Configuring a WiFi LAN

Defining SSID Groups

Optionally, you can define SSID Groups. An SSID Group has SSIDs as members and can be specified just like an

SSID in a FortiAP Profile.

 

To create an SSID Group – GUI

Go to WiFi & Switch Controller > SSID and select Create New > SSID Group. Give the group a Name and choose Members (SSIDs, but not SSID Groups).

 

To create an SSID Group – CLI:

config wireless-controller vap-group edit vap-group-name

set vaps “ssid1” “ssid2” end

 

Dynamic user VLAN assignment

Clients connecting to the WiFi network can be assigned to a VLAN. You can do this with RADIUS attributes when the user authenticates or with VLAN pooling when the client associates with a particular FortiAP. You cannot use both of these methods at the same time.

 

VLAN assignment by RADIUS

You can assign each individual user to a VLAN based on information stored in the RADIUS authentication server. If the user’s RADIUS record does not specify a VLAN ID, the user is assigned to the default VLAN for the SSID.

The RADIUS user attributes used for the VLAN ID assignment are: IETF 64 (Tunnel Type)—Set this to VLAN. IETF 65 (Tunnel Medium Type)—Set this to 802

 

IETF 81 (Tunnel Private Group ID)—Set this to the VLAN ID. To configure dynamic VLAN assignment, you need to:

1. Configure access to the RADIUS server.

2. Create the SSID and enable dynamic VLAN assignment.

3. Create a FortiAP Profile and add the local bridge mode SSID to it.

4. Create the VLAN interfaces and their DHCP servers.

5. Create security policies to allow communication from the VLAN interfaces to the Internet.

6. Authorize the FortiAP unit and assign the FortiAP Profile to it.

 

 

To configure access to the RADIUS server

1. Go to User & Device > RADIUS Servers and select Create New.

2. Enter a Name, the name or IP address in Primary Server IP/Name, and the server secret in Primary Server

Secret.

3. Select OK.

 

To create the dynamic VLAN SSID

1. Go to WiFi & Switch Controller > SSID, select Create New > SSID and enter:

Name                                           An identifier, such as dynamic_vlan_ssid.

Traffic Mode                              Local bridge or Tunnel, as needed.

SSID                                            An identifier, such as DYNSSID.

Security Mode                           WPA2 Enterprise

Authentication                           RADIUS Server. Select the RADIUS server that you configured.

2. Select OK.

3. Enable dynamic VLAN in the CLI. Optionally, you can also assign a VLAN ID to set the default VLAN for users without a VLAN assignment.

config wireless-controller vap edit dynamic_vlan_ssid

set dynamic-vlan enable set vlanid 10

end

 

To create the FortiAP profile for the dynamic VLAN SSID

1. Go to WiFi & Switch Controller > FortiAP Profiles, select Create New and enter:

Name                                           A name for the profile, such as dyn_vlan_profile.

Platform                                      The FortiAP model you are using. If you use more than one model of

FortiAP, you will need a FortiAP Profile for each model.

Radio 1 and Radio 2

SSID                                            Select the SSID you created (example dynamic_vlan_ssid). Do not add other SSIDs.

2. Adjust other radio settings as needed.

3. Select OK.

 

To create the VLAN interfaces

1. Go to Network > Interfaces and select Create New > Interface.

2. Enter:

 

Name                                           A name for the VLAN interface, such as VLAN100.

Interface                                     The physical interface associated with the VLAN interface.

VLAN ID                                      The numeric VLAN ID, for example 100.

Addressing mode                     Select Manual and enter the IP address / Network Mask for the virtual inter- face.

DHCP Server                              Enable and then select Create New to create an address range.

3. Select OK.

4. Repeat the preceding steps to create other VLANs as needed.

Security policies determine which VLANs can communicate with which other interfaces. These are the simple Firewall Address policy without authentication. Users are assigned to the appropriate VLAN when they authenticate.

 

To connect and authorize the FortiAP unit

1. Connect the FortiAP unit to the FortiGate unit.

2. Go to WiFi & Switch Controller > Managed FortiAPs.

3. When the FortiAP unit is listed, double-click the entry to edit it.

4. In FortiAP Profile, select the FortiAP Profile that you created.

5. Select Authorize.

6. Select OK.


Having trouble configuring your Fortinet hardware or have some questions you need answered? Check Out The Fortinet Guru Youtube Channel! Want someone else to deal with it for you? Get some consulting from Fortinet GURU!

One thought on “Configuring a WiFi LAN

  1. starking9b

    thank you very much about this helpful article
    but if there is any php script which you can insert into the article to help me send data from external portal to fortigate
    it willl be more helpful

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.