Beryl 7 (GL-MT3600BE) firmware 4.9.0: WDS repeater drops 5 GHz uplink on group key rekey (reason 16), then takes ~2.5 min to recover

Setup

  • Device: GL.iNet Beryl 7 (GL-MT3600BE), firmware 4.9.0
  • Mode: Repeater with WDS, 5 GHz uplink (apclii0 is bridged into LAN; LAN gets its IP from the main router via DHCP)
  • Uplink: SSID HomeNet-5G, channel 36, WPA3-SAE, MLO disabled on the client (ApcliMloDisable = 1)
  • Main router: Banana Pi R4, OpenWrt-based hostapd on MediaTek
  • Frequency: every group rekey

MAC addresses and SSID are anonymized. [REPEATER] is the GL.iNet's apclii0 and [MAIN-AP] is the main router's BSSID; each is the same device in both logs.

Problem 1: Uplink is dropped when the main router rotates its group key

When the main router does a group key rekey, the GL.iNet never answers the group key handshake. After 4 tries the main router deauthenticates it with reason 16 (group key handshake timeout). Other clients on the same SSID complete the same rekey without trouble.

Main router log:

[2:47:46 PM] hostapd: phy0.1-ap0: STA [CLIENT-A] WPA: group key handshake completed (RSN)
[2:47:46 PM] hostapd: phy0.1-ap0: STA [CLIENT-B] WPA: group key handshake completed (RSN)
[2:47:49 PM] hostapd: phy0.1-ap0: STA [REPEATER] WPA: group key handshake failed (RSN) after 4 tries
[2:47:49 PM] hostapd: phy0.1-ap0: AP-STA-DISCONNECTED [REPEATER]
[2:47:49 PM] hostapd: mtk: update disconnect counter: type=DEAUTH, from_sta=0, addr=[REPEATER], reason=16
[2:47:54 PM] hostapd: phy0.1-ap0: STA [REPEATER] IEEE 802.11: deauthenticated due to inactivity (timer DEAUTH/REMOVE)
[2:47:54 PM] hostapd: handle_assoc_cb: STA [REPEATER] not found
[2:50:06 PM] hostapd: phy0.1-ap0: AP-STA-CONNECTED [REPEATER] auth_alg=sae

The GL.iNet log has nothing about the rekey. The first entry is the disconnect itself:

Fri Oct  9 14:47:49 2026 daemon.err gl-repeater[14912]: (repeater.lua:663) disconnected from HomeNet-5G [MAIN-AP]

Problem 2: Recovery takes ~2.5 minutes and drops every client on the GL.iNet

The uplink loss itself is brief, but gl-repeater's recovery makes it much worse:

  1. It restarts the whole network: both radios, all local SSIDs, both Ethernet ports, even loopback. Every wired and wireless client on the GL.iNet loses connectivity.
  2. The 5 GHz rescan times out, costing ~40 s:
Fri Oct  9 14:49:11 2026 daemon.err gl-repeater[14912]: (repeater-mtkwifi7.lua:478) rai15 : wait scan done fail: timeout
  1. The next scan finds the main router but skips it because the BSSID is still marked disabled, adding another 30 s:
Fri Oct  9 14:49:21 2026 daemon.info gl-repeater[14912]: (repeater.lua:1204) switch to HomeNet-5G
Fri Oct  9 14:49:21 2026 daemon.info gl-repeater[14912]: (repeater.lua: 62) skip disabled bss [MAIN-AP]
Fri Oct  9 14:49:21 2026 daemon.info gl-repeater[14912]: (repeater.lua:1213) not found matched bss for HomeNet-5G
Fri Oct  9 14:49:21 2026 daemon.info gl-repeater[14912]: (repeater.lua:1706) switch in 30 seconds...
  1. It finally reconnects at 14:49:58 and gets a DHCP lease at 14:50:08. Total outage: about 2 min 20 s.

Questions

  • Is the group key rekey failure a known issue with the repeater client (WPA3-SAE, WDS mode)? Is it fixed in a newer firmware?
  • Can the recovery be made less disruptive? For example, not restarting the entire network, or not blocking the only saved BSSID?

Raising wpa_group_rekey on the main router would make the drops rarer, but it doesn't fix the underlying problem. I can provide full logs from both devices if needed.