This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
Good day people,
Is there a way to block intra-ssid traffic when using a captive portal ? At the moment, the only way to block intra-ssid traffic is to use a WPA/WPA2 security mode.
On a side note, why is it not possible to block intra-ssid traffic when using a captive portal ?
Hi Philippe,
I'm not clear on why this wouldnt work on your end. It does behave fine on my unit here (albeit granted, I am currently running 5.4 pre-release code). Are you able to change it in the CLI but not in the GUI?
config wireless-controller vap
edit "SANSFILGRATUIT"
set vdom "root"
set ssid "SANSFILGRATUIT"
set security captive-portal
set portal-type disclaimer
set intra-vap-privacy enable
set local-switching disable
next
end
--
Mathieu Nantel - NSE4, CCIE 24349
Principal System Engineer / Consultant Technique Senior, Office of the CTO
-- Mathieu Nantel Systems Engineer / Conseiller Technique - Fortinet Montreal, QC
Hi Mathieu, thank you for responding.
The current configuration I have is:
config wireless-controller vap
edit "ESICaptiveTest"
set vdom "root"
set ssid "esi_captive_portal_test"
set security captive-portal
set portal-message-override-group "captive-portal-ESICaptiveTest"
set selected-usergroups "CaptivePortalTest"
set intra-vap-privacy enable
set local-switching disable
next
end
When I select the Captive portal security mode, the option to block intra-ssid traffic disapears from the web interface.
Even with the current configuration which states "intra-vap-privacy enable", devices connected to that SSID can still see each other.
I'm running on FortiOS 5.0.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.