Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
sagvan
New Contributor III

Seeking Recommendations

Hello, everyone!
I hope everyone is doing great.

 

In our environment, we have three SSIDs, one of which is for guests. We have also given access to some of our employees on this guest SSID because of its limitations, defined within policies.

 

Since this SSID only requires a password, the employees have shared the password with their friends, but apparently, we cannot control this. Changing the password will solve nothing in this regard.

 

I did my research and found out that there is an option for "mac-address filtering" to either ALLOW or DENY users' access based on their devices' mac addresses. However, I find this to be too much of a headache and more work for me as any time a user needs access, I have to get their mac address, and of course, keep all of them within a sheet for documentation.

 

Is there a more convenient way to face this?

Best regards,

Sagvan Saleem
Sagvan Saleem
6 REPLIES 6
Tahsin
New Contributor II

Hi Sagvan,

 

I think, use captive portal will be best way in this situtaion.I shared docment below about how can you apply captive portal in your system.

 

https://docs.fortinet.com/document/fortiap/7.4.2/fortiwifi-and-fortiap-configuration-guide/292926/ca...

 

TahsinCabuk

If my writings have helped you find a solution. Please like so that others can easily access it as well.
TahsinCabuk
If my writings have helped you find a solution. Please like so that others can easily access it as well.TahsinCabuk
sagvan
New Contributor III

We already have two SSIDs that require username and password for login. However, this one was only created for guests, but then it was decided that users with limited access should use this guest SSID.

What is the difference between Captive Portal and SSID with WPA3?

Sagvan Saleem
Sagvan Saleem
Tahsin
New Contributor II

Hi Sagvan,

shortly we can explain difference between Captive Portal and WPA3 like below 

Captive Portal is used for managing user access and authentication in public or guest networks and involves user interaction with a web page. It does not inherently provide encryption for data transmission.

WPA3 is a security protocol providing strong encryption and secure access to a network, requiring a pre-shared key for authentication without further user interaction. It is ideal for environments where data security is paramount.



If my writings have helped you find a solution. Please like so that others can easily access it as well.
TahsinCabuk
If my writings have helped you find a solution. Please like so that others can easily access it as well.TahsinCabuk
sagvan
New Contributor III

Security matters in our environment, so I guess we need to create a new SSID for the users with limited access.

Sagvan Saleem
Sagvan Saleem
Tahsin
New Contributor II

In that case, you can use guest sponsor for limited acces.

If my writings have helped you find a solution. Please like so that others can easily access it as well.
TahsinCabuk
If my writings have helped you find a solution. Please like so that others can easily access it as well.TahsinCabuk
sagvan
New Contributor III

Thank you!

Sagvan Saleem
Sagvan Saleem
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors