I have seen couple of compatibility complains on this forum from different users between Mikrotik and Apple. And I share my experience, which can help anybody and even Mikrotik. That is all.
You will see similar complaints on ANY forum discussing WiFi. The implementation of WiFi, especially in IoT and Apple products, is often not resilient against changes in features. What works today with today’s firmware may break at the next upgrade, and there is little that the AP manufacturer can do about it.
IoT devices often cannot be upgraded (even when there are firmware upgrades for the device, they will usually not upgrade the WiFi stack which is just some Espressif or similar standard firmware, and Apple is known for their stubbornness.
I always wonder why people tend to make your life miserable with unneded features switched on.
I understand "playing" with them, tinkering with all options but why to enable the resource consuming features just for enabling them and making devices' life tougher and decresing communication speeds?
Encryption/decryption eats power so it draws more energy from mobileswhat needs more charging that implies shorter battery life. No sense for me.
Repating .... I understand checking "what if" and testing strange configurations in home lab, but I'm also aware thet not all devices follow rules and have their own "I do like this as I can" habits. We have to live with that.
Sorry BartoszP, I share experience. And I don’t understand toxic answers without WITHOUT ANY REAL information and ONLY EMOTIONS. ![]()
Enabling WPA2 PSK SHA2 can add incompatibilities. I have seen that newer devices are able to connect without problems but older devices might not be able to connect in this situation.
Same applies to encryption cipher selection.
Simple search reveals IMHO nontoxic information:
https://9to5mac.com/2020/09/17/ios-14-privacy-cisco/
https://wlan1nde.wordpress.com/2017/07/07/apple-client-fails-with-mandatory-pmf-on-802-1x-ssid/
https://forum.opnsense.org/index.php?topic=43766.0
It's a shame that so many brands are incompatibile with Apple's devices. They should be really ashamed of themselves and do they best to satisfy Apple's requirements.
![]()
Implicitly is always better revealed for understanding, sadly I will explicitly bug you for months to come to a better understanding the ramifications of spilling the previously hidden worms in my soup.
Well, I went through “IMHO nontoxic information” - everything is closed, solved and obsolete. To share something, what is 1-9 years old is little bit unprofessional. If you would like to waste the time of others, fine, but for me you are little bit primitive.
And back to the topic - Apple devices working fine with Mikrotik RouterOS 7.22 and WPA2-PSK and WPA3-PSK. They have connection problems with WPA2-PSK-SHA2, which is not properly documented, what really this setting do and what is the real difference between standard WPA2-PSK.
Folks are trying to help. And you're responding in all-caps "TOXIC".
I'll provded a link:
https://support.apple.com/en-us/102766
Apple does not mention anyhting about using anything related to using any "-SHA2" scheme.
If the question what is the "WPA2-PSK-SHA2" mode, that's be better question. Not my iPhone doesn't work when I set a random new setting. Critizing answers you don't like just muddles this thread with back-and-forth on commentary who is more rude.
There is an issue with WPA3-EAP / WPA3-EAP-192 as well.
I'm wondering, when did this discussion turn into criticizing each other instead of focusing on the technical points?
The main questions are:
Whos side was the source of problems and why?
Who solved the problem by bending/dumbing down it's implementation to make it work with the other one?
Truth always is somwhere in between. It's not the primitive binary white-black world.
As it is a common point of discussion in manufacturer forums, I’ll reply once again, even though it seems to be a fruitless discussion.
Every time a manufacturer releases new firmware for WiFi access points, there will be comments on the forum like “the speeds have dropped”, “it does not work on my IoT device anymore”, “Apple devices now cannot connect anymore” or “I needed to delete my entire WiFi connection and re-create it to get connection again”.
These are often explained by other things than the upgrade. But the user experienced them during the upgrade, so it must be caused by the update.
However, one can often observe that merely rebooting the AP can cause similar effects. The issue is not the upgrade, but the fact that the client saw the AP disappear and went into a mode that it normally rarely is using. E.g. it is normally connected to 5GHz, sees that disappear, tries to reconnect, that fails, it scans, sees the 2GHz (AP is back by now), connects that. User is surprised speeds are lower now.
Or client has a broken 802.11k/r/v implementation (e.g. “none at all”) and will not re-connect when the AP disappears. Common with IoT devices. Triggered by enabling “fast roaming” somewhere in the past, the current issue is not caused by the upgrade just by the reboot.
For Apple devices there seems to be the additional problem that when the client sees the parameters of the AP have changed (e.g. security parameters changed), it won’t use its existing saved profile anymore and fails to reconnect until that is removed/re-created. Causing any setup change or change in firmware functionality that results in different security parameters to cause problems.
There is nothing an AP manufacturer can do about all that. It is client related, often the client side could fix the issues with a software update but they simply won’t do that. So these problems will remain.
Usualy the side/person to be blamed of a problem is the one that lately "touched" the THING.
Many do misinterpret stable, but maybe functioning by a chance, state of something as a good correct configuration.
If, as you wrote, that "something" gets restarted/refreshed/changed/timeouted and new working "equilibrium" gets reached, the different one of course, who/what is blamed for this? I know the answer as I tangled myself blindly with that attitude many times : the latest change situation.
Typical such situations we all could face with:
- Car does not start after visiit in the garage to change tires ... the garage "shurely did something else". No matter that tires have no influence on the engine but it' easier to think like that.
- Changed firewall rules seem to work for days till connections would timeout and then devices fall to connect but you blame the OS updates applied to them. 100%
- You slipped on the sidewalk in winter, the caretaker is to blame, not your favourite summer moccasins, worn only to get to the neighbor's house.
As I wrote: Truth always lies somewhere in between. It's not the simple binary white-black world.
This is a new one for me ![]()
We learn all our lives ... if only we want ![]()
As someone who frequently had to step in and investigate what had gone wrong and why, I can confirm my first request was always a list of what was changed, and when.
Sometimes, previously safe changes caused a sudden, major failure. It’s incredible how many times I've encountered 255 devices (or addresses or entries in a table) = safe and 257 devices = total failure. The previous 200 ish changes went smoothly, then boom.
Anyone having issues coping files from the routers using SCP?
x@a:/home $ scp x@b:/file.rsc .
x@b's password:
./file.rsc: Permission denied
2026-02-02 11:26:49 ssh,error 0000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
2026-02-02 11:26:49 ssh,error 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Modifying the comment for the DHCPv6 Client causes a rebind / restart of the service? why?