Hi there,
We have a single fortigate with one interface operating as a wired captive portal for guest internet (this is not wifi). We use the guest admin (the receptionist) to provision accounts for guests.
It works well, but now we have introduced a 2nd Fortigate at a seperate site, and would like to have a single user across both sites.
We also have FortiAuthenticator. We are wondering if/how we can set the Guest Portal on the FortiAuthenticator, and configure the Fortigate to use an "External" captive portal.
I'm sure this is possible, bit all the cookbook documentation is either old, or for captive portal wifi only. Does anyone have a step by step to do this. We are running fortigate 6.2 and Fortiauthenticator 6.0
Can anyone help?
Thanks
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
how about this way .. You need to invest a little bit of effort, but raw skeleton might look like this:
step 1 - on FortiGate (FGT hereinafter) set FortiAuthenticator (FAC hereinafter) as external captive portal
step 2 - on FAC decide how would you like to manage users.
- are those going to get synced from Microsoft Active Directory ? .. tag "#Remote_user_sync_rules" - are those local or guests ? .. tag #Guest_users
step 3 - your FGT will be RADIUS Client to FAC and it needs to be set up
step 4 - set Guest portal on FAC ... https://docs.fortinet.com/document/fortiauthenticator/6.0.4/administration-guide/617902/guest-portal...
step 5 - testing with known user
on FGT - https://kb.fortinet.com/kb/microsites/searchEntry.do search for troubleshooting
- use packet captures to see RADIUS packets (default auth port 1812.udp)
- flow debug to see which policies handled the stuff
- diag debug app fnbamd 7
- diag firewall auth list
etc. etc.
Tomas Stribrny - NASDAQ:FTNT - Fortinet Inc. - TAC Staff Engineer
AAA, MFA, VoIP and other Fortinet stuff
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.