Hello Community,
I’m working on configuring Captive Portal on my FortiGate firewall with FSSO integration, and I’d appreciate some guidance.
Objective:
Domain users should be authenticated automatically via FSSO (or group-based policies) when they are on the corporate network.
Non-domain users (not logged into the domain) should be redirected to the Captive Portal.
On the Captive Portal page, these non-domain users should still be able to log in using their Active Directory credentials (username/password) to access the internet.
Is there a recommended approach or workaround to achieve this setup?
Thanks in advance!
Having local fail-through policies is a pretty standard policy. Don't forget to allow your clients to get dhcp/dns etc, if they are not authenticated so they reach the portals still.
You can also change the behavior or your policy evaluation with the config user setting and set auth-on-demand always
With this set to always, an authenticated policy will not be skipped for unauthenticated users, while if it is set to [implicitly], unauthenticated users will skip these policies and keep searching for a match. Only if it does not find a match will it come back to the authentication policy.
User | Count |
---|---|
2626 | |
1400 | |
810 | |
672 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.