FortiExtender
FortiExtender offers wireless connectivity for nearly any operational network.
Andy_G
Staff
Staff
Article Id 194061

Description

This article gives the steps to configure the FortiExtender.


Scope

FortiOS 5.2.3, FortiExtender firmware version 2.0.1 build 0009 and TP-Link MA260 have been used to produce this article.


Solution

It is recommended to use a SIM card with no PIN assigned for an initial configuration, so this is not going to represent a failure point in a first configuration. A Smartphone or Tablet can be used to remove the PIN.

It is also recommended to use a 3 foot USB extensor wire to connect the USB Modem to the FortiExtender device.

Configuration Steps

Connect FortiExtender to a free interface in the FortiGate. The interface must be configured as “Dedicated to FortiAP”.

agodwin_FD36643_tn_FD36643-1.jpg

From the FortiGate CLI, enable FortiExtender and wireless controller:
config system global
set fortiextender enable
set wireless-controller enable
end
A new entry will now appear under the Network Menu. It is necessary to access to this new option and authorize the FortiExtender device.

agodwin_FD36643_tn_FD36643-2.jpg

After authorization process, the connection parameters can be configured (depending on the ISP) through the “Configure Settings” button.

agodwin_FD36643_tn_FD36643-3.jpg

Vodafone-Spain Parameters:
APN : ac.vodafone.es
User : vodafone
Password : vodafone
Phone number: *99***1#
Movistar-Spain Parameters:
APN : movistar.es
User : MOVISTAR
Password : MOVISTAR
Phone number: *99***1#
The parameters for the carrier should be entered as shown below:

agodwin_FD36643_tn_FD36643-4.jpg

By default, the modem is configured as “Always connect”, if the configuration is changed to “On Demand”, the following FortiGate CLI command must be executed to force the connection:
execute extender dial <FortiExtender serial number>
A Policy must be created to allow connection from the LAN to the internet, using the modem connected to the FortiExtender. The outgoing interface must be: FEXT-WAN1.

If connection to FortiExtender management IP is needed, a new policy must be in place, allowing traffic from the interface where the management computer is connected to and destination interface must be the interface in the FortiGate where FortiExtender is connected. HTTP access to the FortiExtender will be allowed by default, using next credentials: admin/admin.



 

 

Contributors