No WPA3 logins possible after updating to 7.19.1 and adding new ESSID after upgrade

Hi

Today, the WLAN on a campus of a client goes down today.

We just added a new ESSID to an existing VLAN where is managed by CAPsMAN, but after this change, nobody was able to login again - on all ESSID’s, except the guest WLAN, where is managed by vouchers. We deleted the whole CAPsMAN configuration and started from scratch - no luck!

After hours of debugging, tracing etc. we saw, that some very old device are able to login - all with WPA2 PSK. We disabled WPA3 PSK on all ESSID’s and all 300 users are back again online.

One week ago, we did the update from 7.18.2 to 7.19.1, but nothing else and we didn’t add a new ESSID, last time was with 7.18.2. So maybe the update is working as long the security is not touched.

At the moment we run WPA2 PSK only.
Anybody with the same expiriences?

Ivo

Not the experience…can you please share the config to check for anything unusual?
Especially the before and after situation.

/export file=anynameyoulike

Remove serial and any other private info, post between code tags by using the </> button.

Hi
As attached, you can find the anonymized version with and without WPA3.
Ivo
wpa2only.cfg.rsc (70.7 KB)
wpa2and3.cfg.rsc (68.2 KB)

Nothing odd in regards to security. What CAP do you use? Seems there are some problems with specific Qualcomm chipsets where a new firmware is tested. Could be related to your problem as well.

Antenna gain should only be set explicitly in case of external antennas. If you want to reduce transmission power, you can set Max Tx Power.

We use only the cAP ax (cAPGi-5HaxD2HaxD).

Thank you for the hint about Max TX Power - we configure both, is this a recommendation to only set Max TX Power or what is the effect if we configure both?

Thanks a lot
Ivo

Max Tx Power is used to limit transmission power (if higher than regulated, the latter will be complied to), while antenna gain is used to calculate to stay within regulations. Setting both is far from optimal (and really makes no sense). In the old days, antenna gain was the only way to have control on transmission power.

I’ll search for the remark about the Qualcomm firmware. Then you have an indication when a possible solution will be available.

Here it is:
http://forum.mikrotik.com/t/not-responding-f-k-a-sa-query-timeout/168864/385

Hi
We did some measurements today in a distance ~6m away from the AP.

  • If we set the Antenna Gain to max (=30) without setting TX Power, we got ~-71db


  • If we set the TX Power to min (=1) without setting Antenna Gain, we got ~-60db


  • If we set the Antenna Gain to max (=30) and TX Power to min (=1), we got ~-73db


  • If we remove both, we got ~-57db

So, it’s true to set both doesn’t make sense, but why we have this difference between only TX Power set and only Antenna Gain set?
I read some articles in the forum and on the confluence, but there is no clear description how it should be managed. We must have the lowest possible radiation on the AP’s in the class rooms to protect the kids.

About the Qualcomm firmware - well, this can be the problem, but why not after the upgrade? We experience the problem after a week when we added a new ESSID, before everthing working as expected.

Thanks a lot

Ivo

I read the topic where you linked to, as I understand, this is focused on chrome cast devices. On our environment, all devices goes down, Apple, Android, Thinkpad, Linux, Windows, Printers…032003

Hi

Last night, we go on with the WPA3 problem on our lab. Updating two AP’s to 7.19.2 and then the switches too. Everthing is working fine, we can connect with WPA3.

Then, we updated also the prod environment to 7.19.2, but with the result, WPA3 is still not working, but a new observation:

While we activated WPA2 + WPA3 for 5 minutes, the CPU is 100%, where is consumed from the management and wireless process. No client registration at all. Then, we removed WPA3, only WPA2 was active. After ~1 minute the CPU consumption goes down and the clients came back with WPA2.

We have 37 AP’s connected to the CAPsMAN in the prod environment and there was 130 clients in the night where tried to connect.

Are there any limits?

Ivo