Created on 12-02-2021 06:10 AM Edited on 12-03-2021 07:51 AM By Anthony_E
Description |
This article describes how to configure captive portal in bridge mode when 2nd FortiGate is acting as a portal server. |
Scope |
|
Solution |
SSIDs of a FortiAP is configured as local-bridge and captive-portal.
After a wireless client connects to the SSID on the FortiAP, the first HTTP(s) web request from client to internet will be redirected to portal server by the FortiAP, in this case, the portal server is a 2nd FortiGate.
The flows and steps:
Sample Configuration.
# config wireless-controller vap
Trouble-shooting commands.
debug log on FAP:
FAP # cw_debug app fapportal 8 FAP# fapportal_diag -d sta
Note. If there is an NAT between client and Portal server (2nd FortiGate in this case), it will not work.
The reason behind this is that FortiGate only support IP based session lookup when it is used as portal server. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.