Hi,
Hope can someone assist me.
How can I get the FortiAP Bridge mode work with multiple VLAN + Third-party DHCP server?
I'm trying to run multiple SSIDs in different VLANs.
Here's my setup:
1. FortiGate 100F > FortiAP Controller
2. Cisco L3 Switch > VLANs and DHCP Server are configured here
3. FortiAP > Will hold multiple SSID with different VLANs
Cisco L3 Switch
>connected to FGT via trunk port
FortiGate 100F
>All VLAN interfaces are added
FortiAP
>Connected to Cisco L3 Switch via port trunks with Native VLAN assigned and all other VLAN set to allow
>SSID VLAN settings assigned
>Management VLAN set to 0
FortiAP able to connect to FGT100F using Native VLAN IP.
SSIDs are broadcasting. However, unable to get IP address from other VLANs configured.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Bridge mode SSID traffic just goes out to the FAP's local/physical ethernet, in your case the switch's native vlan on the trunk port, so can't connect to different networks(VLANs) if you have multiple SSIDs.
It's not easy to do what you want to set up with FGT+FAP although a way I can think of would probably work. But I don't recommend because it's difficult to configure/manage and the performance wouldn't be great.
The way I can think of is:
1. make those SSIDs to tunnel mode
2. don't configure DHCP at the controller FGT
3. create all VLAN subinterfaces on the port of the FGT, connected to the Cisco SW trunk port
4. create a software switch interface for each VLAN subinterface and the corresponding SSID pair.
With this way, those Client DHCP requests get to the FGT over the native VLAN then hairpin back to the switch over the VLAN.
Now you can see why I said the performance would be questionable. Also software switch's performance isn't too great either.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1665 | |
1077 | |
752 | |
446 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.