How To Reset a FortiAP FAP-234F-A to Factory Defaults
Hello Everyone:
We need to reset an FAP-234F-A to factory defaults because we don't have the admin password.
Here are the details:
1. We have the unit connected to a FortiGate 40F, which has the default IP address of 192.168.1.99 for now while we set things up. The FAP-234F-A is set to 192.168.1.2 and we can ping it and browse to the GUI.
2. The QuickStart Guide for this unit says that it comes with a special POE injector that has a reset button on it because the AP doesn't. Probably because it's a ruggedized outdoor unit and having a reset button would compromise the ruggedness. The model number of the PO injector that shows in the QSG is EPA5006GPR-4P. It's made by EnGenius, but the only one they have is the EPA5006GR, so we bought that one. It has a reset button on it but pressing it for more than 10 seconds doesn't reset the AP to factory defaults. It does nothing. Probably because it's slightly different than the EPA5006GPR-4P and the pinout is different. Here is a link to the unit: https://store.engeniustech.com/products/epa5006gr?variant=48010898735420
3. We can connect to the AP via the console. Our understanding is that if we install/replace the firmware during boot, it will reset the unit to factory defaults. We have downloaded firmware for it and gone through the whole process several times, but still can't login to the unit. We'll paste the CLI text in hopes that someone can spot something there that is preventing the unit from accepting the new firmware. There are probably errors there that explain why the unit is not accepting the firmware replacement, but we don't know enough to understand what we're looking at.
4. We found the article below and it's exactly what we're going through. We read the articles suggested by the Fortinet staff member that replied to the post a couple of times, but they don't look like they will work just like they didn't work for the person that added that post. Link: https://community.fortinet.com/t5/Support-Forum/Factory-reset-FortiAP-222E/m-p/213157
Thanks in advance.
===
U-Boot 2016.01-svn152333 (Sep 01 2022 - 18:06:00 +0000)
DRAM: smem ram ptable found: ver: 2 len: 4
1 GiB
NAND: ONFI device found
ID = 1190acc2
Vendor = c2
Device = ac
qpic_nand: changing oobsize to 80 from 128 bytes
ipq_spi: page_size: 0x100, sector_size: 0x10000, size: 0x800000
520 MiB
MMC: sdhci: Node Not found, skipping initialization
Flash: 8 MiB
Ver:04000003
Serial number: FP234FTF23025865
Region code: A
PCI0 is not defined in the device tree
In: serial@78B1000
Out: serial@78B1000
Err: serial@78B1000
machid: 8030200
To boot Kernel image at active partition rootfs
Net: MAC0 addr:80:80:2c:e2:0c:40
PHY ID1: 0x4d
PHY ID2: 0xd0b2
eth0
Hit any key to stop autoboot: 5
[G]: Get OS image from TFTP server.
[Q]: Quit menu and continue to boot with default OS.
[S]: Switch partitions. current active partition is rootfs
[H]: Display this list of options.
Enter G,Q,S or H:
Enter TFTP server address [192.168.1.254]:
Enter local address [192.168.1.2]:
Enter firmware image file name [image.out]:
eth0 PHY0 Down Speed :10 Half duplex
eth0 PHY1 Down Speed :10 Half duplex
eth0 PHY2 up Speed :1000 Full duplex
eth0 PHY3 Down Speed :10 Half duplex
eth0 PHY4 Down Speed :10 Half duplex
Please connect TFTP server to Ethernet port 'LAN1'.
Using eth0 device
TFTP from server 192.168.1.254; our IP address is 192.168.1.2
Filename 'image.out'.
Load address: 0x41000000
Loading: *
Got TFTP_OACK: TFTP remote port: changes from 69 to 65068
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
#################################################################
###########################################################
3.9 MiB/s
done
Bytes transferred = 31388351 (1def2bf hex)
unzipped : 33426996(0x01fe0e34)
Save as Default firmware[D]?D
Programming the boot device now.
## Executing script at 44000000
crc32+ Flashing ubi: [ done ] 0
ubi0: attaching mtd2
ubi0: scanning is finished
ubi0: volume 3 ("rootfs_data") re-sized from 1 to 657 LEBs
ubi0: attached mtd2 (name "mtd=0", size 128 MiB)
ubi0: PEB size: 131072 bytes (128 KiB), LEB size: 126976 bytes
ubi0: min./max. I/O unit sizes: 2048/2048, sub-page size 2048
ubi0: VID header offset: 2048 (aligned 2048), data offset: 4096
ubi0: good PEBs: 1024, bad PEBs: 0, corrupted PEBs: 0
ubi0: user volume: 4, internal volumes: 1, max. volumes count: 128
ubi0: max/mean erase counter: 1/0, WL threshold: 4096, image sequence number: 899233225
ubi0: available PEBs: 0, total reserved PEBs: 1024, PEBs reserved for bad PEB handling: 80
Read 0 bytes from volume kernel to 44000000
No size specified -> Using max size (4821140)
## Loading kernel from FIT Image at 44000000 ...
Using 'config@cp03-c1' configuration
Trying 'kernel@1' kernel subimage
Description: ARM OpenWrt Linux-4.4.60
Type: Kernel Image
Compression: gzip compressed
Data Start: 0x440000e4
Data Size: 4117942 Bytes = 3.9 MiB
Architecture: ARM
OS: Linux
Load Address: 0x41208000
Entry Point: 0x41208000
Hash algo: crc32
Hash value: 213ba820
Hash algo: sha1
Hash value: 89b3b92fb111e7be7532972236ab68977c6f0a55
Verifying Hash Integrity ... crc32+ sha1+ OK
## Loading fdt from FIT Image at 44000000 ...
Using 'config@cp03-c1' configuration
Trying 'fdt@cp03-c1' fdt subimage
Description: ARM OpenWrt qcom-ipq60xx-cpxx device tree blob
Type: Flat Device Tree
Compression: uncompressed
Data Start: 0x44488010
Data Size: 67057 Bytes = 65.5 KiB
Architecture: ARM
Hash algo: crc32
Hash value: 726714b3
Hash algo: sha1
Hash value: c7f9658846f4599e93a2b0678a5350d5fec24839
Verifying Hash Integrity ... crc32+ sha1+ OK
Booting using the fdt blob at 0x44488010
Uncompressing Kernel Image ... OK
Loading Device Tree to 484ec000, end 484ff5f0 ... OK
Could not find PCI in device tree
Using machid 0x8030200 from environment
Starting kernel ...
[ 0.257881] <CORE> glink_core_register_transport: IPC Logging disabled
[ 0.257956] msm_glink_smem_native_xprt rx fifo not found
[ 0.258259] <CORE> glink_core_register_transport: IPC Logging disabled
[ 0.834424] mtdsplit: no squashfs found in "rootfs"
[ 1.260536] DEV CI test message
[ 3.784387] msm-usb-ssphy-qmp 78000.ssphy: QMP PHY initialization timeout
[ 3.784411] msm-usb-ssphy-qmp 78000.ssphy: USB3_PHY_PCS_STATUS:68686868
65536+0 records in
65536+0 records out
65536 bytes (64.0KB) copied, 0.182939 seconds, 349.8KB/s
2116+0 records in
2116+0 records out
2116 bytes (2.1KB) copied, 0.006312 seconds, 327.4KB/s
[ 7.427254] ubi: mtd19 is already attached to ubi0
[ 9.898996] Supported Frequencies -
[ 9.899013] 187.2 MHz 748.8 MHz
[ 9.956320] 1.4976 GHz [ 9.967764]
[ 9.995092] 7f6fe180: NSS core 0 DDR from 40000000 to 41000000
[ 10.049240] Invalid macid 6
[ 10.068327] diag: IPC Logging disabled
qcawifi configuration is disable
*****starting cnssdaemon*****
*********initiating cold boot calibration*************
*****cnssdaemon pid=1060*********
[ 18.879206] diag: In diag_send_feature_mask_update, control channel is not open, p: 2, 7f8cb3c4
Found unused ubi device: /dev/ubi1
qcawifi qcawificfg80211 disable radio wifi0
qcawifi qcawificfg80211 disable radio wifi1
qcawifi qcawificfg80211 disable radio wifi2
qcawifi qcawificfg80211 disable radio wifi0
qcawifi qcawificfg80211 disable radio wifi1
qcawifi qcawificfg80211 disable radio wifi2
*****Registers configuration for qdss_tracing completed*******
******Starting cnss_cli********
FortiAP-234F login:
process '/usr/sbin/lldpd' (pid 2649) exited. Scheduling for restart.
[ 38.247442]
[ 38.264686]
FortiAP-234F login: admin
Password:
Login incorrect
FortiAP-234F login: