FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Anonymous
Not applicable
Article Id 351391
Description This article provides a workaround to fix the issue of endpoints connected to FortiAP where traffic is going through FortiGate but reply traffic does not reach back to the endpoints.
Scope FortiOS, FortiGate, FortiSwitch, FortiAP.
Solution

Scenario:

 

FortiGate (172.18.0.1) <----> FortiSwitch <----> FortiAP <----> (172.18.0.27) Endpoint

In the presented scenario, the endpoint is unable to browse the internet by failing DNS queries with FortiAP presenting the action 'DNS-no-resp'. Also, the Endpoint is failing to ping its Gateway IP (FortiGate internal IP 172.18.0.1).


fortiap_Action.png

 

However, debugs and logs show that FortiGate is allowing the traffic. With DNS responses and icmp replies observed going out of the FortiGate towards the FortiSwitch, but never received on the Endpoint. The below image shows Endpoint ICMP requests reaching FortiGate and FortiGate interface replying.


ping working.png

 

The next images show DNS traffic being allowed out, but also that FortiGate recorded reply traffic on the logs.

 

fw_policy_trigered.png

 

dns_reply.png

 

As a workaround disable CAPWAP offloading, and reboot the wireless controller, using the below commands on FortiGate:

 

config system npu

    set capwap-offload disable

end

execute wireless-controller restart-acd


The last command will prompt the message below before rebooting the wireless controller, requiring 'Y' be pressed to reboot, which will briefly disconnect all FortiAPs from the FortiGate.

 

This operation will reboot wireless controller daemon!

Do you want to continue? (y/n)


After the reboot, the Endpoint should start receiving the traffic.
If the above does not resolve the issue and it persists, open a support ticket for further investigation. 

 
Note: When using an NP7 processor, make sure to check CAPWAP offloading compatibility for the FortiAPs. The link is available in the related documentation section.

Related documentation: