Following from a previous post, which was kindly resolved (External CA for Captive Portal). I am doing further testing and have come across a minor query:
How to configure FortiGate Captive Portal... - Fortinet Community
This article mentions using DNS, so that it can resolve the FAC address, now, I dont use internal DNS I use google DNS on my Fortigate to resolved external and get out to fortiguard etc, Am I right in assuming, in order to allow the Guest Portal to see Fortiauth, Ill need to set up a local DNS Zone with the internal DNS as forwarders and apply it on the Guest SSID interface? is this the correct way to do it?
It is said you require local DNS server when FQDN is used. So if you use IP and not FQDN you don't need DNS server just for that.
But in case you still want to use FQDN then you have to setup a local DNS server. You also can set it up on your FortiGate, it is quick and easy.
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/960561/fortigate-dns-server
Hope it helps.
Thank you, I have done that, I will have to use FQDN as we are going to be using public signed cert, as we don't want them to get cert errors. I have created local DNS entries on the gate now, Ill see if it does the trick!
User | Count |
---|---|
2094 | |
1182 | |
770 | |
451 | |
344 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.