Skip to main content
AnthonyH
Staff
Staff
December 13, 2024

Technical Tip: Unable to enable VLAN pooling in SSID when security mode is set to WPA3-SAE from the GUI

  • December 13, 2024
  • 0 replies
  • 454 views
Description The article describes an issue when the security mode in the SSID is set the WPA3-SAE, the VLAN pooling option cannot be enabled from the GUI.
Scope FortiGate v7.6.0, FortiAP.
Solution

In some cases, when the SSID under WiFi & Switch Controller -> SSID -> Security Mode is set the WPA3-SAE, the VLAN pooling is unavailable to enable from the GUI.

 

WPA3-SAE.PNG

 

VLAN_pooling.PNG

 

Workaround:

  • Enable VLAN pooling from the CLI.

FortiGate # config wireless-controller vap


FortiGate (vap) # edit "WPA3-SAE"


FortiGate (WPA3-SAE) # set vlan-pooling
wtp-group Enable VLAN pooling with VLAN assignment by wtp-group.
round-robin Enable VLAN pooling with round-robin VLAN assignment.
hash Enable VLAN pooling with hash-based VLAN assignment.
disable Disable VLAN pooling.

 

VLAN pooling can be enabled from the GUI after upgrading the FortiGate to v7.6.1.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.