FortiGate captive portal email capture for FortiAP guest WiFi
A FortiGate firewall with FortiAP access points already has the network side of guest WiFi covered: a guest SSID, a Captive Portal security mode and a RADIUS client. What it lacks is somewhere for a guest's email address to go once they have typed it, and anything to do with that address afterwards. This guide takes a FortiAP guest network from a plain SSID to a branded sign-in page that captures email into CaptiFi, in the same six steps as our Fortinet setup page.
It applies to FortiAP access points managed by a FortiGate wireless controller running FortiOS 7.0 or later, in tunnel mode or bridge mode, as of September 2026. You need admin access to the FortiGate GUI and CLI, because the NAS identifier and the hard timeout are CLI settings, and outbound UDP 1812 from the firewall to radius.captifi.io. No inbound ports are needed.
What the FortiGate captive portal gives you on its own, and what it cannot
On a FortiOS guest SSID the security mode can be set to Captive Portal. The portal type is Authentication in tunnel mode or External Authentication in bridge mode, and the authentication portal can be set to External with an address of your choosing. The firewall then does two jobs: it redirects each new guest to the portal address, and it puts the device online once a RADIUS server accepts it.
Those two jobs are all the firewall contributes to email capture. The branded sign-in page, the record of who signed in, and the review request or marketing message that follows all live in the service the External setting points at. The setup page does not describe FortiOS's own portal pages, so this guide covers the External route alone, which is the one CaptiFi uses.
The integration covers FortiAP access points managed by a FortiGate firewall. FortiAP units managed by FortiLAN Cloud without a FortiGate are not covered; if that is your estate, contact CaptiFi support before you start.
How the external portal plus RADIUS flow works
A guest joins the SSID. The FortiGate wireless controller redirects them to your CaptiFi portal URL. The guest sees your branded sign-in page and submits the form.
CaptiFi adds the device to its RADIUS allow-list and hands the sign-in back to the firewall. The firewall sends an Access-Request to radius.captifi.io, which accepts the device CaptiFi has just authorised, and the guest is online a moment later. There is no redirect-back URL to configure; the hand-off happens on its own.
Two consequences shape the setup. RADIUS traffic is outbound only, UDP 1812 from the firewall to radius.captifi.io, so nothing is opened inbound and accounting is not required. And because every sign-in is confirmed against RADIUS, a portal that loads perfectly still puts nobody online until the RADIUS server and user group exist.
Step 1: create the Fortinet location and collect the values
Log in to my.captifi.io, go to My Locations, then Add location, and choose Fortinet FortiAP. If you are still in onboarding, the set-up wizard asks for your hardware and offers the same choice. Name the location and finish the wizard.
CaptiFi then shows the portal URL, the RADIUS shared secret and the NAS identifier, along with a FortiGate configuration pack your network team can paste in. Enter the three values exactly as shown; incorrect values stop the captive portal from working.
The portal URL has the form app.captifi.io/guest/fortinet/YOUR_SITE_ID, where YOUR_SITE_ID is the site ID from your dashboard. Enter it without http:// or https://, because the external portal field on the firewall does not accept a scheme, and add nothing after the site ID. The firewall appends the guest's MAC address and its session parameters itself.
Step 2: RADIUS server and user group
Go to User & Authentication, RADIUS Servers, Create New. Name the server CaptiFi-RADIUS, set the authentication method to PAP, set the primary server IP/Name to radius.captifi.io and paste the shared secret from your dashboard as the primary server secret.
The form has no port fields. The firewall sends RADIUS to UDP 1812 by default, which is the port CaptiFi listens on, so only change radius-port under config system global if your FortiGate firewall has already been moved off it. Accounting is not required.
Then go to User & Authentication, User Groups, Create New. Choose the Firewall type, name the group CaptiFi-Guests and add CaptiFi-RADIUS under Remote Groups. This is the group the guest SSID references in tunnel mode.
