Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Nark0t
New Contributor

Captive Portal issues with Logins on some Android and iPhones

Hi Everyone, 

 

Having a slight issue with a guest WiFi with Guest token implementation I am currently busy with, firstly some background:

 

Site has a Fortigate 80F firewall and a few FAP-221E APs installed on site, Fortigate and AP's updated to the latest firmware revision.

 

Guest Wifi SSID setup with captive portal and Guest token for authentication.

 

Issue I am having is that if I connect to the Guest Wifi on a laptop, I get a redirect to the captive portal where I am requested to enter the guest token details for authentication, that works fine.

I have also tested the Guest Wifi on my personal Android phone, and as soon as I connect to the Guest wifi I get a "Push notification" that sign-in is required, and get redirected to the Logon page.

However I tested it on a few other Android and iPhones, but once connected to the Guest Wifi network, the "Push notification" for sign in never pops up, and the phone just reports that its "connected without internet" and even if I open up Safari on the apple or the native browser on the Android phone then browser just reports "no connection"

 

Is there something I am missing?

 

Thanks in advance. 

5 REPLIES 5
scan888
Contributor

 

Hello

 

Do you get an IP-Address on the Smartphone? If yes, from which Subnet do you get one (APIPA or from your Wifi Subnet)?

How are the Client authenticated on the FortiGate (as User from the Captive-Portal, only with the MAC-Address or unauthenticated)?

 

- Have you found a solution? Then give your helper a "Like" and mark the solution.
- Have you found a solution? Then give your helper a "Like" and mark the solution.
Nark0t
New Contributor

Hi,

 

Yes the devices get an IP from the firewall, as for the authentications, there is no MAC filtering and the only authentication for internet access is via tokens with a pre generated username and password.

scan888
Contributor

Has the Client also an IP from the right subnet when he has "no connection"?

If the client has "no connection" is the client listed on the Wifi-Clients (Dashboard -> WiFi -> Clients by FortiAP)?
What FortiGate Version are you using?

- Have you found a solution? Then give your helper a "Like" and mark the solution.
- Have you found a solution? Then give your helper a "Like" and mark the solution.
Nark0t
New Contributor

Correct yes, the client gets the correct IP from the correct subnet, and am able to see the device connected on the Wifi Clients list and able to see which fortiAP the device is connected to, the current Fortigate version is 7.2.1

 

Nark0t_1-1665666816118.pngNark0t_2-1665666857349.pngNark0t_3-1665666917718.pngNark0t_4-1665666942892.png

 

 

Above is how the SSID is setup, if that helps? this has worked fine in the past for me, the "Guest_Wifi" user group is the group where the list of pre-generated authentication tokens are 

 

 

scan888
Contributor

The configuration looks ok for me.

Do the following check no a device which the portal is NOT working:

  1. open an internet browser
  2. enter the following url:
    - Android: https://clients3.google.com/ -> Empty Page if internet connection success
    - iPhone: https://captive.apple.com/hotspot-detect.html -> "Success" Webpage if the internet connection success

What is the result on your device?

   

- Have you found a solution? Then give your helper a "Like" and mark the solution.
- Have you found a solution? Then give your helper a "Like" and mark the solution.
Labels
Top Kudoed Authors