Fortinet black logo

Cookbook

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

To create a firewall policy for guest access to DNS and FortiAuthenticator:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
  4. In Outgoing Interface, select the interface for FortiAuthenticator and DNS access.
  5. In Source, select an Address object.
  6. In Destination, select address objects for the FortiAuthenticator and DNS servers.
  7. Enable or disable NAT as required.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.
To create firewall policy for guest user internet access:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
  4. In Outgoing Interface, select the interface for internet access.
  5. In Source, select an address object and the guest group configured in Guest group on FortiGate.
  6. In Destination, select the All address object.
  7. Enable NAT.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

To create a firewall policy for guest access to DNS and FortiAuthenticator:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
  4. In Outgoing Interface, select the interface for FortiAuthenticator and DNS access.
  5. In Source, select an Address object.
  6. In Destination, select address objects for the FortiAuthenticator and DNS servers.
  7. Enable or disable NAT as required.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.
To create firewall policy for guest user internet access:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the wired guest interface created in Wired Guest Interface.
  4. In Outgoing Interface, select the interface for internet access.
  5. In Source, select an address object and the guest group configured in Guest group on FortiGate.
  6. In Destination, select the All address object.
  7. Enable NAT.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.