Sora Yazılım
English
Custom software solutions from Türkiye

What Is FortiAP? Choosing Enterprise Wi-Fi 6, 6E and Wi-Fi 7 Access Points

FortiAP is Fortinet's family of enterprise wireless access points covering the Wi-Fi 6, Wi-Fi 6E and Wi-Fi 7 generations. It needs no separate WLAN controller appliance: access points are managed by the FortiGate integrated controller, FortiEdge Cloud or FortiSASE, and wireless traffic passes through the same security policy as wired traffic. This guide explains the criteria for choosing the right generation and model.

What is FortiAP and how does it differ from a classic WLAN controller architecture?

FortiAP is an enterprise Wi-Fi family that moves the management plane out of a dedicated controller box and into the Fortinet Security Fabric. In the traditional architecture, access points attach to a redundant pair of WLAN controllers; with FortiAP that role is taken by the FortiGate integrated controller, the FortiEdge Cloud portal or FortiSASE.

A conventional enterprise wireless network has three separate components: the access points, the WLAN controller that manages them, and the firewall that inspects the traffic. Each has its own management interface, its own rule set and its own log stream. Because the policy applied to a wireless client and the policy applied to a wired client are defined in different places, they drift apart over time. FortiAP simplifies this structure: access points register directly with the FortiGate, and wireless traffic passes through the IPS, application control and web filtering profiles configured on the FortiGate.

This consolidation brings the network team three concrete benefits. First, there is no separate rule set to maintain per SSID; a wireless user sees the same policy as a wired user. Second, incident investigation happens in a single log stream; the wireless authentication event and the firewall event are read on the same timeline. Third, there is one less appliance to manage, patch and back up. According to the Fortinet FortiAP Series data sheet, access points are managed centrally by the FortiGate integrated wireless controller, and NAC functions are built in when the deployment is FortiGate-managed.

The product family covers indoor, outdoor and ruggedized models. On the Wi-Fi 7 side, the FAP-441K and FAP-443K, with four radios and four spatial streams, are the flagship models; the FAP-241K and FAP-243K also carry four radios (three for access, one for scanning) but offer two spatial streams plus one 10 Gigabit and one 1 Gigabit port, and are positioned for medium-density areas; the ruggedized outdoor Wi-Fi 6E models are the FAP-432G and FAP-234G. For the current model list and technical values, consult the Fortinet FortiAP Series data sheet; for our deployment and procurement scope in Türkiye, see our FortiAP solution page.

Which management models does FortiAP support, and which one suits you?

FortiAP works with one of three management models: the FortiGate integrated WLAN controller, the FortiEdge Cloud provisioning and management portal, or FortiSASE. If a FortiGate already exists at the site or head office, the first model requires no additional investment; cloud management fits multi-site organizations without on-site IT, and FortiSASE fits micro-branches and home offices.

Management modelHow it worksTypical scenarioDesign consideration
FortiGate integrated controllerAccess points register with the FortiGate's built-in WLAN controller; wireless traffic passes through FortiGate security profilesSingle site or branches that already have a FortiGate; campusVerify the number of APs the FortiGate model can manage and the FortiOS version, with growth headroom
FortiEdge CloudAccess points are provisioned and managed from the cloud portal; a local FortiGate is not mandatoryStore and office chains without on-site ITPlan for the cloud management subscription and internet dependency; a FortiGate may still be needed for security profiles
FortiSASEThe access point acts as a SASE edge; traffic that must be inspected is steered to the cloud security stackMicro-branches, home offices of critical staffDefine split-tunneling rules and the per-user licensing model up front

In practice, the first model is the most common choice. If the organization already owns a FortiGate, no extra hardware is bought for the wireless controller; we covered which entry-level appliance fits which office in our FortiGate 40F, 60F, 70G and 90G comparison. For a business that does not yet have a FortiGate, the sequence matters: firewall first, then the access layer. That is why we recommend reading our firewall selection guide for SMBs before starting a wireless project.

One detail is often missed: new-generation access points require a minimum FortiOS version. Wi-Fi 7 models gained support in the FortiOS 7.4 branch, and every FortiAP firmware release specifies a minimum FortiOS version on the FortiGate side; for example, Fortinet's FortiAP 7.4.7 release notes list FortiOS 7.4.9 and later for that firmware. If your existing FortiGate runs an older release, an upgrade window should be planned alongside the access point purchase; always confirm the model-to-version match against the current release notes.

