WiFi network with wired LAN configuration
This section includes the following topics:
- How to combine a WiFi network and wired LAN with a software switch
- How to configure a FortiAP local bridge (private cloud-managed AP)
- How to increase the number of supported FortiAPs
How to combine a WiFi network and wired LAN with a software switch
A WiFi network can be combined with a wired LAN so that WiFi and wired clients are on the same subnet. This is a convenient configuration for users.
Software switches are only available if your FortiGate is in Interface mode.
Wireless Mesh features cannot be used in conjunction with this configuration because they enable the FortiAP Local Bridge option. |
To create the WiFi network and wired LAN configuration, you need to:
- Configure the SSID so that traffic is tunneled to the WiFi controller.
- Configure a software switch interface on the FortiGate unit with the WiFi and internal network interface as members.
- Configure Captive Portal security for the software switch interface.
To configure the SSID - GUI
- Go to WiFi and Switch Controller > SSIDs and select Create New.
- Complete the following fields:
Interface name
A name for the new WiFi interface.
Traffic Mode
Local bridge with FortiAP interface.
SSID
The SSID visible to users.
Security Mode
Configure security as you would for a regular WiFi network.
Pre-shared Key
A network access key for the SSID.
- Click OK.
- Go to WiFi and Switch Controller > Managed FortiAPs, select the FortiAP unit for editing.
- Authorize the FortiAP unit.
The FortiAP unit can carry regular SSIDs in addition to the Bridge SSID.
To configure the SSID - CLI
This example creates a WiFi interface “homenet_if” with SSID “homenet” using WPA-Personal security, passphrase “Fortinet1234”.
config wireless-controller vap
edit "homenet_if
"
set vdom "root"
set ssid "homenet
"
set security wpa-personal
set passphrase "Fortinet1234"
end
config wireless-controller wtp
edit FAP22B3U11005354
set admin enable
set vaps "homenet_if
"
end
To configure the FortiGate software switch - GUI
- Go to Network > Interfaces and select Create New > Interface.
- Complete the following fields:
Interface Name
A name for the new interface. For example,
homenet_nw
.Type
Software Switch
Physical Interface Members
Add homenet_if and the internal network interface.
Addressing mode
Select Manual and enter an address, for example
172.16.96.32/255.255.255.0
DHCP Server
Enable and configure an address range for clients.
Security Mode
Select Captive Portal. Add the permitted User Groups.
- Select OK.
To configure the FortiGate software switch - CLI
config system interface
edit homenet_nw
set ip 172.16.96.32 255.255.255.0
set type switch
set security-mode captive-portal
set security-groups "Guest-group"
end
config system interface
edit homenet_nw
set member "homenet_if" "internal"
end
VLAN configuration
If your environment uses VLAN tagging, you assign the SSID to a specific VLAN in the CLI. See Reserved VLAN IDs. For example, to assign the homenet_if interface to VLAN 100, enter:
config wireless-controller vap
edit "homenet_if
"
set vlanid 100
end
Additional configuration
The configuration described above provides communication between WiFi and wired LAN users only. To provide access to other networks, create appropriate firewall policies between the software switch and other interfaces.