FortiAP devices are thin wireless access points (AP) supporting the latest Wi-Fi technologies (multi-user MIMO 802.11ac Wave 1 and Wave 2, 4x4), as well as 802.11n, 802.11AX , and the demand for plug and play deployment.
This article describes the steps to disable DTLS encryption in communication between FortiGate controller and FortiAP.
To disable DTLS encryption (enabled by default):
On the FortiGate:
diag wireless wlac plain-ctl <wtp-id> 1
replace <wtp-id> with the appropriate wtp id, which should be the serial number of the FortiAP.
On the FortiAP:
cw_diag plain-ctl 1
It should be noted that the above setting is for temporary diagnostic purpose only, and will not be saved as part of the configuration. If the FortiAP or AC are rebooted they will go back to DTLS based control channel.