Hi WANKiller,
Thanks for your feedback.
Effectively, the syslog server is on the same network wich the AP are.
To separate the wifi public from our lan, i created a vlan without IP address for the wifipublic on our catalyst 4500.
We dedicate an ethernet port on our firewall (fortinet) (attachement1) and give to this physical interface an IP (IP who is the gateway of our meraki AP) like a wire mode
I edited --> DHCP, DNS for the AP (attachement 2)
On my meraki dashboard i can see that my AP recover well An IP (ex : attachement3) and my ipV4 policy is ok (attachement 4)
I checked on our analyzer the traffic, we see traffic (DNS,NTP) from the syslog, AP but not for the logs on port 514 (attachement5,6)
Thanks for your help