NWA50AX no connection problem hk.

Options
ALYJUAN
ALYJUAN image  Freshman Member
First Comment

On NWA50AX PRO devices, during rooming, the client's MAC address sometimes seems to be blocked, preventing internet access. I'm using 350 access points. I have NWA50AX PROs in the rooms, and WAX655E and NWA210BE in the outdoor areas. This problem only occurs with NWA50AX PROs. If a guest has three devices in the room, for example, this problem only occurs with one of them. It happens randomly, even when the MAC address is disabled. I can share screen recordings. Forgetting the network causes it to revert to a random MAC address, and the problem is solved. Or resetting the Access Point device in the affected room also solves it. Could this problem be related to the firmware? I experienced this with previous firmwares as well.

All Replies

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @ALYJUAN,

    Firstly, please check whether the affected clients' drivers have been updated to the latest version, as outdated drivers can sometimes cause roaming or connectivity issues.

    To help us narrow down the root cause, could you please provide the following information?

    1. What firmware is currently running on the affected devices?
    2. Could you share your network topology (e.g., how the APs, switches, and router/gateway are connected)?
    3. Are the affected APs running in standalone mode or managed via Nebula Control Center (NCC)? If managed via NCC, please enable Zyxel Support Access and share your organization/site name with us so we can take a closer look.
    4. Is this issue concentrated in specific rooms, floors, buildings, or a particular batch of APs, or does it occur randomly across the entire property?
    5. Can this issue be reliably reproduced? Roughly how often does it occur, and does it correlate with specific times (e.g., during peak periods)?
    6. As you mentioned this issue only affects NWA50AX PRO units and randomly affects 1 out of 3 client devices in a room, rather than consistently blocking a specific brand/type of device, kindly share how you determined this (e.g., screen recordings, test methodology, or any error messages/logs you observed). Any AP or client logs showing errors at the time of the issue would also be very helpful.
    7. If possible, could you share the MAC of the affected client devices?
    8. Clarification on "MAC address is disabled" – Are you referring to the MAC Filter profile configuration in the SSID settings?

    This information will help us better understand the situation and determine the next troubleshooting steps. Thank you for your cooperation!

    Zyxel Tina

  • ALYJUAN
    ALYJUAN image  Freshman Member
    First Comment
    Options

    Hello again

    Version running on devices:

    V7.12 (ACGE.0)

    I'm attaching the topology. All devices are connected to the Mikrotik device. There is no firewall in the system.

    The entire system is connected to Nebula. Company: Mirada Del Mar Site: Main Building

    The problem occurs randomly. For example, if there are 3 devices in the room, it might occur on one of them. It is fixed by resetting the Access Point or changing the client's MAC address.

    Sometimes it occurs every 2-3 days, sometimes 2 times a day.

    It only happens on NWA50AX Pro devices. My WAX655E and NWA210BE devices have no problems. This problem also existed in previous versions of my NWA50AX Pro devices.

    I'm sharing an example of the affected device in the attachment. I will also send a video as I witnessed it on my own device. 20:64:cb:55:b5:fb

    I wanted to mention the random MAC address feature on the phones. As you will see in the video, I am not using a random MAC address.

    2026-08-08 13:37:301253Wireless LANStation: 20:64:cb:55:b5:fb left on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -56dBm, Download/Upload: 407KB/353KB, reason 23, Interface: wlan-2-1

    2026-08-08 13:37:291260Station RoamingSTA roamed, MAC:20:64:CB:55:B5:FB, From:1253, To:1260, SSID:MiradaHotels.

    2026-08-08 13:37:291260Wireless LANStation: 20:64:cb:55:b5:fb connected on Channel: 100, SSID: MiradaHotels, 5GHz, Signal: -79dBm, Interface: wlan-2-1

    2026-08-08 13:34:461253Wireless LANStation: 20:64:cb:55:b5:fb connected on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -56dBm, Interface: wlan-2-1 [count=2]

    2026-08-08 13:32:141253Wireless LANStation: 20:64:cb:55:b5:fb connected on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -57dBm, Interface: wlan-2-1

    2026-08-08 13:32:121253Wireless LANStation: 20:64:cb:55:b5:fb left on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -65dBm, Download/Upload: 10KB/15KB, reason 3, Interface: wlan-2-1

    2026-08-08 13:32:031253Wireless LANStation: 20:64:cb:55:b5:fb connected on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -55dBm, Interface: wlan-2-1

    2026-08-08 13:32:001253Wireless LANStation: 20:64:cb:55:b5:fb left on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -55dBm, Download/Upload: 280KB/171KB, reason 3, Interface: wlan-2-1

    2026-08-08 13:16:24OD-Orta Açık HavuzWireless LANStation: 20:64:cb:55:b5:fb left on Channel: 36, SSID: MiradaHotels, 5GHz, Signal: -71dBm, Download/Upload: 100KB/64KB, reason 23, Interface: wlan-2-1

    2026-08-08 13:16:211253Station RoamingSTA roamed, MAC:20:64:CB:55:B5:FB, From:OD-Orta Açık Havuz, To:1253, SSID:MiradaHotels.

