| Description |
This article describes additional steps and behaviors that product documentation does not cover, where there are 2 uplinks for the FortiAPs. The idea is to have the same wireless-controller (FortiGate), but the FortiAP is connected to 2 different FortiSwitches. This means that in the event of a failure, the FortiAPs will be able to connect to the controller with reduced downtime. |
| Scope | FortiAPs are managed by FortiGate. |
| Solution |
See LAN port uplink redundancy without LACP. By default, the discovery type of all FortiAPs is set to automatic. This means that they will try to be managed following the order below, until they receive a response from a wireless controller:
1(static) → 2(dhcp) → 3(dns) → 7(fortiapcloud) → 5(multicast) → 6(broadcast).
There is a possibility to enhance the recovery time for the FortiAP to become managed again on FortiGate. This is achieved by changing the discovery type to Static (1).
Following the example, configure the IP addresses as follows:
On the FortiAP CLI:
cfg -a AC_IPADDR_1=192.168.2.1
This process can be automated by FortiGate. See Technical Tip: Enhance recovery times for FortiAPs after disconnection from FortiGate so a new FortiAP can receive these configuration changes once it comes online on FortiGate at least once.
Behaviors to keep in mind:
If FortiAP already joined a FortiGate, FortiAP configuration can be done with an AP configuration profile on the FortiGate Wireless Controller module.
First, a profile needs to be created (FortiGate commands)
config wireless-controller apcfg-profile edit 3
Once 'apcfg-profile' has been created, it can be assigned to one AP profile.
config wireless-controller wtp-profile end
With 'cfg -s' command on FortiAP, the configuration can be validated.
FP231ETF19001958 # cfg -s 2rguBHCVBxMOR84wdqEeWOS5suVO6LuTlc6zBbf4+4Zc4aZ/Ncw2wswlhjDqdV3mZQMLL0VnyWXwt6 rEvf2yEq1BzJ2be24Q9EiNXa1eBDkIsrz3jTDPF/LUPr3pKAbKUwhwg== |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.