Remote AP's Bridge to SSID Issues
Hi All
I have been battling this issue for a few months now, and so far have not had any joy (Even from Fortinet Support)
Basically we have a client with a 200B HA cluster at their data-center. Said client then has several small remote branches (2 to 3 devices max) which make use of FortiAP 14C's to connect to the corporate network.
Essentially each remote site has it's own unique SSID and IP range. The AP/AP Profile is then set to bride the 14c LAN ports to the SSID - This allows desktops, phones etc to access the corporate network as well as internet breakout via the Datacenter with various policies and UTM features applied.
The 14C's are connected to an ADSL router and have the controller (Fortigate) public IP statically set in the AC discovery.
So... The above works amazingly well... When it works...
The problem we have is that out of the blue, devices at the remote sites loose connection to the corporate network and internet. Internally (At the remote sites) devices can still talk to each other - For example, a user can still print to a network printer. Basically all comms out of the remote site stop.
When this happens, the FortiAP is still online. I can even see it as well as the devices connected to it on the Fortigate. There are no error logs that I can see.
After loads of backwards and forwardsing with Fortinet, we were advised to upgrade the Fortigate to v5.2.4 and the AP's (Downgraded) to 5.0.10. We did this and had no issues for about a week... Now the problem is back.
Now for the extra strange part. Sometimes a reboot of the AP gets the site back up. Sometimes not. Most times, if I override the AP profile with the exact same settings, the site comes back online. Sometimes this is done in reverse and again the site comes back online.
Another odd thing here is that DNS seems to stay working. When doing a diag debug flow on the Fortigate, DNS traffic still goes through - This was confirmed by trying to ping devices on the corporate network - While they did not reply to pings, DNS did resolve.
I have completely run out of ideas, and our client is of course a sad panda... We have replaced several of the AP's as well as they were initially thought to be faulty.
Any advise would be greatly appreciated!
Regards
