Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
koli
New Contributor

iPhone connected but no Internet Access

Hi Forti People, I am a new member of Fortinet Family and it is great device Fortiwifi 60D, but I need your help. I created my WIFI SSID and computer and for example Apple TV are just coming fine in the Internet but my iPhone does not. Interesting is when I use default "fortinet" connection iPhone can access the Internet. All other LAN connected devices have their own subnet and works just fine. Only iPhone 7 connects but no access to the Internet. I read many posts but I still haven't figured it out how to solve this problem. Please help. Thanks!

1 Solution
Dave_Hall
Honored Contributor

A laundry list of possible troubleshooting steps:

[ul]
  • Confirm via "Monitor->WiFi Client Monitor" that the device(s) in question are able to connect then confirm they are receiving a valid IPs.
  • Confirmed the fgt is hand out proper IP address info - Check the wifi (e.g. fortinet) interface to see the proper IP/subnet mask/gateway address, DNS info is correct. 
  • From the "Monitor->DHCP Monitor" section confirm you can see the device(s)'s IP address.
  • From the CLI see if you can ping the device(s)' IP.  Likewise from the device - there should be some simple ping tools for pinging the fgt's IP.
  • On the wifi (e.g. "fortinet") interface, enable "Device Detection" then check "User & Device->Device Inventory" to see if the fgt can detect the device.
  • In FortiView. under "Sources" locate the device(s) in question, right-click on one and choose "Drill down to details" - here you have a lot of options to see if the device(s) is getting blocked for some reason.[/ul]

    And of course, there is the "catch-all simple fix" - telling the device to "forget this network" then rescan for it, join it and enter new password.

  • NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    View solution in original post

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    5 REPLIES 5
    Not applicable

    Hi Koli!

    This is not the right forum for Secure Access questions, because this is for FortiADC forum. Your topic is related to Secure Access and it is part of FortiGate functionalities, so maybe you can find a more suitable forum for your question.

     

    Regarding your issue, have you tried following this video on ho to configure Secure Access using FortiGate?

    https://www.youtube.com/watch?v=bFYlr33NOBY

     

    There are many more videos in YouTube depending on your FortiOS version, but the workflow is very similar.

     

    Make sure:

    - You've created an SSID

    - You've created a VLAN for wireless traffic

    - You've assigned the VLAN to FortiSwitch ports where APs are being connected

    - You've created a firewall policy to allow traffic from your wireless VLAN to the Internet

     

    Hope it helps.

     

    Regards

     

    koli
    New Contributor

    Hi Barak, thanks for your answer. 

     

    Everything You said I actually have already done.

     

    What's confusing here is the fact that other wireless devices - laptop and apple tv are just working fine on the same SSID. 

     

    On the other hand, default "fortinet" WLAN connection works just fine - straight after factory reset and WAN configuration. That's it. 

     

    It is only the lack of knowledge :(

     

    Thank You and hope I figure it out these days.

     

     

    Dave_Hall
    Honored Contributor

    A laundry list of possible troubleshooting steps:

    [ul]
  • Confirm via "Monitor->WiFi Client Monitor" that the device(s) in question are able to connect then confirm they are receiving a valid IPs.
  • Confirmed the fgt is hand out proper IP address info - Check the wifi (e.g. fortinet) interface to see the proper IP/subnet mask/gateway address, DNS info is correct. 
  • From the "Monitor->DHCP Monitor" section confirm you can see the device(s)'s IP address.
  • From the CLI see if you can ping the device(s)' IP.  Likewise from the device - there should be some simple ping tools for pinging the fgt's IP.
  • On the wifi (e.g. "fortinet") interface, enable "Device Detection" then check "User & Device->Device Inventory" to see if the fgt can detect the device.
  • In FortiView. under "Sources" locate the device(s) in question, right-click on one and choose "Drill down to details" - here you have a lot of options to see if the device(s) is getting blocked for some reason.[/ul]

    And of course, there is the "catch-all simple fix" - telling the device to "forget this network" then rescan for it, join it and enter new password.

  • NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

    NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
    sw2090
    SuperUser
    SuperUser

    Annother thing could be the "I need to check if I have internet access" thing. Many mobile devices like cellphones do that when they connect to a wlan. THey want to access a specific url to check their internet access. If that fails they consider themselves as offline (even if they aren't).

    If you use UTM like URL-Filter and/or Webfilter check that those are not blocked.

    -- 

    "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams

    -- "It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
    lawrence

    Hello, you could have a try these following methods to get your problem resolved.

    1. Force restart iPhone.

    2. Toggle Airplane Mode on and off.

    3. Reset network settings. Settings > General > Reset.

    4. To fix iPhone network issue, try to fix IOS system without data loss.

    Announcements

    Select Forum Responses to become Knowledge Articles!

    Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

    Labels
    Top Kudoed Authors