Skip to main content
Ironhead82
New Member
June 19, 2025
Question

FortiNAC 7.4 - guest redirect - radius fail post auth

  • June 19, 2025
  • 2 replies
  • 693 views

Hello,

 

I have configured FortiNAC-F 7.4.1 to use a guest captive portal for self registration. A FortiGate is configured using radius locally on FNAC. This is successfull in the FGT UI.

 

On FNAC I have role based access enabled for the SSID, and the dynamic VLANs. The Guest modelling config also has registration set to enforced.

 

My problem is that any client trying to connect to the SSID doesn't appear to be authorized to register. Has someone come across this issue before and could point me in the right direction?

The error is Registration - Access Deny (Post-Auth) and the client will not be redirected to the captive portal.

Ironhead82_0-1750318084674.png

 

 

 

 

 

2 replies

ebilcari
Staff
Staff
June 19, 2025

This will happen if the Registration is not configured in model configuration for the SSID or the network device or if the MAC address is not considered valid, which looks like it's not the case.

You can try with a resync interface in FGT and double check the configuration steps with this article: Technical Tip: A simple deployment including FortiGate/FortiAP (self-registered guest)

Emirjon
Ironhead82
New Member
June 26, 2025

Thank you for your response, ebilcari.

 

Turns out, this was a bug confirmed with Fortinet TAC which will be fixed in 7.6.3 or 7.4.2 as both streams are affected. Internal ticket 1129743.

 

Cheers