FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
jera
Staff
Staff
Article Id 407311
Description This article describes how to create a wireless-only dedicated network called Tunnel Mode.  The client traffic is tunneled back to the FortiGate over CAPWAP and managed centrally.
Scope FortiGate v7.4.8
Solution
  1. Navigate to WiFi Controller -> SSIDs -> Create. Configure a new SSID by adding a name.
  2. Choose the traffic mode as 'Tunnel-mode'.
  3. Add the IP or Network Mask for the wireless interface.

 

image.png

 

  1.  Enable DHCP. The address range will be automatically populated based on the IP Network assigned to the SSID.

 

 

image.png

 

  1. Complete the WiFi settings by adding the SSID and passphrase. Keep the rest of the configuration on default or configure Radius if necessary.

 

image.png

 

  1. Create an AP Profile for a specific hardware model, WiFi Controller -> FortiAP profiles > Create.
  2. Supply the name and the hardware model for the platform on which the profile will be applied.

 image.png

 

  1. The SSIDs, by default, assign all Tunnel-mode SSIDs to the profile. The SSIDs must be the same for Radio 1 and Radio 2. Leave the rest of the setting to default. Select 'OK' to save.

 

image.png

 

  1.  Create a firewall policy to allow internet traffic for the wireless network. Ensure that the SSID is selected as the Incoming interface and the Internet-facing Interface as the Outgoing Interface. 

 

image.png