Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Fast Roaming and AP hopping problems for VOIP and data in a FGT200B HA & FortiAP 220B infrastructure

Hi, we have in our building a FGT200B HA active-active configuration with 4 FortiAP220B on PSK (WPA/WPA2 and AES) for the VOIP WLAN. Furthermore we have also a data VLAN with WPA/WPA2 Enterprise and AES running. Both WLANs are configured on radio 1 the rogue scanning is configured on radio 2. At radio 1 also additional the radio resource provision is activated. For the Band 802.11n we enabled the channels 1, 6 and 11. Now we are observing a very instable network, where we see an AP hopping of the VOIP Clients (CISCO Phones and Blackberry) as well also on the laptops. (We see the quality indication is hopping from very good to pure and back again). How can we trace the problem? Do anyone have the same problem? Thanks. Stefan. PS: AP FW: FAP22B-v4.0-build214 FGT FW: v4.0,build0458,110627 (MR3 Patch 1)
14 REPLIES 14
yzhang_FTNT
Staff
Staff

Was the AP' s channel changed by the radio resource provision very often? You can check the operationing channel from Managed FortiAP page. Is the connection between AP and the FGT stable? AP join time can also be checked from Managed FortiAP page. have you tried to disable the radio resource provision to see if the problem is gone?
FortiRack_Eric
New Contributor III

Furthermore which version are you running on the FG? I hope 4.2.7 AP version on the cluster and the latest AP firmware 4.3.1 Regards, Eric

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

Hi, thanks for your hints. The connection to the FGT AP is stable. Also there is no high dynamic channel switching. It seems to me very stable. We are using AP FW: FAP22B-v4.0-build214 FGT FW: v4.0,build0458,110627 (MR3 Patch 1) because we had a lot of troubles with the 4.2.x and UTM scanning/policies in the HA setup. Thanks a lot. Stefan.
yzhang_FTNT
Staff
Staff

We see the quality indication is hopping from very good to pure and back again
Did you see this problem on all your 4 FAPs? Was the mobile device moving when you saw this? The internal antenna used in FAP are directional antenna.

yes, I see this on all 4 FAPs. Testing was done: Laptop and Blackberry Client localized at one location. The signal quality is hopping from good to bad (hopping between two FAPs). Additional the reconnecting during roaming takes a long time. Is there a possibility to trace this hopping and the reasons for this at the CLI, either of the FAP or of the FGT. Thanks. As following you will see a snapshot of one client - Logs out of Fortimanager. As you see there is no principle hopping but a running reauth. 850 2011-09-15 15:15:00 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 851 2011-09-15 15:15:00 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 854 2011-09-15 15:14:51 notice wireless client-denial Client <mac-address> denied. 855 2011-09-15 15:14:50 notice wireless client-denial Client <mac-address> denied. 904 2011-09-15 15:08:55 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 905 2011-09-15 15:08:55 notice wireless oper-channel AP WLAN_AP2 radio 1 operating channel 6 ==> 1. 906 2011-09-15 15:08:54 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 907 2011-09-15 15:08:54 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 908 2011-09-15 15:08:53 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 932 2011-09-15 15:06:22 notice wireless client-denial Client <mac-address> denied. 933 2011-09-15 15:06:18 notice wireless client-denial Client <mac-address> denied. 935 2011-09-15 15:06:14 notice wireless client-denial Client <mac-address> denied. 950 2011-09-15 15:04:56 notice wireless client-ip-detected Client <mac-address> assigned an IP address. 951 2011-09-15 15:04:55 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 952 2011-09-15 15:04:55 notice wireless client-denial Client <mac-address> denied. 988 2011-09-15 14:59:51 notice wireless client-ip-detected Client<mac-address> assigned an IP address. 989 2011-09-15 14:59:51 notice wireless client-authentication Client <mac-address> authenticated. WLAN_AP1 990 2011-09-15 14:59:50 notice wireless client-denial Client <mac-address> denied. In this case it is a laptop. But the same phenomena we can observe of CISCO VOIP Phones and BB Handhelds. We can see this behavior as well at WPA/WPA2-Personal and WPA/WPA2-Enterprise.
yzhang_FTNT
Staff
Staff

could you check the scan setting on the FAP using " cw_diag -c radio-cfg" ? Make sure the sta scan is not enabled on the radio which provides the wlan service. There is a sta scan related bug (which is called Rogue AP on-wire scan in the controller GUI) in FAP 214 build.

Hi, perhaps a simple question. How can I reach the AP in the connected Authorized status, because I cannot use the telnet session anymore - it seems to be deactivated by the WLAN Controller (FGT200B). Thanks. stefan.
yzhang_FTNT
Staff
Staff

For security reason, the telnet daemon will be turned down after a FAP is connected to the controller. It can be enabled from the controller cli: FWF60C3G10000698 # con wireless-controller wtp FWF60C3G10000698 (wtp) # edit FAP22B3U11004887 FWF60C3G10000698 (FAP22B3U11004887) # set login-enable enable FWF60C3G10000698 (FAP22B3U11004887) # end

Hi, you are right the sta scan is enabled. This means I have to deactivate it at each AP. Can you give me a hint for the deactivation CLI. Radio 0: AP radio type : 11N_2.4G beacon intv : 100 tx power : 27 HT mcs : 15 HT gi : 0 HT bw : 0 channel : 0 auto_chan : 1 chan list : 1, 6, 11, ap scan : background regular scan ap scan passive: disabled ap scan period : 300s ap scan intv : 1s ap scan dur : 20ms ap scan idle : 0ms ap scan rpt tmr: 30s sta scan : enabled darrp : enabled darrp wait : 3 darrp_chan : 1 Radio 1: Monitor ap scan rpt tmr: 15s Radio 2: Disabled
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors