Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ashish-pal
New Contributor

FortiAP 221C stuck in discovery AC and unable to connect to fortigate firewall

I have replaced the FortiAP 221c from Fortigate 100F to fortigate 80E. I was connected on 100F but when i connect the same AP to 80E it is showing as discovery AC and stuck in connecting mode. I am able to connect reach the device and able to https also but not able to connect to fortigate 80E at new location. 

Fortiap 221c v4.jpgFortiap 221c v3.jpgFortiap 221c v2.jpgFortiap 221c v1.jpg

7 REPLIES 7
ebilcari
Staff
Staff

It may be a firmware incompatibility issue, you can check in the Compatibility Matrix the firmware versions of FortiAP and FortiOS.

There is also a note that applies for this AP:

*These FortiAP models and versions do not support strong ciphers. To allow connections, input the following commands in the FortiOS CLI:

For FortiOS 7.0.0:

config system global

set ssl-static-key-ciphers enable

set strong-crypto disable

end

For FortiOS 7.0.1+:

config wireless-controller global

set tunnel-mode compatible

end

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Ashish-pal

Hi @ebilcari , I tried the same command but there is no improvement on this. still the AP is showing as offline mode only. kindly suggest further

Forti OS 80E - v7.0.15 build0632 (Mature)

Forti AP - 6.0.6Fortiap 221c v5.jpg

ebilcari

You can try to delete the AP from the FGT, reset it to default and add it again.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Ashish-pal

Hi @ebilcari  i tried that part also but unfortunately it didn't work is anything related to date and Time for that i tried below command but that also didn't work neither the date and Time changed on AP. Also, Radio 1 and Radio 2 are in disabled mode.

 

cfg -a AC_DISCOVERY_FCLD_APCTRL=208.91.113.187
cfg -a AC_CTL_PORT=443
cfg -c

 

Fortiap 221c v2.jpgFortiap 221c v1.jpg

 

ebilcari

Yes correct, time is required to validate the certificates, you can take a look at this article for more details and some troubleshooting commands.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Ashish-pal

I tried that also but still no success and on Fortigate firewall side NTP is configured properly

 

show full system nt
config system ntp
set ntpsync enable
set type fortiguard
set syncinterval 30
set source-ip 0.0.0.0
set source-ip6 ::
set server-mode enable
set authentication disable
set interface "fortilink"
end

 

Fortiap 221c v6.jpg

ebilcari

You can check with the debug or the sniffing commands to verify if the AP is actually willing to communicate with FGT, for example NTP or CAPWAP traffic.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors