Fortinet white logo
Fortinet white logo

Cookbook

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

To create a firewall policy for guest access to DNS and FortiAuthenticator:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the guest SSID created in Wireless Guest SSID.
  4. In Outgoing Interface, select interfaces for FortiAuthenticator and DNS access.
  5. In Source, select an Address object.
  6. In Destination, select address objects for the FortiAuthenticator and DNS servers.
  7. Enable or disable NAT as required.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.
To create firewall policy for guest user internet access:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the guest SSID created in Wireless Guest SSID.
  4. In Outgoing Interface, select the interface for internet access.
  5. In Source, select the All address object and the guest group configured in Guest group on FortiGate.
  6. In Destination, select the All address object.
  7. Enable NAT.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

Creating firewall policies for guest access to DNS, FortiAuthenticator, and internet

To create a firewall policy for guest access to DNS and FortiAuthenticator:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the guest SSID created in Wireless Guest SSID.
  4. In Outgoing Interface, select interfaces for FortiAuthenticator and DNS access.
  5. In Source, select an Address object.
  6. In Destination, select address objects for the FortiAuthenticator and DNS servers.
  7. Enable or disable NAT as required.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.
To create firewall policy for guest user internet access:
  1. Go to Policy & Objects > Firewall Policy and click Create New.
  2. Enter a name for the policy.
  3. In Incoming Interface, select the guest SSID created in Wireless Guest SSID.
  4. In Outgoing Interface, select the interface for internet access.
  5. In Source, select the All address object and the guest group configured in Guest group on FortiGate.
  6. In Destination, select the All address object.
  7. Enable NAT.
  8. Optionally, enable other options including Security Profiles for performing inspection using the security features of FortiGate.
  9. Click OK.