FCSS_LED_AR-7.6 · Question #73
APs have been manually configured to connect to FortiGate over an IPsec network, and FortiGate successfully detects and authorizes them. However, the APs remain unmanaged because FortiGate is unable…
The correct answer is B. Assign a custom AP profile for the remote APs with the set mpls-connection option enabled. When FortiAPs connect to FortiGate overIPsec tunnels, this is treated similarly to WAN/MPLS In these scenarios, FortiGate must know that CAPWAP must traverse anon-L2transport. FortiAP profiles include: set mpls-connection enable This setting is required so that: FortiGate can…
Question
APs have been manually configured to connect to FortiGate over an IPsec network, and FortiGate successfully detects and authorizes them. However, the APs remain unmanaged because FortiGate is unable to establish a CAPWAP tunnel with them. What configuration change can resolve this issue and enable FortiGate to establish the CAPWAP tunnel over the IPsec connection?
Options
- AConfigure a static route on FortiGate to reach the APs over the IPsec tunnel.
- BAssign a custom AP profile for the remote APs with the set mpls-connection option enabled.
- CDecrease the CAPWAP tunnel MTU size for APs to prevent fragmentation.
- DUpgrade the FortiAP firmware image to ensure compatibility with the FortiOS version.
How the community answered
(31 responses)- A10% (3)
- B65% (20)
- C6% (2)
- D19% (6)
Explanation
When FortiAPs connect to FortiGate overIPsec tunnels, this is treated similarly to WAN/MPLS In these scenarios, FortiGate must know that CAPWAP must traverse anon-L2transport. FortiAP profiles include: set mpls-connection enable This setting is required so that: FortiGate can encapsulate CAPWAP inside the transport tunnel Remote FortiAPs can establish CAPWAP even when behind routed/IPsec networks Without this option, the FortiGate detects the AP butcannot bring CAPWAP UP, leaving the AP in "discovered/unauthorized" or "offline" state.
Topics
Community Discussion
No community discussion yet for this question.