On ax platform during roaming get "no internet available" error

Dear All,

I use ax CAPS and a HeX POE router for CAPSMAN. Main router is a hAP ax3. CAPS are 2 CAP ax and 1 wAP ax. On 5Ghz config FT is enabled, on 2,4Ghz disbled. I have a server inside LAN , available from outside using dst-nat.
My client is an S24 Ultra. If I connect any of the CAPS expect the main router everyting is working fine, but if client roaming back to the main router I receive “no internet available” error. If I try to ping the server I receive “no route to host” error. In this case if I disable the client wifi and enable it again it starts to work or if I wait a few minutes (3-4) also starts to work correctly. I have no idea what should be the problem.
On main router port5 is the WAN port. port1-4 and 2 WIFI ports are in a bridge. port1 connects to the first CAP ax’s port1. CAP ax’s port2 connects to the hEx poe bridge. ON hEX POE all ports are in a bridge and the 2nd CAP ax and wAP ax connects to the hEX POE. on all CAPS all ports are in a bridge. DHCP runs on main router, DNS resolver on the hEX POE.
Last week I did a clear netinstall on all devices, not solved the problem.

Could you be please give me some idea where to start solving the problem. I have absolutly no idea, I tried almost everyting.

Thanks in advance.

Why did you disable FT on 2.4GHz? Do 2.4GHz and 5GHz have the same SSID?
Looks like your hAP AX3 wifi interfaces are not managed by CAPsMAN…correct?

For providing better feedback, please share your CAPsMAN’s and hAP AX3 configs:

/export file=anynameyoulike

Remove serial and any other private info.

Spanning Tree Protocol enabled on bridge?

Or u can try set wifi iface in bridge → ports as edge=yes or edge=yes-discovery

Hi,

SSID is different due to I have many IOT devices and some can drop connection is the SSID is same.
On 2,4Ghz FT is disabled because some of the IOT devices started to play “ping-pong” between CAP ax devices if it was enabled on 2,4GHz, so I disabled.
ax3 interfaces are managed by CAPMAN.
I’m new user , so I have no right to upload config, mayme I can paste here, but it is not short. I exported boot hEX Poe and ax3 config and removed all sensitive data.

Not yet. Earlier I’ve tried to enable , but no change in situation and HW offload on bridge disabled, but no loop in the wired network.

Currently bridge hardware offload for the devices with IPQ-PPE switch chip, which include your cAP ax and hAP ax³ is incomplete and MikroTik recommend that you enable RSTP on those devices to disable HW-Offload: Bridging and Switching - RouterOS - MikroTik Documentation

  1. Currently, HW offloaded bridge support for the IPQ-PPE switch chip is still a work in progress. We recommend using, the default, non-HW offloaded bridge (enabled RSTP).

Please share from both hEX PoE and hAP AX3:

/interface/wifi export

This will give insights on your CAPsMAN configuration.

Thanks, I will tryí it today

I did the full export, but can’t share file,because I’m new user :frowning:

Here is the wifi part from ax3:

/interface wifi
# managed by CAPsMAN 192.168.88.8, traffic processing on CAP
# mode: AP, SSID: Amajor_Home, channel: 2412/ax/Ce
set [ find default-name=wifi2 ] configuration.manager=capsman .mode=ap disabled=no name=router-wan_2G
# managed by CAPsMAN 192.168.88.8, traffic processing on CAP
# mode: AP, SSID: Amajor_Home_5G, channel: 5500/ax/Ceee/D
set [ find default-name=wifi1 ] channel.frequency=5470-5700 configuration.manager=capsman .mode=ap \
    disabled=no name=router-wan_5G
/interface wifi cap
set caps-man-addresses=192.168.88.8 discovery-interfaces=ether1-pince enabled=yes
/interface wifi capsman
set enabled=yes interfaces=LAN-bridge,lo package-path="" require-peer-certificate=no upgrade-policy=none

