Meshed, Meraki MR76 in repeater mode fails RADIUS

Einstein
Getting noticed

Meshed, Meraki MR76 in repeater mode fails RADIUS

Gateway AP succeeds at RADIUS test, but not meshed repeater. 

Since the repeater has no IP address, how do I add it to RADIUS list? DNS name does not work either.

Cannot seem to find anything on this. 

Thank you all in advance. 

8 Replies 8
alemabrahao
Kind of a big deal
Kind of a big deal

As far as I know the mesh AP will use the gateway AP IP for the Radius authentication.

 

Is the authentication working on the gateway AP?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Einstein
Getting noticed

Gateway auth is working, but when I run the RADIUS test through Meraki, it sees the repeater and fails it. Just trying to see if there was a way to either verify the AP through RADIUS, or just clear the error. 

Thank you

I have mesh APs and the authentication via 802.1x is working fine.

 

Have you checked the radius server log?

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

What does the RADIUS server say?

 

If you do a packet capture on the RADIUS server, what IP address do you see the RADIUS requests coming from?

Ryan_Miles
Meraki Employee
Meraki Employee

I can confirm RADIUS testing works from mesh repeaters. Repeaters don't have IPs themselves so they will use the IP of the gateway AP they're connected to.

Einstein
Getting noticed

Nothing telling that I can see in the log file (I can see results from all other AP's).  Since the repeater has no IP address, it is not even tested by Meraki when I run a manual RADIUS test. All other AP's are seen, and pass. When I try to connect to the repeater with my laptop, the connection sits at "Trying to authenticate". If the auth happens on the gateway, traffic does not seem to be getting forwarded from the repeater to the gateway for this. Since the traffic never gets to the gateway, it never makes it to the RADIUS server, hence nothing in the log. Just more info, we also have an open SSID on this repeater that works fine. I am 1 firmware ver behind. Maybe next week I will rev the AP's to the newest firmware. I will read up on new firmware over the weekend. 

Thanx again everyone!

I have 2 gateways and 3 repeaters (and 2 offline APs). When I test RADIUS it shows 5 passes and 2 fails for the offline APs. So it is showing test results for repeaters. 

 

Perhaps you have something else going on. Have you opened a Support case?

Einstein
Getting noticed

I have not. The community is always my first goto 😉

The repeater is working for one of my SSID's, so I know it's halfway?.....working.....lol

I will open a case and  post what I find. 

Thank you everyone again!!!

 

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels