Skip to main content
Guides Last updated: September 2026 9 min read

FortiGate captive portal email capture for FortiAP guest WiFi

C
CaptiFi Editorial Team
CaptiFi · September 2026
FortiGate captive portal email capture for FortiAP guest WiFi
UDP 1812
Outbound to radius.captifi.io, no inbound ports
FortiOS 7.0
Minimum version; 7.2.4 for a custom NAS identifier
5 hosts
In the CaptiFi-Exempt list so the page loads before sign-in
5 min
The default idle timeout; raise it to your session length

A FortiGate firewall with FortiAP access points already has the network side of guest WiFi covered: a guest SSID, a Captive Portal security mode and a RADIUS client. What it lacks is somewhere for a guest's email address to go once they have typed it, and anything to do with that address afterwards. This guide takes a FortiAP guest network from a plain SSID to a branded sign-in page that captures email into CaptiFi, in the same six steps as our Fortinet setup page.

It applies to FortiAP access points managed by a FortiGate wireless controller running FortiOS 7.0 or later, in tunnel mode or bridge mode, as of September 2026. You need admin access to the FortiGate GUI and CLI, because the NAS identifier and the hard timeout are CLI settings, and outbound UDP 1812 from the firewall to radius.captifi.io. No inbound ports are needed.

What the FortiGate captive portal gives you on its own, and what it cannot

On a FortiOS guest SSID the security mode can be set to Captive Portal. The portal type is Authentication in tunnel mode or External Authentication in bridge mode, and the authentication portal can be set to External with an address of your choosing. The firewall then does two jobs: it redirects each new guest to the portal address, and it puts the device online once a RADIUS server accepts it.

Those two jobs are all the firewall contributes to email capture. The branded sign-in page, the record of who signed in, and the review request or marketing message that follows all live in the service the External setting points at. The setup page does not describe FortiOS's own portal pages, so this guide covers the External route alone, which is the one CaptiFi uses.

The integration covers FortiAP access points managed by a FortiGate firewall. FortiAP units managed by FortiLAN Cloud without a FortiGate are not covered; if that is your estate, contact CaptiFi support before you start.

How the external portal plus RADIUS flow works

A guest joins the SSID. The FortiGate wireless controller redirects them to your CaptiFi portal URL. The guest sees your branded sign-in page and submits the form.

CaptiFi adds the device to its RADIUS allow-list and hands the sign-in back to the firewall. The firewall sends an Access-Request to radius.captifi.io, which accepts the device CaptiFi has just authorised, and the guest is online a moment later. There is no redirect-back URL to configure; the hand-off happens on its own.

Two consequences shape the setup. RADIUS traffic is outbound only, UDP 1812 from the firewall to radius.captifi.io, so nothing is opened inbound and accounting is not required. And because every sign-in is confirmed against RADIUS, a portal that loads perfectly still puts nobody online until the RADIUS server and user group exist.

Step 1: create the Fortinet location and collect the values

Log in to my.captifi.io, go to My Locations, then Add location, and choose Fortinet FortiAP. If you are still in onboarding, the set-up wizard asks for your hardware and offers the same choice. Name the location and finish the wizard.

CaptiFi then shows the portal URL, the RADIUS shared secret and the NAS identifier, along with a FortiGate configuration pack your network team can paste in. Enter the three values exactly as shown; incorrect values stop the captive portal from working.

The portal URL has the form app.captifi.io/guest/fortinet/YOUR_SITE_ID, where YOUR_SITE_ID is the site ID from your dashboard. Enter it without http:// or https://, because the external portal field on the firewall does not accept a scheme, and add nothing after the site ID. The firewall appends the guest's MAC address and its session parameters itself.

Step 2: RADIUS server and user group

Go to User & Authentication, RADIUS Servers, Create New. Name the server CaptiFi-RADIUS, set the authentication method to PAP, set the primary server IP/Name to radius.captifi.io and paste the shared secret from your dashboard as the primary server secret.

