Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ernie
New Contributor III

Wireless client fails to receive DHCP when connecting to a Meraki AP / FortiAuthenticator

We are trying to authenticate a wireless client using EAP-TLS on a Meraki AP against a FortiAuthenticator (with RADIUS).

The EAP-TLS is successful but the wireless client doesn´t receive a DHCP IP address, nor does it have network access. However, a wired EAP-TLS (computer authentication) request from the same client works flawlessly.

 

Parts of the debug log show:

 

(2794) facauth: ===>NAS IP:192.168.100.96
(2794) facauth: ===>Username:host/W10CLIENT.company.local
(2794) facauth: ===>Timestamp:1707907999.157486, age:1ms
(2794) facauth: Comparing client IP 192.168.100.96 with authclient Meraki-AP1 (192.168.100.96, 1 IPs)
(2794) facauth: ------> matched!
(2794) facauth: Found authclient from preloaded authclients list for 192.168.100.96: Meraki-AP1 (192.168.100.96)
(2794) facauth: authclient_id:2 auth_type:'eap-tls'
(2794) facauth: Found authpolicy 'EAPTLS' for client '192.168.100.96'

<SNIP>

(2794) facauth: Updated auth log 'host/W10CLIENT.company.local' for attempt from 192.168.100.96: 802.1x authentication successful
(2794) facauth: User-Name: host/W10CLIENT.company.local (from request)
<SNIP>
(2794) Sent Access-Accept Id 23 from 192.168.0.100:1645 to 192.168.100.96:49544 length 220
(2794) MS-MPPE-Recv-Key = <<< secret >>>
(2794) MS-MPPE-Send-Key = <<< secret >>>
(2794) EAP-Message = 0x031b0004
(2794) Message-Authenticator = 0x00000000000000000000000000000000
(2794) User-Name = "host/W10CLIENT.company.local"
(2794) Framed-MTU += 994
(2794) Tunnel-Type += VLAN
(2794) Tunnel-Medium-Type += IEEE-802
(2794) Tunnel-Private-Group-Id += "500"
(2794) Finished request

 

Has anyone else experienced this issue?

 

1 Solution
Ernie
New Contributor III

After multiple support calls with Fortinet and Meraki in the same call, the Meraki engineer concluded that this wasn´t an authentication issue... she asked us to disable 802.11r on the SSID and after that, RADIUS authentication worked instantly!

 

Also, it worked with the default Framed-MTU of 994 bytes communicated by the FortiAuthenticator in the Access-Accept. 

 

View solution in original post

10 REPLIES 10
AEK

AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors