Creating SSIDs
When creating a new SSID, the available options will change depending on the selected traffic mode: Tunnel , Bridge, or Mesh.
When you create SSID profiles, you can select a QoS profile and/or an Access Control List profile.
For information on the settings available while creating SSIDs, see the FortiAP/FortiWiFi documentation on the Fortinet Document Library.
To create a new SSID:
-
Go to AP Manager.
-
In the tree menu, go to Wifi Profiles > SSID.
-
In the toolbar, click Create New > SSID. The Create New SSID Profile windows opens.
-
Enter the following information, then click OK to create the new tunnel to wireless controller SSID:
Name
Type a name for the SSID.
Alias
Set the alias for SSID.
Traffic Mode
Select the traffic mode: Tunnel, Bridge, or Mesh.
Address
These options are only available when Traffic Mode is Tunnel.
IP/Network Mask
Enter the IP address and netmask.
IPv6 Address
Enter the IPv6 address.
Restrict Access
Administrative Access
Select the allowed administrative service protocols.
IPv6 Administrative Access
Select the allowed administrative service protocols.
DHCP Server
Turn the DHCP server on or off.
Networked Devices
Device Detection
Detect connected device type.
WiFi Settings
SSID
Type the wireless service set identifier (SSID), or network name, for this wireless interface. Users who want to use the wireless network must configure their computers with this network name.
Security Mode
Select a security mode:
Captive Portal
OSEN
OWE
Open
WEP 128-bit WEP 64-Bit WPA Enterprise WPA Personal WPA Personal with Captive Portal WPA/WPA2 Enterprise WPA/WPA2 Personal WPA/WPA2 Personal with Captive Portal WPA2 Enterprise WPA2 Personal WPA2 Personal with Captive Portal WPA3 Enterprise WPA3 Enterprise (PMF Protection) WPA3 Enterprise Transition WPA3 SAE WPA3 SAE Transition Only Open, WPA/WPA2 Personal, and WPA2 Personal modes are available when the traffic mode is Mesh.
Local Standalone
Enable/disable AP local standalone (default = disable).
This option is only available when the traffic mode is Bridge.
Local Authentication
Enable/disable AP local authentication.
This option is only available when the traffic mode is Bridge.
Client Limit
The maximum number of clients that can simultaneously connect to the AP (0 - 4294967295, default = 0, meaning no limitation).
Pre-shared Key Mode
Select Single to specify a single passphrase.
Select Multiple to specify a multiple pre-shared key group.
Passphrase
When Pre-shared Key Mode is set to Single, enter the pre-shared key for the SSID.
This option is only available when the security mode includes WPA or WPA2 personal.
Broadcast SSID
Enable/disable broadcasting the SSID (default = enable).
Broadcasting enables clients to connect to the wireless network without first knowing the SSID. For better security, do not broadcast the SSID.
Schedule
Select a schedule to control the availability of the SSID. For information on creating a schedule object, see Create a new object.
Block Intra-SSID Traffic
Enable/disable blocking communication between clients of the same AP (default = disable).
Optional VLAN ID
Enter the ID of the VLAN this SSID belongs to. Enter 0 for non-VLAN operation.
Broadcast Suppression
Enable and add broadcasts you want to suppress.
Filter Clients by MAC Address
Enable/disable using a RADIUS server to filter clients be MAC address, then select the server from the dropdown list. See RADIUS servers for information on adding a RADIUS server.
VLAN Pooling
Enable/disable VLAN pooling, allowing you to group multiple wireless controller VLANs into VLAN pools. These pools are used to load-balance sessions evenly across multiple VLANs.
- Managed AP Group: Select devices to include in the group.
- Round Robin
- Hash
This option is not available when the traffic mode is Mesh.
Quarantine Host
Enable/disable station quarantine (default = enable).
This option is only available when the security mode includes WPA or WPA2.
Encrypt
Select the data encryption protocol:
- TKIP: Temporal Key Integrity Protocol, used by the older WPA standard.
- AES: Advanced Encryption Standard, commonly used with the newer WPA2 standard (default).
- TKIP-AES: Use both protocols to provide backward compatibility for legacy devices. This option is not recommended, as attackers will only need to breach the weaker encryption of the two (TKIP).
This option is only available when the security mode includes WPA or WPA2.
QoS Profile
Select the QoS profile from the dropdown list. See QoS profiles.
L3 Firewall Profile
Select the L3 Firewall profile from the dropdown list. See L3 Firewall Profiles.
Client Limit per Radio
The maximum number of clients that can simultaneously connect to each radio (0 - 4294967295, default = 0, meaning no limitation).
This option is only available when Local Standalone is enabled.
Multiple Pre-Shared Keys
Enable/disable multiple pre-shared keys.
In the table, click Create to create a new key. Enter the key name, value, client limit, and comments (optional), then click OK. Click Edit to edit the selected key. Click Delete to delete the selected key or keys.
This option is only available when the security mode includes WPA or WPA2 personal and the traffic mode is not Mesh.
Default Client Limit Per Key
Enable/disable a maximum number of clients that can simultaneously connect using each pre-shared key, then enter the maximum number.
This option is only available when the Multiple Pre-Shared Keys is enabled.
Portal Type
Select the portal type: Authentication (default), Disclaimer + Authentication, Disclaimer Only, or Email Collection.
This option is only available when the security mode includes Captive Portal.
Authentication Portal
Select Local or External. If External is selected, enter the URL of the portal.
This option is only available when the portal type includes authentication.
User Groups
Select the user group to add from the dropdown list. Select the plus symbol to add multiple groups.
This option is only available when the portal type includes authentication.
Exempt Sources
Select exempt sources to add from the dropdown list.
This option is only available when the portal type includes authentication.
Devices
Select exempt devices to add from the dropdown list.
This option is only available when the portal type includes authentication.
Exempt Destinations
Select exempt destinations to add from the dropdown list.
This option is only available when the portal type includes authentication.
Exempt Services
Select exempt services to add from the dropdown list.
This option is only available when the portal type includes authentication.
Customize Portal Messages
Select to allow for customized portal messages. Portal messages cannot be customized until after the interface has been created.
This option is only available when the portal type includes disclaimer, email collection, or CMCC without MAC authentication.
Redirect after Captive Portal
Select Original Request or Specific URL. If Specific URL is selected, enter the redirect URL.
This option is only available when the security mode includes captive portal.
Authentication
Select the authentication method for the SSID, either Local or RADIUS Server, then select the requisite server or group from the dropdown list.
This option is only available when the security mode includes WPA or WPA2 enterprise.
Additional AKMs
Use AKM suite employing SHA256 keys.
This option is only available when the security mode includes WPA3 Enterprise Transition or WPA3 SAE Transition.
Advanced Options
Configure advanced options. For information, see the FortiOS CLI Reference.
Per-Device Mapping
Enable per-device mapping to override the SSID profile settings for selected devices. See Adding SSID per-device mapping.
If you select WPA Enterprise, WPA Only Enterprise, or WPA2 Only Enterprise, you can add a different RADIUS server using per-device mapping. See Adding SSID per-device mapping. |