The form has no port fields. The firewall sends RADIUS to UDP 1812 by default, which is the port CaptiFi listens on, so only change radius-port under config system global if your FortiGate firewall has already been moved off it. Accounting is not required.

Then go to User & Authentication, User Groups, Create New. Choose the Firewall type, name the group CaptiFi-Guests and add CaptiFi-RADIUS under Remote Groups. This is the group the guest SSID references in tunnel mode.

The NAS identifier is set in the CLI only and needs FortiOS 7.2.4 or later. The block below creates the RADIUS server with the NAS identifier and the user group together, so you can run it instead of the GUI steps above, with the two placeholders replaced by the values from your dashboard.

config user radius
    edit "CaptiFi-RADIUS"
        set server "radius.captifi.io"
        set secret "YOUR_SHARED_SECRET"
        set auth-type pap
        set nas-id-type custom
        set nas-id "YOUR_NAS_IDENTIFIER"
    next
end
config user group
    edit "CaptiFi-Guests"
        set member "CaptiFi-RADIUS"
    next
end

On FortiOS older than 7.2.4 the custom NAS ID setting is not available, and the firewall sends its default NAS identifier: the hostname, or the HA group name on an HA cluster. Leave the two nas-id lines out and email hello@captifi.io with that value so CaptiFi can store it against your location.

Step 3: the guest SSID in tunnel and bridge modes

Go to WiFi & Switch Controller, SSIDs, and open your guest SSID or create one. Tunnel mode and bridge mode take slightly different settings, so follow the column that matches your SSID.

Setting Tunnel mode Bridge mode (local bridging)
Security modeCaptive Portal (on FortiOS 7.6 a Captive Portal toggle under the security mode)Captive Portal
Portal typeAuthenticationExternal Authentication
Authentication portalExternal, with the portal URL from step 1, no https://External, with the same portal URL
RADIUS serverThrough the user group: select CaptiFi-Guests under User groupsChosen on the SSID itself: CaptiFi-RADIUS
Exempt destinations and servicesCaptiFi-Exempt with HTTP, HTTPS and DNS (step 4)CaptiFi-Exempt with HTTP, HTTPS and DNS (step 4)
Also neededA firewall policy from the SSID interface to your WAN interface, as any SSID doesEmail hello@captifi.io with your FortiOS version before go-live so the hand-off can be checked

Save the SSID once the settings match your column. There is no redirect-back URL to fill in on either mode. The CLI equivalents for both modes are on the setup page.

Step 4: exempt destinations

Exempt destinations are the FortiGate walled garden: the hosts a guest can reach before they have authenticated. Without them the sign-in page cannot load, and the browser reports the portal as unreachable.

Create an address object for each of the five hosts under Policy & Objects, Addresses, Create New, with Type set to FQDN: app.captifi.io, captifi.io, *.captifi.io, fonts.googleapis.com and fonts.gstatic.com. Enter *.captifi.io as an FQDN value with its wildcard; the separate Wildcard FQDN Addresses table cannot be used here.

Put the five objects in a security exempt list named CaptiFi-Exempt with the services HTTP, HTTPS and DNS, and select that list on the guest SSID. The two Google Fonts hosts let the sign-in page load its fonts before the guest has authenticated. The page still works without them, with a fallback font.

Step 5: the authentication timeout

By default the firewall signs an authenticated user out after 5 minutes idle, which would drop a guest part way through a visit. Go to User & Authentication, Authentication Settings, and set Authentication Timeout to your CaptiFi session length in minutes, anywhere from 1 to 1440; 240 gives a four-hour session. On the same page enable Redirect HTTP Challenge to a Secure Channel (HTTPS) so the sign-in hand-off between CaptiFi and the firewall is encrypted.

