| Description |
This article describes the issue when FortiAP is not showing online on FortiGate when trying to register from a VPN. |
| Scope | FortiGate, FortiAP. |
| Solution |
Topology: FortiAP <---> FortiGate1 <---IPsec----> FortiGate 2.
The configuration is when FortiAP is behind FortiGate1 but needs to establish a CAPWAP tunnel with FortiGate2 at the remote site over the tunnel. FortiAP is receiving the IP address and DTLS Client Hello packets are reaching the remote FortiGate2 but remote FortiGate does not reply back.
To resolve the issue, enable the Security Fabric Connection settings at the tunnel interface as it is a minimum management requirement that FortiAP establishes a CAPWAP tunnel with the FortiGate.
After enabling the Security Fabric Connection at the tunnel interface, FortiAP will be online.
If a secondary VPN is configured, the Security Fabric is needed on that VPN to ensure high availability works with it |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.