Technical Tip: Configuring a shared FQDN and certificate for the Captive Portal without using a loopback interface
| Description | This article describes the simplest way to use the same certificate for multiple Captive Portals. |
| Scope | FortiOS. |
| Solution | To use the same certificate for Captive Portals on different interfaces, they all need to share the same FQDN but resolve to the corresponding IP the FortiGate has for that interface. This can be achieved in multiple different ways, the simplest would be to use a DNS filter. The following is the first Captive Portal configured in the device. The certificate has 'captiveportal.lab.lan' as the domain (this should be a real certificate signed by a public CA). Currently, this resolves to 100.64.0.1 as per the local DNS database:
 
The following is the second Captive Portal configured in the device. Notice how the interface IP is 100.65.0.1, so the domain would not resolve correctly:
  This configuration can be scaled to as many Captive Portals as needed. A different DNS filter would be used for each additional Captive Portal on its DNS policy.
  When accessing the Captive Portal on Captive2, no certificate warning is seen:
![]() |







