Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Niesten
New Contributor

FortiWifi in combination with Apple products

Hello, I am new on this forum so if i am doing something wrong regarding this post i apologize. We are running a FortiGate 100d with 13 FortiAP223b units. All AP' s are being managed by the FGT100d, there are two SSID being broadcast. When using wifi the connection to the AP is always very stable but the connection with some apps are not. For example it happens, when i am using the app " whatsup" to send messages, images and videos sometimes the messages are being send but images are not. What i am also experimenting is that when sending a message the delay after sending is more that 5 minutes. When doing the same without wifi so using the 3G mobile network the message is send and received within 10 seconds. Does anybody knows why this is happening and/or what i am doing wrong? Thank you.
4 REPLIES 4
AndreaSoliva
Contributor III

Hi difficult to say to less information availalbe but what you can do is following: - Check if you use on FGT and FAP newest release: FGT FortiOS 5.0.6 FAP FortiOS 5.0.7 - Check if you are using on your FortiGate Controller the right country this means: # config wireless-controller setting get After that you see the country. If this country does not reflect your country you HAVE TO change. To be able to change the country you have to delete ALL profiles first: # config wireless-controller wtp-profile # get # del [profile name] After that you can set the country: # set country [Country Code example for Switzerland " CH" ] # end - Do not use " automatic" profile. Create you own profile for you needs. Profiles can be done over Gui. On CLi the command to create a profile is: # config wireless-controller wtp-profile NOTE in the first view do not config DTLS within CAPWAP! Look that you use 5 GHz instead of 2.4 GHz. If you use 2.4 GHZ look that choosen channels are in your env not in use. Between channels leave a space of 3 unused channels. - Do not forgett to attache the profile to your FAP which can be done over the GUI. Over cli you do it with following command: # config wireless-controller wtp # edit [FAP] # set wtp-profile [Name of profile] - After that set MTU size for CAPWAP to prevent defragmentation: # config wireless-controller wtp-profile # edit [Wähle das entsprechende Profile] # set ip-fragment-preventing [tcp-mss-adjust | icmp-unreachable] # set tun-mtu-uplink [0 | 576 | 1500] # set tun-mtu-downlink [0 | 576 | 1500] # end # end NOTE if you use at least DTLS keep in mind that you need addtional Data which means I would beginn with 1492 but it depends. At least I have to say this is only a recommendation. A lot of people mean Wirless is used " out of the box no problems easy is the same as I use at home" . This is clear not the case. Thee are many factors which can prevent good performance etc. hope this helps. have fun Andrea
jtfinley

Andrea - I like your recommendations. Where did you come across these settings, experience or best practice document?
Niesten
New Contributor

Hello Andrea, Thank you for your reply. I had change the settings as you required. And it seems to resolve some problems. Indeed the country was incorrect, it was configured on US. So I changed it to NL, the " ip-fragment-preventing tcp-mss-adjust icmp-unreachable" setting was added as well. I also set the " tun-mtu-uplink" and " tun-mtu-downlink" to " 1500" . The communication seems to be better, the whatsup application on the iPhone is working like it suppose to. The migration is planned on the 24th of March, so i am hoping to have solved all the WIFI problems on time. Thank you. Regards! Erwin
AndreaSoliva
Contributor III

Hi I' m working for a distributor supporting our customers. This with the country is something which is often overlooked by customer to have the country set correctly which is in our country Switzerland very important because if you do not so in Switzerland you pay a penalty of about 3500 CHF :-) To set the country at first stage is described in the PDF of FAP' s at first stage but it can be overlooked. A best practice does actually not exist it means to do the profiles manually is absolutly recommended but to do so you should know WHAT EACH positions means and how Wireless is working. Hope this helps have fun Andrea
Labels
Top Kudoed Authors