Disconnections on a WPA2-Enterprise SSID
Probably the most bizarre IT problem I've ever come across.
We are in the process of migrating from Aruba to Fortinet, wired and wireless. One building has now been completely moved to FortiAPs and since day one we've been experiencing random disconnections from our WPA2-Enterprise SSID.
The initial symptoms were these: out of the blue, without moving, a device would lose internet connection, showing the 'globe' in the bottom right corner (Windows), claiming to still be connected to the network, but with no internet and with an auto-assigned APIPA address.
Having done A LOT of investigation, most of the time with little to no result, I have noticed that clients are very frequently re-associating (often with the same AP), sometimes failing (hence the 'disconnections'). The signal is high, APs are generally a few feet away, it happens on both 2.4 and 5Ghz.
We have done a lot of tweaking, including changes recommended by Fortinet Support, which included disabling fast roaming, PMF, adjusting APs power levels, removing frequency and AP hand-offs, changing to WPA3-Enterprise, etc. Nothing has helped in any meaningful way.
Weirdly, I am able to fairly consistently trigger the disconnections if I initiate a file transfer from my laptop to a remote server. The connection first becomes unstable, then it drops after a few minutes/seconds. Even more weird is that sometimes if I initiate a file transfer from my laptop, another laptop connected to the same AP gets disconnected.
All the devices seem to be using variations of Intel cards, like the AX201 and the AX211. Tried to use an external TP-Link USB adaptor and the file transfers went smoothly.
We are using mainly 231K units, but the problem also happens on the 441K. Firmware, tried both 7.4 and 7.6, no change.
It feels like it's got something to do with EAP-TLS (we use computer certificates).
I am at a loss, because we've had to stop our FortiAP deployment since the issue has never happened on the Aruba ones.
