it says at the end "
The following settings are required to avoid certificate and security errors on the client. After the user is authenticated using the external captive portal, the browser redirects briefly to the firewall authentication portal over HTTPS. The browser then redirects the user to the original URL or a specific URL.
The specific URL needs to be configured in the Redirect after Captive Portal option in Create New SSID dialog.
config firewall auth-portal
set portal-addr <addr> #portal-addr setting must be an FQDN that resolves to the interface IP address of the guest SSID. The client must be able to resolve this using the DNS server configured in the DHCP scope.
end
"
This makes no sense? surely I need a public signed cert for the FAC for a guest to trust the portal?
The FortiGate and FAC are on the same domain, so in the DNS SAN, I would add the hostname of the gate and the FAC yes? myfortigate.local and myfac.local?
Thank you for your help, one question though, I dont have a certificate yet, so surely, I would be able to "accept risk" on the browser and I should still see the page?
If I browse to it manually, I get "403 Forbidden" despite allowing guest portals on the interface? I can browse to the self service portal? but not this one?
Hi, I managed to get a public cert with multi SAN, but as it was created on the FAC with a CSR, I cannot get the private key to also import onto the Fortigate?! how can I get the cert on the gate to make this work please
Why not generate a new CSR for the FortiGate?
they are expensive, and to create 2 Public Certs for a quick redirection just seems overkill to me, wanted to create a MULTISAN certificate, without using a CSR so its not tied to one device, not sure thats even possible!
It should be possible by using a CSR generator and also the signing entity usually allows to create a CSR on their webpage.
User | Count |
---|---|
2094 | |
1182 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.