Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
tobisfr
New Contributor III

Clients disconnecting Wifi on 6GHz 802.11ax - no stable connection

We use FortiAPs 231G ( v7.4 build0734) on a Fortigate 200F ( V7.2.10)

The Wifi on 2.4Ghz and 5Ghz works without any problems. However with WIFI6 on 6Ghz the clients reconnect every few seconds, even on strong signal. Different clients with different WLAN adapters are affected.

 

Anyone having a suggestion or similar problems?

 

Error:

msg="AP sent disassociate frame to client c8:94:02:ff:f9:cd"
msg="Client c8:94:02:ff:f9:cd had an IP address detected (by DHCP packets)."
msg="Client c8:94:02:ff:f9:cd disconnected by WTP."
msg="Client c8:94:02:ff:f9:cd no OKC match for PMKID"
msg="Client c8:94:02:ff:f9:cd no OKC match for PMKID"
msg="Client c8:94:02:ff:f9:cd no OKC match for PMKID"
msg="DHCP ACK for IP 192.168.115.52 from server 10.1.1.20 with MAC 00:09:0f:09:01:1a for client c8:94:02:ff:f9:cd from router 192.168.115.254 on subnet 255.255.255.0 with dns 10.1.1.6, 10.1.1.20"
msg="DHCP REQUEST for IP 192.168.115.52 from client c8:94:02:ff:f9:cd"
msg="Client c8:94:02:ff:f9:cd authenticated."
msg="AP received 4/4 message of 4-way handshake from client c8:94:02:ff:f9:cd"
msg="AP sent 3/4 message of 4-way handshake to client c8:94:02:ff:f9:cd"
msg="AP received 2/4 message of 4-way handshake from client c8:94:02:ff:f9:cd"
msg="AP sent 1/4 message of 4-way handshake to client c8:94:02:ff:f9:cd"
msg="AP sent reassociation response frame to client c8:94:02:ff:f9:cd"
msg="AP received reassociation request frame from client c8:94:02:ff:f9:cd"
msg="AP sent WPA3(non-SAE) authentication response frame to client c8:94:02:ff:f9:cd"
msg="AP received WPA3(non-SAE) authentication request frame from client c8:94:02:ff:f9:cd"
msg="AP sent disassociate frame to client c8:94:02:ff:f9:cd"
msg="Client c8:94:02:ff:f9:cd had an IPv6 address detected (by IP packets)"
msg="Client c8:94:02:ff:f9:cd had an IP address detected (by DHCP packets)."
msg="Client c8:94:02:ff:f9:cd had an IP address detected (by DHCP packets)."
msg="Client c8:94:02:ff:f9:cd disconnected by WTP."
msg="DHCP ACK for IP 192.168.115.52 from server 10.1.1.20 with MAC 00:09:0f:09:01:1a for client c8:94:02:ff:f9:cd from router 192.168.115.254 on subnet 255.255.255.0 with dns 10.1.1.6, 10.1.1.20"
msg="DHCP REQUEST for IP 192.168.115.52 from client c8:94:02:ff:f9:cd"
msg="Client c8:94:02:ff:f9:cd authenticated."

 

Config SSID:

show full-configuration wireless-controller vap BFCLIENTS-6GHZ 
config wireless-controller vap
    edit "BFCLIENTS-6GHZ"
        set fast-roaming enable
        set external-fast-roaming disable
        set atf-weight 20
        set max-clients 0
        set ssid "BFCLIENTS-6GHZ"
        set broadcast-ssid enable
        set security wpa3-enterprise
        set pmf enable
        set pmf-assoc-comeback-timeout 1
        set pmf-sa-query-retry-timeout 2
        set okc enable
        set mbo disable
        set voice-enterprise disable
        set fast-bss-transition disable
        set eapol-key-retries enable
        set mac-username-delimiter hyphen
        set mac-password-delimiter hyphen
        set mac-calling-station-delimiter hyphen
        set mac-called-station-delimiter hyphen
        set mac-case uppercase
        set radius-mac-auth disable
        set auth radius
        set encrypt AES
        set radius-server "FortiAuth-BA"
        set local-standalone disable
        set local-bridging enable
        set intra-vap-privacy disable
        set schedule "always"
        set ldpc rxtx
        set high-efficiency enable
        set target-wake-time enable
        set port-macauth disable
        set bss-color-partial enable
        set nac disable
        set vlanid 15
        set vlan-auto disable
        set dynamic-vlan disable
        set multicast-rate 0
        set multicast-enhance disable
        set igmp-snooping disable
        set dhcp-address-enforcement disable
        set broadcast-suppression dhcp-up dhcp-ucast arp-known
        set ipv6-rules drop-icmp6ra drop-icmp6rs drop-llmnr6 drop-icmp6mld2 drop-dhcp6s drop-dhcp6c ndp-proxy drop-ns-dad
        set me-disable-thresh 32
        set mu-mimo enable
        set probe-resp-suppression disable
        set radio-sensitivity disable
        set vlan-pooling disable
        set dhcp-option43-insertion enable
        set dhcp-option82-insertion disable
        set ptk-rekey disable
        set gtk-rekey disable
        set eap-reauth disable
        set qos-profile ''
        set hotspot20-profile ''
        set access-control-list ''
        set primary-wag-profile ''
        set secondary-wag-profile ''
        unset rates-11a
        unset rates-11bg
        unset rates-11n-ss12
        unset rates-11n-ss34
        set rates-11ac-mcs-map ''
        set rates-11ax-mcs-map ''
        set utm-status disable
        set address-group-policy disable
        set sticky-client-remove disable
        unset beacon-advertising
        set application-detection-engine disable
        set l3-roaming disable
    next
end

 

 

 

4 REPLIES 4
framoshzv
New Contributor

Hola, tenemos el mismo problema, tenemos el caso en el TAC y fue derivado al área de desarrollo.

tobisfr
New Contributor III

I opend a TAC Ticket as well. But nevertheless. Has anyone a working configuration of Wifi6E 6Ghz with windows Clients and Radius authentication? It would be nice if someone could post the full config of the ssid and perhaps AP Profile.

dynasoft
New Contributor II

Hi, could you solve this?

framoshzv

Hasta el momento no tenemos una respuesta, al parecer si es un bugg que lo elevaron al área de Desarrollo. Se realizo todas las recomendaciones de la marca a nivel de configuración y no funciono nada.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors