Basic Settings
Configure the following basic settings for an SSID assigned to your network.
Field |
Description |
---|---|
SSID | Type a name for this wireless network. Wireless clients use this name to find and connect to this wireless network. |
Enabled | Select to have the SSID active. |
Broadcast SSID | Select to advertise the SSID. All wireless clients within range can see the SSID when they scan for available networks. |
Beacon Advertising |
You can enable the advertising of vendor specific elements in beacons that contain FortiAP information such as its name, model, and serial number. This enables administrators to easily identify the coverage areas using site surveys. Consider the following scenarios that use this feature effectively.
|
MAC Access Control |
Select to allow clients identified in the MAC address import list to connect to that SSID.
|
Mesh Link | Select to enable the mesh link. A wireless mesh eliminates the need for Ethernet wiring by connecting Wi-Fi APs to each other by radio. Only one AP (root AP) is connected to the wired network and all other APs (leaf APs) connect to this mesh root AP over the wireless backhaul SSID. This is supported for WPA3 - SAE, WPA2 - Personal, and Open modes of authentication. |
Data Encryption | When either of the mixed mode authentication methods are enabled, select a data encryption protocol: AES, TKIP, or TKIP-AES. |
Simple Multiple Pre-shared Keys (MPSK) |
Simple Multiple PSKs can also be configured for Personal SSIDs, in which case stations will be able to connect to an SSID using either a common PSK or their own PSK. You can select the configured schedule profile for activating multiple PSKs. For more information, see Schedule Profile. Note:A maximum of 128 multiple PSKs are allowed per SSID. |
MPSK |
You can create multiple pre-shared key groups to associate with VLANs; up to 16000 keys are supported per network. Adding MPSK Groups
Adding Pre-shared keys
|
RADIUS Authentication by |
The FortiAP acts as a RADIUS client and sends accounting information to the configured RADIUS server. This configuration parameter is applicable ONLY when the SSID operates in the OPEN security mode with external captive portal and RADIUS authentication and accounting parameters. When RADIUS Authentication by is enabled, the FortiAP redirects clients to the configured external captive portal, collects credentials and performs RADIUS authentication and accounting. When disabled (default), the legacy functionality continues where the FortiAP redirects all clients to a centralized FortiLAN Cloud which then redirects them to the configured external captive portal. When you enable RADIUS Authentication by, the following parameters become configurable.
Note: This feature is supported on FAP-S and FAP-W2 models with firmware versions 6.2 and 6.4. |
RADIUS Acct Settings |
Select the RADIUS profile for accounting. CoA is also supported and can be enabled in RADIUS Accounting profile. |
IP assignment |
Select Bridge or NAT. If you choose NAT, then complete the following:
|
QoS Profile |
If you want to apply a QoS profile that you have already created, select it from the list. |
VLAN ID |
If the IP assignment is Bridge, you can type the ID of the VLAN for your wireless network (SSID). To view the dynamic VLAN ID based on the FortiAP data, see Clients. |