Question
cisco ISE captive portal authentication with fortigate
Hello everyone,
I'm currently trying to integrate Cisco ISE with a FortiGate firewall for Captive Portal authentication, and I'm running into a couple of issues.
- FortiGate Network Device Profile
- In Cisco ISE, I cannot find a FortiGate Network Device Profile when adding the FortiGate as a Network Access Device (NAD).
- Is there an official FortiGate device profile that needs to be installed, or should I use a generic RADIUS device profile instead?
- Redirect ACL in Cisco ISE
- For the authorization profile used during captive portal authentication, Cisco ISE typically requires a Redirect ACL (DACL/ACL).
- Since the FortiGate is performing the captive portal redirection, what should be configured for the Redirect ACL in Cisco ISE?
- Should I leave it empty, create a permit ACL, or is there a FortiGate-specific configuration required?
If anyone has successfully integrated Cisco ISE Guest/Captive Portal with FortiGate, I would really appreciate it if you could share how you configured it, including:
- Cisco ISE configuration (Network Device, Authentication/Authorization Policies, Authorization Profiles, Redirect ACL, etc.)
- FortiGate configuration (RADIUS settings, Captive Portal configuration, policies, user groups, etc.)
- Any best practices or deployment guides you followed.
Thank you in advance for your help!