What is the difference between Wi-Fi 6, Wi-Fi 6E and Wi-Fi 7?

The difference is usable spectrum and channel width. Wi-Fi 6 (802.11ax) uses the 2.4 and 5 GHz bands more efficiently; Wi-Fi 6E carries the same radio into the relatively uncongested 6 GHz band; Wi-Fi 7 (802.11be) adds 320 MHz channels, 4K-QAM and Multi-Link Operation (MLO) on top of 6 GHz to increase capacity and latency consistency.

GenerationStandardBandsHeadline featureWhere it makes a difference
Wi-Fi 6802.11ax2.4 + 5 GHzOFDMA, MU-MIMO and BSS coloring for efficiency in crowded environmentsOffices, stores and classrooms with a mostly older client fleet; cost-driven refresh
Wi-Fi 6E802.11ax (6 GHz)2.4 + 5 + 6 GHzNew, uncongested 6 GHz spectrumCity-center offices with heavy neighbor interference, open-plan floors
Wi-Fi 7802.11be2.4 + 5 + 6 GHz320 MHz channels, 4K-QAM, MLO, preamble puncturingNew buildings, high-density meeting and training spaces, latency-sensitive applications

In practice, Wi-Fi 7's three innovations mean the following. Multi-Link Operation (MLO) lets a client stay connected on more than one band at once; when one band becomes congested, traffic shifts to another, which translates into latency consistency for voice and video sessions. 320 MHz channels are only possible in the 6 GHz band and raise the theoretical ceiling for a single client. 4K-QAM requires excellent signal quality; in a typical office only clients close to the access point benefit from it. The peak rates on a data sheet are therefore theoretical PHY values per band, not the speed a single user will see.

A concrete example: according to the Fortinet data sheet, the theoretical maximum data rates of the FAP-441K and FAP-443K are 1.148 Gbps on 2.4 GHz, 8.648 Gbps on 5 GHz and 11.53 Gbps on 6 GHz (4x4 MU-MIMO). Real throughput is determined by the generation of the client fleet, the channel plan, wall materials, interference from neighboring buildings and uplink capacity. Another important point is that the 6 GHz band is regulated per country. In Türkiye, the regulator BTK's technical criteria for licence-exempt radio equipment open the lower 5945–6425 MHz band to wireless LAN use. That 480 MHz range severely limits 320 MHz channel options, so multi-AP enterprise designs usually favour narrower channels for channel reuse. Verify power limits and conditions of use against BTK's current technical criteria and the product's approved configuration for the country before the project starts.

The client side must also be considered. Existing Wi-Fi 6 and 6E devices connect to a Wi-Fi 7 access point without issues, but they cannot take advantage of features such as MLO. If the organization's laptop and mobile fleet is predominantly Wi-Fi 6, the benefit of Wi-Fi 7 arrives not today but in the years when the fleet is refreshed. This is not a reason to postpone Wi-Fi 7, but a reason to time it correctly together with cabling.

Which FortiAP generation for which environment?

Three variables drive the choice: the generation of the client fleet, user density per square meter and the remaining life of the cabling. If an existing Wi-Fi 6 deployment runs without problems, there is no need to replace it just to skip a generation; in a new building or a comprehensive refresh, Wi-Fi 7 should be planned together with cabling and PoE.

ScenarioRecommended generation / model typeRationale
Small office, mostly older client fleetWi-Fi 6 indoor modelNo congested-spectrum problem; budget is better spent on coverage and security
Open-plan floor in a city centerWi-Fi 6E6 GHz band away from neighbor interference; an existing 2.5G uplink may be sufficient
New building, campus, large meeting and training roomsWi-Fi 7 four-spatial-stream model (FAP-441K/443K class)High density, latency consistency with MLO, 10G uplink installed together with new cabling
Mid-size office with a new cabling planWi-Fi 7 two-spatial-stream model (FAP-241K/243K class)Wi-Fi 7 features and a dedicated scanning radio; two spatial streams suit medium density, single 10G port
Yard, loading dock, open warehouseRuggedized outdoor Wi-Fi 6E (FAP-432G / FAP-234G)Temperature and humidity tolerance; mesh SSID where cable cannot be pulled
Hotel room, dormitory, patient roomWall-plate modelIn-room coverage and wired port needs; ceiling-mount Wi-Fi 6E/7 models in common areas
Micro-branch, home officeFortiSASE-managed modelCentral policy without an on-site firewall; split tunneling

The principle behind the table is simple: cabling is a far longer-lived investment than an access point. Installing Cat6A cable and 802.3bt-capable switches today and mounting Wi-Fi 6E access points lets you move to Wi-Fi 7 in a few years by replacing only the access points. The reverse, connecting a Wi-Fi 7 access point to a 1G port on an 802.3at switch, forces the device into a reduced-power mode and turns the uplink into the bottleneck.

For readers who want to evaluate a non-Fortinet alternative, our portfolio also includes Ruijie; for projects with a different coverage and budget profile, our article on the Ruijie RG-AP enterprise access point is useful for comparison. When the existing infrastructure is built on FortiGate, however, the single management surface and single policy advantage is usually decisive.

How do you plan the PoE budget, cabling and FortiSwitch?

The access point's PoE class must match the power the switch port can deliver. Depending on the model, FortiAP requires 802.3at (PoE+) or 802.3bt (PoE++); Wi-Fi 7 flagship models need 802.3bt for full performance and carry 10 Gigabit uplinks. Switch, cable and access point must be sized as a single project.

The trap on the power side is an access point that appears to "work" on reduced power. The Fortinet data sheet defines two PoE modes for the FAP-441K and FAP-443K: full mode (802.3bt, two 802.3at ports or DC power) runs 4x4 radios at maximum power; high mode (a single 802.3at feed) reduces the radios to 2x2 and transmit power to 17 dBm and disables the USB port. In other words, a Wi-Fi 7 flagship connected to an older PoE+ switch will provide connectivity, but part of the capacity you paid for goes unused. The same models ship with two multi-gigabit RJ45 ports (100M/1G/2.5G/5G/10G) and support 802.3bt on both, providing hit-less PoE failover.

On the power delivery side, every model in the FortiSwitch Secure Access family supports PoE+; selected models deliver 90 W per port with 802.3bt and scale to 48 access ports with 10GE uplinks in a 1 RU chassis. Connecting FortiSwitch to the FortiGate via FortiLink means wired port policy and wireless SSID policy are managed from the same interface. We covered PoE budgets, uplink speeds and FortiLink topology in detail in our FortiSwitch and FortiLink selection guide.

Items we recommend checking during planning:

  • Total PoE budget: class per access point (at/bt) times quantity, plus other PoE consumers such as cameras and IP phones; the switch's total PoE budget is a separate limit from its port count.
  • Uplink speed: 2.5G is sufficient for Wi-Fi 6E in most scenarios; Wi-Fi 7 models should use the 10G port.
  • Cable category: Cat6A for new runs; on existing Cat5e runs, multi-gig speed and distance limits must be tested.
  • Ceiling height and mounting: the weight and antenna pattern of Wi-Fi 7 models affect placement; an RF site survey determines mounting points.
  • Redundancy: dual PoE feeds in critical areas and coverage overlap between neighboring access points.

Wireless security: WPA3, rogue APs and guest separation

The wireless network should be designed as a separate trust zone. WPA3 with 802.1X authentication on the corporate SSID, separate SSIDs and VLANs for guests and IoT, a default-deny rule between them and continuous rogue AP scanning; with FortiAP these controls are applied from one place through FortiGate policy.

According to the FortiAP data sheet, authentication supports WPA, WPA2 and WPA3 with 802.1X or pre-shared keys, a web captive portal and MAC lists; at the radio level, rogue scanning and WIPS/WIDS can run in background or dedicated-radio mode. Models with a dedicated scanning radio listen to the environment continuously without slowing the client-serving radios; this is the basic control needed to detect an unauthorized access point plugged into the corporate network or a fake network impersonating the corporate SSID.

The real difference is on the policy side. When wireless traffic passes through FortiGate profiles, IPS, application control and web filtering are applied to the wireless client too; no separate rule on a separate controller is needed to stop a device on the guest SSID from reaching the corporate server network. SSID modes also shape the design: the data sheet lists Local-Bridge, Mesh and Tunnel modes. In Tunnel mode all wireless traffic is carried to the FortiGate and fully inspected; in Local-Bridge mode traffic is dropped onto the local VLAN and the branch uplink is preserved. Which SSID runs in which mode is a balance between security requirements and branch bandwidth.

