FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssanga
Staff
Staff
Article Id 374204
Description This article describes an issue where a FortiAP may appear offline on the secondary FortiGate GUI in a FortiGate WiFi controller, specifically when the FortiAP traffic is not being routed through the secondary FortiGate.
Scope FortiGate v7.4.5, v7.6.1.
Solution

When the FortiAP traffic is not routed through the secondary FortiGate in the HA cluster, the FortiAP may incorrectly appear as offline in the GUI of the secondary FortiGate WiFi controller. This behavior is observed in FortiGate Wifi Controller 1+1 fast failover setup and also in HA Active-Passive setup.

APstatus.png

 

However, the FortiAP remains functional, and its status can be verified through the CLI.
From the command ‘diagnose wireless-controller wlac -c ws’, the FortiAP status appears as 'CWAS_RUN_STANDBY', indicating that it is online but in a standby state on the secondary FortiGate.

diagnose wireless-controller wlac -c ws
-------------------------------WTP SESSION 1----------------------------
WTP session : 0-10.60.0.100:5246 MP00 CWAS_RUN_STANDBY,43363 1,1
Ctrl in_ifIdx : 42/aggr.fap
indev : 42/aggr.fap
Data in_ifIdx : 42/aggr.fap
indev : 0/
mesh uplink : ethernet
id : FP234FTF2*******

 

This issue has been resolved in FortiOS versions:

  • v7.4.8 (scheduled to be released in April; 2025).
  • v7.6.3 (scheduled to be released in March; 2025).


These timelines for firmware release are estimates and may be subject to change.

Workaround:
Verify the AP status using the CLI command 'diagnose wireless-controller wlac -c ws'.

General debug information required by FortiGate TAC for investigation.

 

  1. Debugs:


diagnose wireless-controller wlac -c ws
diagnose wireless-controller wlac -c ha

  1. TAC Report:


execute tac report

  1. Configuration file of the FortiGate.
  2. Fortinet Support Tool data: Troubleshooting Tip: Collect GUI slowness and errors debugs via Fortinet Support Tool