- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
One SSID for domain and guest users
Hi,
it is possible to configure fortigate/fortiap to have one SSID for domain and guest users, I mean:
1. if computer is member of domain computers (windows radius - nps), then connect automatically to that ssid without any login/passwords.
2. if computer is not member of domain computer (guest users) - then show for them authentication page (login and password) that are configured locally on fortigate.
is this possible? Or I need to create two separate SSID?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
You can not mix authentication methods on an SSID because of the 802.11 standards. If you were not looking for radius auth on the corporate SSID, you could you use multiple PSK on the same SSID and put users in different VLANs based on the PSK used.
I would recommend two different SSIDs though and use a higher security network for Corporate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
But this is only network with internet access nothing more this wifi network will be located in conference rooms and I would like to simplify logging to it to employess, but guest and outside persons should login using generated login/password.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If it’s just internet then you could do the multi-psk. You could create different psk for different guest.
Creating a network that is the same (like a captive portal) creates some security issues being an open ssid (no encryption) and having employees and guest on the same network could expose employee machines.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Here is an article in mpsk for a better understanding
https://docs.fortinet.com/document/fortigate/6.4.2/administration-guide/997400/mpsk-groups
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't understand this description, how could I create two groups using MPSK, one to login using login/password and second to auto-login based on domain membership ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No, it would all be a password when connecting to the network using WPA2-personal (like at your house). If you want a portal for guests and radius for employees you are going to have to have two different SSIDs.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
My 50 cents on top of @distillednetwork suggestion.
SSID with MPSK is a solution for your case.
But If you do not want the domain user to enter the PSK upon connecting to that specific SSID, you can push SSID, encryption type, and the PSK of the Wireless network the PCs via Group Policy, so the connection to that SSID will be seamless for domain users.
Guest users on the other side will get a prompt to enter the PSK.
Ahmad
