question

kenleach avatar image
0 Likes"
kenleach asked

Can't get AP to Auth stuck on Waiting for Authorization

Trying to add my 1st AP (of many)
Powered by POW and connected to a switch that is connected to internal interface 2. I can see the AP and right click to register but it has been sitting there for 20 min. Orange light on the AP itself. "Waiting for Authorization" is all it says.
Is a connection from the firewall to Fabric Connector required?

FortiAP
10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

1 Answer

·
Metropolis avatar image
0 Likes"
Metropolis answered

Hello kenleach,

A connection from the FortiGate to the Fabric Connector is not required.

However, it is important to verify each of the following settings:

1. The FortiGate interface to which the FortiAP is connected is properly configured to accept CAPWAP traffic (CLI: set allowaccess fabric, GUI: Administrative Access with Security Fabric Connection selected).

2. The FortiAP has a valid IP address and valid connectivity to the FortiGate.

3. The FortiGate and FortiAP are using NTP time to ensure CAPWAP negotiation involving certificates completes successfully.

I suggest reviewing these pages:

https://docs.fortinet.com/document/fortiap/7.2.4/fortiwifi-and-fortiap-configuration-guide/252439/configuring-the-fortigate-interface-to-manage-fortiap-units

https://docs.fortinet.com/document/fortiap/7.2.4/fortiwifi-and-fortiap-configuration-guide/540137/discovering-authorizing-and-deauthorizing-fortiap-units

https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/512210/setting-the-system-time

(namely "Setup device as local NTP server")

If the FortiGate's interface has an IP address other than the default 192.168.1.99 for an internal interface, then you will need to log into the FortiAP GUI and configure the "AC IP address" to point to the actual IP address for the FortiGate's interface. You can use the steps here (https://docs.fortinet.com/document/fortiap/7.2.4/fortiwifi-and-fortiap-configuration-guide/66962/fortiap-cli-access) and use the same steps to connect your computer to the FortiAP and accessing the GUI via http://192.168.1.2 (FortiAP's default IP).

Hope this helps.

10 |600

Up to 8 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Write an Answer

Hint: Notify or tag a user in this post by typing @username.

Up to 10 attachments (including images) can be used with a maximum of 1.0 MiB each and 10.0 MiB total.

Welcome to FortiAnswers

FortiAnswers is the space dedicated to FortiSASE and FortiOS questions and suggestions.

  • Please review the Community guidelines
  • If you are a moderator, please refer to the Moderation guidelines
  • If something in the above guidelines is unclear, please post your question to the Community Feedback space or the Moderators' space