β οΈ Important: This guide has been tested with FortiOS versions 7.2 and above.
SSL certificates
To prevent SSL errors on laptops it is recommended you follow the Fortinet guides and deploy a certificate; this will then prevent the messages being generated by connections to your Fortinet controller.
The following URLs may help:
Guest WiFi configuration
To configure the Guest WiFi via on your Fortigate hardware, first login to your FortiGate web interface, then follow each of the sections below in order.
RADIUS server set up
To configure the RADIUS servers, please follow the steps below:
On the left-hand menu click User & Authentication and then select RADIUS Servers.
Click Create New and configure with:
Name: GuestRadius.
Primary Server:
Europe: radius1-eu.wireless-social.com
Americas: radius1-us.wireless-social.com
Primary Shared Secret: Please contact Support.
Secondary Server:
Europe: radius2-eu.wireless-social.com
Americas: radius2-us.wireless-social.com
Secondary Shared Secret: Please contact Support.
Authentication Method: Specify.
Method: PAP.
Click OK to Save.
Next, click on User Groups and Create New. Configure with:
Name: WS_GuestGroup.
Type: Firewall.
Under Remote groups click Create New and under Remote Server choose GuestRadius.
Click OK to Save.
Walled Garden set up
To configure your walled garden, please follow the steps below:
In the left-hand menu, click Policy & Objects and then choose Addresses.
Click Create New and click Address. Configure with:
Name: GuestOnline
Type: Subnet
IP/Netmask: 10.1.0.0/255.255.255.0
Interface: any
Click OK to Save.
Next, click Create New and Address again, then configure with:
Name: *.wireless-social.com
Type: FQDN
FQDN: *.wireless-social.com
Click OK to Save.
Repeat Step 4 for all of the following walled garden domains. There may also be other relevant regional accounts if your venue is outside of the UK or US that you will need to add.
Next, under Addresses click Create New then click Address Group. Configure with:
Category: IPv4 Group.
Group Name: GuestWhitelist.
Members: click the + button and select all the domains you added earlier.
Click OK to Save.
Guest SSID and portal redirect set up
To configure your Guest SSID and captive portal redirects, please follow the steps below:
From the left-hand menu, click WiFi & Switch Controller, then select SSIDs.
Click Create New and then click SSID. Configure with:
Interface Name: GuestWiFiInterface.
Type: WiFi SSID.
Traffic Mode: Tunnel to Wireless Controller.
Address: 10.1.0.1/255.255.255.0
DHCP Server: Enabled.
DNS Server: Specify: 8.8.8.8
SSID: e.g. _Venue Name Guest WiFi - or whatever you wish.
Security Mode: Captive Portal.
Portal Type: Authentication.
Authentication Portal: External:
User Groups: GuestGroup.
Broadcast SSID: Enabled.
Block Intra-SSID Traffic: Enabled.
Redirect after Captive Portal: Specific URL:
Click OK to Save.
Next, under Policy & Objects click Firewall Policy.
Click Create New, then configure with:
Name: GuestWiFiPolicy.
Incoming Interface: _Venue Name Guest WiFi (GuestWiFiInterface).
Outgoing Interface: wan1 (your WAN connection).
Source: all.
Destination Address: GuestWhitelist.
Schedule: always.
Service: ALL.
Action: ACCEPT.
Enable this policy: Enabled
Click OK to Save.
From the left-hand menu, click WiFi & Switch Controller, then click SSIDs.
Choose the SSID created earlier, and add the GuestWhitelist you created above to the Exempt destinations/service.
Insights Plus FortiGate Presence set up
To collect data for Insights Plus, follow the below steps:
From the left-and menu, click WiFi & Switch Controller and then select FortiAP Profiles.
Click on the profile your access points (APs) are associated with - you may have more than one.
Scroll down and locate the FortiPresence entry - click to expand the options.
Fill in the details listed below: replacing the Project Name and IP if required.
Mode: Foreign and Home Channels.
Project name: fortipresence.
Password: Unique to your network - provided by Support.
FortiPresence server IP: 18.134.187.121.
FortiPresence server port: 3000.
Report Rogue APs: Enabled.
Report unassociated clients: Enabled.
Notify Support once you have completed the configuration and we can monitor for data coming in.
Your login and Insights Plus presence data will appear in the Insights portal within 24 hours.
