Have Forti AP's connected though Fortiswitches
Guest WIFI works fine
Work WIFI using RADIUS auth on NTP server - very intermittent.
One minute its connected - next minutes - no internet
the domain never drops - only the internet connection drops
Lots of DNS errors on the logs. DNS-NO-RESPONSE, DNS-NO-DOMAIN
Internal DNS on our domain controllers set - dont use the forti ones.
Just dont understand what's causing the constant drops - then it just randomly reconnects.
very unstable.
Forti Support just told me to upgrade the AP's and it's made no difference.
Should I understand your issue is that DNS is not stable?
IS it the same behavior when you try using public DNS for your client?
Well the connection to the Staff (LAN) wifi keeps dropping - assume it's DNS
Nope - Guest WIFI is fine - DHCP req DHCP ACK - done.
I would suggest to start isolating the problem. Is this an association/authentication issue, do you see the host getting frequently re-authenticated in the WiFi Events? Is the host able to always ping its gateway? Have you checked if there is more than one SSID configured in the end host and it is frequently jumping after the DNS failures?
If the issue seems related to the DNS only, I doubt that the AP or WiFi configuration will affect this service only, maybe check the DNS server or any DNS filter in the firewall policies.
no assoc/auth issues - once on thats it - the internet connection drop is always client side
not sure on the ping of gateway - cant connect to those devices until tommorow.
wha do you mean more than one SSID configured? there are 3 SSID's on each AP?
DNS server is just set to our domain controllers.
no DNS filters in place on policies.
I was referring to the SSIDs saved/configured in the end host. The host may jump from one SSID to another, making the troubleshooting difficult. I would suggest to forget other SSIDs on the host and leave only one.
OK so get this....
old laptop - connection solid to staff wifi - no drops.
new laptop - constantly dropping off - constant DHCP request/acks
central snat rule ONLY shows the new laptop going through? not the old working one?
why would that be?
any ideas?
older laptops seem to be fine on this but not the newer ones
Thanks
Its Forticlient! thats the issue!
any idea which part it might be?
Anything interesting in FortiClient logs or in Windows event logs?
The web filter profile had gone back to default - must of been when the EMS server upgraded!
phew!
User | Count |
---|---|
2428 | |
1303 | |
778 | |
551 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.