Fortinet white logo
Fortinet white logo

FortiWiFi and FortiAP Configuration Guide

WiFi data channel encryption

WiFi data channel encryption

Optionally, you can apply DTLS encryption to the data channel between the wireless controller and FortiAP units to enhance security.

There are data channel encryption settings on both the FortiGate unit and the FortiAP units. At both ends, you can enable Clear Text, DTLS encryption, or both. The settings must agree or the FortiAP unit will not be able to join the WiFi network. By default, both Clear Text and DTLS-encrypted communication are enabled on the FortiAP unit, allowing the FortiGate setting to determine whether data channel encryption is used. If the FortiGate unit also enables both Clear Text and DTLS, Clear Text is used.

Data channel encryption settings are located in the FortiAP profile. By default, only Clear Text is supported.

Note

Data channel encryption is software-based and can affect performance. Verify that the system meets your performance requirements with encryption enabled.

Configuring encryption on a FortiGate unit

You can configure data channel encryption from a FortiAP profile. For more information about encryption options, see Data channel security: clear-text, DTLS, and IPsec VPN

To enable encryption - CLI:

In the CLI, the wireless wtp-profile command contains a dtls-policy field, with the following options

  • clear-text (non-encrypted)
  • dtls-enabled
  • ipsec-vpn
  • ipsec-vpn-sn

To enable encryption in profile1 for example, enter:

config wireless-controller wtp-profile

edit profile1

set dtls-policy dtls-enabled

end

To enable encryption - GUI:

To configure encryption from the GUI, you must enable Advanced Wireless Features (see Advanced Wireless Features).

  1. Once you enable Advanced Wireless Features, navigate to WiFi & Switch Controller > Operation Profiles > FortiAP Profiles.
  2. Select the profile you want to enable encryption on.
  3. Under Advanced Settings, select the DTLS policy you want to apply to the profile.
  4. When you are finished, click OK.

Configuring encryption on a FortiAP unit

The FortiAP unit has its own settings for data channel encryption.

To enable CAPWAP encryption - FortiAP GUI:
  1. On the System Information page, in WTP Configuration > AC Data Channel Security, select one of:
    • Clear Text
    • DTLS Enabled
    • Clear Text or DTLS Enabled (default)
  2. Select Apply.
To enable encryption - FortiAP CLI:

You can set the data channel encryption using the AP_DATA_CHAN_SEC variable: 'clear', 'ipsec', 'ipsec-sn, or 'dtls'.

For example, to set security to DTLS and then save the setting, enter:

cfg -a AP_DATA_CHAN_SEC=dtls

cfg -c

WiFi data channel encryption

WiFi data channel encryption

Optionally, you can apply DTLS encryption to the data channel between the wireless controller and FortiAP units to enhance security.

There are data channel encryption settings on both the FortiGate unit and the FortiAP units. At both ends, you can enable Clear Text, DTLS encryption, or both. The settings must agree or the FortiAP unit will not be able to join the WiFi network. By default, both Clear Text and DTLS-encrypted communication are enabled on the FortiAP unit, allowing the FortiGate setting to determine whether data channel encryption is used. If the FortiGate unit also enables both Clear Text and DTLS, Clear Text is used.

Data channel encryption settings are located in the FortiAP profile. By default, only Clear Text is supported.

Note

Data channel encryption is software-based and can affect performance. Verify that the system meets your performance requirements with encryption enabled.

Configuring encryption on a FortiGate unit

You can configure data channel encryption from a FortiAP profile. For more information about encryption options, see Data channel security: clear-text, DTLS, and IPsec VPN

To enable encryption - CLI:

In the CLI, the wireless wtp-profile command contains a dtls-policy field, with the following options

  • clear-text (non-encrypted)
  • dtls-enabled
  • ipsec-vpn
  • ipsec-vpn-sn

To enable encryption in profile1 for example, enter:

config wireless-controller wtp-profile

edit profile1

set dtls-policy dtls-enabled

end

To enable encryption - GUI:

To configure encryption from the GUI, you must enable Advanced Wireless Features (see Advanced Wireless Features).

  1. Once you enable Advanced Wireless Features, navigate to WiFi & Switch Controller > Operation Profiles > FortiAP Profiles.
  2. Select the profile you want to enable encryption on.
  3. Under Advanced Settings, select the DTLS policy you want to apply to the profile.
  4. When you are finished, click OK.

Configuring encryption on a FortiAP unit

The FortiAP unit has its own settings for data channel encryption.

To enable CAPWAP encryption - FortiAP GUI:
  1. On the System Information page, in WTP Configuration > AC Data Channel Security, select one of:
    • Clear Text
    • DTLS Enabled
    • Clear Text or DTLS Enabled (default)
  2. Select Apply.
To enable encryption - FortiAP CLI:

You can set the data channel encryption using the AP_DATA_CHAN_SEC variable: 'clear', 'ipsec', 'ipsec-sn, or 'dtls'.

For example, to set security to DTLS and then save the setting, enter:

cfg -a AP_DATA_CHAN_SEC=dtls

cfg -c