CAPWAP tunnel traffic is dropped when offloading is enabled (with FAP managed by a VLAN interface). There are three workarounds:Disable capwap-offload in system npu and reboot.Set dtls-policy dtls enabled in wireless-controller wtp-profile. This may cause traffic to slow.Enable UTM in the firewall policy (does not require reboot). This workaround cannot be applied on NP6Xlite FortiGates (FG-6xF and FG-10xF).config firewall policy edit set utm-status enable set ssl-ssh-profile "certificate-inspection" set av-profile "g-default" nextend