Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
anonimis
New Contributor

Apple TV, iMac, iPhone / iPad and iTunes not communicating properly

I have an AP220B connected to a FGT60C and it works fine for my notebooks and iDevices for all normal internet type functionality, like web browsing, email and the like. The problem I' m having though is getting any Airplay functions working over the wifi network. Can see the Apple TV from the remote app on my iPad and iPhone but not able to control it. Music will not push from any (iMac, iPad or iPhone) to the Apple TV. I' ve read that there may be issues with certain wifi chipsets and there has been mention that changing to only G 2.4Ghz might work. After a lot of experimentation of turning of radios and changing channels, it still fails to work. My older D-Link WAP-1353 works every time so I know I have no problems with the home sharing on the iDevices. Swapped back and forward between D-Link and AP220B connection to test and it is consistently not working on the AP220B network. Involved devices; Fortigate 60C with firmware v5.0, build0147 (GA Patch 1) FortiAP 220B with firmware v5.0, build024 (GA) iPhone 5 with iOS 6.0.1 iPad 2 with iOS 6.0.1 Apple TV 2 with software 5.1.1 (5433) iMac running OS X 10.6.8 and latest iTunes
10 REPLIES 10
Dave_Hall
Honored Contributor

How is the wifi or wlan interface (to the AP220B) configured on the 60C? Is it a separate interface on the 60C or is it merged with the internal interface? If the FortiAP has its own separate interface I would make damn sure there wasn' t any UTM features enabled on the firewall policy between the internal ->wlan interfaces (i.e. web filter, app control sensor, etc.) that could be blocking the ports used by the apple products you have mentioned. I am not familiar with Airplay, but a quick google search shows page hits on what ports are needed to be open for this service to properly function. As you have indicated normal web/email traffic appears to be functioning well, I am more inclined to to suspect some sort of port blocking is involved.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
anonimis

Hi Dave, thank you for your response. The FortiAP is on its own interface with no UTM of any sort. This would not be the cause as all the devices were joined to the same wireless network so all ports are open. As described in the original post I replicate the network with another access point and it works perfectly, leading me to believe it is the FortiAP at fault not the networking configuration.
Dave_Hall
Honored Contributor

Connect an actual serial cable to the console port on the AP220B and watch for any error messages that might show up during/after it boots up and also during normal operation.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
RaviR_FTNT
Staff
Staff

We had a similar issue with Apple TV and Iphone, but in our case IPhone never discovered the Apple TV which was connected to the WAN port and then found the issue was with Multicast forwarding need to be enabled and we enabled the mulitcase policy and it worked. Now sure whether your issue is the same as this one. If not, please let us know the topology, Apple TV is connceted to which port of the 60c? Is Wifi and the port (apple TV) are in the same SoftSW interface ?
RaviR_FTNT
Staff
Staff

http://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&externalId=FD33598 Check this Article
anonimis

Thank you RaviR, the KB article relates to extending between SSID etc. As mentioned previously but maybe not clearly, I have used a D-Link accesspoint for testing but am not trying to incorporate it in my network. All the iDevices are wireless on the same FortiAP, on the same SSID and subnet. This means no traffic even requires exiting the interface the it is connected to on the FG60C.
ORIGINAL: RaviR http://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&externalId=FD33598 Check this Article
Dave_Hall
Honored Contributor

All the iDevices are wireless on the same FortiAP, on the same SSID and subnet. This means no traffic even requires exiting the interface the it is connected to on the FG60C.
What does your " config wireless-controller vap" and " config wireless-controller" sections look like?

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Adrian_Lewis
Contributor

config wireless-controller vap
    edit example_wlan
    set multicast-enhance enable
 end
Worth a shot (or disable if it' s currently enabled). Had issues with DLNA on AeroHive APs before and their multicast handling was the issue.
Dave_Hall
Honored Contributor

set multicast-enhance enable
I was wondering too if " intra-vap-privacy" was enabled (default setting is disabled).

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Labels
Top Kudoed Authors