Android Device passed remote RADIUS authentication, but cannot receive IP from DHCP.

Kamome
Building a reputation

Android Device passed remote RADIUS authentication, but cannot receive IP from DHCP.

I have one AP, and it served 3 SSID with 2 VLANS.

One of them is for mobile devices, and use 802.1x EAP with remote RADIUS server.

 

Today, one of user called me and said that he cannot connect to WLAN with his Android phone (probably Oreo). When I checked Event Log, there are EAP success message, and after that one, just "client has left AP". No DHCP lease. But when he tried with his Windows laptop, it can connect to AP and got IP from DHCP with no problem.

 

I cannot understand what's going on with this situation. RADIUS Server cannot distinguish Android phone from Windows PC, so it seems that Meraki AP have some issues with latest Android phones.

 

Is there anyone have similar problem like this one?

3 Replies 3
GreenMan
Meraki Employee
Meraki Employee

I don't believe there's a generic problem with 802.1x and Android - I can see other MR networks successfully authenticating and connecting Android clients using 802.1x

 

I think you need to raise a case with Meraki Support - probably via a phone call -  to investigate your problematic client.   Contact details can be found via Help > Get help at the top of the Dashboard.   They may want to take some packet captures, so if you haven't used that tool before, you may want to read this knowledgebase article:  https://documentation.meraki.com/zGeneral_Administration/Cross-Platform_Content/Packet_Capture_Overv...

 

PhilipDAth
Kind of a big deal
Kind of a big deal

Have you tried rebooting the phone?

stroighne
Here to help

I was having the exact same problem. The issue was that the SSID firewall was set to allow clients local lan access. When I denied local lan access, it was as though the DHCP request was forced over the VPN and therefore the routing was corrected. It started working straight away.

 

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels