Skip to main content
nflnetwork29
Explorer III
November 14, 2024
Question

NAC - isolation vlan firewall rules for captive portal

  • November 14, 2024
  • 3 replies
  • 1163 views

Hello we a have installed a public certificate on our captive portal . when a machine is connected its initial  location is the isolation vlan as per design. 

 

Cert looks to be installed correctly but we are still getting SSL Certificate error upon initial browser launch . 

 

 

Do we need to modify the firewall rule for isolation vlan? do we need to allow outbound internet access to the certificate authority ? What are people doing in this scenario. 

 

Running FortiNAC-f 7.4

 

Thanks, 

3 replies

ebilcari
Staff
Staff
November 15, 2024

If a public certificate is used, the root CA should be already present in the end host so internet access is not required. Usually this happens when the intermittent certificate is not properly uploaded in FNAC, some details can be found in this article.

Emirjon
nflnetwork29
Explorer III
November 18, 2024

well i was on with TAC and we confirmed the certificate was loaded correctly.  anything else i can check? 

ebilcari
Staff
Staff
November 19, 2024

Can you tell which URL is listed in the browser when you get the certificate error, is it still showing the original website or is it already redirected to the FNAC portal page?

Emirjon
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!