Skip to main content
Partisan44
Visitor III
September 19, 2024
Solved

FORTIGATE SESSION BASED AUTHENTICATION INSTEAD OF IP BASED AUTHNTICATION USING LDAP

  • September 19, 2024
  • 4 replies
  • 2033 views

Hi 

 

Is there a way to implement session based authentication for users instead of IP Based Authentication ,as I have  The below scenario:

1. FortiGate Firewall running version 7.4.3, is the Gateway & DHCP Server configured with a Captive Portal ,it authenticates users against LDAP .

2. The wireless network has 1 SSID, with different Access point vendors, when users move-in between the different access points ,they obtain different  IP address`s ,they are prompted to re-authenticate on the portal.

3. The previous gateway was a Meraki firewall ,it was able to authenticate users based on sessions, whereby you only logged in once on the portal and re-AUTH happened when the account duration had ended .It was not based on IP address`s hence users didn`t get the portal to re-authentication as they moved around.

 

Edit 1 : Most of the users use tablets /laptops not joined to the domain

 

Is there a way to do this ?

 

Thanks 

Best answer by mpandya

Hi Partisan,

I don't think that feature is avail on fortigate 

4 replies

AEK
SuperUser
SuperUser
September 19, 2024
AEK
Partisan44
Visitor III
September 20, 2024

Thanks ,however i am looking at an agent-less solution .

mpandya
Staff
mpandyaAnswer
Staff
September 20, 2024

Hi Partisan,

I don't think that feature is avail on fortigate 

Partisan44
Visitor III
November 26, 2024

Hi 

 

Thanks,i was asked to put it as an NFR(new feature request) through my fortinet se ,i did it ,lets see if it will materialise.

Cheers!

obrunori
Staff
Staff
February 18, 2026

Hi,
"form-based authentication(captive portal) cannot use session-based authentication"
Related documentation:
https://docs.fortinet.com/document/fortiproxy/7.4.0/fortiproxy-authentication-guide/129531/authentication-methods
Regards.