Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jasys
New Contributor III

Apple Devices with Captive Portal

Having had quite a few issues, there is one annoying one that is remaining, I have a Fortigate running an SSID using the FAC as the Portal for registration etc, which is working fine on Android, Laptops etc. but any apple device when selecting the SSID redirects to the "captive.apple.com" page on the phones and displays the message "Hotspot login, cannot open the page, the server cannot be found"

 

if the user browses to this captive address you do get the "success" message. Im raising this here as there are a few articles that tell you , on the Fortigate to "exempt" captive.apple.com from the SSID, which I have done. this article: Captive Portal on Apple devices - Fortinet Community doesnt do anything, is anyone able to offer some assistance? is this because the iphone has cellular data turned on or related setting?

thanks

16 REPLIES 16
Markus_M
Staff & Editor
Staff & Editor

Do you have a screenshot etc? The message "server cannot be found" sounds like a DNS error. What is the "captive address" that gives you the success page?

The cellular data CAN be a problem IF the device is able to contact the captive portal detection pages outside the FortiGate network through its "live" WAN connection.

You can simply run a sniffer on FortiGate towards the client IP and see if the IPs would match the captive portal detection page. This is a bit of a pain, but will give you the right answer for that question.

- Markus
Jasys
New Contributor III

Yes, I think to start with it was DNS related, the DHCP of the WIFI interface was set to use "system DNS" it should have been "interface DNS" as I have recursive DNS to look up the IP of the FAC etc,  so the error message has now gone,  What happens now , is a pop up (looks like a web pop up) appears VERY quickly then closes without being able to see what it was, and the phone goes back to the WIFI list, it does this on multiple phones.

 

So the original error, seems to have been resolved, but now its this.. I JUST wish everything would work as it should :D 

Markus_M

Packet capture will tell you most of what is going on. I'm sure you remember my rambling about a certain article with steps of what is supposed to happen and when. These steps all reflect in a packet capture and indicate where to search.

- Markus
Jasys
New Contributor III

Yes, the article is fine for locating the issue, but not for what could be wrong and as this is on the apple device, its hard to place whats wrong, its clearly the way apple devices are performing, it looks like its opening a window, but its blank and very quick! so I can only assume its opening the portal as it should, but then I have nothing to troubleshoot, as the FAC is just waiting for registration etc.

ebilcari

Make sure to also check the SSL certificates used for the portal pages, as Apple devices tend to be very strict with verification.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Jasys
New Contributor III

OK, so a tester has reported the certificate isnt trusted on an iPhone,  when opening safari he gets "This connection is not private - This website may be impersonating MYFORTIAUTHFQDN"
when viewing the cert it says "Not Trusted', Issued by Go Daddy with an expiry date of 23/03/26 18:35:11. " the cert is trusted by android, windows etc...

ebilcari

Then you may need to check the trust chain and ensure that the correct intermediate certificates are uploaded to FAC.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Jasys
New Contributor III

Hi Thanks for this, The Fortigate has the correct, ROOT and INTERMEDIATE, but the FAC had the incorrect Intermediate after checking, I don't know if this made a difference yet, as its been tested this afternoon. I do hope so, I cant see any info in the Apple community that this is a requirement, but the cert message on the iphone does indicate a trust issue...

Jasys
New Contributor III

No difference:

Behaviour is this:

Connected to GUEST WIFI
'No Internet Connection' showing against SSID
Opened Safari, navigated to BBC.CO.UK
'This connection is not private' displayed in browser
Entered http://captive.apple.com/hotspot-detect.html in browser address bar
When Link opened in EDGE browser - 'Connect to a WiFi hostpot shown' - clicking on 'connect' reverts to the same page. Still 'No Internet Connection' showing against SSID
When Link opened in SAFARI browser - 'This connection is not private - This website may be impersonating fortiauthenticatorfqdn' 
Clicked on view certificate - shown as valid until 23/03/26, but not trusted.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors