Skip to main content
rain
Staff
Staff
June 18, 2025

Troubleshooting Tip: How to set up a captive portal managed by FortiGate over a FortiAP SSID

  • June 18, 2025
  • 0 replies
  • 1727 views
Description This article describes how to set up an SSID that lives over an interface at the L3 level, and the portal is being managed by the FortiGate.
Scope FortiGate, FortiAP.
Solution

To set up a captive portal being managed by the FortiGate and use it as an alternative to 802.1x authentication, follow the next:

  • Create an SSID interface in the Wireless Controller section.
  • Assign an IP address to work as a gateway for the SSID.

 

CAPTIVE_WIRELESS_01.png

 

  • To enable the captive portal function will be necessary to enable the 'Captive portal' option under ' Security Mode Settings'. Configure the portal to be 'local' or 'External' based on need, to filter the access by 'users' is needed it to select the function 'Restricted to Groups', the 'User access' option.
  • Starting with v7.4.4 and later, the captive portal is an independent setting, separated from the wireless authentication methods.

v7.4.3 and earlier:


config wireless-controller vap
    edit <name>
        set security { captive portal | wpa-personal+captive-portal | wpa-only-personal+captive-portal | wpa2-only-personal+captive-portal }
    next
end

v7.4.4 and later:


config wireless-controller vap
    edit <name>
        set security { open | wpa-personal| wpa2-only-personal | wpa3-sae | wpa3-sae-transition | owe }
        set captive-portal enable
    next
end

 

CAPTIVE_WIRELESS_02.png

 

The redirection after captive portal successful access is optional, but it works to push the successful authentication access to an external URL.

 

After this setup, when a user tries to use a resource that comes across the SSID interface will be redirected to a captive portal before being forwarded to the destination.

 

CAPTIVE_03.png

 

Note:

Do not forget to create the respective policy to allow access to the source SSID to a destination (In this example, the internet. For the FortiGate, the interface WAN acts as an upstream Interface).

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.