Skip to content
Notifications
Clear all

Step-by-step: Setting up a secure guest portal with vouchers and time limits.

1 Posts
1 Users
0 Reactions
48 Views
(@cloud_ops_amy)
Honorable Member
Joined: 7 months ago
Posts: 453
Topic starter   [#15713]

Hey everyone, I recently needed to set up a secure guest Wi-Fi network for our office visitors, with proper isolation and time-limited access. We use FortiGate firewalls, and I found the voucher system combined with a guest portal to be a solid fit. Here's a breakdown of my steps and a few things I learned along the way.

**My main goals were:**
* Isolate guest traffic from the internal corporate network completely.
* Provide easy-to-use, time-limited access (like 8-hour vouchers).
* Avoid a shared password that never changes.
* Keep a basic audit trail of who generated vouchers.

Here's the high-level workflow I implemented:

1. **Created a dedicated VDOM (or at least a separate VLAN interface)** for guest traffic. This keeps the firewall rules simple and segregation clear.
2. **Configured the Wireless Controller (or SSID)** to bridge to the guest VLAN/interface.
3. **Set up the Guest Portal:**
* Enabled the built-in FortiGate captive portal.
* Set the authentication method to "Voucher Only."
* Customized the login page with basic instructions.
4. **Configured the Voucher System:**
* Under *User & Authentication > Vouchers*, I created a new local database for vouchers.
* Generated a batch of vouchers with an 8-hour validity and single-use policy. The command line was easier for bulk generation:
```bash
execute voucher generate batch name "Guest-Batch-Oct2024" count 50 validity 480 duration 480
```
* This creates 50 vouchers, each valid for 480 minutes (8 hours) from first login, and the duration is also 8 hours of continuous use.
5. **Built the Firewall Policies:**
* A policy from the guest interface to WAN, sourcing from the voucher user group, allowing HTTP/HTTPS/DNS.
* Explicitly blocked all traffic from the guest interface to the internal corporate networks.
* Made sure NAT was enabled on the guest-to-WAN policy.

**Pitfalls & Tips:**
* **Voucher Printout:** The generated list is a CSV. I used a simple Python script to format it into a printable sheet with QR codes (encoding `FORTINET_VOUCHER:`). This made distribution much easier.
* **Timeout vs. Duration:** Pay close attention to the `validity` (how long the voucher is alive from generation) and `duration` (how long the session lasts after login). For a true "8-hour access from login," they should be equal.
* **Cleanup:** Old, expired vouchers can clutter the local database. Schedule periodic cleanup or use the CLI to remove them.

The setup has been running smoothly for a few months now. It's a good balance of security and convenience. If you've done something similar, I'm curious about how you handled the voucher distribution or if you integrated it with an external auth source.

-- Amy


Cloud cost nerd. No, I don't use Reserved Instances.


   
Quote