Skip to content
Hardware guide: Fortinet

FortiGate and FortiAP captive portal, explained

On Fortinet wireless the FortiGate runs the captive portal, and an SSID can point guests at a portal hosted elsewhere. This guide covers the portal types and the hand off from Fortinet’s own configuration guide.

Not supported by VoqadoWiFi. Written from Fortinet documentation read on 7 October 2026.

Does VoqadoWiFi work with FortiGate and FortiAP?
No. VoqadoWiFi does not support Fortinet today. A FortiGate captive portal SSID offers Authentication, Disclaimer plus Authentication, Disclaimer Only and Email Collection portals, and an external-web setting that sends guests to a portal you host, which posts back to the FortiGate with a user from an allowed user group.

How Fortinet wireless is put together

FortiAP access points are managed by a FortiGate or FortiWiFi, and the SSID settings, including the captive portal, are configured there under the wireless controller. So the portal is a firewall feature as much as a wireless one, and the user groups it checks are FortiGate user groups.

How an external portal grants access on a FortiGate

On the SSID you set security to captive-portal, set external-web to the portal address (without the protocol), and set selected-usergroups to the user groups allowed through.

When the guest submits the portal, the portal posts back to the FortiGate at https://<FGT_IP>:1000/fgtauth with magic (the session id), username and password. The FortiGate checks those against the selected user groups and opens the network if they match.

That means even a portal that only asks for an email address has to present some username and password to the FortiGate, for example one account shared by every guest in a local group. Fortinet recommends enabling auth-secure-http so credentials are sent over HTTPS.

Guest WiFi you can run on FortiGate and FortiAP today

Guest access options Fortinet documents
OptionWhat it doesSource
AuthenticationCredentials required before network access.Vendor docs
Disclaimer + AuthenticationA legal agreement plus a login.Vendor docs
Disclaimer OnlyGuests accept terms without authenticating.Vendor docs
Email CollectionThe FortiGate portal gathers the guest’s email address.Vendor docs
External portal (external-web)Guests are sent to a portal you host, which posts back to the FortiGate.Vendor docs
Exempt listsSources and destinations that bypass captive portal authentication.Vendor docs

Email Collection is worth a look before adding anything: the FortiGate already gathers an address on its own portal. How you then use those addresses, and whether the wording gives you marketing consent, is up to you.

Things to plan on a FortiGate

Put the portal host in an exempt list so guests can reach it before they are authorized.

Decide which user group the portal will use. A local group with one shared guest account keeps RADIUS out of the picture, at the cost of every guest presenting the same credentials to the FortiGate.

VoqadoWiFi and FortiGate and FortiAP: the honest status

VoqadoWiFi does not support FortiGate and FortiAP today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.

This page describes what Fortinet documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with FortiGate and FortiAP.

FortiGate and FortiAP at a glance
QuestionAnswer
VoqadoWiFi statusNot supported by VoqadoWiFi yet
What the vendor calls the external portalCaptive portal, external-web
How access is granted, as documentedForm post from the guest browser. After the guest signs in, the guest browser posts a small form back to the access point or router, which then opens the network.

The fgtauth post back is documented, so a portal that presents a venue account could work, but it would need building and testing on a FortiGate with a FortiAP. VoqadoWiFi has not done that, and there is no date.

If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.

FortiGate and FortiAP questions

Can a FortiGate SSID use an external captive portal?
Yes. Set security captive-portal, external-web to the portal address without the protocol, and selected-usergroups.
How does the portal tell the FortiGate to let the guest in?
It posts to https://<FGT_IP>:1000/fgtauth with magic, username and password, which the FortiGate checks against the selected user groups.
Can a FortiGate collect guest emails on its own?
Fortinet lists an Email Collection portal type that gathers the user’s email address.
Does VoqadoWiFi work with Fortinet?
Not today. VoqadoWiFi supports TP-Link Omada and Ubiquiti UniFi. Leave your email below to hear if that changes.

Sources

Every Fortinet fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.

Keep reading

Which access points support an external captive portalCheck your hardwareTP-Link Omada captive portal setupOne of the two platforms VoqadoWiFi supports today.Ubiquiti UniFi captive portal setupThe other supported platform, controller by controller.

Fortinet, FortiGate, FortiAP and FortiWiFi are trademarks of Fortinet. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by Fortinet.

Notify me when FortiGate and FortiAP is supported

VoqadoWiFi does not support FortiGate and FortiAP today and we cannot promise a date. Leave your email and we will tell you if that changes. No account is created.