Quote from: Monviech (Cedrik) on January 02, 2026, 08:58:25 PMI would suggest to create the simplest topology for the wifi (no virtual IP addresses, no CARP, no firewall aliases (just any as destination).Simplifying first often reveals hidden issues. Rebuilding step by step with a clean VLAN and SSID is a smart troubleshooting approach.
Then retry if you have issues.
If not, introduce these features back in one by one.
Best if you use a new vlan you send out via another SSID to check.
Maybe the devices don't like using a vietual CARP MAC address as their gateway, or something about the firewall policies is wrong.
As general rule of thumb, reducing complexity is always a good way to catch bugs.
"