cancel
Showing results for 
Search instead for 
Did you mean: 

Monitoring authentication events

Monitoring authentication events

HHRINetwork
New Contributor II

AP650s, using ExtremeCloud IQ.  I have MAC authentication on one SSID, using one of the AP650s as RADIUS.  One iPhone user is having trouble connecting, even though I’ve entered her MAC address in the user base and she says she’s entering the password correctly (there’s a pre-shared key so that the SSID isn’t open, and then MAC authentication takes over).

So, it should work, but isn’t, and I want to look at authentication logs to see if I can find errors relating to that MAC address - something like “xx:xx:xx:xx:xx:xx tried to authenticate and failed.”  But, I don’t see anything like that in the logs that I can see (at Manage/Events and Manage/Tools).  Am I looking in the wrong place?

1 ACCEPTED SOLUTION

HHRINetwork
New Contributor II

Figured it out!  It’s Apple #&$^&%^ Private MAC address.  See https://support.apple.com/en-us/HT211227 for details.  By default, the iPhone sends a fake MAC to each AP it connects to, so doing MAC authentication by the real one won’t work.  You can turn it off per SSID.  Once we did that, she connected.

View solution in original post

6 REPLIES 6

HHRINetwork
New Contributor II

Figured it out!  It’s Apple #&$^&%^ Private MAC address.  See https://support.apple.com/en-us/HT211227 for details.  By default, the iPhone sends a fake MAC to each AP it connects to, so doing MAC authentication by the real one won’t work.  You can turn it off per SSID.  Once we did that, she connected.

HHRINetwork
New Contributor II

Only one AP on her floor, no other devices handy, but I had her connect to the guest network and found that her iPhone reported a different MAC address. 

Of course, once I put that into the user base, it still failed.  Kind of stuck now, but when I’m in the office later this week I’ll try again.

SamPirok
Community Manager Community Manager
Community Manager

That’s what it sounds like to me too. Are there any near by APs she could be roaming to that we could try to see with a client monitor? Also, does she have any other devices she can try to connect with to see if it’s an issue isolated to one device or not?

HHRINetwork
New Contributor II

Thanks for the quick replies.  So, I set up a client monitor for her MAC address on the one AP that she would connect to.  Told her to connect, she tried and it failed - but the monitor picked up nothing at all. 

I’m working from home, so not looking over her shoulder, so I can’t guarantee she’s doing what she says she is.  But she’s generally a smart user.   But that sure sounds like she’s not even trying to connect to the right AP, right?

GTM-P2G8KFN