Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jasys
New Contributor II

Apple Devices with Captive Portal

Having had quite a few issues, there is one annoying one that is remaining, I have a Fortigate running an SSID using the FAC as the Portal for registration etc, which is working fine on Android, Laptops etc. but any apple device when selecting the SSID redirects to the "captive.apple.com" page on the phones and displays the message "Hotspot login, cannot open the page, the server cannot be found"

 

if the user browses to this captive address you do get the "success" message. Im raising this here as there are a few articles that tell you , on the Fortigate to "exempt" captive.apple.com from the SSID, which I have done. this article: Captive Portal on Apple devices - Fortinet Community doesnt do anything, is anyone able to offer some assistance? is this because the iphone has cellular data turned on or related setting?

thanks

3 REPLIES 3
Markus_M
Staff & Editor
Staff & Editor

Do you have a screenshot etc? The message "server cannot be found" sounds like a DNS error. What is the "captive address" that gives you the success page?

The cellular data CAN be a problem IF the device is able to contact the captive portal detection pages outside the FortiGate network through its "live" WAN connection.

You can simply run a sniffer on FortiGate towards the client IP and see if the IPs would match the captive portal detection page. This is a bit of a pain, but will give you the right answer for that question.

- Markus
Jasys
New Contributor II

Yes, I think to start with it was DNS related, the DHCP of the WIFI interface was set to use "system DNS" it should have been "interface DNS" as I have recursive DNS to look up the IP of the FAC etc,  so the error message has now gone,  What happens now , is a pop up (looks like a web pop up) appears VERY quickly then closes without being able to see what it was, and the phone goes back to the WIFI list, it does this on multiple phones.

 

So the original error, seems to have been resolved, but now its this.. I JUST wish everything would work as it should :D 

Markus_M

Packet capture will tell you most of what is going on. I'm sure you remember my rambling about a certain article with steps of what is supposed to happen and when. These steps all reflect in a packet capture and indicate where to search.

- Markus
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors