FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ESCHAN_FTNT
Staff
Staff
Article Id 189683

Description

 
In a typical configuration when using FortiAP, the SSID is configured in 'Local Bridge' mode and this SSID is grouped into the software switch. However, there may be issues if trying to add the 'Local Bridge' SSID into FortiAP Profiles. The error is shown as 'Maximum number of entries has been reached'.
 
This article describes how to bridge a FortiWifi SSID to a wired network or VLAN network.
 
Scope
 
FortiGate, FortiWifi.


Solution

 

'Local Bridge' mode is not supported for FortiWifi.

For a FortiWifi unit, SSID can only be configured in 'Tunnel' mode. The key point is to configure a tunnel mode SSID with no IP address configured and DHCP server disabled. After, add this 'Tunnel' mode SSID into the software switch so it will be in same subnet with the local LAN network.
 
Below are the steps:
 
  1. Create an SSID with tunnel mode with no IP address and with DHCP disabled and Create address object matching subnet to disabled 
 

A screenshot of a computer__Description automatically generated.png

Note: Make sure the dependent VLAN 'wqtn' is also removed in order to be able to add the new SSID into the software switch.

tunnel.png

 

  1. Now, add a new SSID to the Local LAN interface software switch. 

 

A screenshot of a computer__Description automatically generated (1).png

 

  1. Once added, it will work as bridge mode.

A screenshot of a computer__Description automatically generated (2).png