Overview
Join Keith Barker as he discusses and demonstrates how to design a Fortinet wireless network.
Intro to Fortinet Wireless Design
Keith introduces this set of videos.
Overview of Wireless Design
Keith presents an overview of wireless design in a Fortinet network.
Knowledge Check
Which of the following is Fortinet's primary tool that can assist with a Wireless Site Survey?
Site Survey
Keith demonstrates tools that can be useful as part of a wireless site survey.
Knowledge Check
A spectrum analyzer could be used to see the RF in use both in and out of the ranges used for WiFi.
Fortinet Wireless Components
Keith discusses the components used in a Fortinet Wireless network.
Knowledge Check
If the APs are connected to access ports with a native VLAN of 2, that means all clients that connect to SSIDs supported by those APs will also be on VLAN 2. True or false?
Connecting APs
Keith demonstrates how to connect APs to the Switched network as well as directly to the FortiGate.
Knowledge Check
Which is the most typical method for supplying power to a FortiAP in a commercial setting?
Knowledge Check
How do you place an AP into config mode?
FortiPresence
Keith introduces a tool from Fortinet called FortiPresence.
Knowledge Check
Which tool is best suited for processing and correlating a client's use of Wi-Fi at many locations?
Conclusion
I hope this has been informative for you and I would like to thank you for consuming.
View Transcript
Intro to Fortinet Wireless Design
0:07Hello and welcome.
0:09My name is Keith Barker.
0:10And in this set of videos, you and I
0:12get to focus our attention on wireless network design.
0:15Because in a very small network, like a small office space,
0:18one or two access points put on the ceiling,
0:21and away we go, and it probably work just fine.
0:24But in a larger environment, like a large floor
0:26or multiple floors of a building,
0:27we need to really take some additional steps, including
0:29doing some site surveys and doing some estimates
0:32and testing to verify that we had the right gear in place.
0:34So in this set of videos, we'll take a look at some tools
0:37to do exactly that.
0:38And some tools, once we have our network set up,
0:40that we can use to help monitor and maintain those networks
0:42as well.
0:43So join me in the next video.
0:44We'll do a big overview and then we'll
0:45walk through the video step-by-step.
0:47I'll see you, my friend, in the very next video.
Overview of Wireless Design
0:00[MUSIC PLAYING]
0:06In this video, you and I get to take a big picture
0:08look in the world of designing a Wireless Local Area Network.
0:11And one of the first steps is going to be planning.
0:14And that's going to involve asking a bunch of questions.
0:16For example, how many square feet are we trying to cover?
0:20Or how many users are we trying to support?
0:22Because it's going to be very different for implementing
0:24Wi-Fi services, for example, in a baseball
0:26stadium, or a huge environment like that, or a school,
0:29compared to a small office, home office.
0:31So regarding what, that would include what space are we
0:34trying to cover?
0:35What applications are the users trying
0:36to use on this wireless network?
0:38Because some applications are more sensitive to latency
0:40than others like voice over IP and other real time
0:42applications.
0:43Also in the planning stage, we'd want
0:45to ask when they expect this to be ready or when they need it.
0:47We'd also want to plan on whether or not
0:49we're going to include guest access as part
0:51of our wireless services.
0:53We also want to get our hands on some floor plans
0:55that we can use with our site survey tools,
0:57and also for our documentation regarding where the access
0:59points are going to be.
1:00And then when we have our data from our planning,
1:02our next step would be the site survey.
1:03And that's where we're going take our set of tools, which
1:06could include things such as the radio frequency
1:08analyzer or a spectrum analyzer.
1:10And quite often, we're going to put those on a cart
1:12and actually take that cart and walk it around the floor
1:15or walk around the building where
1:16we're going to be implementing the wireless.
1:18In that way, we can map out the space.
1:21And we can also do some testing with access points just
1:23to verify that the coverage we expect
1:24to have from one location is working as expected.
1:27And one of the tools for that from Fortinet
1:29is called FortiPlanner.
1:31And they've got a free light version
1:32and they also have a full blown version.
1:34And that can help with the mapping
1:35other tools include NetSpot.
1:37And there's other commercial tools
1:38as well we could use in combination
1:40with a laptop and a wireless network interface card
1:43as we do the site survey, and map out
1:45our plan for implementation of our access points.
1:48Also, doing the actual site survey in the walkthrough
1:50helps us identify objects that would impede signals,
1:53for example brick walls, or for that matter any walls.
1:57Or large objects like refrigerators, or generators,
2:00or other elements that might otherwise negatively impact
2:03signals in our Wi-Fi environment.
2:05Also as part of our site survey, we
2:06can identify where we want the signals not to go.
2:09So if we have a building like this
2:11and over here is the parking lot and we
2:12don't want signals to spill into the parking lot,
2:15we might put in some directional antennas here going this way.
2:18So inside the office we have the signals,
2:20but we don't have the signals over here.
2:21And then further in, we could use an omnidirectional antenna.
2:24So this would be a directional antenna over here,
2:26and then omnidirectional antenna's
2:27here for the major coverage.
2:29And then with our site survey done and our plan in place,
2:31we could then go ahead and implement the architecture,
2:34which in most environments are going to include a FortiGate
2:36acting as the controller which is connected to a switch stack.
2:39And there's inner switch links there.
2:41And then off of these switches with power over Ethernet,
2:43we're going to have our access points.
2:45So there's AP 1, and here we can have AP 2, and AP 3.
2:49And we also might want to name those access points based
2:51on where they physically are.
2:52And that way if we have the location integrated
2:54with the name, then when we see the name of an AP,
2:56we have an idea of exactly where it is.
2:57For example what building it is in,
2:59and what floor it's in, and what location on that floor it's in.
3:01And then once the wireless networks are set up
3:03and the SSIDs are in place with the security that we want,
3:06we then want to go ahead and do monitoring just
3:08to verify what's happening in the environment.
3:10And one of the tools that Fortinet offers for monitoring
3:12of our wireless network environments
3:14is called FortiPresence.
3:16And FortiPresence connect is a clearinghouse
3:17regarding what's going on for multiple locations.
3:20So we feel like 10 locations or 10 sites
3:22and you have Wi-Fi in each one of them,
3:24all that information can be fed into FortiPresence.
3:26And then with FortiPresence, it can give us
3:28a single pane of glass the ability to report on and dig
3:30through the data regarding what's happening
3:32in those wireless environments.
3:33So that's the big picture regarding
3:35Fortinet wireless design.
3:36And in the next video, I'd like to take
3:38a closer look at site surveys and many of the tools
3:40that we could leverage in mapping out and planning out
3:43our wireless networks.
3:44So I'll see you in that video in just a moment.
3:46Meanwhile, I hope this has been informative.
3:48And I'd like to thank you for viewing.
Site Survey
0:06One of the critical things to do when
0:08implementing a Wi-Fi network is to do a site survey.
0:10Now in preparation for that, we'd want to identify OK,
0:13what is the space we're trying to cover?
0:15What's the quantity, the density of devices
0:17that we're going to have supported with Wi-Fi?
