Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rmon
New Contributor

FAP11C - Can I disable LAN port?

Helllo! I have a FAP11C that I would like to deploy remotely and will provide the WPA2 key to authorized users but do not want anyone plugging directly into the LAN port after hours or when no one is around. Is it possible to somehow just disable the LAN port? If not, what would be the best way to prevent users from actually pulling an IP by plugging directly into it? I have set up with 90D POE and both the 90D and FAP11c are running 5.2 It seems when I do plug directly into the LAN, it issues a 192.168.99.x address which is the main subnet of the fortigate itself and dont think thats a very good thing. Thanks in advance for any suggestions. RMON
5 REPLIES 5
rwdorman
New Contributor III

Is there a reason that you have DHCP server turned on on the Fortigate for that subnet? (maybe that' s what your wired clients use). I see two options 1. If your switches support it you can put a MAC filter on the port so that it wont give L2 access to anythign that isn' t that MAC 2. Define a VLAN or Physical interface just for your FortiAP' s and then do DHCP reservations on the Fortigate or Static IP' s on the FAP

-rd 2x 200D Clusters 1x 100D

1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D

-rd 2x 200D Clusters 1x 100D 1x 60D FortiOS 5.2 FortiAP 221C FAZ 200D
Dave_Hall
Honored Contributor

I think rmon is referring to the LAN port on the FAP11C itself, which according to the hardware manual is " currently not supported" , but I understand that a recent firmware upgrade has " enabled" this port. I am not familiar with this AP but I would suggest just logging into it (either HTTP/S, SSH or USB MGMT) and checking to see if there are any " interface" settings that allows you to disable that LAN port.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
yzhang_FTNT
Staff
Staff

what' s the output from the FAP11C? brctl cw_diag -c wtp-cfg
Bromont_FTNT
Staff
Staff

Are you not able to set the LAN port to " NONE" ?
Dave_Hall
Honored Contributor

The Wireless Deployment Handbook indicates the LAN port (bridge) setting are configured in wtp profile....I would assume you can somehow disable it from there.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors