Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Cavey
New Contributor

FortiAPs goes down together

Dear all,

 

i used to have the 110C but since is going to be EOL , i changed to the 100E, i have 3 FortiAPs 221C which are connected and using the firewall's default controller to control the fortiAPs.

 

Over the last few months, the fortiAPs will just go down together (about every 30 days or so), rebooting the APs dont help and only a reboot of the firewall will bring all the APs up. Just wondering what should i do or look out. When using the 110C there was no such issue

 

The FW firmware is v5.4.4,build6003 and the APs are on FortiAP-221C v5.4,build0371,171102 (GA) [Update]

 

C

3 REPLIES 3
Toshi_Esumi
SuperUser
SuperUser

Not much you can do since the problem seems to be on FGT controller side. We experienced 1 min WiFi off-line in the past but they always came back on-line without doing anything. What I would do is:

- check WiFi event log at the time when wifi drops

- sniff the interface at FGT if any packet exchange is happening after they dropped. (We always use a separate/dedicated vlan for FAP's CAPWAP termination so easy to identify those packets. I don't know your case though.)

- try pinging FAPs from another admin session while sniffing. Likely they respond (means FAPs are fine).

- Then open a ticket with TAC providing above test result. They would instruct you what to do/gather when it happens next time.

 

That's all I would do. But since I saw some WiFi related bug fixes in 5.4.5 and 5.4.6 release notes, I would try upgrading the FGT to the latest 5.4, which is 5.4.9 first to see if the symptom still occurs in a month or so. TAC might suggest the same.

Cavey

Opened a case with fortinet and this is what they say.

 

“From the logs, we could see CAPWAP Discovery Request/Response between FAPs and FGT, but when FAP sends SSL Client-Hello packet, there's no Server Hello Response packet from FGT. Thus FAP fails to establish DTLS (SSL) connection with FGT and hence FPA stays offline.”

 

No solution as of yet, except to wait for the next downtime to collect more logs

Toshi_Esumi

Actually that's a very good sign. They're looking for a bug or a special condition on the FGT that causes it to stop talking. Just be aware that if they update the ticket last and you don't respond, the system tries to automatically close the ticket in one week. Keep updating like "It still doesn't happen." every week.

Labels
Top Kudoed Authors