Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet
To create a firewall policy for guest access to DNS and FortiAuthenticator:
- Go to Policy & Objects > Firewall Policy and click Create New.
- Enter a name for the policy.
- In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
- In Outgoing Interface, select the interface for FortiAuthenticator and DNS access.
- In Source, select an Address object.
- In Destination, select address objects for the FortiAuthenticator and DNS servers.
- Enable or disable NAT as required.
- Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
- Click OK.
To create firewall policy for guest user internet access:
-
Go to Policy & Objects > Firewall Policy and click Create New.
- Enter a name for the policy.
- In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
- In Outgoing Interface, select the interface for internet access.
- In Source, select an address object and the guest group configured in Guest group on FortiGate.
- In Destination, select the All address object.
- Enable NAT.
- Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
- Click OK.