The GUI value is an idle timeout. To make it a hard timeout, so the session ends at the set length even while the guest is active, set the type in the CLI:

config user setting
    set auth-timeout 240
    set auth-timeout-type hard-timeout
    set auth-secure-http enable
end

Step 6: test from a phone and read the wizard's checks

Connect a phone or laptop to the guest SSID. The CaptiFi sign-in page should appear on its own; on some devices you need to open a browser and visit an HTTP site such as http://example.com to trigger the redirect, because HTTPS traffic cannot be transparently redirected on any vendor's hardware. Complete the form and you should have internet access within a few seconds.

Keep the set-up wizard on my.captifi.io open while you test. It shows when the FortiGate firewall has started sending RADIUS traffic and when the first guest has reached the sign-in page. If a guest has reached the page and submitted the form but no RADIUS traffic has arrived, step 2 is where to look.

Then open Guest Visits in the dashboard. If your test guest is listed there, you are live.

Troubleshooting

The table collects the faults the setup page answers. Each fix points back to the step it belongs to.

Symptom Cause Fix
The sign-in page never appearsSecurity mode, portal type or authentication portal is wrong, or the address does not match your dashboardMatch the step 3 settings and enter the exact address from your dashboard, no http:// or https://
The browser reports the portal as unreachableExempt destinations missingAdd app.captifi.io, captifi.io and *.captifi.io to the CaptiFi-Exempt list selected on the SSID
The page loads, the guest signs in, but never gets onlineThe RADIUS step is incompleteCheck CaptiFi-RADIUS exists (radius.captifi.io, UDP 1812, PAP), is in CaptiFi-Guests (or is the SSID's RADIUS server in bridge mode) and carries your NAS identifier
"Access denied" after signing inThe shared secret does not matchCopy and paste the secret from your CaptiFi dashboard
Guests are dropped after five minutesThe default 5-minute idle timeoutSet Authentication Timeout to your session length, then set auth-timeout-type hard-timeout under config user setting
The portal does not trigger from an HTTPS siteHTTPS traffic cannot be transparently redirectedOpen an HTTP site such as http://example.com
Tunnel mode: signed in, no internetNo firewall policy from the SSID interface to WANAdd the policy, as for any SSID
The wizard never shows RADIUS trafficNo form has been submitted yet, or outbound UDP 1812 is blockedSign in from a phone; allow outbound UDP 1812 to radius.captifi.io

After capture: reviews, workflows and multi-site

Once a guest is in Guest Visits, the firewall's part is done. Each record is ready for review requests and marketing: a review request after the visit, and campaigns to the list the WiFi builds. The guest data capture and review automation pages describe what happens to the record next, and workflows on my.captifi.io run off the same record.

Multi-site groups add one CaptiFi location per FortiGate site. Each location has its own splash page design, portal URL, shared secret and NAS identifier, all managed under My Locations, and each additional location beyond the one included in your plan is charged at your currency's extra-venue rate. The multi-venue management page covers running them from one dashboard, and prices are on the pricing page, shown in your currency.

If you would rather leave the firewall alone, the included plug-and-play CaptiFi device is the other path. Plug it into your existing network by Ethernet, it pulls its config from the cloud and a guest SSID appears in about two minutes, with no controller, static IP or firewall change. It is the same platform either way, so you can start on the device and move to your FortiAP access points later. The hardware page lists all ten supported ecosystems, and there is a 30-day free trial.

Sources: the CaptiFi Fortinet setup page (captifi.io/fortinet-setup, September 2026) and the CaptiFi release notes of 24 September 2026, which introduced Fortinet FortiAP support. FortiOS menu labels are as the setup page records them; check them against your firmware before configuring. Fortinet, FortiGate and FortiAP are trade marks of Fortinet, Inc.; CaptiFi is not affiliated with or endorsed by Fortinet.

Frequently asked questions

Quick answers to the most common questions about this topic.

