FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Patterson
Staff
Staff
Article Id 207401

Description

 

This article describes how to create a Guest Management account.

 

Scope

 

All FortiGates.

 

Solution

 

A temporary visitor to the premises will need a user account in the premise during their stay.

If there is a large event, such as a conference, there would be a need to create many temporary accounts for the attendees.

 

Usually, this kind of request is handled by the front-desk operator/receptionist.

For this, create a 'Restrict admin to guest account provisioning only' account to provision temporary accounts for the guest user.

 

The following example illustrates sending login details via SMS and Email.

 

Prerequisite.

 

SMS-Server.

 

config system sms-server

edit "SMS-Server"

set mail-server "IP/FQDN"

next

end

 

Email Service.

 

config system email-server

set server "IP/FQDN"

end

 

Config- required in FortiGate related to this article.

 

For group, select the Guest type:

 

Patterson_0-1648016384465.png

 

Toggle the options according to requirements.

 

For admin-accounts, make sure to toggle 'Restrict admin to guest account provisioning only'.

 

Patterson_1-1648016791323.png

 

For policy, select the appropriate inbound interface and call the group 'GUEST-WIFI' with a specific source IP pool allocated.

 

Patterson_3-1648016949036.png

 

Now, log in to the provisioning account and create a temp account for the visitor.

 

Patterson_4-1648017209561.png

 

Creating a visitor account.

 

Patterson_5-1648017300283.png

 

Sending the Login details via SMS.

 

Patterson_6-1648017348966.png

If SMS fails, the details can be given as a printout:

 

Patterson_7-1648017446829.png

 

Verify the visitor's internet access.

 

Patterson_8-1648018621760.png

 

As seen above, the user was successfully authenticated.

 

Patterson_9-1648019038319.png

 

To check the expired duration left for this visitor account:

 

Patterson_0-1648021123755.png

 

In order to expire guest users before timeout, de-authenticate the test user under the 'Firewall User Monitor' widget.

 

Related document: 

Configuring guest access - FortiGate cookbook.