Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nflnetwork29
New Contributor III

NAC - isolation vlan firewall rules for captive portal

Hello we a have installed a public certificate on our captive portal . when a machine is connected its initial  location is the isolation vlan as per design. 

 

Cert looks to be installed correctly but we are still getting SSL Certificate error upon initial browser launch . 

 

 

Do we need to modify the firewall rule for isolation vlan? do we need to allow outbound internet access to the certificate authority ? What are people doing in this scenario. 

 

Running FortiNAC-f 7.4

 

Thanks, 

3 REPLIES 3
ebilcari
Staff
Staff

If a public certificate is used, the root CA should be already present in the end host so internet access is not required. Usually this happens when the intermittent certificate is not properly uploaded in FNAC, some details can be found in this article.

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
nflnetwork29

well i was on with TAC and we confirmed the certificate was loaded correctly.  anything else i can check? 

ebilcari

Can you tell which URL is listed in the browser when you get the certificate error, is it still showing the original website or is it already redirected to the FNAC portal page?

- Emirjon
If you have found a solution, please like and accept it to make it easily accessible for others.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors