Fortinet black logo

Cookbook

Configuring guest access

Copy Link
Copy Doc ID 9bd2f947-ece6-11ec-bb32-fa163e15d75b:860416
Download PDF

Configuring guest access

A visitor to your premises may need a user account on your network during their stay. If you are hosting a large event, such as a conference, you may need to create many temporary accounts for the attendees. You can create many guest accounts simultaneously using randomly generated user IDs and passwords to reduce your workload for these large events.

The following describes managing guest access:

  1. Create one or more guest user groups. All members of a group have the same user ID type, password type, information fields used, and type and time of expiry.
  2. Create guest accounts.
  3. Use captive portal authentication and select the appropriate guest group.
  4. The guest receives an email, SMS message, or printout containing their user ID and password from the FortiOS administrator.
  5. The guest logs onto the network using the provided credentials.
  6. After the configured expiry time, the credentials are no longer valid.

This configuration consists of the following steps:

  1. Add an SMS service.
  2. Create a guest management administrator.
  3. Create a guest user group.
  4. Create guest user accounts.
To add an SMS service:

To send SMS notifications to guest users, add an email to SMS service to your FortiGate using the following commands:

config system sms-server

edit <server-name>

set mail-server <server-name>

next

end

To create a guest management administrator:
  1. Go to System > Administrators.
  2. Click Create New > Administrator.
  3. Enable Restrict admin to guest account provisioning only.
  4. For Guest Group, select the desired guest groups.
To create a guest user group:

The guest group configuration determines the provided fields when you create a guest user account.

  1. Go to User & Device > User Groups.
  2. Click Create New.
  3. For Type, select Guest.
  4. If desired, enable Batch Guest Account Creation. When this is enabled, the following is true:
    • User IDs and passwords are auto-generated.
    • User accounts only have the User ID, Password, and Expiration fields. You can only edit the Expiration field. If the expiry time is a duration, such as eight hours, the countdown starts at initial login.
    • You can print the account information to provide to the guest. Guests do not receive email or SMS notifications.
  5. For User ID, select one of the following:

    Option

    Description

    Email

    Guest's email address.

    Auto Generated

    FortiOS creates a random user ID for the guest.

    Specify

    The administrator assigns a user ID to the guest.

  6. For Password, select one of the following:

    Option

    Description

    Disable

    No password.

    Auto Generated

    FortiOS creates a random password for the guest.

    Specify

    The administrator assigns a password to the guest.

  7. For Start Countdown, select one of the following:

    Option

    Description

    On Account Creation

    FortiOS counts expiry time from time of account creation.

    After First Login

    FortiOS counts expiry time from the guest's first login.

  8. For Time, configure the expiry time. You can change this for individual users.
  9. Configure any other field as required, then click OK.

Creating guest user accounts

To create a guest user account:
  1. Go to User & Device > Guest Management.
  2. Select the desired guest group.
  3. Click Create New.
  4. Configure the guest as desired.
  5. Click OK.
To create multiple guest user accounts automatically:
  1. Go to User & Device > Guest Management.
  2. Select the desired guest group. This group must have Batch Guest Account Creation enabled.
  3. Click Create New > Multiple Users.
  4. Enter the Number of Accounts.
  5. If desired, change the expiry.
  6. Click OK.

Configuring guest access

A visitor to your premises may need a user account on your network during their stay. If you are hosting a large event, such as a conference, you may need to create many temporary accounts for the attendees. You can create many guest accounts simultaneously using randomly generated user IDs and passwords to reduce your workload for these large events.

The following describes managing guest access:

  1. Create one or more guest user groups. All members of a group have the same user ID type, password type, information fields used, and type and time of expiry.
  2. Create guest accounts.
  3. Use captive portal authentication and select the appropriate guest group.
  4. The guest receives an email, SMS message, or printout containing their user ID and password from the FortiOS administrator.
  5. The guest logs onto the network using the provided credentials.
  6. After the configured expiry time, the credentials are no longer valid.

This configuration consists of the following steps:

  1. Add an SMS service.
  2. Create a guest management administrator.
  3. Create a guest user group.
  4. Create guest user accounts.
To add an SMS service:

To send SMS notifications to guest users, add an email to SMS service to your FortiGate using the following commands:

config system sms-server

edit <server-name>

set mail-server <server-name>

next

end

To create a guest management administrator:
  1. Go to System > Administrators.
  2. Click Create New > Administrator.
  3. Enable Restrict admin to guest account provisioning only.
  4. For Guest Group, select the desired guest groups.
To create a guest user group:

The guest group configuration determines the provided fields when you create a guest user account.

  1. Go to User & Device > User Groups.
  2. Click Create New.
  3. For Type, select Guest.
  4. If desired, enable Batch Guest Account Creation. When this is enabled, the following is true:
    • User IDs and passwords are auto-generated.
    • User accounts only have the User ID, Password, and Expiration fields. You can only edit the Expiration field. If the expiry time is a duration, such as eight hours, the countdown starts at initial login.
    • You can print the account information to provide to the guest. Guests do not receive email or SMS notifications.
  5. For User ID, select one of the following:

    Option

    Description

    Email

    Guest's email address.

    Auto Generated

    FortiOS creates a random user ID for the guest.

    Specify

    The administrator assigns a user ID to the guest.

  6. For Password, select one of the following:

    Option

    Description

    Disable

    No password.

    Auto Generated

    FortiOS creates a random password for the guest.

    Specify

    The administrator assigns a password to the guest.

  7. For Start Countdown, select one of the following:

    Option

    Description

    On Account Creation

    FortiOS counts expiry time from time of account creation.

    After First Login

    FortiOS counts expiry time from the guest's first login.

  8. For Time, configure the expiry time. You can change this for individual users.
  9. Configure any other field as required, then click OK.

Creating guest user accounts

To create a guest user account:
  1. Go to User & Device > Guest Management.
  2. Select the desired guest group.
  3. Click Create New.
  4. Configure the guest as desired.
  5. Click OK.
To create multiple guest user accounts automatically:
  1. Go to User & Device > Guest Management.
  2. Select the desired guest group. This group must have Batch Guest Account Creation enabled.
  3. Click Create New > Multiple Users.
  4. Enter the Number of Accounts.
  5. If desired, change the expiry.
  6. Click OK.