Skip to main content
technologist36
New Member
June 25, 2015
Question

WiFi Guest Management

  • June 25, 2015
  • 2 replies
  • 12324 views

Hi,

 

So the guest management let me generate random usernames and passwords so that each guest can use them for WiFi guest authentication. This means that i have to print a paper for each random credential and pass it to each guest, which is a nightmare practice.

 

Here is my scenario that i want to accomplish in more intelligent method:

 

1) Each guest will connect to a guest SSID

2) Each guest will fire up the browser and fortigate shows up a "Welcome to WiFi Guest" page

3) In this page, each guest will click a "Generate" button to generate a random credential.

 

Note: Of course, this button will make a call to the "Create new user" in the "Guest Management" section.

 

4) Each a guest will use the generated credential to access the internet.

 

It should work like this instead of passing a piece of paper for each guest.

 

Does FG support this scenario? If not, can i have access to FOS API so a developer i know can do this?

 

Thanks

    2 replies

    gschmitt
    New Member
    June 25, 2015

    You can use an external Captive Portal which supports this if all else fails.

    But by default this isn't supported by FortiGate

    technologist36
    New Member
    June 25, 2015

    I am not sure if i am following you correctly. What "if all else fails" means"?

    Do you know from where i can download this external captive portal?

     

    Details please?

    gschmitt
    New Member
    June 25, 2015

    technologist36 wrote:

    I am not sure if i am following you correctly. What "if all else fails" means"?

    Do you know from where i can download this external captive portal?

    I can't think of a way to let the guests create accounts for themselves without resorting to an external captive portal but maybe I am missing something

     

    You can use many different external captive portals like pfSense or ipCop or chilliSpot

    But I cant tell you if any of them offer what you want

    Big_Abe
    New Member
    June 26, 2015

    I think if you explained your goal a little bit better than a hard-case scenario, people might be able to help you a bit better. 

     

    If I understand you correctly, your WiFi guests have to come to an 'Administrator' of some sorts - who currently generates a username and password and physically provides it to your Guest on paper.

     

    Are you matching this information with actual identification?  For example a motel that has a room's occupant information and then just says the username is 'funkymonkey' and the password is 'blueberrysunset'  and writes it next to John Smith room 10.

     

    In the above example - you could use any number of the 3rd party Captive Portal tools to tie into your system housing the 'John Smith' data to create users and randomly generate a password. 

     

    If you're not matching to actual identification then why bother with the user/pass on the portal?  Just use a frequently changing wifi password.  

     

     

    Again, it's hard to dream up solutions without really knowing your goal.  But everyone above has given good ideas as well. 

     

    technologist36
    New Member
    June 27, 2015

    You are not so nice, Big Abe. I didn't offend anyone in here to make you say such awful words. In fact, i was very clear in my scenario and i explained using numbers but it seems you focused more on how to annoy me than helping me. Actually, you made my scenario looks more complicated and i am sure you've done this in purpose. Even user "gschmitt" didn't complain and let's say if i was wrong, he got more priority to complain than you.

     

    Looks like seeking the answer somewhere else is the best idea right now.

    Big_Abe
    New Member
    June 27, 2015
    I don't think I complained and I certainly didn't mean to offend. I meant your usage is outside of "the norm" and tried to guess your environment and explain methodologies through examples. To be simple... Can you explain your environment a bit further to try to assist you? Not nice, eh? I think that's a first for me.