The NAS identifier is set in the CLI only and needs FortiOS 7.2.4 or later. The block below creates the RADIUS server with the NAS identifier and the user group together, so you can run it instead of the GUI steps above, with the two placeholders replaced by the values from your dashboard.
config user radius
edit "CaptiFi-RADIUS"
set server "radius.captifi.io"
set secret "YOUR_SHARED_SECRET"
set auth-type pap
set nas-id-type custom
set nas-id "YOUR_NAS_IDENTIFIER"
next
end
config user group
edit "CaptiFi-Guests"
set member "CaptiFi-RADIUS"
next
end
On FortiOS older than 7.2.4 the custom NAS ID setting is not available, and the firewall sends its default NAS identifier: the hostname, or the HA group name on an HA cluster. Leave the two nas-id lines out and email hello@captifi.io with that value so CaptiFi can store it against your location.
Step 3: the guest SSID in tunnel and bridge modes
Go to WiFi & Switch Controller, SSIDs, and open your guest SSID or create one. Tunnel mode and bridge mode take slightly different settings, so follow the column that matches your SSID.
| Setting | Tunnel mode | Bridge mode (local bridging) |
|---|---|---|
| Security mode | Captive Portal (on FortiOS 7.6 a Captive Portal toggle under the security mode) | Captive Portal |
| Portal type | Authentication | External Authentication |
| Authentication portal | External, with the portal URL from step 1, no https:// | External, with the same portal URL |
| RADIUS server | Through the user group: select CaptiFi-Guests under User groups | Chosen on the SSID itself: CaptiFi-RADIUS |
| Exempt destinations and services | CaptiFi-Exempt with HTTP, HTTPS and DNS (step 4) | CaptiFi-Exempt with HTTP, HTTPS and DNS (step 4) |
| Also needed | A firewall policy from the SSID interface to your WAN interface, as any SSID does | Email hello@captifi.io with your FortiOS version before go-live so the hand-off can be checked |
Save the SSID once the settings match your column. There is no redirect-back URL to fill in on either mode. The CLI equivalents for both modes are on the setup page.
Step 4: exempt destinations
Exempt destinations are the FortiGate walled garden: the hosts a guest can reach before they have authenticated. Without them the sign-in page cannot load, and the browser reports the portal as unreachable.
Create an address object for each of the five hosts under Policy & Objects, Addresses, Create New, with Type set to FQDN: app.captifi.io, captifi.io, *.captifi.io, fonts.googleapis.com and fonts.gstatic.com. Enter *.captifi.io as an FQDN value with its wildcard; the separate Wildcard FQDN Addresses table cannot be used here.
Put the five objects in a security exempt list named CaptiFi-Exempt with the services HTTP, HTTPS and DNS, and select that list on the guest SSID. The two Google Fonts hosts let the sign-in page load its fonts before the guest has authenticated. The page still works without them, with a fallback font.
Step 5: the authentication timeout
By default the firewall signs an authenticated user out after 5 minutes idle, which would drop a guest part way through a visit. Go to User & Authentication, Authentication Settings, and set Authentication Timeout to your CaptiFi session length in minutes, anywhere from 1 to 1440; 240 gives a four-hour session. On the same page enable Redirect HTTP Challenge to a Secure Channel (HTTPS) so the sign-in hand-off between CaptiFi and the firewall is encrypted.
The GUI value is an idle timeout. To make it a hard timeout, so the session ends at the set length even while the guest is active, set the type in the CLI:
config user setting
set auth-timeout 240
set auth-timeout-type hard-timeout
set auth-secure-http enable
end
Step 6: test from a phone and read the wizard's checks
Connect a phone or laptop to the guest SSID. The CaptiFi sign-in page should appear on its own; on some devices you need to open a browser and visit an HTTP site such as http://example.com to trigger the redirect, because HTTPS traffic cannot be transparently redirected on any vendor's hardware. Complete the form and you should have internet access within a few seconds.
