Advanced Settings
With a FortiAP advanced management license, you can enable the following advanced settings.
|
Field |
Description |
|---|---|
| Radio Sensitivity (Rx-SOP) | The Receiver Start of Packet (Rx-SOP) configures a threshold to allow FortiAPs to adjust the SSID cell size. The radio discards all received wireless frames with minimum WiFi signal lesser than the configured threshold value. Adjusted cell size ensures that wireless clients are connected to the nearest FortiAP at highest possible data rates and distant clients do not deprive other clients of airtime. The valid range of signal strength is -95 to -20 dBm with a default value of -79 dBm for 2.4GHz and -76 dBm for 5GHz. |
| Probe Response Suppression | Restricts distant wireless clients from connecting to the FortiAP if the received signal strength is less than the configured threshold. The FortiAP does not send any probe response to these distant wireless clients and responds to the probe requests sent from nearby clients only. The valid range of signal strength is -95 to -20 dBm with a default value of -80 dBm. |
| Sticky Clients Removal | De-authenticates sticky wireless clients (distant clients that stick to the FortiAP) if the signal strength is less than the configured threshold. The valid range of signal strength is -95 to -20 dBm with a default value of -79 dBm for 2.4GHz and -76 dBm for 5GHz. |
|
Applications Usage Visibility |
FortiAPs collect and report usage information about applications accessed by wireless clients in specific networks. The application data available in FortiEdge Cloud provides greater visibility and risk assessment capability over the networks that are managed by FortiEdge Cloud. The FortiAPs collect and report the application usage information at the configured time interval.
|
| Protected Management Frames (802.11w) |
Provides a layer of security for wireless management frames by ensuring that traffic comes from legitimate sources. Network attackers and malicious entities are unable to disrupt legitimate wireless connections by sending spoofed clear text wireless management frames.
Note: Any change in the PMF configuration requires the controller to delete and then add the SSID. This disrupts existing connections. |
|
Fast BSS Transition (802.11r) |
This feature allows faster roaming for Wi-Fi clients by enabling swift BSS transitions between APs. This minimizes delay caused due to a client transitioning from one BSS to another in a multi-AP deployment.
|
|
Radio Measurements (802.11k) and BSS Transition Management (802.11v) |
Note: The Voice Enterprise (802.11kv) configuration is not available with release 24.1. If you were using the 802.11kv setting in the previous release, then in the current version both 802.11k and 802.11v will be enabled. |
| Airtime Fairness Weight (%) |
Wi-Fi has a natural tendency for clients farther away or clients at lower data rates to monopolize the airtime and drag down the overall performance. Airtime Fairness (ATF) helps to improve the overall network performance.
Airtime Fairness is supported with FOS 6.2.0 and on all FortiAP-S and FortiAP-W2 models. |
| Broadcast Suppression |
Suppresses the transmission of specific broadcast traffic to secure the wireless network and optimize airtime usage. When the received broadcast traffic exceeds the threshold, the interface discards it until the broadcast traffic drops below a specific threshold.
|
| L3 Firewall Profile | Create L3 Firewall rules. For more information, see L3 Firewall Profile. |
|
Block intra-SSID traffic |
To block intra-SSID network traffic. |
|
Tunnel Settings |
Select Tunnel Profile to add an existing GRE/L2TP Tunnel profile.
|
|
DHCP Option 82 |
DHCP option 82 (DHCP relay information) secures wireless networks served by FortiAPs against vulnerabilities that facilitate DHCP IP address starvation and spoofing/forging of IP and MAC addresses. The Circuit ID and Remote ID parameters enhance this security mechanism by allowing the FortiAP to include specific AP and client device information into the DHCP request packets. Both these options are disabled by default.
|
|
Wireless Multicast Enhancement |
This enhancement is set to improve the performance of applications using multicast traffic over a wireless network. Consider an example, where a media streaming application uses multicast packets, this can potentially compromise the media (audio/video) quality through packet loss and induced latency. With this release, you can convert the multicast packets into unicast and send them over the wireless medium. This ensures high reliability and performance due to the high data rates used for unicast packets.
|
|
IGMP Snooping |
The FortiAP snoops wireless IGMP packets and maintains a subscription list of all multicast groups joined by the wireless clients. This data is used to manage multicast packets for enhanced performance. |
|
Radio and Rates Optional Settings |
Customize the 2.4 GHz and 5 GHz rate settings. FortiEdge Cloud supports 11b/g, 11a, 11n, 11ac, 11ax, and 11be data rates in SSID configuration. Note: The 11ax data rates are supported only on FortiAPs with version 7.2.1 and above. |