Created on
10-14-2014
07:01 AM
Edited on
10-27-2025
05:47 AM
By
Stephen_G
Description
Solution
If it is necessary to have the WiFi network on the same subnet of the VLAN network that is configured in FortiGate, enter the VLAN ID. By default, the VLAN ID is 0.
Configure the bridge SSID with CLI commands.
config wireless-controller vap
show
config wireless-controller vap
edit "Corporate_Wifi"
set ssid "Office_Wifi"
set passphrase ENC
set local-bridging enable
set schedule "always"
set vlanid 10
next
end
Note:
Here is a picture for reference:
Note:
FortiAPs are connected to port 7-PoE of FortiSwitch and are managed through the FAP_MGMT VLAN interface.
A firewall policy cannot be created using a Bridge SSID because, in bridge mode, wireless client traffic is directly bridged to the local network (LAN/VLAN).
To enforce firewall policies, a Tunnel SSID must be used.
Note:
Related documents:
Captive Portal Security
Troubleshooting Tip: Wireless clients do not receive IP through DHCP from Bridged SSID
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.