| Description | This article describes how to create a wireless-only dedicated network called Tunnel Mode. The client traffic is tunneled back to the FortiGate over CAPWAP and managed centrally. |
| Scope | FortiGate v7.4.8, v7.6.x |
| Solution |
Note: Starting FortiOS v7.6.5, the quarantine option is disabled by default when creating tunnel-mode SSID, preventing automatic creation of unused quarantine VLANs and simplifying configuration and management.
In the CLI:
Endeavour-kvm63 # config wireless-controller vap Endeavour-kvm63 (vap) # edit tunnel_vap Endeavour-kvm63 (tunnel_vap) # sh fu | grep quarantine Endeavour-kvm63 (tunnel_vap) # |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.