Fortinet WLC (System Director)

  • Updated

Configuration Instructions

Please log in to your Fortinet WLC controller and click Configuration > RADIUS on the left menu.

Click on Add and configure as per the following:

RADIUS Profile Nameguestwifi1
RADIUS IP*insert radius_server_ip here*
RADIUS Secret*insert radius_secret here*
RADIUS Port1812
Remote RADIUS ServerOff
MAC Address DelimiterHyphen (-)
Password TypeMacAddress
Called-Station-ID TypeMacAddress
COAOn

Click on OK and then Add. Configure as per the following:

RADIUS Profile Nameguestwifi2
RADIUS IP*insert radius_server2_ip here*
RADIUS Secret*insert radius_secret here*
RADIUS Port1812
Remote RADIUS ServerOff
MAC Address DelimiterHyphen (-)
Password TypeMacAddress
Called-Station-ID TypeMacAddress
COAOn

Click OK and then on the left menu click QoS Settings. Select the QoS and Firewall Rules tab.

Click Add and configure as per the following:

ID1
Destination IP*insert walled_garden_ip here*     Match: Ticked
Destination Netmask255.255.255.255
Firewall Filter IDGUEST     Match: Ticked
QoS Protocolother
ActionFORWARD
Traffic ControlOn

Press OK to Save, and then click Add again. Configure as per the following:

ID2
Source IP*insert walled_garden_ip here*     Match: Ticked
Source Netmask255.255.255.255
Firewall Filter IDGUEST     Match: Ticked
QoS Protocolother
ActionFORWARD
Traffic ControlOn

Press OK to Save and then on the left menu, under Security click on Captive Portal. Select the Captive Portal Profiles tab and then click Add. Configure as per the following:

CP Nameguestwifi
Authentication Typeradius
Primary Authenticationguestwifi1
Secondary Authenticationguestwifi2
Primary Accountingguestwifi1
Secondary Accountingguestwifi2
External Portal URL*insert access_url here*
Public IP of ControllerEnter your public IP of the controller (see important note below)
Session Timeout1440
Activity Timeout60
CNA BypassOff
IMPORTANT NOTE: You will also need to set up an inbound port forward rule on your firewall/router to forward TCP port 443 to your internal controller IP. This is required so that we can submit authentication requests from our cloud servers. Without this guest authentication cannot proceed and the user will be unable to log in. Contact support if you require help with this.

Click on Add to Save and then on the left menu, under Security click on Profile then Add. Configure as per the following:

Security Profile Nameguestwifi
L2 Modes AllowedClear
Captive PortalWebAuth
Captive Portal Profileguestwifi
Captive Portal Authentication Methodexternal
Firewall Capabilityconfigured
Passthrough Firewall Filter IDGUEST

Click OK to Save and then on the left menu, under Wireless click on ESS then Add. Configure as per the following:

ESS Profileguestwifi
Enable/DisableEnable
SSIDGuest WiFi (or whatever you wish)
Security Profileguestwifi
Accounting Interim Interval600
SSID BroadcastOn
Dataplane ModeTunnelled

Click OK to Save.

Configuration Complete

The configuration is now complete.

Share online:
Was this article helpful?
0 out of 0 found this helpful