Skip to main content
magarwal
Staff
Staff
September 9, 2022

Technical Tip: Manage a FortiAP with FortiGate

  • September 9, 2022
  • 0 replies
  • 11628 views
Description

This article describes how to get a FortiAP online on the FortiGate (Wireless-Controller).

FortiAP is connected to FortiGate through a FortiLink Managed FortiSwitch.

Scope FortiAP v6.x or above and FortiGate v6.4.x or above.
Solution

The following steps describe how to bring up a FortiAP online on the FortiGate:

 

1) Plug the FortiAP into a FortiLink Managed FortiSwitch port (PoE switchport).

 

2) Create a new FortiSwitch VLAN (from which the FortiAP will receive an IP address from that FortiSwitch VLAN DHCP Server) on FortiGate:

 

Go to WiFi & Switch controller > FortiSwitch VLANs > Create New:

 

magarwal_33-1662733389102.png

 

3) Enable CAPWAP 'Security-Fabric' and DHCP Server in the VLAN (FortiAP managed VLAN). Also, set 'Wireless-Controller' to 'Same as Interface IP':

 

Note: SSH and ping can also be enabled – these are optional settings.

 

magarwal_34-1662733414216.png

 

magarwal_35-1662733429358.png

 

4) Map the VLAN under 'Native-VLAN' on the FortiAP uplink switchport.

Afterwards, FortiAP should obtain an IP address from this Native VLAN:

 

Navigate to WiFi & Switch controller > FortiSwitch Ports > Select Ports on the top right corner of the screen and map this VLAN on the FortiAP uplink switchport:

 

magarwal_36-1662733464234.png

 

5) FortiAP will discover the FortiGate and appear in 'WiFi & Switch Controller' > 'Managed FortiAPs'. Thereafter, right-click the FortiAP Entry and 'Authorize' the FortiAP.

Then FortiAP should show up as 'Online' on FortiGate:

 
magarwal_37-1662733495602.png

 

magarwal_38-1662733508786.png

 

6) The FortiAP will be automatically mapped to a default FortiAP profile. Create a new FortiAP profile with your local correct country code to activate the FortiAP radios.

 

Refer this link for instructions: https://docs.fortinet.com/document/fortiap/6.4.6/fortiwifi-and-fortiap-configuration-guide/140799/creating-a-fortiap-profile

 

Note: To enable FortiAP-C compatibility (disabled by default) on the FortiGate:

 

# config wireless-controller setting
set fapc-compatibility enable
end

 

7) The above steps remain the same for the other FAP models (FortiAP, FortiAP-W2, FortiAP-C, FortiAP-U and FortiAP-S).

 

Reference links:

 

a) FortiAP and FortiOS 6.x and FortiOS 7.x firmware compatibility matrix links are available below:

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/b7a1ac06-4ead-11ea-9384-00505692583a/FAP-FOS_6.x_Firmware_Compatibility_Matrix.pdf

 

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/c403e9ae-b78e-11ec-9fd1-fa163e15d75b/FAP-FOS_7.x_Firmware_Compatibility_Matrix.pdf

 

b) FortiWiFi and FortiAP 6.4.x Configuration Guide link below:

 

https://docs.fortinet.com/document/fortiap/6.4.6/fortiwifi-and-fortiap-configuration-guide/13665/whats-new-in-this-release

 

c) Manage FortiSwitch with FortiGate v6.2.x: 

https://www.youtube.com/watch?v=1vIL8w55Nac

 

 

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!