Keep the set-up wizard on my.captifi.io open while you test. It shows when the FortiGate firewall has started sending RADIUS traffic and when the first guest has reached the sign-in page. If a guest has reached the page and submitted the form but no RADIUS traffic has arrived, step 2 is where to look.
Then open Guest Visits in the dashboard. If your test guest is listed there, you are live.
Troubleshooting
The table collects the faults the setup page answers. Each fix points back to the step it belongs to.
| Symptom | Cause | Fix |
|---|---|---|
| The sign-in page never appears | Security mode, portal type or authentication portal is wrong, or the address does not match your dashboard | Match the step 3 settings and enter the exact address from your dashboard, no http:// or https:// |
| The browser reports the portal as unreachable | Exempt destinations missing | Add app.captifi.io, captifi.io and *.captifi.io to the CaptiFi-Exempt list selected on the SSID |
| The page loads, the guest signs in, but never gets online | The RADIUS step is incomplete | Check CaptiFi-RADIUS exists (radius.captifi.io, UDP 1812, PAP), is in CaptiFi-Guests (or is the SSID's RADIUS server in bridge mode) and carries your NAS identifier |
| "Access denied" after signing in | The shared secret does not match | Copy and paste the secret from your CaptiFi dashboard |
| Guests are dropped after five minutes | The default 5-minute idle timeout | Set Authentication Timeout to your session length, then set auth-timeout-type hard-timeout under config user setting |
| The portal does not trigger from an HTTPS site | HTTPS traffic cannot be transparently redirected | Open an HTTP site such as http://example.com |
| Tunnel mode: signed in, no internet | No firewall policy from the SSID interface to WAN | Add the policy, as for any SSID |
| The wizard never shows RADIUS traffic | No form has been submitted yet, or outbound UDP 1812 is blocked | Sign in from a phone; allow outbound UDP 1812 to radius.captifi.io |
After capture: reviews, workflows and multi-site
Once a guest is in Guest Visits, the firewall's part is done. Each record is ready for review requests and marketing: a review request after the visit, and campaigns to the list the WiFi builds. The guest data capture and review automation pages describe what happens to the record next, and workflows on my.captifi.io run off the same record.
Multi-site groups add one CaptiFi location per FortiGate site. Each location has its own splash page design, portal URL, shared secret and NAS identifier, all managed under My Locations, and each additional location beyond the one included in your plan is charged at your currency's extra-venue rate. The multi-venue management page covers running them from one dashboard, and prices are on the pricing page, shown in your currency.
If you would rather leave the firewall alone, the included plug-and-play CaptiFi device is the other path. Plug it into your existing network by Ethernet, it pulls its config from the cloud and a guest SSID appears in about two minutes, with no controller, static IP or firewall change. It is the same platform either way, so you can start on the device and move to your FortiAP access points later. The hardware page lists all ten supported ecosystems, and there is a 30-day free trial.
Sources: the CaptiFi Fortinet setup page (captifi.io/fortinet-setup, September 2026) and the CaptiFi release notes of 24 September 2026, which introduced Fortinet FortiAP support. FortiOS menu labels are as the setup page records them; check them against your firmware before configuring. Fortinet, FortiGate and FortiAP are trade marks of Fortinet, Inc.; CaptiFi is not affiliated with or endorsed by Fortinet.
Frequently asked questions
Quick answers to the most common questions about this topic.
Does the FortiGate firewall need any inbound ports open for CaptiFi?
Which FortiOS version does the CaptiFi captive portal need?
Do I enter https:// in the FortiGate external portal field?
Does CaptiFi work with FortiAP access points in bridge mode?
Why are guests dropped off the WiFi after five minutes?
Can I use CaptiFi with FortiAP access points managed by FortiLAN Cloud?
Can one CaptiFi account cover several FortiGate sites?
How do I know the FortiGate firewall is talking to CaptiFi?
The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.
Ready to turn your guest WiFi into a marketing engine?
CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.