0:19And then once we have that data, it
0:20would be important to have the tools ready to do a site survey
0:23and map out that space.
0:24And in performing a site survey, some of the tools we could use,
0:27one from Fortinet which is FortiPlanner,
0:29there are other commercial tools like NetSpot
0:32and others that can be used as well.
0:34And with both of these examples, you
0:35can run these applications on your computer, your laptop.
0:38It can be on the cart as you go around.
0:40And it can help you dynamically map out that space,
0:43with the intention of putting the correct number of access
0:45points, the right types of access
0:46points in the right locations to give appropriate coverage.
0:49So we might be intending to use the 2.4 gigahertz range, as
0:53well as the 5 gigahertz range.
0:54When I say 5 gig, I'm also referring
0:56to the possible six and a little bit of seven that
0:59are with the latest standards.
1:00And one of the things about Wi-Fi
1:02is that Wi-Fi signals may not be the only things that
1:05are consuming that space.
1:07So in addition to planners for Wi-Fi,
1:10we also may want to use a Spectrum Analyzer,
1:12because the Spectrum Analyzer can just
1:14look at the raw frequencies in that space,
1:16even if they're not Wi-Fi related.
1:18And that can give us a better indication of other signals
1:20that just may be noise as far as that frequency space is
1:23concerned.
1:24So in this video, I thought it'd be
1:25fun to give you a peek at FortiPlanner, NetSpot,
1:28as well as a Spectrum Analyzer as an example of three
1:30tools that could be used as part of a site survey.
1:33So this is FortiPlanner Lite.
1:35Now currently, I'm using version 2.6.5,
1:37which is current as of this recording.
1:39And the Lite version is also referred to as demo mode.
1:42So some of the features, including real-time heat maps,
1:44are not available until you actually license it.
1:46But even in the demo mode, we can
1:48take a look at a sample file and still get a good idea
1:50of what it can do for us.
1:51So if we click here on Open Project,
1:53and I'm going to open the sample project that came with it.
1:55And so over the top, we have tabs.
1:56Here we have a tab for the floor plan.
1:58And when we're putting together the floor plan,
2:00there's an option for selecting the wall types.
2:02And that way, it can help identify
2:03based on the type of wall how much attenuation or degradation
2:07of a Wi-Fi signal will happen as it
2:09tries to go through that wall.
2:10So here in the sample, we're looking at building 1 and floor
2:131 on that building.
2:14There's a tab for the Wi-Fi Planner, which gives us
2:16the ability to grab an access point
2:18and then place it manually in our topology.
2:20When I say manually, I mean manually
2:22here within FortiPlanner.
2:23So if we wanted more detail regarding a specific type
2:26of access point, the fastest way to do that
2:28is just to go to doc.fortinet.com.
2:31And from here, we can click on FortiAP
2:33And as of March 31st of 2022, they just upgraded to 7.2.
2:39So if we click here on 7.0 as of this recording,
2:42here we have the hardware guide for access points
2:44that can help us identify what the features and functions are,
2:47as well as some concept and architecture guides
2:49for deploying access points.
2:51Also if you want to check to see whether or not the access point
2:54that we're working with is compatible with the FortOS
2:57on the FortiGate, we're using--
2:58we can use the compatibility matrix right here.
3:01Let's go and open that up.
3:02So here in the FortiAP and FortOS compatibility matrix,
3:05currently behind me I've got a few of the FAP-221E.
3:09And here it's saying that we recommend that the FortiAP-W2
3:12firmware be matched with the respective FortiOS version.
3:14Now, the current FortiOS version that I'm running
3:17is 7.2 because they just updated it,
3:19and they don't yet have a 7.2 for the FAP-221E.
3:23So it's good news that says other variations of FortiOS
3:26and FortiAP-W2 versions may technically work for the lower
3:29common feature set.
3:30So when in doubt, go right to the source
3:32up to docs.fortinet.com for the latest and greatest information
3:35regarding the product that you're currently
3:37working with from FortiNet.
3:38All right, let me go and minimize that.
3:40So because this is the light or the demo version,
3:42I don't have a tab here for site survey.
3:44I don't have a tab here for live services.
3:46So once again, it won't give you a full functionality
3:49without a license.
3:50But even with that limitation, one
3:51of the cool things we can do here
3:52is with this map that's been built out
3:54that specifies the walls and windows where everything is,
3:56we could go up here to auto placement,
3:58click on that Go button, and it will automatically
4:01place access points where it thinks they may be needed,
4:04which is pretty cool.
4:05Or if we want to manually place somewhere
4:06we can select the AP we want to place, and then place it here
4:09on the map.
4:09Then what we want to do is after we put those in place,
4:12we'd want to go back and test it and verify
4:14that we have the appropriate coverage everywhere
4:16we expect to with the access points in place.
4:19Another example of a tool that we could use is NetSpot.
4:22Let's bring that up now.
4:23So with NetSpot, which we've looked at in a previous video,
4:26it's a fantastic tool.
4:27It's from the perspective of the device that's running on.
4:29So this is currently running on a Windows computer.
4:32It has a wireless network interface card
4:34with radios that support the 2.4 gigahertz range and the 5
4:37gigahertz range.
4:38And as a result, it can report on everything
4:40that it sees, including the SSIDs, the Service Set
4:43Identifier, which is effectively the wireless network name,
4:45and the respective basic service set
4:48identifiers that are being advertised by the access
4:51points.
4:51Then it's showing the relative signal strength and the band,
4:545 or 2.4 gigahertz.
4:55Then the channel or channels being used.
4:57The channel width, the vendor, and that's
4:59based on the basic service set identifier in those Mac
5:02addresses.
5:03And then the type of security that's being implemented.
5:05And then the mode, whether it's Wi-Fi 4, 5, or 6 or something
5:08really old to see if we have something really old
5:11here within the range of this computer.
5:13Oh, and I don't.
5:13Sometimes I'll get a G in here for like an old printer
5:16or something that's showing up.
5:17But this is a great tool that we could then
5:19use as part of our site survey.
5:20So we had an access point in place,
5:22we could then take the laptop with this software running
5:25and wheel it around as if that user was roaming just
5:28to verify the signal strength anywhere
5:30we want to test in that building.
5:31So the free version of NetSpot doesn't have a site survey
5:34capability, where it helps you build
5:36a map as you wheel this around.
5:38However, NetSpot has a very affordable low end
5:42cost if you want to license it.
5:43And if you do, you then get the option for these surveys.
5:46So here is an example survey that comes with it as a sample.
5:49So you start off with the blueprint of your space,
5:52and then you simply take this software running on a laptop.
5:55And then as you wheel this through the space,
5:57you can go ahead and pinpoint individual locations.
5:59In that way, you can build a map and color code it
6:01regarding signal strength.
6:02So down here, a dark blue is a very weak signal
6:05and the red would be a good strong signal.
6:07So in our wireless network, we want
6:09to make sure that everywhere we expect
6:10to have wireless coverage that we are somewhere
6:13other than aqua or blue, which represents a poor signal.
6:16And more towards the light green and yellow and red, which
6:19indicates a stronger signal.
