Did you use Tunnel mode for the SSID? I had more success with the
tunnel-mode.Also, policy from guest-range to DNS-server to allow
resolving and HTTPs to the FortiAuth.I also used a wildcard-cert on my
FortiGate for authentication and set the followi...