Hi,
I have FortiGate connected to Cisco switches (core + access), which is connected to 7 FortiAPs.
I want to create multiple SSIDs (VLAN 10 and VLAN 20).
Currently, I have created two VLANs under my LAN physical interface on my FortiGate, and two SSIDs in bridge mode. on the switch side. I changed the point-to-point interface (to FG and to AP) to Truck. and created (vlan10, vlan20).
Unfortunately, the internet is very slow, and AP keeps restarting suddenly. I opened a ticket with TAC, but it was not helpful.
Kindly advise if my config is correct. Or better to move to Tunnel mode. And what is the difference between Tunnel and Bridge mode in function and configuration on a Cisco switch?
SSIDs in tunnel mode are easier to configure from a switch perspective, as only the AP management VLAN needs to be set up. This article provides detailed information: Technical Tip: SSID Local bridge vs Tunnel mode
When using an SSID in bridge mode, there's a risk of creating Layer 2 loops. Please ensure this isn't the case and verify whether the Cisco switch is disabling the AP port due to STP.
thanks for your replay. I saw the mentioned post but still not able to understand the different of configuration needed on cisco switch in both options?!
should i create vlans and enable trunk port with tunnel mode? what config diff
In tunnel mode SSID, WiFi user traffic is tunneled. The Cisco switches will only see communication between the FortiGate and the FortiAP, so only the AP management VLAN needs to be extended across the switches.
User | Count |
---|---|
2599 | |
1382 | |
803 | |
663 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.