Hi WANKiller,
Thanks for your feedback.
Effectively, the syslog server is on the same network wich the AP are.
To separate the wifi public from our lan, i created a vlan without IP address for the wifipublic on our catalyst 4500.
We dedicate an ethernet port on our firewall (fortinet) (attachement1) and give to this physical interface an IP (IP who is the gateway of our meraki AP) like a wire mode
![attachement1.PNG attachement1.PNG](https://community.meraki.com/t5/image/serverpage/image-id/546i22F3180771326D07/image-dimensions/427x241?v=v2)
I edited --> DHCP, DNS for the AP (attachement 2)
![attachement2.PNG attachement2.PNG](https://community.meraki.com/t5/image/serverpage/image-id/547i6C4F75F222E17ECB/image-dimensions/499x504?v=v2)
On my meraki dashboard i can see that my AP recover well An IP (ex : attachement3) and my ipV4 policy is ok (attachement 4)![attachement3.PNG attachement3.PNG](https://community.meraki.com/t5/image/serverpage/image-id/548iAA39BE3D5E3D7242/image-dimensions/480x494?v=v2)
![attachement4.PNG attachement4.PNG](https://community.meraki.com/t5/image/serverpage/image-id/549iF8C3867435CF3707/image-dimensions/629x61?v=v2)
I checked on our analyzer the traffic, we see traffic (DNS,NTP) from the syslog, AP but not for the logs on port 514 (attachement5,6)
![attachement6.PNG attachement6.PNG](https://community.meraki.com/t5/image/serverpage/image-id/550iC093919D9EB0B2DE/image-size/large?v=v2&px=999)
![attachement5.PNG attachement5.PNG](https://community.meraki.com/t5/image/serverpage/image-id/551iA16693DC72E22912/image-size/large?v=v2&px=999)
Thanks for your help