Skip to main content
Nascimento
New Member
January 23, 2024
Solved

Cisco wireless with FortiAuthenticator for MAC Authentication - MAB - does not deliver IP from dhcp

  • January 23, 2024
  • 1 reply
  • 1695 views

Hello!

I have a simple WiFi for legacy devices working well with Cisco WLC, Cisco AP's and SSD with static WPA password.

Today I started to integrade this WiFi with FortiAuthenticator for MAC Authentication - MAB. But i am having problems.

The problem is that the authentication is working well, but the DHCP server is not delivering IP when on this mode.

When I just break this integration from Cisco Wireless and FortiAuthenticator, this returns to deliver IP from dhcp.

Has anyone here already implemented one of these?

Best answer by Nascimento

Hello,  Thanks for reply. But I saw that the problem is just a delay in the first connection to start with a new IP, but after the first connection, the next connections works fine. I convinced that I don't think more that this is a problem by FortiAuthenticator, and I'll try to wipe this infra. I will put the DHCP for this case in a best position in my network design.

1 reply

AEK
SuperUser
SuperUser
January 23, 2024

Hello

If you agree this should just meen that the client is not being properly assigned to the VLAN.

  • Check in your AP GUI if the client is properly assigned to the right VLAN
  • If not then check of the RADIUS response has the format expected by AP. Indeed the authentication can work even if VLAN/profile assignment os wrong
  • In your AP try set default SSD VLAN if not already done
  • If VLAN assignment is dynamic and there are many target VLANs for the SSD, then as far as I remember you need to sed some related WiFi ACLs

Hope it helps

AEK
Nascimento
NascimentoAuthorAnswer
New Member
February 21, 2024

Hello,  Thanks for reply. But I saw that the problem is just a delay in the first connection to start with a new IP, but after the first connection, the next connections works fine. I convinced that I don't think more that this is a problem by FortiAuthenticator, and I'll try to wipe this infra. I will put the DHCP for this case in a best position in my network design.