Fortinet white logo
Fortinet white logo

CLI Reference

config ap-security

config ap-security

Description: Configure security mode for WiFi access point.

config ap-security

set security-mode <encryption mode>

# Security encryption modes including:

OPEN

WPA2-Personal

WPA-WPA2-Personal

WPA3-SAE

WPA3-SAE-Transition

WPA2-Enterprise

WPA3-Enterprise-Only

WPA3-Enterprise-Transition

WPA3-Enterprise-192-bit

if security-mode chooses OPEN:

set pmf <option>

# pmf option includes the options:

disabled

optional

required

if security-mode chooses these options: WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE,WPA3-SAE-Transition, configure the following commands:

set pmf <option>

set passphrase <password>

if security-mode chooses these options: WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, WPA3-Enterprise-192-bit, configure the following commands:

set auth-server-addr <url>

set auth-server-port <port number> # default as 1812

set auth-server-secret <password>

Sample command
config wifi vap
    edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Enterprise
            set auth-server-addr 192.168.11.99
            set auth-server-port 1812
            set auth-server-secret ******
            set pmf optional
        end
    next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf disabled
            set passphrase ******
        end
    next
end

config ap-security

config ap-security

Description: Configure security mode for WiFi access point.

config ap-security

set security-mode <encryption mode>

# Security encryption modes including:

OPEN

WPA2-Personal

WPA-WPA2-Personal

WPA3-SAE

WPA3-SAE-Transition

WPA2-Enterprise

WPA3-Enterprise-Only

WPA3-Enterprise-Transition

WPA3-Enterprise-192-bit

if security-mode chooses OPEN:

set pmf <option>

# pmf option includes the options:

disabled

optional

required

if security-mode chooses these options: WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE,WPA3-SAE-Transition, configure the following commands:

set pmf <option>

set passphrase <password>

if security-mode chooses these options: WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-Enterprise-Transition, WPA3-Enterprise-192-bit, configure the following commands:

set auth-server-addr <url>

set auth-server-port <port number> # default as 1812

set auth-server-secret <password>

Sample command
config wifi vap
    edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Enterprise
            set auth-server-addr 192.168.11.99
            set auth-server-port 1812
            set auth-server-secret ******
            set pmf optional
        end
    next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf disabled
            set passphrase ******
        end
    next
end