Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Boosted
New Contributor

Fortiwifi 90d configuring FortiAP's on Internal1 subnet

I would like to add my 2 FortiAP 221c's to the 10.6.10.0 network with IP's 10.6.10.4 and 10.6.10.5 but still carry the wireless subnets of 10.6.30.0 and 10.6.40.0. Does anyone know how I can accomplish this?

8 REPLIES 8
Toshi_Esumi
SuperUser
SuperUser

I think you already figured out how to set up tunnel mode SSIDs with separate subnets based on the interface screen you attached. They're just interfaces so that you can build policy sets to wherever you want to connect them to.

Boosted
New Contributor

But I want the actual AP's themselves to have the 10.6.10.4 and 10.6.10.5 IP addresses. Currently I have one set as static with the 10.6.10.4 and it doesn't work. The other one I plugged it in with no configuration and it works but its on a 169.254.1.0 network.

Boosted

Here is a screenshot of the settings in the AP I gave the Static IP to. It auto generated the 169.254.2.1 IP and won't let me change it to 10.6.10.1...

Toshi_Esumi

What version of firmware is running on FAP221C and FG90D?

Boosted

FG90D - v5.2.4,build688

Both AP's - v5.2,build245

Toshi_Esumi

I tested a little with FG60D(5.2.3) and FAP221B(5.2.4) with static IP on the FAP. It connects just fine with the IP I configured. Are you sure you allowed "capwap" tunnel on your internal1 interface, where you're intending to terminate the tunnels from those APs?

Boosted

Is your 60D a PoE? I think I've come to the conclusion it's impossible unless I start all over and put the Fortigate back into "Switch Mode" and implement a VLAN switch to communicate between the 2 ports. I've factory reset the AP that I added the static address to and I'm going to use the "Zero Configuration" mode for now. As soon as I get a spare 90D to play with I'm going to try it in "Switch Mode". Thanks for all your help!

Toshi_Esumi

No PoE. Using an ac power adapter. I don't know about 90D but with 60D it changed the internal switch configuration after 5.2.2 or 5.2.3. So all internal interfaces (7 of them) are bound to "internal" with hard-switch(virtual-switch). I split it to have a different virtual-switch interface for APs.

Labels
Top Kudoed Authors