Why is there no traffic data in syslog when a client roams between APs?

Zyxel_Bella
Zyxel_Bella Posts: 558  Zyxel Employee
Zyxel Certified Network Engineer Level 2 - Switch Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch 50 Answers

In scenarios where you are using syslog to analyze AP and station use, you might observe instances where there is no traffic shown in the logs despite the station being connected.

Here are some key points to understand the behavior:

1. Syslog simply forwards event logs. If an event (like a client disconnection) occurs without recorded traffic, it is likely because the client left before any traffic reached the AP's interface.

2. The logs might display zero traffic data if the variables capturing traffic data are not updated promptly. This is due to the fast transition of station between APs during roaming.

3. Different log updates occur at different times. For example, STA Tx (transmit) and Rx (receive) are updated upon receiving STA management frames. If roaming happens too quickly, the AP may miss these frames, leading to zero traffic logs.

To better capture traffic data, consider monitoring client connections for a longer period.