6:21So again this is another tool that we could use
6:23as part of doing a site survey.
6:24So I think we have a couple of samples here.
6:26So we go to Survey and Open Sample.
6:28And let me go open up the home office and family space.
6:31I'll say no to any changes there.
6:33Oh, that's what I had open.
6:34Let me go ahead and open up the other sample,
6:36which is a single family house.
6:37There we go.
6:38And this is an example of somebody
6:39who's doing a site survey, and they
6:41look like they're 1/3 the way through.
6:43And by doing a site survey, we can
6:44verify that our access points are providing
6:46the appropriate coverage for our Wi-Fi network or our networks.
6:49Now if we go back to discover here in NetSpot.
6:52And let me go ahead and sort by level.
6:54And let me go ahead and turn everything on here.
6:57And let's bring up this graph.
6:58So here is the 2.4 gigahertz graph
7:00based on what's currently being seen by my network adapter
7:04on this computer.
7:05And it looks like we have a bunch of stuff over on one.
7:07We have a bunch of stuff with the center channel 6.
7:10It's like what the heck happened over here?
7:11There's nobody over here with a significantly strong signal
7:14with a center channel of 11.
7:15So another tool that we may want to bring to the table
7:18is a Spectrum Analyzer or an RF analyzer
7:20that can help us identify what frequencies are in use
7:23and how much.
7:24And just the--
7:25I'm always interested in toys and tools.
7:28And I saw the other day on Amazon, they had one on sale.
7:31And in fact, let me show it to you.
7:33So this is it right here.
7:34So oh, I have 389.
7:35So it was under $500.
7:37I thought to myself, that's pretty amazing for a Spectrum
7:40Analyzer.
7:40So as a result, I bought it.
7:42So it's pretty cool, because this mobile
7:45has an internal battery also plugs into USB.
7:47So you can have graphs on your computer.
7:49So it's fantastic because you could actually
7:51walk around with this and look for what
7:52are the highest signals in a certain frequency range?
7:55So let me share with you what the output looks
7:56like on a computer.
7:58And that output would look something
8:00like this as a little USB cable.
8:02And so this is showing us real time
8:05regarding those frequencies in these channels,
8:07especially those frequencies what's currently in use.
8:09So this helps confirm what we're seeing down here.
8:12So from the computer perspective,
8:13it is saying yep I see these Wi-Fi networks
8:15with these center channels.
8:16And approximately these signal strengths.
8:18And here we can verify with the analyzer that's the case.
8:21So based on these two different inputs,
8:23I expect to see quite a bit of traffic over here
8:25in this range of frequencies with the center channel of one,
8:28which we do right here.
8:29And also I'd expect to see quite a bit
8:31here with the center channel frequency of channel 6.
8:34So NetSpot is showing us the APs, and which APs
8:37are using which frequencies.
8:38And the spectrum analysis tool is showing us the actual usage
8:41of those frequencies.
8:42So it looks like even though this access point here
8:44with the center channel of six has the strongest signal,
8:47it looks like the busiest as far as traffic being used
8:51is down here in the frequencies with a center channel of one.
8:54And that's based on what's being shown here
8:55live by the RF Explorer.
8:58That's the name of this Spectrum Analyzer.
9:00So using a combination of site survey tools and Spectrum
9:04Analyzers, it's going to help us get an accurate
9:06picture of how solid our coverage is,
9:09and also an idea regarding what channels
9:10we should be focusing towards and implementing our wireless
9:13networks.
9:14So if we are going to manually implement
9:16new access point in the 2.4 gigahertz range,
9:19we would want to target the center channel of 11,
9:22at least for this position right here in my Studio,
9:24because that's the one that currently
9:26is the most available.
9:27And then we can do the same technique for the 5 gigahertz
9:30range as well.
9:31So if we wanted to try this also for the 5 gigahertz range,
9:33we could go to the 5 gigahertz channels tab
9:35here, instead of NetSpot.
9:37So it looks like we have a whole bunch in this range and a few
9:40up here of the higher end.
9:41And then we could bring in the Spectrum Analyzer
9:43again to help verify that what it sees concurs
9:47with what's shown here, which it seems to agree.
9:50Let me go and make that bigger.
9:51Also the Spectrum Analyzer has a couple of different antennas,
9:53and I have the same ones on for the 2.4 and the 5 gigahertz
9:57testing.
9:58So using a collection of tools, including site survey
10:00tools such as FortPlanner and NetSpot and others,
10:03as well as radio frequency spectrum analyzers
10:05are going to be helpful in planning out and building
10:08a successful wireless local area network.
10:10So thanks for joining me in this video.
10:12In the next video, we'll take a look at the Fortinet wireless
10:14components we're going to use as part of our wireless network.
10:17So I'll see you there in just a moment.
10:19Meanwhile, I hope this has been informative,
10:21and I'd like to thank you for viewing.
Fortinet Wireless Components
0:07And welcome back.
0:08In this video, we're going to take a closer look
0:09at the components from Fortinet that we're
0:11going to use it as part of our wireless networks.
0:13And I thought to myself, let's bring back our big design
0:16that we took a look at a few sets of videos ago,
0:19because that will serve us here as well.
0:21And let's start off with our access points.
0:22We're going to have at least one access point, maybe more.
0:25In my lab here, I think I have four or five
0:26that we can play with.
0:27And depending on the type of access point you have,
0:29that's going to control how many radios it has,
0:32what standards it supports, and what
0:34security features it supports.
0:36And for more details on the specific access point,
0:38just go to the documentation, and it'll
0:40specify what those access points are capable of.
0:42So regardless of type of access point, one thing all
0:45access points need is they're going to need power.
0:47So in our topology, we're going to use a switch that
0:49has power over Ethernet, delivering power over
0:52to these access points.
0:53And as we discussed in our previous video,
0:55we're going to use VLAN 2 with these ports here associated
0:58with VLAN 2, and that will be the VLAN dedicated
1:00for the management and working with our access points.
1:03So the access points are connected to switch, who's
1:05doing the power over Ethernet.
1:06They're in VLAN 2.
1:07The switch has interswitch links between switch 2 and switch 1.
1:10And switch 1 has two ethernet connections
1:13going up to the FortiGate.
1:14So from the switch's perspective,
1:16this would be the FortiLink trunk.
1:17And from the FortiGate perspective,
1:19this would be the FortiLink interface going down
1:21to switch 1.
1:22And the benefit of that is we can then use the FortiGate
1:24as the controller to configure and work with and manage
1:27our access points.
1:28And the default mode for setting up SSIDs in Fortinet
1:31with our access points is to use tunnel mode, which effectively
1:35creates a logical tunnel between the FortiGate and the access
1:38point.
1:39And it is a CAPWAP tunnel.
1:41And that allows us to go ahead and create, for example,
1:43SSID 30 and SSID 40.
1:46Clients can connect to those wireless networks.
1:48And the traffic from those clients going through the AP
1:51is sent through the CAPWAP tunnel up to the FortiGate.
1:54And with that CAPWAP logical tunnel in place between
1:56the access points and the FortiGate, then,
1:58as clients connect to, for example, SSID 30--
2:01which is the 10.30 network--
2:03or SSID 40-- which is going to be the 10.40 network,
2:05once we create those-- those clients exist on those networks
2:08and not on VLAN 2.
2:09Even though the access point that supporting those wireless
2:11networks is directly connected to a port
2:13with the native VLAN of VLAN 2.
2:15So the tunneling between the access point and the FortiGate
2:17makes that possible.
2:18And regarding the access points, they
2:20could be standalone external access points like these are,
2:23or they could be access points that
2:24are integrated as part of a FortiGate firewall.
2:27And when the access point is integrated
2:29as part of the FortiGate, they call that FortiWiFi.
2:31And so with FortiWiFi, of course,
2:32we're going to manage the Wi-Fi built
2:34into the FortiGate via the FortiGate.
2:35And with these external APs, we're
2:37also going to manage them using the FortiGate
2:39as the controller.
2:40There also is the option of doing
2:42cloud management of our wireless environments with FortiAP.
2:45and.
2:46That was the old name for it.
2:47And that was called FortiLAN Cloud.
2:48And with FortiLAN Cloud, that's a cloud-based web service
2:51that can support access points as well as switches.
2:54So you log on to cloud services to go ahead and manage them,
2:57as opposed to logging onto them directly.
2:58Now, because we have most of this infrastructure in place--
3:01we have the FortiGate, we have the switches--
3:03in the next video, I'd like to go ahead and take one access
3:06point and plug it into port number
3:081 here on switch number 2 and just
3:10verify that it can be discovered.
3:12We'll also take a look at some methods that
3:14are used between the FortiGate and the access point
3:16to allow the access point to be managed by the FortiGate.
3:19So we'll do that in the very next video.
3:20So I'll see you there in just a moment.
3:22Meanwhile, I hope this has been informative,
3:24and I'd like to thank you for viewing.
Connecting APs
0:06In this video, we're going to add an access point to the mix.
0:08We're going to take our existing infrastructure
0:10from a few sets of videos ago and then plug in one access
0:13point to make sure it comes up.
0:15So let's first start off by verifying
0:16we can log in to our FortiGate.
0:17Also, I'll verify our switches are in place.
0:20Let's make sure that these ports here
0:21on switch 2, the first five ports,
0:23are associated with VLAN 2.
0:25And then we'll plug our access point into the first port.
0:28All right, so here we go.
0:29We are at firewall 1, firmware 7.2.
0:32It says we're unable to connect to FortiGuard servers,
0:34and that is because it's been up for just a few minutes
0:37and it hasn't had a chance yet to fully initialize and get out
0:40there and get updated.
0:41So we'll give it a few minutes before we
0:42start worrying about that.
0:43And then right here, it shows us that we
0:45have two connected FortiSwitches, which
0:46is a good sign.
0:47And there they are, switch number 1 and switch number 2.
0:50And those are off of the FortiLink interface.
0:52So if we go down to Wi-Fi and Switch Controller
0:55and we go to the FortiLink interface,
0:57those switches are connected over the FortiLink interface.
0:59And so they should have the IP addresses
1:01in the 10.1.0 address space.
1:03So if we go down to Manage FortiSwitches, here
1:05indeed they are.
1:05They're switch number 1 and switch number 2.
1:08Go over here and click on List and go down
1:09to the topology view.
1:11We can verify how they're connected.
1:13So what we want to do is go down to FortiSwitch VLANs.
1:16And here is VLAN 10 and VLAN 20, which we're using for users.
1:19And here is VLAN 2 that we're going
1:21to use for our access points.
1:22So on switch number 2, we want to make sure
1:24that the native VLAN on part 1 is associated with VLAN 2.
1:28So if we go one below here on the left down
1:30to the FortiSwitch ports and we expand switch 2,
1:33the little lightning bolts represent power over ethernet.
1:36That's a great sign.
1:37So we can supply power to our access points.
1:39And let's configure port 1, 2, 3,
1:42and we'll go all the way through 5.
1:43And we'll associate all of those with VLAN 2.
1:46So I'll go ahead and just select those five
1:49by clicking on port 1, holding down the Shift key,
1:51clicking on port 5.
1:53Then over here, I'm going to click on edit the native VLAN,
1:55and we'll specify we want that to be VLAN 2.
1:58And click on Apply.
1:59And bada-bing, bada-boom, we're done.
2:00So all those five ports, the first five ports on switch 2,
2:03are associated with VLAN 2.
2:05So we'll go ahead and minimize that.
2:07And next, we'll go under Wi-Fi and Switch Controller and click
2:10here on Managed FortiAPs.
2:12So currently, there aren't any.
2:13That's great.
2:14However, when they do show up, they
2:15should be assigned IP addresses from the VLAN 2 address range.
2:18So if we go back down to FortiSwitch VLANs
2:21and we look at the details for VLAN 2,
2:24it should be on the 10.2.0 subnet.
2:26And the DHCP services start at 101.
2:29Oh, I'm also glad we looked at this.
2:31We also want to enable the security fabric connection
2:33on this interface that is supporting those access points.
2:37So this is the logical VLAN 2 interface on the FortiGate.
2:40And again, we want to make sure we're
2:41supporting the security fabric connection on that interface.
2:44All right, that looks good.
2:45So we'll click on OK.
2:46And let's go back to the Managed FortiAPs.
2:49And I'm going to go back to the rack.
2:51And I'm going to plug in the first access point to port
2:53number 1 on switch number 2.
2:56All right, it is plugged in.
2:57So that may take a moment to come up.
2:59So while we're waiting for that, let's go back down
3:01to FortiSwitch ports.
3:02And we can verify that the link is up.
3:05Ah, fantastic, it is.
3:06There's port 1, a little green indicator.
3:08Also delivering 1.9 watts of power at the moment,
3:11which implies that that access point is getting power.
3:14Also, if we right click on this port and we go down to Status
3:17and we disable it, it should be known that that does not
3:19stop the power over ethernet.
3:21It's still delivering power.
3:22So right here, hovering over this port that's down,
3:25it's still delivering power to that device.
3:27So if you want to stop the PoE as well, you could right click.
3:29And then from the drop down, go down to PoE and say Disable.
3:32So I'm going to go ahead and I'm going to leave PoE enabled.
3:35And I'm going to go back to status and enable the port.
3:37All right.
3:38We also have the ability, if we wanted to right here,
3:40just to reset PoE.
3:41That's effectively bouncing that device
3:43by removing power and resupplying power on that port.
3:46Also, it looks like I've got a warning message.
3:49Unable to connect to FortiGuard servers still.
3:51hmm.
3:51Let's just do a quick check real quick.
3:53And I'll do an execute ping out to www.fortinet.com.
3:58Oh, that works.
3:59All right.
3:59So we have internet connectivity.
4:01So it'll be a moment, and that will clear itself up,
4:03regarding unreachable FortiGuard servers.
4:05Also, if you want to speed up that process a little bit,
4:07what we can do is go down to System and FortiGuard.
4:10And then down here, if we get down to filtering,
4:13I have often discovered that if you do a test connectivity,
4:16that will help wake it up.
4:17Or if we go up here, still under FortiGuard, and click here
4:20on Update Licenses and Definitions Now,
4:23that will also trigger some connectivity
4:25to the FortiGuard servers.
4:26All right, so let's go back to Wi-Fi and Switch Controller,
4:28back to Managed FortiAPs, and--
4:31so it's not showing up at the moment.
4:33Let me do a refresh down here.
4:34So I'll give that a few more moments.
4:36And if it doesn't show up, we'll do some troubleshooting.
4:38But I think it's just going to take a moment for it
4:40to come up.
4:40So we'll do a refresh.
4:42So now after doing a refresh, I see here I've
4:44got this access point.
4:45And it shows me over here that I have one device that's
4:48requiring authorization.
4:49So we'll go ahead and right click on this access point.
4:51From the dropdown, we'll click here on Authorize.
4:54And boom, device successfully authorized.
4:56And let me go ahead and name that access point number 1.
5:00So we'll click on Edit and we'll name that AP-1.
5:03We'll come back to more of these details in a subsequent video.
5:06So we'll click here on OK.
5:07So here's the name AP-1.
5:08It shows it's offline.
5:09But that will also correct itself here in a moment or two
5:12once it fully initializes.
5:14If we scroll up to the right, it says there's no LLDP neighbors
5:17found at the moment.
5:18But that will also change once it
5:19gets fully initialized, because LLDP is running on the switch.
5:23It's also running on the access point.
5:25So the access point should be able to report
5:27that it is hanging off of port 1 on switch 2.
5:30Also, here it's showing us the VLAN
5:32it's currently connected to, which
5:33is our AP Management VLAN.
5:34It's also been assigned by default a FortiAP profile based
5:38on the hardware model it is.
5:40So it is a FAP221E.
5:42And if we hover over that, that'll
5:44reveal that based on the serial number, FP221E.
5:47And it assigned it a default profile
5:49based on that model of AP.
5:51So while that's getting fully initialized,
5:53let me go ahead and plug in another AP, which will be AP-2.
5:55And we'll plug it in on port number 2 on switch number 2.
5:59And just as a quick check, if we go down
6:00to FortiSwitch ports, port number 2,
6:02the native VLAN is VLAN 2.
6:04Perfect.
6:04Let me go ahead and plug right now
6:06a second AP into port number 2.
6:08All right, that is plugged in.
6:10So let me go ahead and do a refresh to this page.
6:12And sure enough, port 2 right here
6:14is now supplying power to that second access point.
6:16We can also click here on Faceplates
6:18and take a look at the icons here.
6:20And that also reflects as well.
6:21So here on switch 2, if we hover over those ports,
6:24it'll show us those details for port 1 and port 2.
6:27So let's go back to FortiAPs.
6:29And in a moment here, when it shows up,
6:30we'll authorize it as well.
6:32And actually, come to think of it,
6:33I'm going to go ahead and plug in all the APs.
6:35And then based on naming them, I can
6:37identify based on the LLDP information,
6:40once it shows up, which port they're connected to.
6:42And so we'll just name the access points
6:44based on the port.
6:45So AP-1 will be on port 1, AP-2 will be on port 2,
6:48and so forth.
6:48So let me plug in all the rest of the access points right now.
6:51So we'll have ports 1, 2, 3, 4, and 5 with five access points.
6:55So as these come up online, I'll go ahead and authorize them.
6:59And then once the LLDP information
7:01reports what port they're on, I'll
7:02go ahead and rename them appropriately.
7:04So I'm assuming this is going to be AP-2.
7:06In fact, I'm going to make an educated guess
7:08and say that it is, because I plugged it in second.
7:10So we'll call it AP-2.
7:12Click on OK.
7:13And the other three should be showing up here shortly as
7:16well.
7:16Now, while we wait for those other access points to show up,
7:19we also could have connected an access point directly
7:23to the FortiGate.
7:24Now, the challenge is on my little FortiGate,
7:26I have a little 60F.
7:27It doesn't have power over ethernet ports.
7:29And so as a result, if I want to plug it
7:31in directly to the FortiGate, I have
7:32to have an external power supply feeding into the access
7:34point for power.
7:35So for the benefit of not having to use an external transformer,
7:38I'm going to go ahead and use AP-1, 2, 3, 4, and 5,
7:42all plugged into ports here on switch 2,
7:44providing the power over ethernet.
7:46So back here, I have another one.
7:47So I'll right click on that one, authorize it.
7:50And I plug these in in order.
7:52So I'm assuming that's on port 3, so I'll right click there.
7:54And let me edit that and name it AP-3.
7:57Just like that.
7:58Click on OK.
7:59And also, looking at the LLDP information over here,
8:01so I got AP-2 correct.
8:03That's on port number 2.
8:04So as they come up, we'll authorize them individually,
8:06and then we'll name them appropriately
8:08based on the port they're connected to.
8:10All right.
8:10So there is 4 and 5.
8:12So I'll go ahead and right click and authorize
8:14each one of those.
8:15And then I'll go ahead and name them.
8:16So right click, Edit.
8:18And that'll be AP-4 and this one will be AP-5.
8:22So we'll name those guys.
8:23And I also want to verify here in a moment
8:25that the devices I named AP-4 and AP-5
8:28really are in ports 4 and 5 respectively.
8:30All right, and they line up.
8:32So 1, 2, 3, 4, 5, on ports 1, 2, 3, 4, 5.
8:36Fantastic.
8:36They're all running the same version of firmware.
8:38If we needed to update one, we could right click on it.
8:41From the dropdown, select Upgrade.
8:43And if there was an update available via FortiGuard,
8:45we can choose it.
8:46Or we could browse for it if we downloaded it manually
8:48from Fortinet.
8:49So I just made a quick trip over to support.fortinet.com
8:52and looked at the latest version of firmware for the FortiAP.
8:56And I've got a 221E.
8:57And it is build 700, even though it's in a subfolder called
9:027.0.3 with build number 0060.
9:05And that is currently what I'm running right here.
9:08So my firmware is current on these APs,
9:10which is a great start.
9:11And you know what I'd like to do just as an exercise?
9:13Let's do this.
9:14I'm going to right click on AP number 5
9:16and I'm going to go ahead and delete it and click on OK.
9:20And what I'd like to do as a demonstration
9:22is I'm going to take AP-5, or what was AP-5,
9:24and I'm going to connect it directly
9:26to one of the ethernet ports on the FortiGate.
9:29So if we go to Network and Interfaces on firewall 1
9:32and we take a look at our interfaces for a moment--
9:35now you open up the ones that are not being used.
9:37On this internal switch, it has 2, 3, 4, and 5.
9:39I'm going to go ahead and borrow port number 2 from there.
9:41So I'm going to go ahead and say,
9:43you know what, Mr. Logical Internal VLAN Switch,
9:45I'm not going to have you use interface 2.
9:46I'm going to remove that.
9:47And that way, part 2 can be available
9:49as a normal interface.
9:50So we'll go down to internal 2.
9:52And let's go ahead and call this for AP-5.
9:55And for the use, it's going to be LAN.
9:57And for its IP address, let's use 10.9.0.71
10:02with a 24-bit mask.
10:04And let's enable PING and Security Fabric Connection.
10:07And we'll enable DHCP services.
10:10And we'll start at 101.
10:12And I'll set this really short lease of 300
10:14for my lab environment.
10:15And that way, we can demonstrate using
10:17access points that are hanging off
10:19of a switch that's being managed by the FortiGate
10:21as well as a port directly connected to the FortiGate.
10:24And what I'll do is I'll use a little transformer
10:26to supply power.
10:27Because internal 2 does not do power over ethernet.
10:30And I'll also have it create a little address object for us
10:32as well, representing the 10.9 subnet.
10:35All right.
10:36So having done that, let me go ahead and click on OK.
10:38So I want to take this access point, which
10:40will be access point 5, plug it into port internal 2
10:43on the FortiGate, and then use this transformer to supply
10:46power to this access point.
10:48All right, it is done.
10:49So if we go back down to Wi-Fi and Switch Controller,
10:51I have an access point that was waiting for authorization.
10:54That's the one we just pulled out.
10:56So I'll go ahead and delete that and click OK.
10:59And in a few moments, we should have an access point showing
11:01up off of our internal 2 interface, as opposed
11:04to coming in from VLAN 2.
11:05That should be then wanting to be authorized as well.
11:07On that way, we have examples of two different ways
11:10of connecting the access points and associating it
11:13with the FortiGate with the directly-connected access point
11:15or via the switches.
11:17So as we wait for that, let's go up to Dashboard and Network.
11:20And we'll click on the DHCP widget right here.
11:23And let's see if we have any IP addresses assigned out
11:25in the 10.9 range.
11:26And right there.
11:27All right.
11:28So there's our FortiAP.
11:29It has an IP address.
11:30Fantastic.
11:30And it shows the interface it's connected to.
11:32Great, great, great.
11:33So let's go back down to Wi-Fi and Switch Controller,
11:36back down to Managed FortiAPs.
11:38And in a moment, that access point
11:39should show up right here waiting for us to authorize it.
11:43All right, and there it is.
11:44So I'm going to right click on that and we'll edit it.
11:47And we'll call it AP-5 and click on OK.
11:50And we'll also authorize it, which is important.
11:53So now it's authorized.
11:54And once it's fully initialized, it
11:56should show the OS version, which should
11:58be the same as the others.
11:59And it should also show from an LLDP perspective
12:02that it is directly connected to firewall 1,
12:04as opposed to the individual ports on switch 2.
12:07So it's been a moment.
12:08I just did a refresh.
12:09Here it shows AP-5 online.
12:12If we scroll over to the right, it
12:13shows no LLDP neighbors found.
12:15However, I believe that will also correct itself here
12:17in a few seconds as well.
12:19And then here on the Connected Via,
12:20its connected via the port internal 2 directly
12:23on the firewall.
12:24So let me go ahead and do a refresh.
12:26And here now in the LLDP column, it's
12:27indicating it's connected directly to firewall 1.
12:29So while we're here and talking about access points,
12:32I also want to take a moment and chat with you
12:34about what to do when something goes terribly horribly wrong.
12:37Let's say, for example, access point 5 won't come online.
12:40We can't reach it.
12:41I mean, what do we do?
12:42A lot of these access points do not
12:44have a separate console port, so you can't actually
12:46get a console port and see what's going on at the CLI.
12:49So we need some mechanism for troubleshooting
12:51to get access to a device.
12:53Like, for example, this access point.
12:55And what Fortinet has given us with most of these access
12:57points is the ability to enter something that they
12:59call configuration mode.
13:01And here's how it works.
13:02On the access point, there is a little reset button.
13:05So you get a little pin and you put it in that hole
13:07and you push on it.
13:08And here's the secret about going
13:09into configuration mode-- we do not want to push it
13:12for a longer than 10 seconds.
13:14Because if we do, it's going to do a factory
13:16reset of that access point.
13:17Now, perhaps that's something we want to do.
13:19If so, great, 10 seconds will get you there.
13:21But what we also don't want to do
13:22is we don't want to hold that reset button down
13:25for less than five seconds.
13:27So the sweet spot is five to 10 seconds.
13:30We want to hold down that reset button,
13:32and that's what puts us into configuration mode.
13:34So this access point is going to generate its own SSID--
13:38its own wireless network.
13:40And that wireless network name is going to be very obvious.
13:42It's going to show up as FAP for FortiAP dash config followed
13:47by the serial number of that FortiAP.
13:49And then what we can do is we can use our wireless network
13:51card on our management computer and connect
13:54to that wireless network, where DHCP services are active.
13:58So it's going to have the IP address of 192.168.100.1.
14:04And it will dynamically assign our computer
14:06and address from that subnet.
14:08So what I'd like to do right now is demonstrate that for you
14:11in action.
14:12So let's imagine that we're having
14:13some issue with access point 5.
14:15And I'm going to go over to access point 5
14:17and I'm going to push down the reset button for probably
14:20around seven seconds.
14:21And I'm going to time it too, because if we
14:23go too long, if we go more than 10 seconds,
14:25we're going to do a reset.
14:26So if we just want to get config access to access point 5,
14:28we need to be in that sweet spot between five and 10 seconds.
14:31So I'll go ahead and do that right now.
14:33All right, so it is done.
14:34And I timed myself, seven seconds.
14:37That way I was at least five and less than 10,
14:39and wasn't going to do a reset on that access point.
14:41And let me bring up Control Panel on my computer.
14:44And I'm going to right click on my Wi-Fi adapter.
14:45In fact, before I do that, let me just
14:47see where I'm at with my ethernet right here.
14:49So I'll bring in a command prompt here.
14:51And let's just do a quick IP config.
14:53This is on a windows computer.
14:54So currently, my ethernet adapter
14:56has the IP address of 192.168.1.151
14:59with a 24-bit mask.
15:00Great, great, great.
15:00And I have a wireless network card,
15:02but I'm not currently associated with any wireless network.
15:05So let's also do this.
15:07Let's bring up NetSpot and let's take a look
15:09and see when that network shows up.
15:12So I'm expecting here in a few minutes
15:14for that wireless network from that access point
15:16to be visible so I can join it.
15:18So I'll leave this running right here.
15:19And then over here on the Wi-Fi, I'll right click and say
15:22Connect/Disconnect.
15:23And then over on the other screen,
15:25I'm going to click on More Wi-Fi Settings.
15:27And this will give me the ability
15:28to join a wireless network right here.
15:30So I don't see it yet, but I will give it a few more moments
15:33to initialize and go into configuration mode.
15:37So I'm going to sort these based on signal strength.
15:40And I'm going to change my scan interval to every five seconds.
15:43And that way, when it appears, we should see it right away.
15:46And it is also going to have open authentication.
15:49So we could look for that as well.
15:50Over here at security, I could do a sort based on security.
15:53And look at that, it is right there.
15:55And it's showing right there, but it is grayed out.
