Skip to main content
Nark0t
New Member
October 13, 2022
Question

Captive Portal issues with Logins on some Android and iPhones

  • October 13, 2022
  • 5 replies
  • 8504 views

Hi Everyone, 

 

Having a slight issue with a guest WiFi with Guest token implementation I am currently busy with, firstly some background:

 

Site has a Fortigate 80F firewall and a few FAP-221E APs installed on site, Fortigate and AP's updated to the latest firmware revision.

 

Guest Wifi SSID setup with captive portal and Guest token for authentication.

 

Issue I am having is that if I connect to the Guest Wifi on a laptop, I get a redirect to the captive portal where I am requested to enter the guest token details for authentication, that works fine.

I have also tested the Guest Wifi on my personal Android phone, and as soon as I connect to the Guest wifi I get a "Push notification" that sign-in is required, and get redirected to the Logon page.

However I tested it on a few other Android and iPhones, but once connected to the Guest Wifi network, the "Push notification" for sign in never pops up, and the phone just reports that its "connected without internet" and even if I open up Safari on the apple or the native browser on the Android phone then browser just reports "no connection"

 

Is there something I am missing?

 

Thanks in advance. 

5 replies

scan888
New Member
October 13, 2022

 

Hello

 

Do you get an IP-Address on the Smartphone? If yes, from which Subnet do you get one (APIPA or from your Wifi Subnet)?

How are the Client authenticated on the FortiGate (as User from the Captive-Portal, only with the MAC-Address or unauthenticated)?

 

Nark0t
Nark0tAuthor
New Member
October 13, 2022

Hi,

 

Yes the devices get an IP from the firewall, as for the authentications, there is no MAC filtering and the only authentication for internet access is via tokens with a pre generated username and password.

scan888
New Member
October 13, 2022

Has the Client also an IP from the right subnet when he has "no connection"?

If the client has "no connection" is the client listed on the Wifi-Clients (Dashboard -> WiFi -> Clients by FortiAP)?
What FortiGate Version are you using?

Nark0t
Nark0tAuthor
New Member
October 13, 2022

Correct yes, the client gets the correct IP from the correct subnet, and am able to see the device connected on the Wifi Clients list and able to see which fortiAP the device is connected to, the current Fortigate version is 7.2.1

 

Nark0t_1-1665666816118.pngNark0t_2-1665666857349.pngNark0t_3-1665666917718.pngNark0t_4-1665666942892.png

 

 

Above is how the SSID is setup, if that helps? this has worked fine in the past for me, the "Guest_Wifi" user group is the group where the list of pre-generated authentication tokens are 

 

 

scan888
New Member
October 13, 2022

The configuration looks ok for me.

Do the following check no a device which the portal is NOT working:

  1. open an internet browser
  2. enter the following url:
    - Android: https://clients3.google.com/ -> Empty Page if internet connection success
    - iPhone: https://captive.apple.com/hotspot-detect.html -> "Success" Webpage if the internet connection success

What is the result on your device?

   

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!