FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Hsharma
Staff
Staff
Article Id 376257
Description

This article describes the issue when FortiAP is not showing online on FortiGate when trying to register from a VPN.

Scope FortiGate, FortiAP.
Solution

Topology: FortiAP<---> FortiGate1 <---IPsec---->FortiGate 2.

 

The configuration is when FortiAP is behind FortiGate1 but needs to establish a CAPWAP tunnel with FortiGate2 at the remote site over the tunnel.

FortiAP is receiving the IP address and DTLS Client Hello packets are reaching the remote FortiGate2 but remote FortiGate does not reply back. 

 

pcap.jpg

 

To resolve the issue, enable the Security Fabric Connection settings at the tunnel interface as it is a minimum management requirement that FortiAP establishes a CAPWAP tunnel with the FortiGate.

 

AP.jpg

 

After enabling the Security Fabric Connection at the tunnel interface, FortiAP will be online.