No additional config needed, if the udp 4500 traffic reaches the controller through the NAT on your firewall.
That is except if you have controller clusters with a mobility conductor, in which case you would need to configure the public IP for each of the controllers so the RAP can reach both of them. With single controller or controller HA/VRRP that is not needed.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Jul 12, 2023 05:30 AM
From: mohamed
Subject: RAP AP Configuration
Thanks Herman
Is there are any configuration from controller side related to port forwarding?
Original Message:
Sent: Jul 12, 2023 05:00 AM
From: Herman Robers
Subject: RAP AP Configuration
I'm not a Fortinet expert, but this looks like you are port forwarding UDP port 4500 on your external port (wan) to 192.168.10.100 (your controller, or the VIP) on the same port 4500. That is what I would do as well.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
Original Message:
Sent: Jul 11, 2023 01:07 PM
From: mohamed
Subject: RAP AP Configuration
HI Herman,
Thanks for your effort
I will publish the controller through fortigate firewall .should I publish it with dedicated port ?
is there any configuration on MC relared to port forward?
Original Message:
Sent: Jul 11, 2023 08:32 AM
From: Herman Robers
Subject: RAP AP Configuration
RAPs can only connect on udp/4500. If you forward udp port 4500 on the firewall to your controllers, that should work fine.
Note that gateway clusters (under MCR/MM) require their own public IP (or port forward for udp/4500 on different public IPs). HA/VRRP should work with just a single public IP.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.