    2026-08-08 13:16:211253Wireless LANStation: 20:64:cb:55:b5:fb connected on Channel: 48, SSID: MiradaHotels, 5GHz, Signal: -65dBm, Interface: wlan-2-1 

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @ALYJUAN,

    Thank you for providing the details. After reviewing the video, we noticed something that seems different from your description:

    It appears that the device was initially using its own fixed MAC (“Cihaz”) and had working internet access. After switching to a random MAC (“Rastgele”), the internet connection was lost, and upon reconnecting, the device was redirected to the captive portal login page.

    Could you please confirm whether this is what you intended to show and clarify the sequence of events in the video? Specifically:

    1. Was the device connected to the SSID and able to access the internet normally using its original MAC before switching to a random MAC? Did the disconnection occur immediately after the switch?
    2. Was captive portal re-authentication required only after switching to the random MAC, or does the same behavior also occur when using the original MAC address?

    Zyxel Tina

  • ALYJUAN
    ALYJUAN image  Freshman Member
    First Comment
    Options

    Hello, initially it says "there is no internet on the device" and the device is using Mac. When I say forget the network because there is no internet, a random mace appears and the problem is solved and the captive portal page appears. Access point 1253 name in the image. I also sent the logs to him.

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @ALYJUAN,

    Thank you for your patience. After review, we found that Captive Portal is not enabled in the AP's SSID settings, and the NWA50AX PRO does not support Captive Portal either. Based on this, we believe the Captive Portal is being enforced by your MikroTik device rather than the AP.

    Looking at the disconnection log pattern together with the symptoms you described (no internet access; switching the mobile device to a random MAC, after which the device connects to the internet and is redirected to the portal login page), we suspect the issue may be related to re-authentication timing. In this scenario, when the re-authentication timer expires, the router/gateway might fail to send the re-authentication request to the client, causing the authentication session to expire and traffic to be blocked. It is also possible that the client actively disconnects from the AP on its own when there is no internet access, which can vary depending on the client's chipset/OS behavior.

    To help narrow down the root cause, could you temporarily disable the Captive Portal-related settings on the MikroTik and see if the issue still occurs?

    We appreciate your cooperation!

    Zyxel Tina

  • ALYJUAN
    ALYJUAN image  Freshman Member
    First Comment
    Options

    I understood what you said, but it is not possible to close the captive portal due to law 5651. I am writing to clarify again. When I move away from the 1253 Access Point and go to the 1254 Access Point device, the problem disappears. Even if I reset the 1253 device, there is no problem. If there was a problem with mikrotik or captive portal, I think the problem would not be solved by resetting the 1253 access point device. Thank you for your interest.

  • Zyxel_Tina
    Zyxel_Tina image  Zyxel Employee
    Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Switch 100 Answers 500 Comments
    Options

    Hi @ALYJUAN,

    We understand that fully disabling the Captive Portal on your Mikrotik device may not be feasible in your scenario. As an alternative way to help narrow down the issue, we'd like to suggest the following:

     

    While we're not familiar with the specific configuration options on Mikrotik routers, gateway/firewall devices in general tend to apply captive portal authentication to a specific interface or VLAN. Since each SSID on the AP maps to a corresponding VLAN/interface on your network, could you check whether your Mikrotik device has a similar setting – specifically, which interface/VLAN the Captive Portal is currently applied to – and then create an additional test SSID on the NWA50AX that's mapped to a different VLAN/interface outside that scope?

     

    You could then connect test clients to this new SSID and see if the same issue still occurs, without impacting your existing guest-facing SSID.

     

    We appreciate your cooperation and look forward to hearing how the test goes.

    Zyxel Tina

  • ALYJUAN
    ALYJUAN image  Freshman Member
    First Comment
    Options

    Hello again,

    I'm sending you another video of the problem. I restarted the Mikrotik at the time of the problem, but the result was the same. The problem disappears when I restart the Access Point device. There seems to be a problem with the ARP table in the NWA50AX Pro devices, or something else I don't know about. Could you please check it?

    This isn't a recurring problem, nor does it always occur in the same place. All I know is that restarting the access point solves the problem :)

  • ALYJUAN
    ALYJUAN image  Freshman Member
    First Comment
    Options

    I am also sharing with you the answer I received from the AI; perhaps it will be useful.

    What Exactly Is Happening? (Technical Root Cause)
    Layer-2 (MAC) Table Lockup (State Machine Deadlock):

    When your phone's screen turns off, enters power-saving mode, or performs an instantaneous handover between APs, the driver on the R-1822 continues to maintain your MAC address as "still actively connected."

    When you wake the phone screen and send a reconnection request (Association Request) using the same MAC address, the AP's driver refuses to process the new handshake packets because it has failed to clear your old session from memory (RAM).

    Consequently, the AP does not respond, or the packet times out, resulting in "Auth Timeout" or "handshake fail" entries in the logs.

    Why Does It Resolve When the AP Is Reset?

    When the AP is rebooted (or power-cycled), all client state tables and "stuck" MAC records in the AP's RAM are completely cleared.

    When your phone connects using the same MAC address, the AP treats it as a "fresh/clean session" and approves the connection within milliseconds.