Guest WiFi Accounts

Video Activity

In this video, you will learn how to set up guest WiFi access to a FortiAP in tunnel mode. You will set up a temporary guest WiFi user account that expires in 5 minutes and then create an optional admin account to manage guest accounts. (5.2) Visit Fortinet's documentation library at http://docs.fortinet.com

Join over 3 million cybersecurity professionals advancing their career
Sign up with
Required fields are marked with an *
or

Already have an account? Sign In »

Time
1 hour 35 minutes
Difficulty
Beginner
CEU/CPE
2
Video Description

In this video, you will learn how to set up guest WiFi access to a FortiAP in tunnel mode. You will set up a temporary guest WiFi user account that expires in 5 minutes and then create an optional admin account to manage guest accounts. (5.2) Visit Fortinet's documentation library at http://docs.fortinet.com

Video Transcription
00:00
>> In this video, you will learn how to set up
00:00
guest Wi-Fi access to a FortiAP internal mode.
00:00
You will set up a temporary guest
00:00
Wi-Fi user account that expires in
00:00
five minutes and then create
00:00
an optional admin account to manage guest accounts.
00:00
First, go to user and device,
00:00
user groups, and
00:00
create a new group for guests to access the Internet.
00:00
Set type to guests,
00:00
set user ID to email,
00:00
and ensure the password is set to auto-generate,
00:00
set the password to expire after
00:00
first login with
00:00
the default expiratory time of four hours.
00:00
Next, go to Wi-Fi and switch controller, Wi-Fi network,
00:00
SSID, and create a guest SSID that uses captive portal.
00:00
Set traffic mode to tunnel to wireless controller.
00:00
Assign an IP network mask to
00:00
the interface and to the DHCP server.
00:00
Set security mode to captive portal and user groups,
00:00
to the Wi-Fi guest user group.
00:00
Go to Wi-Fi and switch controller, Wi-Fi network,
00:00
FortiAP profiles, and
00:00
edit the profile for your FortiAP model.
00:00
In the example FortiAP 11C.
00:00
Set the FortiAP to broadcast the new SSID.
00:00
Go to policy and objects, policy,
00:00
IPV4, and create a new policy
00:00
for guest users to connect to the Internet.
00:00
Set incoming interface to the guest SSID,
00:00
source user to the Wi-Fi guest user group.
00:00
Set the outgoing interface to
00:00
the Internet facing interface.
00:00
Set service to HTTP,
00:00
HTTPS, and DNS.
00:00
Go to user and device.
00:00
User guest management and create a new account.
00:00
Enter the user's email address and for testing purposes,
00:00
set the account to expire in five-minutes.
00:00
The temporary account is
00:00
automatically deleted after this time period.
00:00
After you select ''Okay'' a user created
00:00
successfully notice will appear that
00:00
lists the generated password.
00:00
You can then print or email
00:00
the password to the guest user.
00:00
Go to system administrators.
00:00
If you would like to create
00:00
an admin account to manage guest users.
00:00
Create a new account for an administrator.
00:00
Set type to regular and set a password.
00:00
Select ''Restrict to provision guest accounts'' and
00:00
set guest groups to the Wi-Fi guest user group.
00:00
Now sign into the FortiGate using your new admin account.
00:00
As you can see, you will only be able to
00:00
see the menu for the guest user management.
00:00
On a computer connect to the guest SSID.
00:00
When the authentication screen appears,
00:00
login using the guest users credentials.
00:00
You can now successfully connect to the Internet.
00:00
Five minutes after the initial login,
00:00
the temporary user account will
00:00
expire and you will
00:00
no longer be able to log in using those credentials.
00:00
You can also verify your results by
00:00
looking at the Guest Management section.
00:00
Thank you for watching.
00:00
For more information.
00:00
You can access Fortinet's
00:00
documentation library @docs.fortinet.com.
Up Next