Dear All
I'm using FortiAuthenticator as Radius and Fortigate as Internet sharing.
I need to allow some group on FortiAuthenticator to use the internet without web login, just Wifi single sign on. If success login on Wifi then Internet automatically active.
Here is the reference that I use.
The problem is I cannot use the reference with other brand such as tp-link, Dlink, mikrotik or other brand.
On the reference is use FortiAP.
I have tried many time, but always failed, when success login with Wifi then automatically appear login form on browser.
Is there anyone here have a experience to use WSSO without FortiAP.
Please let me know, if anybody can help me.
Regards,
Heri
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Dear Graham
I've just tested with local group and LDAP group, but still doesn't work.
I think this is because I still use Firewall Group on Fortigate. Firewall user group provide access to firewall policies that require authentication. I must use FSSO or RSSO to use Single Sign on through Wifi.
If you have a reference, please let me know.
Best Regards,
Heri
Yes of course... sorry this won't work without a FortiAP since the FortiAP would use the FortiGate as the RADIUS client. Right now you have a different AP acting as RADIUS client so that attributes are not being sent to the FortiGate. Sorry for misleading you!
In this case I think the best thing to do is configure RSSO: https://docs.fortinet.com/document/fortigate/6.2.0/cookbook/85730/radius-single-sign-on-rsso-agent
Dear Graham
Thank you for your information.
Is it possible if we using Different AP with WIndows NPS and fortigate.
Can we implement WSSO with this configure.
Should we use FortiAP also with this alternative.
Regards,
Heri
Unfortunately WSSO requires FortiAP as that is the only way to make Fortigate the RADIUS client which then allows it to receive the RADIUS attributes. Changing RADIUS to NPS will not help.
You should consider RSSO as posted above.
or you could look at doing FSSO too…
Dear Graham
Thank you for your suggestion.
Best Regards,
Heri
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.