Hello All,
I have a Fortigate 60F connected to a Ubiquiti switch, using Ubiquiti Access Points. On the Ubiquiti, I have configured my main network (works without issue), as well as 2 VLANs. I am attempting to connect to one of those VLANs and it seems I can connect to the wireless part of it, but I can't get a DHCP address from either the Fortigate or from my Windows DHCP server when using the "Relay" mode on the Fortigate to assign the address.
There's no option on the Ubiquiti Cloud Controller to define a DHCP Server, so I am assuming that it just lets the client connect to another device that's on the same VLAN to request the DHCP response. However, that does not seem to be happening.
Until I can afford to go all Fortinet (hopefully in a few months) with a Fortigate, Fortiswitches, and FortiAPs, this is the configuration I have.
Has anyone else run into this? The network I am trying to connect on is a VLAN (guest network, testing so when people come over they are not on my main home domain). From what I can see in the logs, the request is sent, but the Fortigate doesn't seem to be sending that request anywhere, even if it's on the device itself.
Hi @jdsauer77
First thing I'd do is set a static IP for my client in the right subnet and try ping my gateway.
If it works I'm in the right VLAN, otherwise something wrong somewhere at L2 level.
Created on ‎08-11-2025 08:30 AM Edited on ‎08-11-2025 08:30 AM
that and i would also check if there is a firewall policy in place to allow DHCP traffic towards the Win Server with DHCP if they are in different VLANs since you configured with Relay, otherwise if they are in the same VLAN no need for it and the broadcast should reach it, in which case tshoot the server.
as AEK mentioned, try setting a static IP and check reachability then change focus on fw rules if any required.
Hi @jdsauer77,
Can you make sure that the user is connected to the correct VLAN? You can also run DHCP debugs to see if FortiGate is receiving DHCP requests or not. https://community.fortinet.com/t5/FortiGate/Technical-Tip-Diagnosing-DHCP-on-a-FortiGate/ta-p/192960
Regards,
I'm having the exact same issue at a client. It seems the Cloud Key does not have the ability to work in this fashion. I have not been able to find any other solutions/work arounds.
I am also running into this issue. The way around it I have found is for the AP Native VLAN create a scope on the switch directly and turn it off for that VLAN on the Fortinet. In some of our smaller clients that have no DHCP servers but we want to have multiple VLANs for several reasons but do not want any type of traffic isolation, I created the scopes on the switches. We then have an isolated vlan to the fortinet that internet bound traffic goes through. This works flawlessly with the Ubiquiti devices.
User | Count |
---|---|
2559 | |
1356 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.