Created on 10-28-2020 03:23 AM Edited on 04-07-2022 12:44 PM By Anonymous
Description
Upon upgrading to FortiOS 6.4.3, configurations with a FortiAP managed through a VLAN interface may have issues with passing CAPWAP traffic from the FortiGate to the FortiAP.
CAPWAP traffic that is offloaded to the NP6 and NP6XLite ASICs will be dropped for tunneled SSIDs.
If the FortiAP is managed by a FortiGate through a non-VLAN interface, then this issue is not encountered.
Scope
For Version 6.4.3.
Solution
Workaround.
Disable CAPWAP session offloading.
By default, managed FortiAP and FortiLink CAPWAP sessions are offloaded to the NP6 or NP6XLite ASICs.
Use the following command to disable CAWAP session offloading:
# config system npu
set capwap-offload disable
end
Note: Disabling the CAPWAP offload may cause high CPU usage, monitor the CPU usage will need to be monitored after the change
Resolution.
Fortinet has resolved the issue in the upcoming FortiOS 6.4.4.
Contact Fortinet Technical Support to request a special build hot fix for an interim solution for use until FortiOS 6.4.4 is available.
Technical Support Contact Information: http://www.fortinet.com/support/contact_support.html
Fortinet technical support home page: https://support.fortinet.com
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.