Wireless event logs 802.1X authentication Successful authentication (EAP success) missing client_ip

jd-1607
Here to help

Wireless event logs 802.1X authentication Successful authentication (EAP success) missing client_ip

Hi all,

I’m having a consistent issue with wireless event logs, the first 802.1X authentication attempt each morning is missing the client_ip. Simply disconnecting and reconnecting the client fixes it, and all subsequent log entries include the client_ip as expected.

I need the client_ip for firewall user authentication via syslog forwarding, so this first-log issue is causing problems.
I cannot accept the only fix for my clients is "just disconnect and reconnect wireless to fix the problem"

Has anyone else come across this behavior? Could this be a limitation of DHCP, Meraki, or something else?

https://documentation.meraki.com/General_Administration/Monitoring_and_Reporting/Syslog_Event_Types_...

The Meraki documentation does not mention the authentication log containing the client_ip. However, as shown in my picture, the AP can provide the client_ip after a disconnect/reconnect following the first connection.

Any insights would be appreciated!

jd1607_0-1756354308455.png

3 Replies 3
jd-1607
Here to help

Incase the information is needed:

DHCP handled by Windows Server (AD/DHCP/DNS)
RADIUS handled by Meraki Access Manager, but same issue is prevalent on devices using Windows NPS for RADIUS

GIdenJoe
Kind of a big deal
Kind of a big deal

Since dot1X happens before receiving an IP.  Isn't that logical that there is no last known IP?

jd-1607
Here to help

Yeh you're right, might need to pursue a client agent to pass the user context through to the firewall instead

Get notified when there are additional replies to this discussion.