Created on
07-04-2017
06:07 PM
Edited on
08-24-2025
11:50 PM
By
Jean-Philippe_P
Description
This article explains how to configure a captive portal for LDAP users.
Scope
FortiGate.
Solution
Note: Only certain traffic can trigger a captive portal redirection. If specific services are selected instead of ALL, it is required to allow at least one of the following services to trigger the captive portal:
Unauthenticated DNS requests are allowed:
If a firewall policy has a user or group configured in the source field, and the firewall policy allows the 'ALL' or 'DNS' service, TCP and UDP port 53 DNS traffic is allowed regardless of authentication status. This is because some DNS access is likely required to initially trigger the captive portal.
Related articles:
Troubleshooting Tip: General captive portal explanation, flow and troubleshooting
Technical Tip: Creating Captive Portal with LDAP users via policy-based
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.