03-02-2021 07:15 PM
AP650s, using ExtremeCloud IQ. I have MAC authentication on one SSID, using one of the AP650s as RADIUS. One iPhone user is having trouble connecting, even though I’ve entered her MAC address in the user base and she says she’s entering the password correctly (there’s a pre-shared key so that the SSID isn’t open, and then MAC authentication takes over).
So, it should work, but isn’t, and I want to look at authentication logs to see if I can find errors relating to that MAC address - something like “xx:xx:xx:xx:xx:xx tried to authenticate and failed.” But, I don’t see anything like that in the logs that I can see (at Manage/Events and Manage/Tools). Am I looking in the wrong place?
Solved! Go to Solution.
03-02-2021 08:55 PM
Figured it out! It’s Apple #&$^&%^ Private MAC address. See https://support.apple.com/en-us/HT211227 for details. By default, the iPhone sends a fake MAC to each AP it connects to, so doing MAC authentication by the real one won’t work. You can turn it off per SSID. Once we did that, she connected.
03-02-2021 07:24 PM
Click on the AP and on the left you can see under monitor “event”.
03-02-2021 07:18 PM
I’d recommend setting up a client monitor for that device so you can start collecting the authentication logs. The client monitor should tell us what step of the authentication process is failing, which will tell us where to troubleshoot. This guide reviews how to set up a client monitor in ExtremeCloud IQ: https://extremeportal.force.com/ExtrArticleDetail?an=000056843&q
If you’d like help reading the results, please feel free to email an export of the client monitor to me at community@extremenetworks.com so I can take a look for you.