This is a work in progress, I will be... Full Story
By Manny Fernandez
July 25, 2019
Managing Guest Users in Fortigate Firewalls
Sometime, a company may want to create guest users
for wireless or wired connections. Additionally, companies may want to have administrators
with limitedv access to ONLY create guest accounts.
Use Case:
Receptionist greets guests of your organization. These guests will require Internet access. The receptionist will collect business cards from the guests and use the information contained therein to create the account.
Steps we will take:
- Define a group
- Define a restricted administrator
- Configure SSID or Wired Captive Portal
Here we go….
Step 1 – Creating the Guest User Group
Let’s start by going to User & Device
then choose User Group
.
- Give the group a descriptive name.
- Choose the pre-defined
Guest
type. - User ID – You can choose
Email Address
,Auto Generated
andSpecify
. I have foundemail
is the simplest. - Required Fields – You can optionally require the administrators to enter name and email.
- Password – You can either have the Fortigate autogenerate or you can specify. I have found the
Autogenerated
is much easier. - Sponsor Information – You can set the information for
Sponsor Name
andCompany
as eitherOptional
orRequired
. - Start Countdown – You can start the countdown either after the creation or after the first login.
- Time – This will define what the default will be when they create a user.
Step 2 – Creating the Limited Administrator
Now we will need to create a restricted administrator that will only be allowed to manage guest accounts.
Go to System
then Administrators
.
- Provide a name for the administrator
- Choose the
Restrict admin to guest account provisioning only
radio button. - Choose the
Guest Group
we create above. - Optionally, you can restrict this user to a
Trusted Host
.
Step 3 – Logging in as restricted administrator
Now we will log into the Fortigate Firewall using the restricted administrator we created in Step 2
Step 4 – Portal View
You will notice upon logging in, that there are limited options. Let’s choose Create New
to create a new guest account.
Step 5 – Creating the guest user
We can see the guest user I am creating. It contains the Name, Sponsor, Company, my eMail, and the default suggested expiration time.
Step 6 – Sending out credentials
Once you create the user, you will have the option to either Print
or Email
the user information. I will choose the Email
option.
Step 7 – Receiving the email
As you can see in the email screenshot, we can see that the following information is provided:
User ID=manny@infosecmonkey.com Password=skd3maf5 Expires=-14400 seconds after first successful login User Name=Manny Fernandez Mobile Phone=none Sponsor=Tony Stark Company=InfoSec Monkey Email=manny@infosecmonkey.com
This is provided to the guest user.
Step 8 – Using what we just created
Step 8 A – Wireless SSID
When you create the SSID, you have the option to change the Security Mode
to Captive Portal
. Then you can define what User Group
can use this SSID.
Step 8 B – Wired Portal
When you modify the interface, you have the option to change the Security Mode
to Captive Portal
. Then you can define what User Group
can use this Authentication.
Hope this helps
Recent posts
-
-
I have been playing with the free version of... Full Story
-
In my day job, I am on a lot... Full Story