Skip to main content
THL
New Member
May 12, 2015
Solved

Add more than 5 FortiAP

  • May 12, 2015
  • 5 replies
  • 5896 views

Hello,

 

I have a Fortigate 60C and 7 FortiAP. I know i can't add all my AP to the Fortigate in normal mode.

 

I read this http://kb.fortinet.com/kb/documentLink.do?externalID=FD36164

But what i don't understand is what involve the bridge mode ?

 

Is there a way to add two differents SSID to an AP, one in bridge mode and the other in normal ?

 

Thanks

    Best answer by Jeroen

    THL wrote:

    OK, i have my vlan and my two SSID.

    I activate Captive portal on the Vlan interface but how do i know this portal is for my guest SSID ?

    You can select the user group when you activated Captive portal. After that you can configure a new SSID with the vlan number that you gave to your vlan. If the switch is configured correctly than you can login to the new configured SSID and than you should get the Captive portal you configured on the interface. Don't forget to create new policy's for the new VLAN.

    5 replies

    Jeroen
    New Member
    May 12, 2015

    Hello THL,

     

    It is possible to add one SSID in bridge mode and the other one in normal mode. But this doesn't solve your problem with the limit. Because when the mixed mode is active the lowest amount of possible AP is selected in your case normal mode.

     

    When you putt everything in bridge mode then you can register more then 5 AP. Bridge mode is simply a local break out to a VLAN. So the traffic doesn't directly travel to the Fortigate unit with the use of a tunnel. But is put on a VLAN for example a office vlan or a guest vlan.

     

    What you need to do in case of bridge mode is creating the following networks:

    [ol]
  • Untagged - Management CAPWAP enabled gateway interface - This will provision your AP's
  • Tagged - (Example) Office network (local break-out)
  • Tagged - (Example) Guest network (local break-out)[/ol]

    Hope this helps you.

     

    THL wrote:

    Hello,

     

    I have a Fortigate 60C and 7 FortiAP. I know i can't add all my AP to the Fortigate in normal mode.

     

    I read this http://kb.fortinet.com/kb/documentLink.do?externalID=FD36164

    But what i don't understand is what involve the bridge mode ?

     

    Is there a way to add two differents SSID to an AP, one in bridge mode and the other in normal ?

     

    Thanks

  • THL
    THLAuthor
    New Member
    May 12, 2015

    Hello Jeroen,

     

    Thank for your answer.

    If i want to create a captive portal for my guest ? because i don't see any possibilities in local bridge mode

     

    mail@jeroenmelis.nl wrote:

    Hello THL,

     

    It is possible to add one SSID in bridge mode and the other one in normal mode. But this doesn't solve your problem with the limit. Because when the mixed mode is active the lowest amount of possible AP is selected in your case normal mode.

     

    When you putt everything in bridge mode then you can register more then 5 AP. Bridge mode is simply a local break out to a VLAN. So the traffic doesn't directly travel to the Fortigate unit with the use of a tunnel. But is put on a VLAN for example a office vlan or a guest vlan.

     

    What you need to do in case of bridge mode is creating the following networks:

    [ol]
  • Untagged - Management CAPWAP enabled gateway interface - This will provision your AP's
  • Tagged - (Example) Office network (local break-out)
  • Tagged - (Example) Guest network (local break-out)[/ol]

    Hope this helps you.

  • Jeroen
    New Member
    May 12, 2015

    You can enable a Captive portal on the vlan interface in your fortigate unit. System > Network > Interfaces > Security mode > Captive Portal

     

    THL wrote:

    Hello Jeroen,

     

    Thank for your answer.

    If i want to create a captive portal for my guest ? because i don't see any possibilities in local bridge mode

    Hallo THL,

     

    THL
    THLAuthor
    New Member
    May 12, 2015

    OK, i have my vlan and my two SSID.

    I activate Captive portal on the Vlan interface but how do i know this portal is for my guest SSID ?

     

     

    Jeroen
    JeroenAnswer
    New Member
    May 12, 2015

    THL wrote:

    OK, i have my vlan and my two SSID.

    I activate Captive portal on the Vlan interface but how do i know this portal is for my guest SSID ?

    You can select the user group when you activated Captive portal. After that you can configure a new SSID with the vlan number that you gave to your vlan. If the switch is configured correctly than you can login to the new configured SSID and than you should get the Captive portal you configured on the interface. Don't forget to create new policy's for the new VLAN.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.