FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
chanm
Staff
Staff
Article Id 264142
Description

This article discusses common misconfigurations to check for when FortiWiFi 80F/81F-2R’s Local WiFi Radio is Offline.

 

FortiWiFi 80F/81F-2R (and some other FortiWiFi models) feature an 'aplink' aggregate interface which is used for the connection between the FortiWiFi and its internal FortiAP. As of FortiOS 6.4.12, 7.0.5, and 7.2.0, the configuration of the 'aplink' aggregate interface can be modified. If the 'aplink' aggregate interface is improperly configured, that can lead to connectivity issues between the FortiWiFi and its internal FortiAP, causing the FortiWiFi's Local WiFi Radio to show as Offline.
Scope FortiWiFi with the 'aplink' aggregate interface running FortiOS 6.4.12, 7.0.5, or 7.2.0 and above.
Solution

If the FortiWiFi's Local WiFi Radio is Offline, review the configuration on the 'aplink' aggregate interface:

 

  1. 'aplink1" and 'aplink2' physical interfaces should be members of the 'aplink' aggregate interface. Make sure that the 'aplink1' and 'aplink2' physical interfaces have not been manually disabled. If their NIC icon is greyed out in the GUI, check the CLI:

 

config system interface

    edit "aplink1"

        set vdom "root"

        set status down <-----

        set type physical

        set snmp-index 11

    next

    edit "aplink2"

        set vdom "root"

        set status down <-----

        set type physical

        set snmp-index 12

 

  1. 'aplink' aggregate interface should have a valid DHCP Server configuration to offer an IP to the internal FortiAP. For example, the DHCP Server address range should match the 'aplink' aggregate interface subnet.

 

  1. 'aplink' aggregate interface should have Security Fabric Connection administrative access enabled to allow for CAPWAP communication between the FortiGate and the internal FortiAP.

 

After the above configuration has been verified, check the communication between FortiGate and internal FortiAP by running a packet capture on the 'aplink' interface: diagnose sniffer packet aplink "none" 4 0 l

 

Related document:

Configuring the network interface for the AP unit

Contributors