Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Paul_Dean
Contributor

FortiAP CAPWAP DTLS no connection

I' m configuring a demo for a client of a FortiAP-14C connecting to a FortiGate 60C across the internet from a remote workers home to their office. They would like to roll out this solution to all their remote workers. The FortiGate 60C is running 5.0.5 build0252 and the FortiAP-14C has version 5.0 build060. I can' t get DTLS working between the two devices. I' ve set the wtp-profile on the FG to dtls-enabled and configured the AP to use DTLS. The access point connection status shows it as connecting and never changes. If I set both ends to clear text the connection is established after a few seconds and works just fine. Have any of you come across this problem before? Have I missed something important?
NSE4
NSE4
11 REPLIES 11
romanr
Valued Contributor

After configuring the dtls-enabled on the AP and also setting dtls-tls on the Fortigate (this must be done via the CLI!!!) - you have to reboot the AP and then it normally works!
Paul_Dean

Thanks romanr! I enabled DTLS via the cli and tried a reboot of the AP. I could not see a restart icon in the FAP gui so had to power it off then on. I will have another look today. Do you know if you can enable split tunneling with these FAPs the same way you can with the SSLVPN client? The customer would like internet traffic to use the local link and not traverse the tunnel.
NSE4
NSE4
romanr
Valued Contributor

Do you know if you can enable split tunneling with these FAPs the same way you can with the SSLVPN client? The customer would like internet traffic to use the local link and not traverse the tunnel.
No this is not possible ... and actually doesn' t make sense from a security point of view...
Paul_Dean

Thanks! Many clients we have who use the SSL VPN client insist on split tunneling. The bandwidth in their office is so slow that routing remote clients internet access in and out would cause issues. Any idea why DTLS is not working?
NSE4
NSE4
Bromont_FTNT
Staff
Staff

May be a good idea to open a support ticket to look at the DTLS issue.
AndreaSoliva
Contributor III

Hi DTLS is not supported in this case you are using which means over the LAN interfaces. Support is given from: FortiOS 5.0.6 FortiAP 5.0.7 If you deactive DTLS on the controller you will see that the conncetion comes up. As soon as you activate DTLS the connection will go down: # config wireless-controller wtp-profile # edit [Name of Profile] # set dtls-policy [" dtls-enabled" or " clear-text" ] # end Tested by myself with 60D as 14C! After upgrade to mentioned release works fine. Fortinet Sophia confirms NO Support for DTLS below mentioned release. kind regards Andrea
Bromont_FTNT
Staff
Staff

The DTLS connection should take place even on lower firmware but LAN port bridging will fail.
romanr
Valued Contributor

FortiOS 5.05 and FortiAP 5.06 does also work fine with DTLS .... on the 11c and on the 14C. We got dozens of them without any real issues...
AndreaSoliva
Contributor III

Hi sorry if we have a misunderstanding: DTLS is not working below the mentioned FortiOS for FGT and FAP if DTLS is used over LAN bridging which means: # config wireless-controller wtp-profile # edit [Name of profile] # config lan # set port-mode offline # end Possible is: offline bridge-to-wan bridge-to-ssid This means: # config wireless-controller wtp-profile # edit [Name of profile] # config lan # set port-mode bridge-to-ssid # set port-ssid [Name of SSID] # end # set dtls-policy [ dtls-enabled | clear-text] # end This means finally as soon as you activate on 14C and/or 28C the LAN port and you configure bridge-to-ssid and you activate DTLS you have to use: FortiOS 5.0.6 FortiAP 5.0.7 Otherwise it does not work because it is not supported! Sorry to be not clear enough in my first message. Have fun Andrea
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors