Skip to main content
lovejit
New Member
May 7, 2018
Solved

I have 7 Forti APs connected in Tunnel Mode and Firewall is controller ....

  • May 7, 2018
  • 6 replies
  • 9231 views

Hello Guys,

 

I have some questions , I am doing vlan Design and add on wireless vlan where i can untagg my FortAPs .

My confusion is that FortiAPs are using CAPWAP tunnel to reach Firewall , so does seperate vlan for these Aps make any difference or not.

 

My target seperate wireless traffic from regular traffic.

 

Other thing, In tunnel mode I got option to set DHCP scope on Firewall but how i can add other server as a DHCp server ?

 

Thanks

Best answer by Toshi_Esumi

There are two VLANs you're talking about. One for AP connection, another for SSIDs. If you don't set a VLAN for AP, AP will be on the same non-tagged interface on the physical interface. It might be a member of hard/soft-switch. If you want to separate AP connection subnet from them, you have to use a vlan.

 

The tunnel mode you're talking about is for SSIDs. If you want to use an outside DHCP server, you need either DHCP server relay or a vlan spanned through your L2 network fabric. In this case, you need to use vlan on an SSID. It takes some good network designing if you want to use both as independent DHCP servers for separate sets of broadcast domains.

 

Also make sure your FG supports 7 APs and enough SSIDs especially tunnel mode. There are limitations per model.

6 replies

Toshi_Esumi
SuperUser
SuperUser
May 7, 2018

There are two VLANs you're talking about. One for AP connection, another for SSIDs. If you don't set a VLAN for AP, AP will be on the same non-tagged interface on the physical interface. It might be a member of hard/soft-switch. If you want to separate AP connection subnet from them, you have to use a vlan.

 

The tunnel mode you're talking about is for SSIDs. If you want to use an outside DHCP server, you need either DHCP server relay or a vlan spanned through your L2 network fabric. In this case, you need to use vlan on an SSID. It takes some good network designing if you want to use both as independent DHCP servers for separate sets of broadcast domains.

 

Also make sure your FG supports 7 APs and enough SSIDs especially tunnel mode. There are limitations per model.

lovejit
lovejitAuthor
New Member
May 7, 2018

hello Toshi,

 

Yeah, I have single  vlan for Wireless (Acesspoints + Staff SSID ), I am going to use two SSIDs , Guest and staff. For Guest SSID,  I will use tunnell mode and set the DHCP scope  on Firewall.

 

For staff SSID, I want to use Same wireless vlan and setup Relay mode and provide DHCP server Address. my concern is just see the IP/Network mask option in SSID not vlan. How to corelate SSID with specific vlan.

 

Thanks

Toshi_Esumi
SuperUser
SuperUser
May 7, 2018

By the way, I haven't this type of setting so you should test yourself to make sure it works, unless somebody else who's using this feature already chimes in with "yea" or "nay".

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!