Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jeroen
Contributor

Captive portal time-out session

We have used a Captive portal for the guest users to sign in (wireless). This captive portal is on one of the vlan interfaces and bridged on the fortiap unit. There is no authentication needed for the wireless network(open network). The only authentication is on the captive portal on the vlan interface. The problem occurs when employees/guest walks outside the range of the fortiap unit and comes back into range of the network. Then the employee has to login again to the portal.

Is it possible to change the time-out values? So that they don't have to login every time they lose wireless connectivity.

 

Things that I already tried.

 

[ul]
  • set client-idle-timeout (it is not a timeout. The device left the network according to the fortigate unit.)
  • set auth-timeout (This is for changing the time out for every user. Not the Guest Users)[/ul]

     

  • 6 REPLIES 6
    jtfinley
    Contributor

    mail@jeroenmelis.nl wrote:

     

    Is it possible to change the time-out values? So that they don't have to login every time they lose wireless connectivity.

     

    Things that I already tried.

     

    [ul]
  • set client-idle-timeout (it is not a timeout. The device left the network according to the fortigate unit.)
  • set auth-timeout (This is for changing the time out for every user. Not the Guest Users)[/ul]

     

  • What version of FGT & AP's, if any?   I've had this issue in the past and messing around the settings you say helped but this was also in conjunction of a daily reset of the FortiAP's.

    Jeroen
    Contributor

    Current version.

     

    Version: 5.2.2

    AP version: v5.2-build0225

    Type AP: FP221B

    Type FG: 100D

     

    The mentioned settings did not solve any of my problems. Users still have to relogin when they leave and come back whitin range of a AP unit.

    selvam_FTNT
    Staff
    Staff

    Are you creating softswitch and adding SSID and VLAN into it? Can give us controller configuration detail.

     

    Captive portal on Softswitch and SSID works as expected. Firewall session not timing out when wireless client is disconnected. 

    Jeroen
    Contributor

    There is a local break-out on the FortiAP to vlan10 that has his termination point on the Fortigate on a LACP interface with vlan 10 included. This interface has a Captive portal where the guest users login.

    selvam_FTNT
    Staff
    Staff

     

    I assume you have enabled local-bridge on SSID and set VLAN . Create VLAN sub interface on the physical where FAP is connected to.  Captive portal is enabled on VLAN sub interface. Wireless clients  are getting IP from this VLAN and get authenticated by captive portal on VLAN. If so, the same configuration is working in our setup.

    Can you check auth list when clients is disconnecting and connecting back. This list should be present even when client is disconnected and should not prompt for login again when connect back.

    FG600B3909600253 # diagnose firewall auth  list

    172.17.0.10, guest, Guest-group         type: fw, id: 0, duration: 208         expire: 52, allow-idle: 60         flag(20): idle         group_id: 1         group_name: Guest-group

     

     

    Jeroen
    Contributor

    The last time i checked was with version 5.2.0 then it still didn't work. I will try it again when i have a new test machine. Maybe the have changed something since 5.2.1 >

    Labels
    Top Kudoed Authors