FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
mle2802
Staff
Staff
Article Id 275403
Description

This article describes the reason why WiFi clients experience connection errors when connecting to bridge SSID with optional VLAN ID.

Scope FortiGate.
Solution

In this example, 'Henry_wifi' is in bridge mode with an optional VLAN ID set to 10.

vlanid.PNG

 

ssid.PNG

 

When attempting to connect to the SSID, the client cannot connect accordingly and timeout after a while.

 

IMG_6562.jpg


This happens because the pre-defined VLAN is not allowed in the FortiSwitch port and hence, the WiFi client cannot get the IP accordingly from the DHCP server.

 

fortiswitch.PNG

 

By adding the optional VLAN configured in SSID to allowed VLANs, the DHCP traffic will be allowed and Wi-fi clients will be able to get the correct IPs for connection.


vlan added.PNG
IMG_6563.jpg