On the compliance side, the reference text in Türkiye is the Personal Data Security Guide (Technical and Administrative Measures) published by the Personal Data Protection Authority (KVKK), which lists network firewalls and access authorization among the technical measures. The practical translation for a wireless network is: separate the guest network from corporate resources, store authentication and session records centrally, and restrict administrative access. For specific obligations and retention periods, verify the current legislation and official guidance; this article is not legal advice.

What determines the cost of a FortiAP project?

Total cost is not a single list price but the sum of six items: model and generation, the quantity derived from the RF plan, the management model, PoE switching and cabling, the FortiCare support term, and the scope of installation and managed services. A figure quoted before these items are settled is not a comparable offer.

Model and generation is the first item; the difference between a four-spatial-stream Wi-Fi 7 flagship and a two-spatial-stream model is not just the device price but the port count, the PoE redundancy option and the switch capacity it requires. The second item is quantity, and this is set by an RF site survey rather than an estimate: wall materials, floor plan and density profile call for different numbers of access points for the same floor area. The third item is the management model; if the FortiGate's capacity is sufficient there is no additional cost, while FortiEdge Cloud brings a subscription and FortiSASE brings per-user licensing.

The fourth item is PoE switching and cabling, in most projects the most overlooked part of the budget. The fifth is the FortiCare support term: 1, 3 or 5 years of coverage for hardware replacement and software updates directly changes the total cost of ownership. The sixth is installation, RF validation measurement and any managed service requested afterwards. As an independent solution partner, Sora Yazılım presents these six items in a single quote with the scope spelled out; the same team handles project, procurement, installation and managed services.

Frequently Asked Questions

Do I need a separate WLAN controller appliance for FortiAP?

No. FortiAP access points are managed by the FortiGate integrated WLAN controller, the FortiEdge Cloud portal or FortiSASE. If the organization already has a FortiGate, no additional controller hardware is purchased; you only verify the number of access points the FortiGate model can manage and the FortiOS version.

How many FortiAPs can one FortiGate manage?

The number depends on the FortiGate model, and a single general figure would be misleading. During design, the manageable access point count on the official data sheet of the chosen FortiGate model is checked and sized with growth headroom; if capacity is insufficient, a larger model or cloud management is considered.

Does it make sense to move to Wi-Fi 7 now?

Yes, if you are building new, refreshing comprehensively or installing new cabling; cabling outlives access points by far, and Wi-Fi 7 flagship models come with 10 Gigabit ports. If an existing Wi-Fi 6 deployment runs well and the client fleet is older, there is no need to replace it just to skip a generation.

Which PoE class does FortiAP require?

802.3at (PoE+) or 802.3bt (PoE++) depending on the model. The Wi-Fi 7 flagship models FAP-441K and FAP-443K require 802.3bt for full performance; on a single 802.3at feed the radios drop to 2x2 and USB is disabled. When choosing a switch, check the total PoE budget separately from the port count.

How should we separate guest Wi-Fi from the corporate network?

With a separate SSID, a separate VLAN and a separate policy set. A default-deny rule is written from the guest VLAN to the corporate server network, and authentication and session logs are collected centrally. In a FortiGate-managed FortiAP deployment these rules are defined in the same interface as the wired policy.

When is a mesh SSID used?

Where an Ethernet cable cannot be pulled. FortiAP supports Local-Bridge, Mesh and Tunnel SSID modes; in mesh mode the access point joins the network over a wireless backhaul. Because capacity and latency are worse than a wired link, mesh should be reserved for exceptional points rather than used as the main coverage method.

Conclusion

FortiAP turns the enterprise wireless network from a hardware list into part of the security architecture: the controller lives inside the FortiGate, there is one policy and one log. The criteria for choosing a generation are the client fleet, density and the life of the cabling; Wi-Fi 6 refreshes an existing setup economically, Wi-Fi 6E provides an escape from congested spectrum, and Wi-Fi 7 should be planned together with cabling for new buildings and high density. PoE class, uplink speed and the FortiSwitch access layer are inseparable parts of that decision; on the security side, WPA3, rogue scanning and SSID/VLAN separation should be standard.

In our field experience, the best results come from projects that begin with an RF site survey and treat switches, cable, access points and support term as a single scope. For a wireless refresh, a new building design or a Wi-Fi 6E/7 migration, you can request a free discovery call and ask for a quote on the model and support combination that fits your existing infrastructure.

Need help with the topics in this post?

Schedule a free discovery call with Sora Yazılım — we'll propose a concrete roadmap.

WhatsApp Support