Strange problem with FT on some Samsung devices

So, i noticed, that some of my Samsung devices stoped doing fast transition to other APs without any apparent reason. It worked before, but i’m not completly sure when this started to happen. For example, i have Galaxy Tab A11 and Samsung A54 5G. Transition to other AP goes through without problem. On the other side i have S24 Ultra and also S25 Ultra that simply don’t do transition to other AP. I tried with resetting Wifi and network on phone and it made no diference. Tried bunch of different options on Capsman controller, and nothing. I added logging for wireless and now i see that S series gets response “76:E7:F4:90:4B:D7@HapAC2_Klet_Kmetija 5(Kmetija) association rejected, FT failed”

and A series gets response

3A:02:23:B3:03:90@CapAX_Kmetija 2(Kmetija) associated, signal strength -77

3A:02:23:B3:03:90@HapAC3_Sobica_Kmetija 2(Kmetija) roamed to 3A:02:23:B3:03:90@CapAX_Kmetija 2(Kmetija), signal strength -77

3A:02:23:B3:03:90@HapAC3_Sobica_Kmetija 2(Kmetija) disassociated, connected to other interface, signal strength -66

3A:02:23:B3:03:90@HapAC3_Sobica_Kmetija 2(Kmetija) associated, signal strength -64

3A:02:23:B3:03:90@CapAX_Kmetija 2(Kmetija) roamed to 3A:02:23:B3:03:90@HapAC3_Sobica_Kmetija 2(Kmetija), signal strength -64

3A:02:23:B3:03:90@CapAX_Kmetija 2(Kmetija) disassociated, connected to other interface, signal strength -67

I ran out of ideas what could be causing this. One time i did see “network selection disabled, association rejection=2 on S series. Not realy sure what it means. S series now simply go to -90 on Wifi signal, then jumps to 5G and then reconnects to other AP with good signal.

I also tried with acess list, but it makes no difference

[admin@5009] > interface wifi export hide-sensitive
# 2026-03-07 20:15:42 by RouterOS 7.21.2
# software id = LSTE-IL0H
#
# model = RB5009UG+S+
# serial number = 
/interface wifi
# operated by CAP 48:A9:8A:E3:3F:A1%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="CapAX_Kmetija 2" radio-mac=48:A9:8A:E3:3F:A3
# operated by CAP 48:A9:8A:E3:3F:A1%bridge, traffic processing on CAP
add channel.skip-dfs-channels=disabled configuration=Kmetija configuration.country=Slovenia .mode=ap disabled=no name=\
    "CapAX_Kmetija 5" radio-mac=48:A9:8A:E3:3F:A2
# operated by CAP 08:55:31:2B:63:40%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="Garaza_Kmetija 2" radio-mac=08:55:31:2B:63:45
# operated by CAP 08:55:31:2B:63:40%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="Garaza_Kmetija 5" radio-mac=08:55:31:2B:63:46
# operated by CAP 48:8F:5A:C9:71:74%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC2_Klet_Kmetija 2" radio-mac=48:8F:5A:C9:71:79
# operated by CAP 48:8F:5A:C9:71:74%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC2_Klet_Kmetija 5" radio-mac=48:8F:5A:C9:71:7A
# operated by CAP 08:55:31:2B:63:86%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC2_Mlekarna_Kmetija 2" radio-mac=08:55:31:2B:63:8B
# operated by CAP 08:55:31:2B:63:86%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC2_Mlekarna_Kmetija 5" radio-mac=08:55:31:2B:63:8C
# operated by CAP 48:8F:5A:AF:4B:A3%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC3_Sobica_Kmetija 2" radio-mac=48:8F:5A:AF:4B:A8
# operated by CAP 48:8F:5A:AF:4B:A3%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAC3_Sobica_Kmetija 5" radio-mac=48:8F:5A:AF:4B:A9
# operated by CAP 48:A9:8A:D2:6B:4E%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAX2_\8Atala_Kmetija 2" radio-mac=48:A9:8A:D2:6B:54
# operated by CAP 48:A9:8A:D2:6B:4E%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="HapAX2_\8Atala_Kmetija 5" radio-mac=48:A9:8A:D2:6B:53
# operated by CAP 78:9A:18:8C:2D:82%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name=SXTsq5ac radio-mac=78:9A:18:8C:2D:83
# operated by CAP 08:55:31:3D:6E:20%bridge, traffic processing on CAP
add configuration=Kmetija configuration.mode=ap disabled=no name="WapAC_Silosi_Kmetija 2" radio-mac=08:55:31:3D:6E:22
# operated by CAP 08:55:31:3D:6E:20%bridge, traffic processing on CAP
add channel.skip-dfs-channels=disabled configuration=Kmetija configuration.mode=ap disabled=no name=\
    "WapAC_Silosi_Kmetija 5" radio-mac=08:55:31:3D:6E:23
/interface wifi access-list
add action=accept comment="ESP display - allow weak signal" mac-address=A4:F0:0F:5A:C1:C0
add action=accept comment="Merros plug - Allow weak signal" disabled=no mac-address=48:E1:E9:9D:60:96
add action=accept comment="ESP32_\9Atala - Allow weak signal" disabled=no mac-address=7C:F6:66:0F:53:75
add action=accept comment="Allow good clients" disabled=yes signal-range=-80..120
add action=reject comment="Kick weak clients" disabled=yes signal-range=-120..-81
/interface wifi capsman
set enabled=yes interfaces=bridge package-path="" require-peer-certificate=yes upgrade-policy=none
/interface wifi configuration
add channel.frequency=5180,2412,2437,2462 country=Slovenia datapath.bridge=bridge disabled=no mode=ap name=Kmetija \
    security.authentication-types=wpa2-psk .encryption=ccmp .ft=yes .ft-over-ds=yes ssid=Kmetija \
    steering.neighbor-group=dynamic-Kmetija-913a6252 .rrm=yes .wnm=yes
/interface wifi provisioning
add action=create-enabled disabled=no master-configuration=Kmetija
[admin@5009] > 

