FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rishab444
Staff
Staff
Article Id 271387
Description

This article describes how to convert an existing SSID in tunnel mode to bridge mode without affecting the user end.

Scope FortiWifi, FortiGate.
Solution
  1. There is an existing SSID in tunnel mode as below and the user would like to change this to bridge mode without affecting anything on the user end,
  2.  There is no option in GUI to make this change.

 

Picture2.png

 

  1. This can be achieved via CLI using the below commands:


config wireless-controller vap
    edit “<Your_SSID_Name>”

        set local-bridging enable

    end

 Picture3.png

 

Picture4.jpg

 

  1. After making this change, the SSID is converted to the bridge mode successfully.

 

Picture5.jpg

 

  1. By default, the FortiAP profile only broadcasts 'All Tunnel Mode SSIDs'. Hence the bridge mode SSID will not be advertised on the Access Points.

 

Picture6.jpg

 

  1. It is possible to change this by going into the profile:
  • Select the in-use FortiAP Profile and go into edit mode.
  • From the SSID option change this from Tunnel to Manual and select all the SSIDs, it is necessary to advertise including tunnel mode and bridge mode SSIDs available on the right side of the menu.
  • Select 'Ok' at the bottom to save changes.

 

Picture7.jpg

   

  1. It is possible to confirm from the FortiAP profile and under the SSID field that all the selected SSIDs from previous step 6 will be advertised over the Radio as per selection.

 

Picture8.jpg