Fortinet white logo
Fortinet white logo

CLI Reference

config vap

config vap

Description: Configure WiFi virtual access point.

Edit <WiFi Access Point Name>
            set ssid <name>
            set broadcast-ssid [enable | disable]
            set dtim {1-255}
            set rts-threshold {256-2347}
            set max-clients {0-512}
            set target-wake-time[enable | disable]
            set bss-color-partial [enable | disable]
            set mu-mimo [enable | disable]
            set wlan-bridge [yes |no ]
            set wlan-members
config ap-security
set security-mode <encryption mode>
Tooltip

FortiExtender supports the following security modes:

  • OPEN

  • WPA2-Personal

  • WPA-WPA2-Personal

  • WPA3-SAE

  • WPA3-SAE-Transition

  • WPA2-Enterprise

  • WPA3-Enterprise-Only

  • WPA3-Enterprise-Transition

  • WPA3-Enterprise-192-bit

Note

If security-mode is set to WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or WPA3-

SAE-Transition, you must also configure the following settings:

set pmf <option>
set passphrase <password>
Note

If security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-

Enterprise-Transition, or WPA3-Enterprise-192-bit, you must configure the following settings:

set auth-server-addr <url>
set auth-server-port <port number> # default as 1812
set auth-server-secret <password> 
Sample command:
config wifi vap
edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set dtim 1
        set rts-threshold 2347
        set max-clients 9
        set target-wake-time enable
        set bss-color-partial enable
        set mu-mimo enable
        set wlan-bridge no
        set wlan-members
config ap-security
set security-mode WPA2-Enterprise
set auth-server-addr 192.168.11.99
set auth-server-port 1812
set auth-server-secret ******
set pmf optional
end
next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set dtim 1
        set rts-threshold 2347
        set max-clients 9
        set target-wake-time enable
        set bss-color-partial enable
        set mu-mimo enable
        set wlan-bridge yes
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf required
            set passphrase ******
        end
next

config vap

config vap

Description: Configure WiFi virtual access point.

Edit <WiFi Access Point Name>
            set ssid <name>
            set broadcast-ssid [enable | disable]
            set dtim {1-255}
            set rts-threshold {256-2347}
            set max-clients {0-512}
            set target-wake-time[enable | disable]
            set bss-color-partial [enable | disable]
            set mu-mimo [enable | disable]
            set wlan-bridge [yes |no ]
            set wlan-members
config ap-security
set security-mode <encryption mode>
Tooltip

FortiExtender supports the following security modes:

  • OPEN

  • WPA2-Personal

  • WPA-WPA2-Personal

  • WPA3-SAE

  • WPA3-SAE-Transition

  • WPA2-Enterprise

  • WPA3-Enterprise-Only

  • WPA3-Enterprise-Transition

  • WPA3-Enterprise-192-bit

Note

If security-mode is set to WPA2-Personal, WPA-WPA2-Personal, WPA3-SAE, or WPA3-

SAE-Transition, you must also configure the following settings:

set pmf <option>
set passphrase <password>
Note

If security-mode is set to WPA2-Enterprise, WPA3-Enterprise-Only, WPA3-

Enterprise-Transition, or WPA3-Enterprise-192-bit, you must configure the following settings:

set auth-server-addr <url>
set auth-server-port <port number> # default as 1812
set auth-server-secret <password> 
Sample command:
config wifi vap
edit fev-home-2g-1
        set ssid fev-home-2g-1
        set broadcast-ssid enable
        set dtim 1
        set rts-threshold 2347
        set max-clients 9
        set target-wake-time enable
        set bss-color-partial enable
        set mu-mimo enable
        set wlan-bridge no
        set wlan-members
config ap-security
set security-mode WPA2-Enterprise
set auth-server-addr 192.168.11.99
set auth-server-port 1812
set auth-server-secret ******
set pmf optional
end
next
edit fev-home-5g-1
        set ssid fev-home-5g-1
        set broadcast-ssid enable
        set dtim 1
        set rts-threshold 2347
        set max-clients 9
        set target-wake-time enable
        set bss-color-partial enable
        set mu-mimo enable
        set wlan-bridge yes
        set wlan-members
        config ap-security
            set security-mode WPA2-Personal
            set pmf required
            set passphrase ******
        end
next