Skip to main content
nmichael
Staff
Staff
September 11, 2017

Technical Note: SSL warning with invalid CN error for internal CP authentication on FortiGate

  • September 11, 2017
  • 0 replies
  • 4967 views
Description
When a user connects to a wireless network with internal captive portal authentication, the device is redirected to url: https://x.x.x.x:1003. Since FortiGate is installed with standard certificate, the user is presented with an SSL warning error of using invalid common name because it does not match the IP address of the captive portal server (or FortiGate).

nmichael_FD40682_tn_FD40682-1.jpg

Scope
All versions.

Solution
This error can be avoided only by redirecting the wireless users to  a Url that includes the FQDN of the FortiGate; instead of the FortiGate IP address. https://<FQDN>:1003

This can be implemented with the following commands:

#config firewall auth-portal
#set portal-addr <FGT FQDN>
#end

Ensure also that there is a DNS resolution entry in the DNS server for the FQDN name with the FortiGate IP address.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!