Sorry, it's a D-Link DIR-860L b1. Re-checked, the WPA2-Personal of both 2.4G and 5G have no problem. It seems still some kind of 801.x regression to me, only presented when using WPA2-Enterprise.
Guys, thanks for your caring. I think I've found the culprit, one 'bridge' line which should not be there with guest0 interface. After removing that line, everything went back to normal.