Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zaheerudin45
New Contributor

Captive Portal Authentication for Non Domain users using FSSO

Hello Community,

I’m working on configuring Captive Portal on my FortiGate firewall with FSSO integration, and I’d appreciate some guidance.

Objective:

  • Domain users should be authenticated automatically via FSSO (or group-based policies) when they are on the corporate network.

  • Non-domain users (not logged into the domain) should be redirected to the Captive Portal.

  • On the Captive Portal page, these non-domain users should still be able to log in using their Active Directory credentials (username/password) to access the internet.

Is there a recommended approach or workaround to achieve this setup?

Thanks in advance!

1 REPLY 1
distillednetwork
Contributor III

Having local fail-through policies is a pretty standard policy.  Don't forget to allow your clients to get dhcp/dns etc, if they are not authenticated so they reach the portals still.

 

You can also change the behavior or your policy evaluation with the config user setting and set auth-on-demand always

With this set to always, an authenticated policy will not be skipped for unauthenticated users, while if it is set to [implicitly], unauthenticated users will skip these policies and keep searching for a match.  Only if it does not find a match will it come back to the authentication policy.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Active-authentication-firewall-policy-fall...

 

::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
::: If a solution is helpful, don't forget to give kudos or Accept as Solution for others. :::
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors