Skip to main content
Contributor
September 14, 2011
Question

Fast Roaming and AP hopping problems for VOIP and data in a FGT200B HA & FortiAP 220B infrastructure

  • September 14, 2011
  • 7 replies
  • 14166 views
Hi, we have in our building a FGT200B HA active-active configuration with 4 FortiAP220B on PSK (WPA/WPA2 and AES) for the VOIP WLAN. Furthermore we have also a data VLAN with WPA/WPA2 Enterprise and AES running. Both WLANs are configured on radio 1 the rogue scanning is configured on radio 2. At radio 1 also additional the radio resource provision is activated. For the Band 802.11n we enabled the channels 1, 6 and 11. Now we are observing a very instable network, where we see an AP hopping of the VOIP Clients (CISCO Phones and Blackberry) as well also on the laptops. (We see the quality indication is hopping from very good to pure and back again). How can we trace the problem? Do anyone have the same problem? Thanks. Stefan. PS: AP FW: FAP22B-v4.0-build214 FGT FW: v4.0,build0458,110627 (MR3 Patch 1)

    7 replies

    yzhang_FTNT
    Staff
    Staff
    September 14, 2011
    Was the AP' s channel changed by the radio resource provision very often? You can check the operationing channel from Managed FortiAP page. Is the connection between AP and the FGT stable? AP join time can also be checked from Managed FortiAP page. have you tried to disable the radio resource provision to see if the problem is gone?
    FortiRack_Eric
    New Member
    September 15, 2011
    Furthermore which version are you running on the FG? I hope 4.2.7 AP version on the cluster and the latest AP firmware 4.3.1 Regards, Eric
    Contributor
    September 15, 2011
    Hi, thanks for your hints. The connection to the FGT AP is stable. Also there is no high dynamic channel switching. It seems to me very stable. We are using AP FW: FAP22B-v4.0-build214 FGT FW: v4.0,build0458,110627 (MR3 Patch 1) because we had a lot of troubles with the 4.2.x and UTM scanning/policies in the HA setup. Thanks a lot. Stefan.
    yzhang_FTNT
    Staff
    Staff
    September 15, 2011
    We see the quality indication is hopping from very good to pure and back again
    Did you see this problem on all your 4 FAPs? Was the mobile device moving when you saw this? The internal antenna used in FAP are directional antenna.
    Contributor
    September 15, 2011
    yes, I see this on all 4 FAPs. Testing was done: Laptop and Blackberry Client localized at one location. The signal quality is hopping from good to bad (hopping between two FAPs). Additional the reconnecting during roaming takes a long time. Is there a possibility to trace this hopping and the reasons for this at the CLI, either of the FAP or of the FGT. Thanks. As following you will see a snapshot of one client - Logs out of Fortimanager. As you see there is no principle hopping but a running reauth. 850 2011-09-15 15:15:00 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 851 2011-09-15 15:15:00 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 854 2011-09-15 15:14:51 notice wireless client-denial Client <mac-address> denied. 855 2011-09-15 15:14:50 notice wireless client-denial Client <mac-address> denied. 904 2011-09-15 15:08:55 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 905 2011-09-15 15:08:55 notice wireless oper-channel AP WLAN_AP2 radio 1 operating channel 6 ==> 1. 906 2011-09-15 15:08:54 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 907 2011-09-15 15:08:54 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 908 2011-09-15 15:08:53 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 932 2011-09-15 15:06:22 notice wireless client-denial Client <mac-address> denied. 933 2011-09-15 15:06:18 notice wireless client-denial Client <mac-address> denied. 935 2011-09-15 15:06:14 notice wireless client-denial Client <mac-address> denied. 950 2011-09-15 15:04:56 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 951 2011-09-15 15:04:55 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 952 2011-09-15 15:04:55 notice wireless client-denial Client <mac-address> denied. 988 2011-09-15 14:59:51 notice wireless client-ip-detected Client<mac-address> assigned an IP address. 989 2011-09-15 14:59:51 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 990 2011-09-15 14:59:50 notice wireless client-denial Client <mac-address> denied. In this case it is a laptop. But the same phenomena we can observe of CISCO VOIP Phones and BB Handhelds. We can see this behavior as well at WPA/WPA2-Personal and WPA/WPA2-Enterprise.
    yzhang_FTNT
    Staff
    Staff
    September 15, 2011
    could you check the scan setting on the FAP using " cw_diag -c radio-cfg" ? Make sure the sta scan is not enabled on the radio which provides the wlan service. There is a sta scan related bug (which is called Rogue AP on-wire scan in the controller GUI) in FAP 214 build.
    Contributor
    September 15, 2011
    Hi, perhaps a simple question. How can I reach the AP in the connected Authorized status, because I cannot use the telnet session anymore - it seems to be deactivated by the WLAN Controller (FGT200B). Thanks. stefan.
    yzhang_FTNT
    Staff
    Staff
    September 15, 2011
    For security reason, the telnet daemon will be turned down after a FAP is connected to the controller. It can be enabled from the controller cli: FWF60C3G10000698 # con wireless-controller wtp FWF60C3G10000698 (wtp) # edit FAP22B3U11004887 FWF60C3G10000698 (FAP22B3U11004887) # set login-enable enable FWF60C3G10000698 (FAP22B3U11004887) # end
    Contributor
    September 15, 2011
    Hi, you are right the sta scan is enabled. This means I have to deactivate it at each AP. Can you give me a hint for the deactivation CLI. Radio 0: AP radio type : 11N_2.4G beacon intv : 100 tx power : 27 HT mcs : 15 HT gi : 0 HT bw : 0 channel : 0 auto_chan : 1 chan list : 1, 6, 11, ap scan : background regular scan ap scan passive: disabled ap scan period : 300s ap scan intv : 1s ap scan dur : 20ms ap scan idle : 0ms ap scan rpt tmr: 30s sta scan : enabled darrp : enabled darrp wait : 3 darrp_chan : 1 Radio 1: Monitor ap scan rpt tmr: 15s Radio 2: Disabled
    yzhang_FTNT
    Staff
    Staff
    September 15, 2011
    You can try a the latest 219 FAP release. It should be ok even sta scan is enabled. Or You can go back to the controller GUI ap-profile configuration page, enable the background scan, disable the on-wire scan, (maybe need a save here). Then disable the background scan. Enable " radio resource provision" will automatic enable " background scan" on the FAP, since it needs the surrounding RF data to make the channel selection.
    Contributor
    September 15, 2011
    ok. Where can I find the 219 release? On the FTP I can see only the 214 release.
    yzhang_FTNT
    Staff
    Staff
    September 15, 2011
    It will be released with FGT 4.3.2. At this time, I think you only can disable it from the controller side
    Contributor
    September 15, 2011
    okay. I configured the Manager in your suggested way and we will test it tomorrow. Thanks a lot for your help. Stefan.
    Contributor
    September 17, 2011
    Hi, the connections are much more stable - thanks all of you for your help. Stefan.