05-13-2022 07:17 AM
When looking at traffic in the FMC I've noticed that I never see wi-fi clients listed. I will see an entry for the AP's IP address, but not the actual client. We have Meraki AP's, ASA with firepower module managed by FMC
Any help would be appreciated.
Solved! Go to Solution.
05-13-2022 07:36 AM
Hi
The only explanation I see would be if the client traffic is tunneled or if you have a different gateway on the network.
05-13-2022 07:36 AM
Hi
The only explanation I see would be if the client traffic is tunneled or if you have a different gateway on the network.
05-13-2022 08:22 AM
Yes, that seems to be correct. Looking at it closer when using an SSID that is configured for NAT using Meraki DHCP, the client can't be seen.
Thanks
05-13-2022 07:56 AM - edited 05-13-2022 09:51 AM
There is capwap tunnel between ap and wlc,
Asa allow this tunnel,
Inisde this tunnel the traffic of wifi client is pass.
So asa not see the inner wifi cleint traffic it see outer tunnel ip.
UDP port for tunnel is
5247 5248,
Check any traffic with this udp port.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide