FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Patterson
Staff
Staff
Article Id 207401

Description

 

This article describes how to create a Guest Management account.

 

Scope

 

All FortiGates.

 

Solution

 

A temporary visitor to the premises will need a user account in the premise during the stay.

If there is a large event, such as a conference, there would be a need to create many temporary accounts for the attendees.

 

Usually, this kind of request is handled by the front-desk operator/receptionist.

For this, create a 'Restrict admin to guest account provisioning only' account to provision temporary accounts for the guest user.

 

The following example illustrates sending login details via SMS and Email.

 

Prerequisite.

 

SMS-Server.

 

config system sms-server

    edit "SMS-Server"

        set mail-server "IP/FQDN"

    next

end

 

Email Service.

 

config system email-server

    set server "IP/FQDN"

end

 

Configuration required in FortiGate related to this article.

 

For group, select the Guest type:

 

Patterson_0-1648016384465.png

 

Toggle the options according to requirements.

 

For admin-accounts, make sure to toggle 'Restrict admin to guest account provisioning only'.

 

Patterson_1-1648016791323.png

 

For policy, select the appropriate inbound interface and call the group 'GUEST-WIFI' with a specific source IP pool allocated.

 

Patterson_3-1648016949036.png

 

Another option aside from specifying the group on the policy is by enabling Captive Portal for the inbound interface and selecting the 'GUEST-WIFI' group under the Restricted to Groups option.

 

8.PNG

 

Now, log in to the provisioning account and create a temporary account for the visitor.

 

Patterson_4-1648017209561.png

 

Creating a visitor account.

 

Patterson_5-1648017300283.png

 

Sending the Login details via SMS.

 

Patterson_6-1648017348966.png

If SMS fails, the details can be given as a printout:

 

Patterson_7-1648017446829.png

 

From the visitor's end, a login page will be prompted when attempting to access the internet.

 

9.PNG

 

After successful authentication, the guest user details will be available under User & Devices dashboard.

 

Patterson_9-1648019038319.png

 

To check the expired duration left for this visitor account:

 

Patterson_0-1648021123755.png

 

To expire guest users before timeout, de-authenticate the test user under the 'Firewall User Monitor' widget.

 

Related documents: 

FortiGate 7.4.5 Administration Guide

Configuring guest access - FortiGate cookbook