Skip to main content
Dan_Eng52
Explorer III
February 1, 2024
Question

FortiLAN - SSID Captive Portal Bypass

  • February 1, 2024
  • 1 reply
  • 2460 views

Hi all, 

 

I hope you're well. 

 

Does anyone have any experience with FortiLAN and know if it is possible to bypass via MAC address the captive portal on an SSID? I have had a look myself in FortiLAN and reviewed documentation but haven't found any of use and am beginning to think this isn't possible. 

 

Regards, 

Dan. 

 

 

1 reply

adambomb1219
SuperUser
SuperUser
February 1, 2024

You mean FortiLAN Cloud correct?

 

MAC Access Control: Select to allow clients
identified in the MAC address import list to connect to
that SSID.
l Fail Through Mode. This mode is available if
you select the Open authentication. If you select
the Fail Through Mode, then the following
applies:
l If a client is not in the MAC address import
list, then the client must pass captive-portal
authentication to access the internet.
l If a client is in the MAC address import list,
then the client can bypass the captive-portal
authentication and access the internet
directly.

Dan_Eng52
Dan_Eng52Author
Explorer III
February 1, 2024

Hi there, 

 

I did see this option however, I didn't proceed because I seen "Enter MAC addresses of clients which are allowed to connect. All other clients will be blocked" statement. 

 

If I enter the device MAC here and apply and have captive portal applied will other devices still be able to authenticate and click through the captive portal and have internet access or will it restrict access purely to that device MAC only? 

 

Many thanks, 

Dan.

adambomb1219
SuperUser
SuperUser
February 1, 2024

You need to enable Fail Through mode.  If a client is not in the MAC address import list, then the client must pass captive-portal authentication to access the internet.
If a client is in the MAC address import list, then the client can bypass the captive-portal
authentication and access the internet directly.