Created on
09-05-2024
10:28 AM
Edited on
01-15-2026
10:01 PM
By
Jean-Philippe_P
| Description | This article describes why a FortiAP-E series machine goes offline during an HA Failover. |
| Scope | FortiAP E series. |
| Solution |
In a FortiGate in HA acting as a wireless controller, each AP establishes a CAPWAP tunnel to the primary FortiGate and another CAPWAP tunnel to the secondary FortiGate with the intention that if there is a failover on the FortiGate, the FortiAPs are immediately online on the secondary FortiGate.
This can be seen with the next FortiAP command:
cw_diag -c ha wcha_mode: FGCP @236126 ACS-0: 192.168.254.99:5246 192.168.254.99:5247 RUN(218542) 53 HA M 5248 FGT60ETK20024394 218542 FGT_Primario-1: 192.168.254.99: <- FortiGate primary. ================================================================================
This feature is described in this document: CAPWAP hitless failover using FGCP.
FortiAP E series does not have this feature, so when there is an HA event, the CAPWAP tunnel will remain offline with the secondary FortiGate until the AP renegotiates the CAPWAP tunnel with the new FortiGate.
In the 'cw_diag -c ha' command output, only one CAPWAP tunnel is established for FortiAP E series:
cw_diag -c ha ================================================================================ Current AC: 192.168.254.99:5246 pri 1 <- Only one CAPWAP tunnel.
WC fast failover AC mode : 0
Discovered AC list: ================================================================================ |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.