from hEX poe:
/interface wifi configuration
add country=Hungary disabled=no mode=ap multicast-enhance=enabled name=Amajor_Home security.authentication-types=\
    wpa2-psk,wpa3-psk .ft=no .ft-over-ds=no .wps=disable ssid=Amajor_Home
add channel.frequency=5470-5700 country=Hungary disabled=no mode=ap multicast-enhance=enabled name=Amajor_Home_5G \
    security.authentication-types=wpa2-psk,wpa3-psk .ft=yes .ft-over-ds=yes .wps=disable ssid=Amajor_Home_5G
add disabled=yes name=Akoska_Home_Akacfa ssid=Akoska_Home_Akacfa
/interface wifi
# operated by CAP 192.168.88.12, traffic processing on CAP
add configuration=Amajor_Home disabled=no name=duhongo_wAP_ax_2G radio-mac=x
# operated by CAP 192.168.88.12, traffic processing on CAP
add configuration=Amajor_Home_5G disabled=no name=duhongo_wAP_ax_5G radio-mac=x
# operated by CAP 192.168.88.9, traffic processing on CAP
add configuration=Amajor_Home configuration.mode=ap .tx-power=7 disabled=no name=pince_cAP_ax_2G radio-mac=\
    x
# operated by CAP 192.168.88.9, traffic processing on CAP
add configuration=Amajor_Home_5G disabled=no name=pince_cAP_ax_5G radio-mac=x
# operated by CAP 192.168.88.14, traffic processing on CAP
add configuration=Amajor_Home configuration.mode=ap disabled=no mtu=1500 name=pince_eloter_cAP_ax_2G radio-mac=\
    x
# operated by CAP 192.168.88.14, traffic processing on CAP
add configuration=Amajor_Home_5G disabled=no name=pince_eloter_cAP_ax_5G radio-mac=x
# operated by CAP 192.168.88.1, traffic processing on CAP
add configuration=Amajor_Home disabled=no name=router-wan_2G radio-mac=x
# operated by CAP 192.168.88.1, traffic processing on CAP
add configuration=Amajor_Home_5G disabled=no name=router-wan_5G radio-mac=x
/interface wifi access-list
add action=accept comment="Samsung TV kisszoba" disabled=no mac-address=x
add action=accept comment=Slimmelezer+ disabled=no mac-address=x
add action=accept comment="A1T Pince lej\E1r\F3" disabled=no mac-address=x
add action=accept comment="M\E9r\F5 h\E1trafel\E9" disabled=no mac-address=x
add action=accept comment="M\E9r\F5 kl\EDma" disabled=no mac-address=x
add action=accept comment=RM4-Pro disabled=no mac-address=x
add action=accept comment="Computherm E400RF" disabled=no mac-address=x
add action=accept comment="G\E1zkaz\E1n vez\E9rl\E9s" disabled=no mac-address=x
add action=accept comment="Xiaomi 1K pince" disabled=no mac-address=x
add action=accept comment="Shelly Plug konyhapult" disabled=no mac-address=x
add action=accept comment="Anyu HP notebook" disabled=no mac-address=x
add action=accept comment="Xiaomi 1K kint" disabled=no mac-address=x
add action=accept comment="\C9jjeli f\E9ny A1T" disabled=no mac-address=x
add action=accept comment="WR remote" disabled=no mac-address=x
add action=accept comment="Xiaomi 1K konyha" disabled=no mac-address=x
add action=accept comment="Vegyeskaz\E1n vez\E9rl\E9s" disabled=no mac-address=x
add action=accept comment="Xiaomi 2K el\F5szoba" disabled=no mac-address=x
add action=accept comment="Xiaomi 1K d\FCh\F6ng\F5" disabled=no mac-address=x
add action=accept comment="Nous A8T pince bels\F5" disabled=no mac-address=x
add action=accept comment="SmartOne el\F5szoba" disabled=no mac-address=x
add action=accept comment="Xiaomi 2k Rasztiles" disabled=no mac-address=x
add action=accept comment="Pince A1T h\FBt\F5" disabled=no mac-address=x
add action=accept comment="Shelly 2PM Nappali villany" disabled=no mac-address=x
add action=accept comment="Inverter SDongleA" disabled=no mac-address=x
add action=accept comment="Pince lej\E1r\F3 NOUS" disabled=no mac-address=1x
add action=accept comment="Vegyeskaz\E1n h\F5m\E9r\F5k" disabled=no mac-address=x
add action=accept comment="Xiaomi 2K EC3 kert" disabled=no mac-address=x
add action=accept comment="Lacib\E1csi A70" disabled=no mac-address=x
add action=accept comment="Lacib\E1csi A70 5G" disabled=no mac-address=x
add action=accept comment="Nous A1T pince el\F5t\E9r" disabled=no mac-address=x
add action=accept comment="Amajor Lenovo laptop" disabled=no mac-address=x
add action=accept comment="Chromecast pince" disabled=no mac-address=x
add action=accept comment="Bluetooth Proxy kisszoba M5Stack" disabled=no mac-address=x
add action=accept comment="HP noti Linux" disabled=no mac-address=x
add action=accept comment="Nous A1T Pince t\F6lt\F5" disabled=no mac-address=x
add action=accept comment="Shelly 1PM Kutyah\E1z" disabled=no mac-address=x
add action=accept comment=Akos-S24-Ultra-eszkoze disabled=no mac-address=x
add action=accept comment=Andrea-A53-eszkoze disabled=no mac-address=x
add action=accept comment=Laszlo-A70-eszkoze disabled=no mac-address=x
add action=accept comment="Bluetooth Proxy nagyszoba ESP32" disabled=no mac-address=x
add action=accept comment="A8T El\F5szoba kamer\E1k" disabled=no mac-address=x
add action=accept comment="Shelly Plug nappali" disabled=no mac-address=x
add action=accept comment="Shelly Plug Mikr\F3" disabled=no mac-address=x
add action=accept comment="Shelly Plug K\E1v\E9f\F5z\F5" disabled=no mac-address=x
add action=accept comment="Shelly Plug Kisszoba" disabled=no mac-address=x
add action=accept comment="Shelly 1PM D\FCh\F6ng\F5 LEDsor Feh\E9r" disabled=no mac-address=x
add action=accept comment="Shelly 1PM D\FCh\F6ng\F5 LEDsor Sz\EDnes" disabled=no mac-address=x
add action=accept comment="Andrea A53" disabled=no mac-address=x
add action=accept comment="Xiaomi C700 El\F5szoba" disabled=no mac-address=x
add action=accept comment="Xiaomi C300 El\F5szoba" disabled=no mac-address=x
add action=accept comment="Xiaomi 2k bej\E1rat" disabled=no mac-address=x
add action=accept comment="Shelly 1PM Szivatty\FA" disabled=no mac-address=x
add action=accept comment="Shelly Plug Haj\F3h\FBt\F5" disabled=no mac-address=x
add action=accept comment="Shelly Plug D\FCh\F6ng\F5 Ventill\E1tor" disabled=no mac-address=x
add action=accept client-isolation=yes comment="Guest VLAN" disabled=no mac-address-mask=FF:FF:FF:FF:FF:FF \
    ssid-regexp=Amajor_Home vlan-id=10
/interface wifi capsman
set enabled=yes interfaces=bridge1 package-path="" require-peer-certificate=no upgrade-policy=none
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=Amajor_Home name-format=%I_2G supported-bands=2ghz-n
add action=create-enabled disabled=no master-configuration=Amajor_Home_5G name-format=%I_5G supported-bands=5ghz-ac

You are running CAPsMAN on your hAP AX3 as well…though it might not interfere you probably want to disable it.

You could add connect-priority=0/1 to have better roaming experience with devices that don’t support FT.

Yes, That is my fault, I forgot to disable it. 2 weeks ago I’ve tried to put the CAPSMAN functionality to the ax^3 , but not solved the problem so moved back it to hEX POE and forgot to disable it on ax^3. Now I disabled, but there was no interference. Thanks for note me.

1 month ago I removed the connect-priority from the wifi configuration because I’ve not experienced any advantage of that, but now I will put is back. Should it be added to both of 5GHz and 2,4GHz config too?

Interesting thread I’ve faced a similar “no internet available” issue during roaming on the AX platform. It seems like certain DHCP or DNS handling quirks pop up when switching access points. Still testing a workaround, but curious if anyone’s had success adjusting roaming sensitivity or lease time?

I only add this setting where I use FT as well.

Thanks. I’ve added to both 2,4Ghz and 5GHz. Some clients started again to play ping-pong between APs.Connects with good signel level, disconects, connects to another AP, disconnects. This is a fix installed camera:

Yesterday I enabled the RSTP on all devices, set the ax^3’s priority to 4000, so that is the root bridge now. I had limited time to test (2 times ), but it worked. During roaming between APs all time I had connection, there was no “no internet available” message, I was able to access all inside resources as well.
During next days I will continue the test.

Thanks everybody!
It seems solved with the settings I wrote previously.

1 Like