Description | This article explains troubleshooting steps and possible remedied for connectivity issues WiFi clients and the FortiGate/FortiWiFi. |
Scope | FortiGate. |
Solution |
Combining WiFi network and wired LAN within a software switch is a common configuration when an administrator of a network wants to simplify the network administration (same rights of wired/wireless users, fewer policies to administer). It can be achieved as per Technical Tip: How to bridge a FortiGate WiFi network to a wired network or VLAN network.
One of the topics that needs to handled is DHCP assignment, which can be achieved by following the instructions outlined in Technical Tip: Combining WiFi network and wired LAN with a software switch for DHCP leases.
The purpose of this KB article is to give an idea what potential issues might arise and the troubleshooting steps on how to locate the issue.
In this particular case study the following configuration was in place
config system interface
config system dhcp server set lease-time 86400 set dns-service default set default-gateway 192.168.44.1 set netmask 255.255.255.0 set interface "THE_LAN" edit 1 set end-ip 192.168.44.150 next end
config system switch-interface set vdom "root" set member "THE_WiFi" "port1" next
config wireless-controller vap edit "THE_WiFi" set ssid "THE_WiFi" set passphrase ENC **** set schedule "always" set broadcast-suppression dhcp-up dhcp-down dhcp-starvation dhcp-ucast arp-known arp-unknown arp-reply arp-poison arp-proxy netbios-ns netbios-ds ipv6 all-other-mc all-other-bc set beacon-advertising name model serial-number next
The following symptoms are perceived:
This is an indication that the broadband suppression policies are restricting the arp, as per the configuration:
config wireless-controller vap edit "THE_WiFi" set broadcast-suppression dhcp-up dhcp-down dhcp-starvation dhcp-ucast arp-known arp-unknown arp-reply arp-poison arp-proxy netbios-ns netbios-ds ipv6 all-other-mc all-other-bc next end
Once the ARP policies are relaxed (in this particular case once arp-poison was removed), the connectivity will be restored.
config wireless-controller vap edit "THE_WiFi" set broadcast-suppression dhcp-up dhcp-down dhcp-starvation dhcp-ucast arp-known arp-unknown arp-reply arp-proxy netbios-ns netbios-ds ipv6 all-other-mc all-other-bc next end |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.