We have used a Captive portal for the guest users to sign in (wireless). This captive portal is on one of the vlan interfaces and bridged on the fortiap unit. There is no authentication needed for the wireless network(open network). The only authentication is on the captive portal on the vlan interface. The problem occurs when employees/guest walks outside the range of the fortiap unit and comes back into range of the network. Then the employee has to login again to the portal.
Is it possible to change the time-out values? So that they don't have to login every time they lose wireless connectivity.
Things that I already tried.
[ul]
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
mail@jeroenmelis.nl wrote:
Is it possible to change the time-out values? So that they don't have to login every time they lose wireless connectivity.
Things that I already tried.
[ul]
set client-idle-timeout (it is not a timeout. The device left the network according to the fortigate unit.) set auth-timeout (This is for changing the time out for every user. Not the Guest Users)[/ul]
What version of FGT & AP's, if any? I've had this issue in the past and messing around the settings you say helped but this was also in conjunction of a daily reset of the FortiAP's.
Current version.
Version: 5.2.2
AP version: v5.2-build0225
Type AP: FP221B
Type FG: 100D
The mentioned settings did not solve any of my problems. Users still have to relogin when they leave and come back whitin range of a AP unit.
Are you creating softswitch and adding SSID and VLAN into it? Can give us controller configuration detail.
Captive portal on Softswitch and SSID works as expected. Firewall session not timing out when wireless client is disconnected.
There is a local break-out on the FortiAP to vlan10 that has his termination point on the Fortigate on a LACP interface with vlan 10 included. This interface has a Captive portal where the guest users login.
I assume you have enabled local-bridge on SSID and set VLAN . Create VLAN sub interface on the physical where FAP is connected to. Captive portal is enabled on VLAN sub interface. Wireless clients are getting IP from this VLAN and get authenticated by captive portal on VLAN. If so, the same configuration is working in our setup.
Can you check auth list when clients is disconnecting and connecting back. This list should be present even when client is disconnected and should not prompt for login again when connect back.
FG600B3909600253 # diagnose firewall auth list
172.17.0.10, guest, Guest-group type: fw, id: 0, duration: 208 expire: 52, allow-idle: 60 flag(20): idle group_id: 1 group_name: Guest-group
The last time i checked was with version 5.2.0 then it still didn't work. I will try it again when i have a new test machine. Maybe the have changed something since 5.2.1 >
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.