Apple users lose authentication

Randomizate
Conversationalist

Apple users lose authentication

Good morning,
I have an SSID with:
- Open security
- Authentication with Splash Page and Sign-on with Radius (Azure)
- External DHCP server for clients
- Valid accounts are assigned for 30 days

I notice that with Windows and Android devices, the accounts work correctly, but with Apple devices, every time the device loses connection, it asks for a new authentication through the Splash Page even though the log indicates that users have been assigned 2,592,000 seconds (30 days).
Is there any solution so that Apple devices do not request new authentications?

5 Replies 5
cmr
Kind of a big deal
Kind of a big deal

Do the Apple devices have MAC randomisation on?  If they do then this needs to be set to retain a particular MAC for the SSID, or turned off completely.  Otherwise the network sees the device as a new one each time.

If my answer solves your problem please click Accept as Solution so others can benefit from it.
Kevin_Monsta
Here to help

change the mac address to 'Use Mac Device'

alemabrahao
Kind of a big deal
Kind of a big deal

This is what @Kevin_Monsta is talking about.

 

https://dhcp.msu.edu/help/randommac.html

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Randomizate
Conversationalist

Thanks for the suggestions, I’m going to try them on some devices and I’ll share the results.

Randomizate
Conversationalist

Hello,
I have been conducting various tests without success. We have changed on the Apple devices to always use the same MAC address, or MAC addresses in "off" mode, and the response is the same: Every time an Apple device disconnects from the network and reconnects, it requires authentication.

I am going to try to create a sponsored SSID to rule out RADIUS Authentication and report the results.

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.