Use Roaming Guests to configure a list of local domains for your local network users. Users who connect and attempt to authenticate with a fully qualified domain name that is NOT on this list are treated as Roaming Guests. This feature was developed to accommodate organizations that meet at each other's sites frequently, such as an educational consortium or a business development group. Supports Eduroam for participating universities.
This feature can only be used for wireless 802.1x connections.
Configure your local RADIUS server with the remote RADIUS servers to which it should proxy authentication requests for users who are not part of one of your local domains.
Modify the Model Configuration of any wireless device to which your roaming guests will connect. Specific treatment can be configured for Roaming Guests in the Model Configuration. This controls network access, such as the VLAN in which the host is placed, or access can be denied for Roaming Guests on a particular device. See the information for the Host State field in Model configuration.
Roaming Guests cannot be controlled at the SSID level only at the device level.
Configure the list of local domains. This allows FortiNAC to distinguish between local users and Roaming Guests. See Add Local Domains below for instructions.
- Roaming Guests may require a supplicant for the wireless connection. This supplicant cannot be configured by FortiNAC. Easy Connect Supplicant Policies cannot be used for Roaming Guests because Roaming Guests are placed in a special network based on the settings in the Model Configuration before the host could be evaluated and assigned a Supplicant Policy.
- Device Profiler automatic registration settings are suspended for Roaming Guests.
- Roaming Guests age out of the database in 24 hours.
- If a Roaming Guest logs into a host registered to a local user, the host is treated like a Roaming Guest.
- If a Roaming Guest logs into an existing Roaming Guest host, they are treated as a Roaming Guest.
- If a Roaming Guest has a Persistent Agent installed on their host from their own FortiNAC system, there is no impact on your FortiNAC server.
When a Roaming Guest connects to the network, the process is as follows:
- FortiNAC proxies the request to a local corporate RADIUS server.
- The local RADIUS server queries the appropriate remote RADIUS server for the domain name contained in the login information. The remote RADIUS servers must be configured within your corporate RADIUS server to allow the authentication request to be proxied to the correct server.
- The remote RADIUS server replies to the local corporate RADIUS server.
- That reply is sent to FortiNAC.
- FortiNAC registers the host in the database as a device and allows the user to connect to the network. The user is shown as a logged in user.
- Users are placed in a special Group called Roaming Guest Users.
- Hosts are placed in a special Group called Roaming Guest Hosts.
- Click System > Settings.
- Expand the Authentication folder.
- Select Roaming Guests from the tree.
- Click Add.
- Enter a domain name.
- Click OK.