FortiGuest
FortiGuest is an access management solution that provides secure network access to guests as per the configured policies. It monitors and reports user activity ensuring policy compliance and network security.
rmittal
Staff
Staff
Article Id 366294
Description This article describes how to Configure a captive portal using FortiGuest with FortiGate for Data restriction.
Scope FortiGate, FortiGuest.
Solution
  1. Create a radius server:

 

1.JPG

Note:

NAS-IP is mandatory.

 

Select 'OK' and Enable Radius Accounting from CLI of FortiGate and edit the below parameters with values:

 

set acct-interim-interval 60

set radius-coa enable

    config accounting-server

        edit xx

 

2.JPG

 

  1. Create SSID with the below fields:

 

3.JPG

  • Captive Portal: Enabled.
  • Portal type: Authentication
  • Authentication portal: External
  • Enter the Captive portal URL from FORTIGUEST.
  • Under user group select FORTIGUEST radius server.
  • Exempt destinations/services =è Enter FortiGuest FQDN/IP and DNS.
  • Redirect after Captive Portal: Enter success URL from FortiGuest

 

  1. Login into FortiGuest GUI using admin credentials:
  • Add FortiGate as a radius client, under Devices -> Radius Clients and Select NEW.


4.JPG

Select Attributes:

5.JPG

 

  • Create a portal and portal Rule under Guest portal -> Portal and select 'Create New'. Guest portal -> Portal Rules.
  • Create a Usage Profile under Network Access policies -> Usage profile and select 'Create New'. Select Data usage and Enter the details.


6.JPG

 

  • Map the Usage profile.