Does the FortiGate firewall need any inbound ports open for CaptiFi?
No. The FortiGate firewall sends RADIUS to radius.captifi.io on UDP 1812, outbound only, and CaptiFi hands each sign-in back to the firewall over that exchange. No inbound ports are needed. The RADIUS server form on the firewall has no port fields because UDP 1812 is its default, and RADIUS accounting is not required. Only change radius-port under config system global if your firewall has already been moved off the default.
Which FortiOS version does the CaptiFi captive portal need?
FortiOS 7.0 or later on a FortiGate firewall managing FortiAP access points, in tunnel or bridge mode. FortiOS 7.2.4 or later is needed to set a custom NAS identifier, which is a CLI-only setting. On older firmware the firewall sends its default NAS identifier, the hostname or the HA group name on an HA cluster. Leave the two nas-id lines out of the CLI block and email hello@captifi.io with that value so CaptiFi can store it against your location.
Do I enter https:// in the FortiGate external portal field?
No. The portal URL has the form app.captifi.io/guest/fortinet/YOUR_SITE_ID and is entered without http:// or https://, because the external portal field on the FortiGate firewall does not accept a scheme. Add nothing after the site ID either: the firewall appends the guest's MAC address and its own session parameters to the address itself. If the sign-in page never appears, an address that does not match your dashboard exactly is one of the first things to check.
Does CaptiFi work with FortiAP access points in bridge mode?
Yes. In bridge mode (local bridging) the portal type is External Authentication and the RADIUS server, CaptiFi-RADIUS, is chosen on the SSID itself; the user group is not used. The external portal address and the CaptiFi-Exempt list are the same as in tunnel mode. CaptiFi asks bridge-mode venues to email hello@captifi.io with their FortiOS version before go-live so the hand-off can be checked.
Why are guests dropped off the WiFi after five minutes?
The FortiGate firewall's default authentication timeout is 5 minutes idle. Set Authentication Timeout under User & Authentication, Authentication Settings, to your CaptiFi session length in minutes (1 to 1440; 240 gives four hours). That GUI value is an idle timeout, so to end the session at the set length even while the guest is active, set auth-timeout-type hard-timeout under config user setting in the CLI. Enable Redirect HTTP Challenge to a Secure Channel (HTTPS) on the same page.
Can I use CaptiFi with FortiAP access points managed by FortiLAN Cloud?
Not through this guide. As of September 2026 the CaptiFi Fortinet integration covers FortiAP access points managed by a FortiGate wireless controller running FortiOS 7.0 or later, in tunnel or bridge mode. FortiAP units managed by FortiLAN Cloud without a FortiGate firewall are not covered, so contact CaptiFi support to talk through that setup. The included plug-and-play CaptiFi device is the alternative: it connects by Ethernet, pulls its config from the cloud and needs no controller, static IP or firewall change.
Can one CaptiFi account cover several FortiGate sites?
Yes. Each site is its own CaptiFi location with its own splash page design, portal URL, shared secret and NAS identifier, managed under My Locations on my.captifi.io. Repeat the six steps on each FortiGate firewall with that location's values. Each additional location beyond the one included in your plan is charged at your currency's extra-venue rate.
How do I know the FortiGate firewall is talking to CaptiFi?
The set-up wizard on my.captifi.io shows when the FortiGate firewall has started sending RADIUS traffic and when the first guest has reached the sign-in page. Once a test guest has signed in and appears under Guest Visits in the dashboard, the portal is live. If the page loads but the guest never gets online, check the RADIUS server, its membership of CaptiFi-Guests and the NAS identifier. An Access denied message after signing in means the shared secret does not match.
C
Written by
CaptiFi Editorial Team

The CaptiFi Editorial Team writes about guest WiFi marketing, captive portals, GDPR-compliant data capture, and local SEO for venue operators. We base our recommendations on real customer outcomes and verified third-party reviews from G2.com.

Ready to turn your guest WiFi into a marketing engine?

CaptiFi captures customer data from every WiFi login, automates Google reviews and email follow-ups, and plugs into the tools you already use. Hardware included (refundable deposit), transparent pricing, 30-day free trial.

Related reading