For the following error:facauth: ERROR: The AP of portal policy X does
not contain client guestwifi.auth.local It is suggested to add
"guestwifi.auth.local" to the Access Point configuration on the FAC,
this however is still not working, The Fortigat...
Following from a previous post, which was kindly resolved (External CA
for Captive Portal). I am doing further testing and have come across a
minor query: How to configure FortiGate Captive Portal... - Fortinet
Community This article mentions using D...
As per -
https://docs.fortinet.com/document/fortiauthenticator/6.5.0/cookbook/578250/fortiauthenticator-as-a-wireless-guest-portal-for-fortigate
it says at the end "Configuring firewall authentication portal settings
on FortiGateThe following setting...
Question on Radius policy, I have a FortiGate connected to a FAC for 2
sets of users (both using the same LDAP source) One set is using a
policy, that requires chained authentication, (RSA Token server) and
that policy is at the top and it works fine...
Client laptop has a cert issued by Microsoft AD (via Intune) the Trusted
CA has been imported to the FAC 6.6.0 as per this video:EAP-TLS
Authentication with FortiAuthenticator | Identity and Access
ManagementThe fortigate is set to use the FAC / WPA2...
Thank you, I have done that, I will have to use FQDN as we are going to
be using public signed cert, as we don't want them to get cert errors. I
have created local DNS entries on the gate now, Ill see if it does the
trick!
Thank you for your help, one question though, I dont have a certificate
yet, so surely, I would be able to "accept risk" on the browser and I
should still see the page?If I browse to it manually, I get "403
Forbidden" despite allowing guest portals o...
The FortiGate and FAC are on the same domain, so in the DNS SAN, I would
add the hostname of the gate and the FAC yes? myfortigate.local and
myfac.local?
I can arrange purchasing a cert for the FAC, but to get another public
signed cert for a "quick redirection" seems like a really bad design to
be honest. I assume, I can just use the hostname of the FAC in the cert
when I create the CSR? I wanted to ...