Description
Solution
This article describes the steps to disable DTLS encryption in communication between FortiGate controller and FortiAP.
Solution
To disable DTLS encryption (enabled by default):
On the FortiGate:
diag wireless wlac plain-ctl <wtp-id> 1
replace <wtp-id> with the appropriate wtp id, which should be the serial number of the FortiAP.
On the FortiAP:
cw_diag plain-ctl 1
It should be noted that the above setting is for temporary diagnostic purpose only, and will not be saved as part of the configuration. If the FortiAP or AC are rebooted they will go back to DTLS based control channel.
On the FortiGate:
diag wireless wlac plain-ctl <wtp-id> 1
replace <wtp-id> with the appropriate wtp id, which should be the serial number of the FortiAP.
On the FortiAP:
cw_diag plain-ctl 1
It should be noted that the above setting is for temporary diagnostic purpose only, and will not be saved as part of the configuration. If the FortiAP or AC are rebooted they will go back to DTLS based control channel.