Hi,
Our network consists of 26 access points, a combination of FAP431G, FAP433F and FAP431F, it is pretty much perfect since it was installed 6 months ago, accept for one odd issue.
Every now and then one of the APs will decide it no longer like Apple devices at which point none of the ones we have (A brand new iPad and several generations of MacBook) simply won't connect, it's just happened again now with the tablet reporting an incorrect password.
When this is happening if the devices are taken in range of another AP they work just fine and android / Windows devices continue to work just fine on the AP that is not working for the Macs.
We have a number of SSID's, one using Radius authentication and the rest standard password auth and it effects both.
A restart of the effected AP resolves the problem.
Any ideas on what might be the cause of this are welcome.
Thanks
Wifi event logs with timestamps when such disconnects were observed - would be a good starting point to find the root cause (FortiGate GUI -> Log & report -> Event logs -> wifi logs). One possible reason for this issue could be load balancing not working optimally, few documents for reference on this and what logs to look for:
Created on 08-14-2025 08:26 AM Edited on 08-14-2025 11:45 PM
Thanks for that, I'll have a read of those pages.
In terms of logging I'm not seeing anything with a higher status than warning, and those are.
However the MAC address's it lists against those messages don't show in my client list (According to various MAC lookup sites, they are not even valid address's)
Next time when the issue happens, a wlac debug (with mac address filter) can be run for a couple of the Apple MAC addresses while they are still having the issue (before they are moved near a different AP), and continue to run the debugs when they successfully connect to the new AP (so that these debugs can be compared to the connection to the previous AP). Below article describes how to setup these debugs on FortiGate CLI.
Regarding the invalid MAC addresses, you could run the same wlac debugs in the above article with mac filter for a few of those MAC addresses to find out more details on them.
I assume the FortiAP and FortiGate firmware versions are latest since they were deployed just 6 months ago, but that's one thing to check to ensure the versions are compatible and not running an old version.
Regards,
Rudresh
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.