Guest users in FSSO are those who are unknown to the Windows AD or Novell network and servers that do not logon to a Windows AD domain.  To enable guest access in an FSSO security policy, an identity-based policy assigned to the built-in user group SSO_Guest_Users is added.

However, sometimes unauthenticated users are not considered guest users.  When the FortiGate receives traffic that has not been identified by FSSO, it checks first whether the traffic matches any policy without guest access enabled.  If any such policy exists, above or below the guest policy, the traffic will be allowed or denied accordingly as unauthenticated user.  Only if no such policies exist will the traffic be identified as guest and allowed through the guest policy.


Policy #1: Allow authenticated users out to the internet.
Policy #2: Allow FSSO Guest users out to the internet.
Policy #3: Deny all traffic to the internet.

In this case, traffic that is not authenticated to FSSO will match policy #3 and be blocked, since this policy does not have any authentication enabled.  If policy #3 were removed, then the traffic would be identified as guest and allowed through.