Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
MikaelF
New Contributor

Users needs to re-authenticate in captive protal

Hi, we have a FG 200B with 4 FortiAP. We use guest access via captive portal. I have a problem when users with ipad/iphone connects via guest portal, and after turning off their screens/locking devices they need to re-authenticate all the time. Is there any way to keep the authentication alive for a timeout , even if the IOS devices turns of their Wifi momentarily during locked screen? I have set the auth timeout to 480 minutes, but this doesnt help. we are running 5.0 patch 4 on the FG and 5.0 build 048 on the AP' s. As a side note, I can get the same behaviour on a PC, if I disconnect the SSID and re-connect. So my question is if authentication can be remembered even so? Thanks! /Mikael
3 REPLIES 3
Bromont_FTNT
Staff
Staff

The issue is that iOS devices send a disassociate packet when the screen locks, this removes the client entry on the Fortigate and they will need to re-auth upon joining again... Looks like some things related to this have been tweaked in 5.0.5 firmware.
pcraponi
Contributor II

Is it instantly or after a few minutes? Fortigate " check" all wireless clients in an interval of 300 seconds to see if they still alive. If this check fail, they delete user from auth table... You can change these times using CLI: config wireless-controller timers set client-idle-timeout xxx end If use " 0" , has no timeout.. But I don' t know if this is a good choice. Regards, Paulo Raponi

Regards, Paulo Raponi

Regards, Paulo Raponi
Nightstalker
New Contributor

I am experiencing this same problem. I have my client-idle-timeout set to 3600, but that makes little difference. Apple devices are the worst. They will disconnect after only about 2 minutes of inactivity. I believe the device itself is shutting down wifi to conserve battery. I also see it with laptops. We run job labs and when patrons are completing complicated and time consuming on-line job applications, when they hit submit they get slapped in the face with our disclaimer page and lose all the work they just completed. This happens in only 30-40 minutes. Terry
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors