Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zone3-TI
New Contributor

Wifi user with limited access

Hi everyone,

I would like to know what is the best way to limit a user access within wifi network.

I want to create a user that can only reach Internet and some PCs. This user will be used for screen casting. I already have a public network but the PC used for screen casting are not reachable from this network. 

 

Thanks for your help.

1 Solution
Markus_M

As noted by Graham and in addition to:

What are the requirements and options? The "best way" does not exist, it will depend on what you have available and what your target and also target users are. Managed clients can be handled very different than unmanaged guest users.

 

- If you have a RADIUS server with authentication, it will actually be very easy - return the isolated VLAN after user/host/MAC authentication.

- If have no such thing, you can use FortiGates NAC feature (ForitOS 7+). The known static (requires to disable MAC randomization on these known clients) MAC addresses or whatever known criteria can have some elevated access (assigning the respective VLAN), unknown ones go to the guest VLAN.

 

 

Best regards,

 

Markus

View solution in original post

3 REPLIES 3
gfleming
Staff
Staff

So you just want to restrict one user/device on an exisiting wifi network and keep everyone else's access the same?

 

You could use L2 address object for that device and create a restrictive policy for it. However, restricting access to only some devices on the same network is going to be very difficult.

 

What's your ultimate end goal here and what are the reasons for restrictions? Can you shed more details on the requirements?

Cheers,
Graham
Markus_M

As noted by Graham and in addition to:

What are the requirements and options? The "best way" does not exist, it will depend on what you have available and what your target and also target users are. Managed clients can be handled very different than unmanaged guest users.

 

- If you have a RADIUS server with authentication, it will actually be very easy - return the isolated VLAN after user/host/MAC authentication.

- If have no such thing, you can use FortiGates NAC feature (ForitOS 7+). The known static (requires to disable MAC randomization on these known clients) MAC addresses or whatever known criteria can have some elevated access (assigning the respective VLAN), unknown ones go to the guest VLAN.

 

 

Best regards,

 

Markus

Zone3-TI
New Contributor

Thank you Markus

Labels
Top Kudoed Authors