Any ideas what more can i try? I also thinked of factory resetting my S24, but chances that S25 on the same network (visiting, no changes on factory wifi) had the same symptoms are realy realy small. Also, added steering options make no difference.

That's quite interesting as the A54 5G doesn't support FT with psk

I have no idea where the problem is. It worked somewhere before. Then it suddenly stopped working (updates of phones and Tik's) for S series but it works for Tab A and A54. Probably also for A53. I can try tomorrow.

can you check the registration table if the S Series connects with FT?
That would at least explain the difference.

Since almost all roaming is client side it might also be a bug in Samsung Firmware.
If it doesnt support 802.11r with PSK (ft-psk) then its all up to the Phone.

Yeah, it's ft-wpa2-psk. It makes no sense.

A53
https://youtube.com/shorts/ndGPeOcsNfs?feature=share

S24
https://youtube.com/shorts/ztpLV3Doa2c?feature=share

Same location, same Wifi (A53 Wifi 5, S24 Wifi6 on the same AP (did try to force Wifi 5 on AP with the same results)) phone in left and right hand, A series does FT, S series falls to 5G and then back to Wifi. Every single time.

Ahh that seems like the S24 likes to stick to the "faster" Wifi 6

Just for testing can you run the cap ax at AC/N?

Another idea would be to go into developer options and disable "wifi scan throttling" for a test (so the phone checks for neighbours more often)

A series DOESNT support FT when using PSK.
It only does normal roaming (without FT) while considering k/v (neighbour reports)

Also, A54 5Gs Wi-Fi chip seems "weak" in my own experience :smiley:
But that's another topic.

Alredy tried with fixing AP to AC mode. No difference.

Also disabled scan throtling. No difference. Realy interesting problem.

I always put “ft-over-ds=no”.

Maybe it is just “historic” and maybe that has been fixed at some moment, but I used to have great problems with Samsung and Apple devices until I found out this, so now I am doing this “automatically” (that is: copy-paste a working config).

Will try that tommorow and report back. Thank you.

Ah im stupid

I forgot about this part:

The S24 is trying to use 802.11r (no matter if via ds or no)

So on Mikrotiks you (still) need the following config for best 802.11r experience:
security.connect-priority=0/1

If I may suggest (and I think you can find that in docs too) to disable all access-list rules, they can be counter-productive in a way that client which gets kicked from an AP sometimes (depending on client) “remembers” that and intentionally avoids it in the future.

And another one: limit 5GHz band to 20MHz and allow frequencies 5200, 5220 and 5240 so that not all of the APs are on the same channel. You might loose some speed (but who needs gigabit wifi in/around a silo or a barn :slight_smile: ?), but will gain some better signal quality over longer distance…

+1 stupid here :slight_smile: I forgot about that too

Ok, i tried both options, disabling acess list rules completly, FT over DS and set security.connect-priority=0/1.
No difference. Other devices still roam normally, S24 gets association rejected, FT failed.

the "connected to other interface" is definitely connect-priority.

As that sets the interface priority for roaming.

Can you post your config?

I tried to put in my whole a bit cleaned export but it exceeded the post size limit.

So i added it to pastebin, if it's of any help.

https://pastebin.com/wx4WiArx

Also i got this. First is from tablet, second and third is from S24U.

It looks like the reason is:
ASSOC_REJECT
assocReason=30



Was hoping that maybe this in 7.22 will help, but no difference :grinning_face:

wifi - fixed FT support with wpa2-psk-sha2

I had the same issue today with the Samsung S24 when I played with router settings. I’ve found out that Disable PMKID option prevented to roam. I have disabled it (hmm, disabled ‘disabled’ option :)), and it started roam. Hope it help.

Thank you for suggestion, i tried but it made no difference in my case. It was worth to try.

Problem dissapeared. Not realy sure if with newer version of RouterOS or Samsung OneUI 8.5 upgrade. Probably the latter. Works perfectly now.