Skip to main content
New Member
July 22, 2026
Question

cisco ISE captive portal authentication with fortigate

  • July 22, 2026
  • 0 replies
  • 75 views

Hello everyone,

I'm currently trying to integrate Cisco ISE with a FortiGate firewall for Captive Portal authentication, and I'm running into a couple of issues.

  1. FortiGate Network Device Profile
    • In Cisco ISE, I cannot find a FortiGate Network Device Profile when adding the FortiGate as a Network Access Device (NAD).
    • Is there an official FortiGate device profile that needs to be installed, or should I use a generic RADIUS device profile instead?
  2. Redirect ACL in Cisco ISE
    • For the authorization profile used during captive portal authentication, Cisco ISE typically requires a Redirect ACL (DACL/ACL).
    • Since the FortiGate is performing the captive portal redirection, what should be configured for the Redirect ACL in Cisco ISE?
    • Should I leave it empty, create a permit ACL, or is there a FortiGate-specific configuration required?

If anyone has successfully integrated Cisco ISE Guest/Captive Portal with FortiGate, I would really appreciate it if you could share how you configured it, including:

  • Cisco ISE configuration (Network Device, Authentication/Authorization Policies, Authorization Profiles, Redirect ACL, etc.)
  • FortiGate configuration (RADIUS settings, Captive Portal configuration, policies, user groups, etc.)
  • Any best practices or deployment guides you followed.

Thank you in advance for your help!

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!