Created on
11-25-2025
09:13 AM
Edited on
01-13-2026
10:04 PM
By
Jean-Philippe_P
| Description | This article describes a scenario where a FortiAP 231C running FortiAP firmware v6.0.4 and managed by a FortiGate 900D on FortiOS v7.2.8 may fail to initiate the 802.11 4-way handshake, preventing clients from completing the WPA2/WPA3 association process. |
| Scope | FortiOS v7.2.8, FortiAP 231C version: 6.0.4. |
| Solution |
The issue is resolved by adjusting the Data Channel Security between the FortiGate and the FortiAP to DTLS.
In FortiOS v7.2.x, the Data Channel Security parameter can operate in the following modes:
Legacy models, such as the FortiAP-C series, may exhibit compatibility issues when using Clear Text or IPsec, leading to failures in the WPA/WPA2/WPA3 key exchange process and preventing the 4-way handshake from initiating.
Note: As a workaround, try disabling CAPWAP offloading on FortiGate with older FortiAP models.
config system global |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.