Hi there
I've set a new setup up and created the SSID, and allowed access with the checkboxes.
Also in the Fortigate Settings allowed listening to the services and SSID.
Somehow i can't access the fortigate when i'm over FortiSwitch and FortiAP. Do i have to allow something else?
my goal is, that from the internal SSID we should have access to the fortigate. And the SSID Guest don't.
Kind regards
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
As it seems i can't create a dedicated VLAN for the FortiGate itself. Since they use the fortilink.
Or did i setup something wrong?
The option 'Listen on Interfaces' in the last screenshot is not used for the management interface service, this option is dedicated to the NTP service only.
nice didn't knew about it :) thanks
If I get it right you want to access FGT from a node/PC that is connected to a FSW port or a SSID/FAP not from the FSW/FAP itself (their management subnet). If this is the case than on the interface (VLAN or SSID) that you configure for the end users (gateway) in 'Administrative Access' you have to enable HTTPS/HTTP. This should be enough to gain access to FGT management interface (GUI) from an end host that is connected to that subnet.
hi cool to know :)
It seems i can't even ping the FGT from the FAP
FGT got a DHCP with 192.169.100.1/24
and FAP DHCP with 192.169.10.1/24
is there a way to create a Shared DHCP so that i can ping them? Or do i have to buy a Forti Switch to handle VLAN Access?
For AP management, a dedicated management subnet/VLAN need to be created in FGT and spanned in the FSW or in a 3rd party switch and have ' Security Fabric Connection' enabled. There is no limitation from FGT, Fortilink/FSW just simplify configuration and monitoring the switch ports.
In case of a 3rd party switch a sub interface with a VLAN ID could be the easiest way to configure the AP management VLAN, like this for example:
After selecting the proper 'Administrative Access' options, FGT and FAP can manage and reach both ways.
The subnets you have shared in the last reply are not in the private IP range and are not in the same network.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.