Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Forti-Mon
New Contributor III

Forti AP constantly dropping off SSID with Radius auth

Have Forti AP's connected though Fortiswitches

Guest WIFI works fine

Work WIFI using RADIUS auth on NTP server - very intermittent.

 

One minute its connected - next minutes - no internet

the domain never drops - only the internet connection drops

Lots of DNS errors on the logs. DNS-NO-RESPONSE, DNS-NO-DOMAIN

Internal DNS on our domain controllers set - dont use the forti ones.

Just dont understand what's causing the constant drops - then it just randomly reconnects.

very unstable.

Forti Support just told me to upgrade the AP's and it's made no difference.

9 REPLIES 9
AEK
SuperUser
SuperUser

Should I understand your issue is that DNS is not stable?

IS it the same behavior when you try using public DNS for your client?

AEK
AEK
Forti-Mon
New Contributor III

Well the connection to the Staff (LAN) wifi keeps dropping - assume it's DNS

Nope - Guest WIFI is fine - DHCP req DHCP ACK - done.

ebilcari

I would suggest to start isolating the problem. Is this an association/authentication issue, do you see the host getting frequently re-authenticated in the WiFi Events? Is the host able to always ping its gateway? Have you checked if there is more than one SSID configured in the end host and it is frequently jumping after the DNS failures?

If the issue seems related to the DNS only, I doubt that the AP or WiFi configuration will affect this service only, maybe check the DNS server or any DNS filter in the firewall policies.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Forti-Mon
New Contributor III

no assoc/auth issues - once on thats it - the internet connection drop is always client side
not sure on the ping of gateway - cant connect to those devices until tommorow.
wha do you mean more than one SSID configured? there are 3 SSID's on each AP?

DNS server is just set to our domain controllers.

no DNS filters in place on policies.

ebilcari

I was referring to the SSIDs saved/configured in the end host. The host may jump from one SSID to another, making the troubleshooting difficult. I would suggest to forget other SSIDs on the host and leave only one.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Forti-Mon
New Contributor III

OK so get this....

 

old laptop - connection solid to staff wifi - no drops.

new laptop - constantly dropping off - constant DHCP request/acks 

central snat rule ONLY shows the new laptop going through? not the old working one?

why would that be? 

any ideas?

older laptops seem to be fine on this but not the newer ones

Thanks

Forti-Mon
New Contributor III

Its Forticlient! thats the issue!

any idea which part it might be?

AEK

Anything interesting in FortiClient logs or in Windows event logs?

AEK
AEK
Forti-Mon
New Contributor III

The web filter profile had gone back to default - must of been when the EMS server upgraded!

phew!

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors