| Description | This article describes the FortiAP DNS discovery method. |
| Scope | FortiAP v7.4.X and beyond |
| Solution |
By default, the FortiAP discovery method is set to auto, which causes the FortiAP to try all discovery methods in sequence until it finds a wireless controller.
Discovery methods=static, DHCP, DNS, FortiAP-Cloud, multicast, and broadcast
When FortiAP is turned on, FortiAP can use a DNS query to find a wireless controller. After v7.4, it will attempt to resolve the DNS of fortinet-capwap-controller.yourdomain
In this example, FortiAP will get a domain name mylab.lab.
With the 'cw_diag -c wtp-cfg' command on FortiAP, the discovery process can be seen (wcfg command gives the same info). In this case, FortiAP is still in the discovery cycle, and trying with DHCP method
Once FortiAP starts the DNS method, it will try to get a DNS resolution for fortinet-capwap-controller.mylab.lab In this example, the DNS is answering that fortinet-capwap-controller.mylab.lab is the IP address 192.168.10.254
With the 'cw_diag -c wtp-cfg' command again, FortiAP can show fsm-state (CAPWAP connection state), ac-ip-addr (wireless LAN controller IP), and the discovery method used to get a Wireless Controller. In this case, DNS
In v7.2 and earlier, FortiAP will try to find dns record _capwap-control._udp.example.com. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.