Fortinet white logo
Fortinet white logo

CLI Reference

config ap-security

config ap-security

Description: Configure security mode for WiFi access point.

config wifi
  config vap
    edit <WiFi Access Point Name>
      config ap-security
        set security-mode <encryption mode>
        set pmf <option>
        set passphrase <password>
        set auth-server-addr <url>
        set auth-server-port <port number>
        set auth-server-secret <password>
      end
    next
  end
end
Sample command
config wifi vap
    edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Enterprise
            set auth-server-addr 192.168.11.99
            set auth-server-port 1812
            set auth-server-secret ******
            set pmf optional
        end
    next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf disabled
            set passphrase ******
        end
    next
end
Parameter Description Type Size Default
security-mode

Select which security mode to use.

option -

Option Description

OPEN

Wi-Fi security OPEN

WPA2-Personal

Wi-Fi security WPA2 Personal

WPA-WPA2-Personal

Wi-Fi security WPA-WPA2 Personal

WPA3-SAE

Wi-Fi security WPA3 SAE

WPA3-SAE-Transition

Wi-Fi security WPA3 SAE Transition

WPA2-Enterprise

Wi-Fi security WPA2 Enterprise

WPA3-Enterprise-Only

Wi-Fi security WPA3 Enterprise only

WPA3-Enterprise-Transition

Wi-Fi security WPA3 Enterprise Transition

WPA3-Enterprise-192-bit

Wi-Fi security WPA3 Enterprise 192-bit

pmf

Protected Management Frames (PMF) support.

This option is available if security-mode is set to OPEN, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or WPA3-SAE-Transition.

option -

Option Description

disabled

Disable PMF completely.

required

Enable PMF and deny clients without PMF.

optional

Enable PMF and allow clients without PMF.
passphrase

WPA pre-shared key (PSK) to be used to authenticate WiFi users.

This option is available if security-mode is set to WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or or WPA3-SAE-Transition.

password
auth-server-addr

Wi-Fi Authentication Server Address (IPv4 format).

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

string
auth-server-port

Wi-Fi Authentication Server Port.

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

integer 1812
auth-server-secret

Wi-Fi Authentication Server Secret.

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

string

config ap-security

config ap-security

Description: Configure security mode for WiFi access point.

config wifi
  config vap
    edit <WiFi Access Point Name>
      config ap-security
        set security-mode <encryption mode>
        set pmf <option>
        set passphrase <password>
        set auth-server-addr <url>
        set auth-server-port <port number>
        set auth-server-secret <password>
      end
    next
  end
end
Sample command
config wifi vap
    edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Enterprise
            set auth-server-addr 192.168.11.99
            set auth-server-port 1812
            set auth-server-secret ******
            set pmf optional
        end
    next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf disabled
            set passphrase ******
        end
    next
end
Parameter Description Type Size Default
security-mode

Select which security mode to use.

option -

Option Description

OPEN

Wi-Fi security OPEN

WPA2-Personal

Wi-Fi security WPA2 Personal

WPA-WPA2-Personal

Wi-Fi security WPA-WPA2 Personal

WPA3-SAE

Wi-Fi security WPA3 SAE

WPA3-SAE-Transition

Wi-Fi security WPA3 SAE Transition

WPA2-Enterprise

Wi-Fi security WPA2 Enterprise

WPA3-Enterprise-Only

Wi-Fi security WPA3 Enterprise only

WPA3-Enterprise-Transition

Wi-Fi security WPA3 Enterprise Transition

WPA3-Enterprise-192-bit

Wi-Fi security WPA3 Enterprise 192-bit

pmf

Protected Management Frames (PMF) support.

This option is available if security-mode is set to OPEN, WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or WPA3-SAE-Transition.

option -

Option Description

disabled

Disable PMF completely.

required

Enable PMF and deny clients without PMF.

optional

Enable PMF and allow clients without PMF.
passphrase

WPA pre-shared key (PSK) to be used to authenticate WiFi users.

This option is available if security-mode is set to WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or or WPA3-SAE-Transition.

password
auth-server-addr

Wi-Fi Authentication Server Address (IPv4 format).

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

string
auth-server-port

Wi-Fi Authentication Server Port.

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

integer 1812
auth-server-secret

Wi-Fi Authentication Server Secret.

This option is available if security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, or WPA3-Enterprise-192-bit.

string