Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alesco
New Contributor

Disclaimer only Captive Portal on LAN Interface

Hi all,

 

I need to set up a disclaimer only captive portal for our public wifi users.

 

Now the thing is that our wifi infrastructure is based on Cisco and I want to use the FortiGate as default gateway for our public wifi. I need the FortiGate to provide the captive portal and to do the traffic filtering.

 

This means that I want to set up the captive portal on the lan interface of the FortiGate where the wifi traffic comes in. I don't want an authentification captive protal it just has to be a disclaimer that the user has to accept so he can connect to the internet.

 

Unfortunatley I am only able to choose "Authentication Portal Local or External" and there is no option to choose the disclaimer only type.

 

How can I solve this?

 

Thanks for your help!

 

Br,

 

Alex

 

1 Solution
ede_pfau
Esteemed Contributor III

Try to configure that in the policy:

config firewall policy

edit nnn

set disclaimer enable


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
6 REPLIES 6
ede_pfau
Esteemed Contributor III

I seem to remember that you can set the disclaimer command in CLI only. Please have a look at the CLI Reference for your firmware version.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Alesco

Thanks for your help!

 

I am running FortiOS 5.4 on my FortiGate 60D.

 

Here is what I tried...

 

config system interface

edit "Name of the Interface"

set security-mode captive-portal

set portal-type disclaimer

 

The command set Portal-type doesn't seem work for the interface.

command parse error before 'portal-type' Command fail. Return code -61

 

Is there another way to do it?

Or does it work with another OS version?

 

Thanks,

Alex

ede_pfau
Esteemed Contributor III

Try to configure that in the policy:

config firewall policy

edit nnn

set disclaimer enable


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Alesco

That is it!  Thank you so much!!

 

Do you know, where the Information is stored that a Client has accepted the disclaimer?

Is the MAC address entered in some kind of white list on the Forti after accepting?

 

Br,

 

Alex

 

 

ede_pfau
Esteemed Contributor III

Sorry, no idea. Just sniff the HTTP traffic...


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
neil_burroughs
New Contributor

Hi. Trying to enable disclaimer only captive portal on a LAN interface, Fortigate 500D, 5.2.7 but cant get the suggested commands to work, any suggestions?

Thanks

N

 

Labels
Top Kudoed Authors