15:57That means it was present for a short period of time
15:59and now it is gone.
16:01So let me do this.
16:03So I'm going to remove that access point from the firewall.
16:06I'm going to remove the cable and then hit the reset button
16:09for seven seconds again to go back into configuration mode.
16:11So it could be, because it's being managed by a FortiGate,
16:14perhaps it's not completely willing to go into config mode.
16:16So I'm going to go ahead and disconnect it from the firewall
16:19and then I'm going to hit reset again for seven seconds.
16:21All right, and there it is.
16:23So I've got options here in the 5 gigahertz range on channel 36
16:27and also at the 2.4 gigahertz range on the center channel 6.
16:32It's also showing up here now as an available network
16:35that I can join.
16:35So I'll go ahead and click on that
16:37and say I want to go ahead and connect.
16:39There's no authentication required.
16:41It's open authentication.
16:42It says we're connected.
16:43Let's take a look at the CLI on my computer just to verify it.
16:46So just a moment ago, I had my local address of 192.168.1.151
16:51on my ethernet adapter.
16:53And I should have now another IP address on my wireless adapter.
16:56So we'll do IP config again.
16:58And sure enough, there's my local area network ethernet
17:01wired connection.
17:02And here is the IP address I've been
17:04assigned by the access point.
17:06So now we can just open up HTTPS to that IP address,
17:08192.168.100.1, which is the IP address of the AP itself.
17:14And we can manage it in config mode.
17:16And look at that.
17:17That IP address is also associated with my cable modem.
17:21So let me do this for the demonstration.
17:24I'm going to go here.
17:25I'm going to disable my ethernet adapter.
17:27And let me go ahead and try back at 100.1.
17:30And now we're at the FortiAP.
17:32That was just a terrible coincidence.
17:34All right, then we'll go ahead and log in.
17:35So we've set up a password on that access point.
17:38We'll go ahead and use that same password and click log in.
17:40And now we are logged in directly to that AP.
17:42So down at the bottom, it shows us that we're in config mode.
17:45And we need to reboot to exit configuration mode.
17:47So from here, we can verify the firmware version,
17:50the base MAC address, the radio information.
17:52So here's the 2.4 gigahertz range radio.
17:55And here's the 5 gigahertz range radio.
17:57And there's the SSIDs that it's currently
17:59offering on both of those.
18:00Then there's an option there for system status
18:02on the left, which can confirm any of those details for us.
18:06And if we select WTP Configuration,
18:07it has a section for CAPWAP session.
18:09So it was connected over to the FortiGate,
18:12and it got an IP address assigned to it as 10.9.0.101.
18:16And it's using that IP address for the CAPWAP tunnel
18:19up to the controller, or at least when I plug it back in,
18:22it will be.
18:22And then one below that, we have radio configuration.
18:25So radio 0 is the 2.4 gigahertz range.
18:28And the radio 1 is the 5 gigahertz range.
18:30And then under Settings, there's an option
18:32here for Local Configuration.
18:34So if we want to change the host name or the password
18:37or other details, we could, including the baud rate.
18:39So it's kind of funny, because the access point
18:42has absolutely no serial port.
18:44So the baud rate is irrelevant for this platform.
18:46But other access points have a console port,
18:48so that would be relevant there.
18:50We also have options regarding discovery type.
18:52So for the discovery type, which is
18:53the means by which this access point can find the FortiGate,
18:56it's set to auto.
18:57And it's going to try multiple different options
18:59to discover and connect up with the FortiGate controller.
19:02However, if you don't want to use the auto method,
19:04you can say static.
19:05And we could specify the IP address of the controller,
19:07or could say DHCP.
19:09And then provide under DHCP services
19:11option 138 specifying the IP address of the controller.
19:15Or we could do it via DNS, where we
19:17create a DNS entry behind this name that
19:19maps to the controller.
19:21Or use broadcast, which is one of the default methods,
19:24or multicast.
19:25And this is the default multicast address.
19:27So if you have multicast routing set up in your enterprise,
19:30this would be an option where the access point doesn't
19:32have to be on the same subnet as the controller,
19:34as the FortiGate.
19:35And as long as multicast routing is set up,
19:37this would act as a mechanism to allow the access
19:39point to find the controller.
19:41Or if we want to use FortiAP Cloud,
19:43we could click FortiAP Cloud, which
19:45is now known as FortiLAN Cloud, because it incorporates
19:48the switching and the apps.
19:49But in either case, we could specify that,
19:51and then putting information for the server.
19:53So by default, it's set to auto.
19:55If you don't need to change that, leave it as auto.
19:57And then option of broadcast, which
19:59is included as part of auto, is going
20:00to do the job for us, especially if we place the access
20:03point directly connected to the FortiGate
20:06to an interface there or to a switch port on a switch
20:09stack that the FortiGate is managing.
20:10All right, so if we needed to make some config changes here,
20:13we could do it here in config mode.
20:14And then once those are made, we just
20:16go up to admin here in the upper right.
20:18And from the dropdown, we just simply say reboot.
20:21And that's going to reboot this FortiAP with those changes
20:24that we modified in config mode.
20:25So I'm going to walk back over to the rack.
20:27I'm going to plug that 40 AP back into the firewall
20:31on internal 2.
20:32I'm also going to reconfigure my computer
20:33so that I have access to the network.
20:35So I'm going to enable my ethernet adapter.
20:38All right, that looks good.
20:39Now, in a few minutes, hopefully this AP-5--
20:41let me refresh the screen.
20:42Hopefully, that's coming back, unless I
20:44made some change in config mode which would prevent that.
20:47And the other great thing about these devices
20:50is, because we're managing these apps from the FortiGate,
20:52we could actually reset this completely.
20:54Just hold down the reset button for a little longer
20:57than 10 seconds, do a factory reset,
20:58and then bring it back into the fold, and we'd be good to go.
21:01In fact, it's been about two or three minutes.
21:03I must have made a change that it didn't like
21:06while I was in config mode.
21:07So I'm going to do exactly that.
21:08I'm going to go ahead and just do a full reset on access point
21:115 and bring it right back in.
21:13Yeah.
21:14When I went over there, the LEDs for the radios for the 2.4
21:18and the 5 gigahertz were on.
21:19And at the moment, they shouldn't
21:21be, because we don't have any SSIDs set up.
21:23So that implies that it was still
21:25in either config mode or acting on its own.
21:28So I just did a full reset.
21:29And it should be back here in the fold in just a moment.
21:32And one of the cool things we're going
21:33to discover as we continue our sets of videos
21:35together, by using FortiAP profiles-- so there's
21:38a profile that was created based on the platform by default
21:41they're all using.
21:42But we can modify this or we can create new AP profiles
21:45and assign them to access points that control and tell them
21:48how to behave.
21:49And that way, we can bring in dozens and dozens of APs,
21:52assign them to the profiles that are appropriate for what
21:54we want them to do.
21:55And that removes a lot of the work
21:57of having to individually configure
21:58access points to support the wireless local area network.
22:01So let's go back to Managed APs.
22:03And I'm going to remove this one just by saying delete and OK.
22:08And when it comes back, I'll just
22:10go ahead and reauthorize them and bring them back in.
22:12And there it is.
22:14So I'll go ahead and bring it back in.
22:15We'll authorize it.
22:16And we'll right click on there and we'll edit it.
22:19And we'll call this once again AP-5.
22:22And that should be fully online.
22:23And the LLDP information should reflect that here
22:26in just a moment as well.
22:27So now that we have most of our infrastructure in place,
22:29there's a few more steps that we need
22:30to take to get wireless network services up and running.
22:33Number one is we need to create Wi-Fi networks, which
22:36we're going to do by creating one or more SSIDs.
22:39And I'll walk that in a separate set of videos.
22:41However, before we leave this set of videos,
22:43I'd like to share with you one additional product
22:45from Fortinet that can help us with the big picture
22:47view of what's happening in our wireless space.
22:50So we'll do that next with a tool called FortiPresence.
22:53I'll see you there in just a moment.
22:55Meanwhile, I hope this has been informative
22:57and I'd like to thank you for viewing.
FortiPresence
0:00[MUSIC PLAYING]
0:06And welcome back.
0:07A big part of wireless networks is to support the business,
0:11and part of that business may be to supply guest access
0:13for your customers.
0:14Maybe we go to a coffee shop or a restaurant,
0:16and there's free Wi-Fi or a hotel.
0:18There's free Wi-Fi.
0:19We love free Wi-Fi or at least, included Wi-Fi.
0:21That's part of the agreement that we're
0:23going to click on oftentimes when we say we're
0:25going to agree to the terms.
0:26It often includes the details that they
0:28can track where you're going, what you're doing,
0:30and they can take that data and sell it.
0:32Now, how did they go about collecting and gathering
0:35all that data?
0:35Well, one solution for the collection
0:37of that data regarding where people
0:38are going, where are they searching for, and so forth is
0:40use a product from Fortinet called FortiPresence.
0:43And in this video, I'd like to give you a presentation of what
0:46that looks like.
0:47So let's begin here, and this is just
0:48a PDF regarding FortiPresence.
0:50And it comes in a few flavors, we
0:51could have it hosted in the cloud as a cloud service
0:54or we could deploy it as a couple of virtual machines
0:57in our infrastructure.
0:58And here's the goal is to gaining insight and behaviors
1:00of visitors within their site, both in real time
1:02and across time period.
1:03So we click the data, have it sent over to
1:06for a FortiPresence, and then FortiPresence
1:08can generate reports and output showing us exactly what's going
1:11on, which could include trends, how many visitors were there,
1:14time spent at a location, comparison across areas,
1:18and so forth.
1:19And there's lots of applications for this in malls, stores,
1:21hospitals, hotels, theme parks, airports, et cetera.
1:24So all Wi-Fi enabled devices, if they're on Wi-Fi,
1:27are sending out signals.
1:28So at 40 AP or if you have Wi-Fi integrated
1:30as part of your FortiGate, which would be for the Wi-Fi,
1:32they capture the Mac address, the strength of the signal
1:35from that smartphone or from that device, that's forwarded
1:38over to for FortiPresence.
1:39And then FortiPresence can take all that data
1:41and help us build reports and make sense of it.
1:43And here's an example of some screens and reports
1:45that it could build.
1:46And as far as the analytics and what it can gather,
1:49it can include things such as total visitor traffic, how long
1:52they were there, repeat visits.
1:54And here's an example of what some of those analytics
1:56could be used for.
1:57So I thought to myself, self, you know what,
1:59I'd love to see this firsthand.
2:00So I have behind me a rack of Dell servers.
2:04So I went to the deployment guide,
2:05I downloaded the files required.
2:08I created two VMs, one for infrastructure, one for apps.
2:11Simply following these instructions,
2:12and I ended up deploying these two, which
2:15are the FortiPresence's infrastructure virtual machine,
2:17and then this one here is the FortiPresence app
2:20virtual machine.
2:21So once they were deployed, which is pretty easy just
2:23a few clicks, I then logged on with the default username
2:26and password.
2:27I verified with the IP addresses were with ifconfig at the CLI.
2:31And by default, they were both DHCP assigned addresses.
2:33And so I just left them at that.
2:35The infrastructure machine-- in fact,
2:36let's take a look real quick.
2:37This guy got the address of 192.168.1.21
2:40in my lab environment.
2:41And the app's VM got the IP address of 192.168.1.22.
2:45So having to do this command as route,
2:47they locked out his route and log back in as user Presence
2:50with the password of Presence, I used a copy program
2:52to copy these two files over to their respective servers.
2:55And to use that, I, used a product
2:56that's integrated as part of secure CRT which is secure
2:59FX, which allowed me to very easily copy
3:01the files that downloaded from Fortinet over to those VMs.
3:06Then I follow the steps for extracting the files.
3:08I ran the scripts they asked me to run.
3:10As part of the setup, it asked me
3:11about the details regarding the infrastructure
3:13host and the app's host, those two VMs respectively.
3:16It asked me to create a new username which I did,
3:18and the password which I did, insert all the processes,
3:20and it was done.
3:21And then when I was done, I simply
3:22used HTTPS from a browser to log in to the application VM.
3:26And that looks something like this.
3:28So from here, you, can go to Admin and site management,
3:31and you can add buildings.
3:33So here, I just clicked on the building.
3:35And let's go ahead and put a building right here on--
3:37how about right at Charleston, near the Arts District.
3:40Boom.
3:41So I basically moved the map around to represent Las Vegas,
3:43and you can just drop where you want the building to be.
3:46I'll go ahead and click on Save.
3:47And then for that building, you can add a floor,
3:49and have the blueprints regarding those floors.
3:52So this is on prem with local virtual machines,
3:54but it also can be integrated as part of your Fortinet account
3:57with cloud services.
3:58And then based on all the information that
4:00sent to FortiPresence, it can then generate reports
4:02for you visitor report, network report, site reports, device
4:05reports, et cetera.
4:06I mean, this is a great tool to help correlate and get
4:09a big picture view of what's happening
4:12in your wireless networks.
4:13So if we go back to the dashboard
4:14I've got two buildings, two sites,
4:16I've got one I did earlier.
4:18And currently, we don't have any details
4:20on what's going on because I don't have any access
4:22points currently supporting any active SSID's
4:24feeding into FortiPresence.
4:26So it's pretty tough to use a tool you're not aware of.
4:28So in this video, I want to make you aware of FortiPresence.
4:31And again, it's available either on prem
4:33or you can do it in cloud services from Fortinet.
4:35So in this set of videos, we focused on wireless network
4:38design and moving a step closer to actually implementing
4:41wireless networks, which by the way,
4:43is the topic of our next set of videos
4:45is actually implementing the wireless networks.
4:47And I'll see you there soon.
4:48Meanwhile, I hope this has been informative,
4:50and I'd like to thank you for viewing.
Team training path
Turn this skill into assignable team training
This free skill is a preview of the courses your team can assign, track, and report on with CBT Nuggets.
$708
seat / year