Fortinet black logo

New features or enhancements

New features or enhancements

The following table includes new features and enhancements in FortiAP-U version 6.2.4 when managed by a FortiGate running FortiOS version 6.2.4 and later, or by FortiLAN Cloud:

For FortiAP-U features managed by a FortiWLC, see the Wireless Controller documentation.

Bug ID

Description

587779

Support extension information of wtp, vap and station statistics.

670725

Support hexadecimal values of EddyStone namespace ID and instance ID in Bluetooth low energy (BLE) profile.

702730

FAP-U LAN port (in WAN-LAN mode) supports dynamic VLAN assignment with RADIUS MAC-address authentication.

738291

802.11ax FAP-U models in single-5G mode support dedicated dual-band scanning on the third radio.

739307

Support Service Assurance Manager (SAM) mode.

739314

FortiPresence PUSH API update: FortiAP sends its region map information to FortiPresence server for positioning wireless stations.

741443

FAP-U234F and FAP-U432F support indoor/outdoor country revision as configured from FortiGate.

Note: FortiGate needs to run FortiOS 7.2.0 and later.

747779

Improve connectivity to FortiGuard server for UTM update and query services.

763506

Support FQDN address of FortiPresence server

763507

From WiFi Controller wtp-profile configuration, FortiAP WAN port can be set as an 802.1X supplicant to authenticate to local infrastructure network using EAP protocols.

763510

Support DHCP address enforcement: Wireless clients must complete the DHCP process and obtain an IP address through FAP-U SSID; otherwise they are denied to connect.

766455

Support downloading firmware image from FortiLAN Cloud over HTTPS.

769599

Support the Federal Information Processing Standard (FIPS) validation.

771071

Support BSS coloring collision event log to FortiGate.

Note: FortiGate needs to run FortiOS 7.0.4, 7.2.0 and later.

Region/country code update and DFS certification

Bug ID

Description

754092

The region code of Israel is changed from "I" to "E" (for 802.11ax FAP-U models only); The default country of region "I" is set as Morocco.

758352

Enable DFS Channels on all FAP-U models with region code P.

Note: FortiGate needs to run FortiOS 7.0.4, 7.2.0 and later.

Changes in CLI

Bug ID

Description

745110

Support presult command output for troubleshooting uniformity; Add presult output to the fap-tech command.

763507

When WiFi Controller won't overwrite FortiAP WAN port authentication, FortiAP can configure its own 802.1X supplicant locally.

New cfg variables:

WAN_1X_ENABLE

WAN port 802.1x supplicant enable/disable

[0(Disabled), 1(Enabled)]. default=0

WAN_1X_USERID WAN port 802.1x supplicant user ID
WAN_1X_PASSWD WAN port 802.1x supplicant password

WAN_1X_METHOD

WAN port 802.1x supplicant EAP methods

[0(EAP-ALL), 1(EAP-FAST), 2(EAP-TLS), 3(EAP-PEAP)]. default=0

Diagnose command:

cw_diag -c wan1x
cw_diag -c wan1x
 [show-ca-cert|show-client-cert|del-all|del-ca-cert|del-client-cert|del-private-key|[<get-ca-cert|get-client-cert|get-private-key>
 <TFTP server IP> <file name>]]

769599

Add new command to enable/disable FIPS mode: fips-cc [enable | disable]

New features or enhancements

The following table includes new features and enhancements in FortiAP-U version 6.2.4 when managed by a FortiGate running FortiOS version 6.2.4 and later, or by FortiLAN Cloud:

For FortiAP-U features managed by a FortiWLC, see the Wireless Controller documentation.

Bug ID

Description

587779

Support extension information of wtp, vap and station statistics.

670725

Support hexadecimal values of EddyStone namespace ID and instance ID in Bluetooth low energy (BLE) profile.

702730

FAP-U LAN port (in WAN-LAN mode) supports dynamic VLAN assignment with RADIUS MAC-address authentication.

738291

802.11ax FAP-U models in single-5G mode support dedicated dual-band scanning on the third radio.

739307

Support Service Assurance Manager (SAM) mode.

739314

FortiPresence PUSH API update: FortiAP sends its region map information to FortiPresence server for positioning wireless stations.

741443

FAP-U234F and FAP-U432F support indoor/outdoor country revision as configured from FortiGate.

Note: FortiGate needs to run FortiOS 7.2.0 and later.

747779

Improve connectivity to FortiGuard server for UTM update and query services.

763506

Support FQDN address of FortiPresence server

763507

From WiFi Controller wtp-profile configuration, FortiAP WAN port can be set as an 802.1X supplicant to authenticate to local infrastructure network using EAP protocols.

763510

Support DHCP address enforcement: Wireless clients must complete the DHCP process and obtain an IP address through FAP-U SSID; otherwise they are denied to connect.

766455

Support downloading firmware image from FortiLAN Cloud over HTTPS.

769599

Support the Federal Information Processing Standard (FIPS) validation.

771071

Support BSS coloring collision event log to FortiGate.

Note: FortiGate needs to run FortiOS 7.0.4, 7.2.0 and later.

Region/country code update and DFS certification

Bug ID

Description

754092

The region code of Israel is changed from "I" to "E" (for 802.11ax FAP-U models only); The default country of region "I" is set as Morocco.

758352

Enable DFS Channels on all FAP-U models with region code P.

Note: FortiGate needs to run FortiOS 7.0.4, 7.2.0 and later.

Changes in CLI

Bug ID

Description

745110

Support presult command output for troubleshooting uniformity; Add presult output to the fap-tech command.

763507

When WiFi Controller won't overwrite FortiAP WAN port authentication, FortiAP can configure its own 802.1X supplicant locally.

New cfg variables:

WAN_1X_ENABLE

WAN port 802.1x supplicant enable/disable

[0(Disabled), 1(Enabled)]. default=0

WAN_1X_USERID WAN port 802.1x supplicant user ID
WAN_1X_PASSWD WAN port 802.1x supplicant password

WAN_1X_METHOD

WAN port 802.1x supplicant EAP methods

[0(EAP-ALL), 1(EAP-FAST), 2(EAP-TLS), 3(EAP-PEAP)]. default=0

Diagnose command:

cw_diag -c wan1x
cw_diag -c wan1x
 [show-ca-cert|show-client-cert|del-all|del-ca-cert|del-client-cert|del-private-key|[<get-ca-cert|get-client-cert|get-private-key>
 <TFTP server IP> <file name>]]

769599

Add new command to enable/disable FIPS mode: fips-cc [enable | disable]