Skip to main content
The_Nude_Deer
Explorer II
February 26, 2026
Question

Lets Encrypt - Public Domain on FAC for Guest Portal

  • February 26, 2026
  • 4 replies
  • 230 views

I have a query about a FAC for a customer, it acts as a Captive Portal for Guest WIFI, and it works fine except for Apple Devices, there is an issue with GoDaddy and trust on IOS, which neither of the vendors seem to care about, so I need to move from GoDaddy,

 

The reason I am using  it is so that Guests don't get a secure warning when accessing the FAC portal page, The company has a domain, that I created a cert for and used DNS to point that FQDN internally to the FAC, this to me is very clumpy, but that's the way its done!

 

The customer doesn't want to use the existing domain and will purchase a new one, "companyxyz.com" for example. How would this work? the FAC is on an internal IP, and if I create a CSR for "fac.companyxyz.com" and get it signed by lets encrypt.  How will this resolve to an internal IP? would the DNS for the domain allow a Private IP? 

 

Has anyone ever done Lets Encrypt on a FAC? Ill be using this same domain to create certificates on the FortiGate's for the Wireless re-direct, so "gate1.companyxyz.com"  and "gate2...." etc these also need to point to the Wireless interfaces which are private IPs

 

Any pointers, or advice greatly appreciated.

 

 

4 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 2, 2026

Hello TheOnlyJames, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Jean-Philippe - Fortinet Community Team
AEK
SuperUser
SuperUser
March 2, 2026

It doesn't matter if FAC has a private IP, but to be signed by a public CA just the domain must be public, and you can then use the signed certificate for a private domain as well, even if the FQDN points to a private IP internally.

AEK
The_Nude_Deer
Explorer II
March 2, 2026

The FAC is behind a Fortigate, the domain is a public one, and there is an entry for the FAC hostname, so I have to have a public IP, how else can it verify?

AEK
SuperUser
SuperUser
March 2, 2026

As per my knowledge ACME uses for validation DNS, HTTP or TLS.

For the two last methods you don't need a public IP directly on the related server, you just use a VIP on your FGT that maps the public IP to the FAC's private IP.

AEK
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!