yes dst-port=\
    5990 protocol=udp to-addresses=192.168.88.202 to-ports=5990
add action=dst-nat chain=dstnat comment="Tally bridgerpi" disabled=yes \
    dst-port=9240 protocol=tcp to-addresses=192.168.88.202 to-ports=9240
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
    ipsec-policy=out,none out-interface-list=WAN
add action=masquerade chain=srcnat comment="defconf: masquerade" disabled=yes \
    ipsec-policy=out,none out-interface-list=WAN
/ip ipsec profile
set [ find default=yes ] dpd-interval=2m dpd-maximum-failures=5
/ip route
add disabled=yes distance=1 dst-address=0.0.0.0/1 gateway=10.2.0.1 \
    routing-table=main scope=30 suppress-hw-offload=no target-scope=10
add disabled=yes distance=1 dst-address=128.0.0.0/1 gateway=10.2.0.1 \
    routing-table=main scope=30 suppress-hw-offload=no target-scope=10
add disabled=yes distance=1 dst-address=/32 gateway=\
    192.168.188.1 routing-table=main scope=30 suppress-hw-offload=no \
    target-scope=10
/ip smb shares
set [ find default=yes ] directory=/pub
/system clock
set time-zone-name=Europe/Bratislava
/system identity
set name=MAIN_Router_SNV
/system note
set show-at-login=no
/system ntp client
set enabled=yes
/system ntp client servers
add address=0.sk.pool.ntp.org
/system resource irq rps
set sfp-sfpplus1 disabled=no
/system routerboard settings
set auto-upgrade=yes
/system scheduler
add interval=1w name="Export DHCP every 7Days" on-event=exportdhcp policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2020-09-29 start-time=13:50:00
add interval=1d name=Email_Backup on-event="/export file=export\r\
    \n/tool e-mail send to=\"\" subject=\"\$[/system iden\
    tity get name]  export\" \\\r\
    \nbody=\" configuration file \$[/system clock get date]\" file=export.rsc" \
    policy=ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon \
    start-date=2024-09-23 start-time=15:48:30
/system script
add dont-require-permissions=no name=exportdhcp owner=admin policy=\
    ftp,reboot,read,write,policy,test,password,sniff,sensitive,romon source="i\
    f ([:len [/file find name=leases.rsc]]>0) do={/file remove leases.rsc}\
    \n/ip dhcp-server lease export file=leases.rsc"
/tool mac-server mac-winbox
set allowed-interface-list=LAN
/tool romon
set enabled=yes
/user group
add name=ftp policy="ftp,read,!local,!telnet,!ssh,!reboot,!write,!policy,!test\
    ,!winbox,!password,!web,!sniff,!sensitive,!api,!romon,!rest-api"

So?

Some people have other things to do from time to time …

Quick look at your config:

add channel.skip-dfs-channels=all .width=20/40/80mhz country=Slovakia \
    disabled=no dtim-period=3 mode=ap name=5ghz_nl_master \
    security.authentication-types=wpa2-psk .connect-group=nl_connect \
    .connect-priority=0/1 .encryption=ccmp .ft=no .ft-over-ds=no \
    .group-encryption=ccmp .wps=disable ssid=newlevel.media \
    steering.neighbor-group=nl_steering .rrm=yes .wnm=no
add channel.frequency=2412,2437,2462 .width=20mhz country=Slovakia disabled=\
    no dtim-period=3 mode=ap name=2ghz_nl_master \
    security.authentication-types=wpa2-psk .connect-group=nl_connect \
    .connect-priority=0/1 .encryption=ccmp .ft=no .ft-over-ds=no \
    .group-encryption=ccmp ssid=newlevel.media steering.neighbor-group=\
    nl_steering .rrm=yes .wnm=no tx-power=8

Why all the dedicated settings ? Do you know for each of them what they do ? If not, best to leave them untouched with default value.

Encryption=ccmp: I never use it.
authentication= use wpa3 when possible, it’s faster then wpa2. Best to use both so the client can decide.
Also, since you use same SSID on both 5Ghz and 2GHz, it makes a lot of sense to use ft. You have it disabled right now. But on the other hand you do set steering.neighbor-group (which does not get used then) ?? It’s created by default based on SSID so no need to specify it again.
5Ghz: why set channel width ? You limit it to 80MHz, blocking possibility to use 160MHz which wAP AX can use.
Leave it blank, let it decide on its own.
2GHz, specify frequency. Don’t let it up to the AP to decide what it will be since it may end up being on a frequency which is crowded (same comment on 5GHz BTW).
group-encryption=ccmp: I don’t use it.
rrm=yes and wnm=no, why set it this way ? Use it or not. Both are yes as default. Leave it that way.