Skip to main content
rcpdkc
Explorer II
March 7, 2024
Question

Fortinac-F Portal Certificate Problem

  • March 7, 2024
  • 29 replies
  • 8794 views

I created a guest network in Fortigate firewall, security mode is on. Dynamic vlan enabled. Fortinac radius is connected behind it. I then included this wireless network in fortinac. When the user connects to the network, it assigns them to the quarantine vlan. Then the fortinac portal opens and the user registers. However, I have a problem like this. When the user connects to this network, the nac portal does not open. There is an untrusted network warning. To overcome this problem, I created a certificate in the active directory. And I included it in fortinac. However, when the user connects to the wireless network, the option to trust this certificate should normally appear, but it does not. The user cannot go to the portal because there is no certificate. How can I solve this problem?
Can I direct a user who is included in the open network directly to the portal without a certificate?
Or can I disable certificate verification from the SSL section in fortinac?

 

29 replies

AEK
SuperUser
SuperUser
March 7, 2024

Guest users on BYOD are not part of the domain so they don't recognize its private cert. I always use public certificate for the isolation portal and like this I never have such issue.

AEK
rcpdkc
rcpdkcAuthor
Explorer II
March 7, 2024

What do you mean by general certificate, I don't know much about the certificate, can you elaborate?

AEK
SuperUser
SuperUser
March 7, 2024

I guess you mean you have a browser warning about untrusted SSL cert when a guest enters the isolation portal, right? Or do you mean you have this issue with RADIUS certificate?

In case you mean isolation portal then the certificate is configured in menu Portal > Portal SSL. There you should use a public SSL certificate since the BYOD don't recognize your domain's CA. A public certificate is signed by a public authority and is recognized by all browsers.

In case you have issue with RADIUS certificate then I don't understand why do you use RADIUS authentication for Guests? Guest should use WPA2 Personal while Corp users should use RADIUS authentication.

AEK
ndumaj
Staff
Staff
March 11, 2024

Hello,

Please find below the guide for SSL configuration:
https://docs.fortinet.com/document/fortinac-f/7.2.0/installing-ssl-certificates/223817/overview

https://docs.fortinet.com/document/fortinac-f/7.2.0/installing-ssl-certificates/228234/step-1-determine-fortinac-certificate-targets-to-secure
For portal Target is recommended public cert:

  • Third party public (External)

    • Certificates issued from Certificate Authorities like GoDaddy, DigiCert, GlobalSign, etc.

    • Certificate types: Individual, SAN* & Wildcard

 

BR

 

rcpdkc
rcpdkcAuthor
Explorer II
March 11, 2024

I bought a certificate from Zerossl. Although I entered the csr code I got from the portal, there is this warning.Ekran Alıntısı.PNG

rcpdkc
rcpdkcAuthor
Explorer II
March 11, 2024

Is there any way to do it without an SSL certificate?

ndumaj
Staff
Staff
March 11, 2024

I agree with AEK response.
The users will get just a URL warning, but anyway depends on from the vendor Device they might not accept at all to allow the device to access that URL.

BR

rcpdkc
rcpdkcAuthor
Explorer II
March 12, 2024

I created a self-signed certificate, but again nothing changed. There is no reaction when the user connects to the wireless network. The portal does not open.cer2.PNG

AEK
SuperUser
SuperUser
March 12, 2024

I think this is not related to certificate.

  • Can you ping FNAC's eth1 IP from the isolated client?
  • What do you get when you browse https://<FNAC eth1 IP>   (using IP)
  • Can you try telnet <FNAC eth1 IP>:443
AEK
ebilcari
Staff
Staff
March 12, 2024

As AEK is suggesting it may not be the problem with the certificate. There are some network configurations that need to be done in order for the portal redirection to happen. FNAC has to be the DHCP and the DNS server (eth1/isolation interface, not eth0) for the end host while it's isolated and is waiting for the portal to show. The redirection is done through what is called a DNS cheat. You can take a look at this simplified network example (red path) to have a better understanding.

Emirjon
ndumaj
Staff
Staff
March 12, 2024

Hello,
Also Check with Users on production are able to reach Https://FNAC-FQDN
What is the IP that guest users are getting? Is that from registration VLAN (Isolation pool scope?)?
Do NSLOOKUP FNAC-FQDN
what do you resolve?
BR

rcpdkc
rcpdkcAuthor
Explorer II
March 12, 2024

Although I obtained a certificate from a global certificate validator, the same problems persist.portal.PNG

ndumaj
Staff
Staff
March 21, 2024

Hello,
Check with Users on production are able to reach Https://FNAC-FQDN
What is the IP that guest users are getting?
Is that from registration VLAN (Isolation pool scope?)?
Do NSLOOKUP FNAC-FQDN from end user
what do you resolve?
Run a pcap on FNAC to see if you do receive traffic from the guest IP:
exec enter-shell
sudo tcpdump -nnvvi any host <Ip of the host>

Can you also provide a view of ipconfig /all

BR

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!