Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
nithishkumar
New Contributor II

User based policy via SAML in wireless users TP-Link AP

Hi Team,

I hope this message finds you well.

I need clarification regarding the configuration of SAML authentication with a user-based policy for a customer. Here is the situation:

  • We have successfully configured SAML authentication, and it works when users are directly connected to the LAN.
  • However, the customer has now deployed TP-Link wireless access points (AP), and users are unable to see the authentication page.

Based on my research in the community portal, it seems that to configure SSO with a user-based policy for wireless users, the Forti-AP SSID needs to have the Captive Portal enabled and mapped to the Azure portal.

 

 

Could you please confirm if enabling the Captive Portal for wireless users is indeed necessary in this case?

 

Additionally, if the customer is not using Forti-AP, what alternative solution can be provided to ensure that wireless users can successfully authenticate?

 

I would appreciate your prompt response as we need to implement a solution as soon as possible.

 

Thank you in advance for your assistance.

 

 

 

Thanks.

@nithishkumar 

 

 

FortiGate FortiAP 

Nithishkumar S
Nithishkumar S
4 REPLIES 4
hbac
Staff
Staff

Hi @nithishkumar,

 

Yes, captive portal is needed. You can refer to this article: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-create-FortiGate-captive-portal-usi...

 

Make sure to exempt initial connection to SAML authentication page and DNS traffic if you are using public DNS server. Refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Captive-Portal-Exempt-list/ta-p/197111

 

Refer to this article at step 6: https://community.fortinet.com/t5/FortiGate/Technical-Tip-Wireless-Authentication-using-SAML-Credent...

 

Regards, 

nithishkumar
New Contributor II

Hi @hbac,

 

 

We are currently facing an issue with the Captive Portal on our network. Our setup involves a TP-Link wireless access point connected directly to a FortiGate firewall via the LAN interface.

 

We have enabled the Captive Portal on the LAN interface, but it appears that the authentication page is not being displayed for users connecting through the TP-Link wireless access point.

 

Could you please assist us in resolving this issue? We would appreciate any guidance or recommendations on how to ensure the Captive Portal authentication page is displayed correctly for all wireless users.

 

Thank you in advance for your support. We look forward to your prompt response.

 

@nithishkumar 

Nithishkumar S
Nithishkumar S
hbac

@nithishkumar,

 

As I already mentioned, you need to exempt initial connection to SAML authentication page and DNS traffic if you are using public DNS server. Please check articles I shared.

 

Regards, 

mle2802
Staff
Staff

Hi @nithishkumar,

Do you have a separate VLAN for Wifi network or using the same LAN network? If not then the captive portal may enforce for LAN traffic also not only with Wifi network.  

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors