FortiGate and FortiAP captive portal, explained
On Fortinet wireless the FortiGate runs the captive portal, and an SSID can point guests at a portal hosted elsewhere. This guide covers the portal types and the hand off from Fortinet’s own configuration guide.
Not supported by VoqadoWiFi. Written from Fortinet documentation read on 7 October 2026.
How Fortinet wireless is put together
FortiAP access points are managed by a FortiGate or FortiWiFi, and the SSID settings, including the captive portal, are configured there under the wireless controller. So the portal is a firewall feature as much as a wireless one, and the user groups it checks are FortiGate user groups.
How an external portal grants access on a FortiGate
On the SSID you set security to captive-portal, set external-web to the portal address (without the protocol), and set selected-usergroups to the user groups allowed through.
When the guest submits the portal, the portal posts back to the FortiGate at https://<FGT_IP>:1000/fgtauth with magic (the session id), username and password. The FortiGate checks those against the selected user groups and opens the network if they match.
That means even a portal that only asks for an email address has to present some username and password to the FortiGate, for example one account shared by every guest in a local group. Fortinet recommends enabling auth-secure-http so credentials are sent over HTTPS.
Guest WiFi you can run on FortiGate and FortiAP today
| Option | What it does | Source |
|---|---|---|
| Authentication | Credentials required before network access. | Vendor docs |
| Disclaimer + Authentication | A legal agreement plus a login. | Vendor docs |
| Disclaimer Only | Guests accept terms without authenticating. | Vendor docs |
| Email Collection | The FortiGate portal gathers the guest’s email address. | Vendor docs |
| External portal (external-web) | Guests are sent to a portal you host, which posts back to the FortiGate. | Vendor docs |
| Exempt lists | Sources and destinations that bypass captive portal authentication. | Vendor docs |
Email Collection is worth a look before adding anything: the FortiGate already gathers an address on its own portal. How you then use those addresses, and whether the wording gives you marketing consent, is up to you.
Things to plan on a FortiGate
Put the portal host in an exempt list so guests can reach it before they are authorized.
Decide which user group the portal will use. A local group with one shared guest account keeps RADIUS out of the picture, at the cost of every guest presenting the same credentials to the FortiGate.
VoqadoWiFi and FortiGate and FortiAP: the honest status
VoqadoWiFi does not support FortiGate and FortiAP today. VoqadoWiFi works with two controller platforms: TP-Link Omada and Ubiquiti UniFi. On those, the controller sends each new guest to the VoqadoWiFi login page as an external captive portal, and VoqadoWiFi asks the controller to open the network once the guest signs in.
This page describes what Fortinet documents, so you can decide what to do with the hardware you have. It is not a setup guide for VoqadoWiFi, and nothing on it means VoqadoWiFi works with FortiGate and FortiAP.
| Question | Answer |
|---|---|
| VoqadoWiFi status | Not supported by VoqadoWiFi yet |
| What the vendor calls the external portal | Captive portal, external-web |
| How access is granted, as documented | Form post from the guest browser. After the guest signs in, the guest browser posts a small form back to the access point or router, which then opens the network. |
The fgtauth post back is documented, so a portal that presents a venue account could work, but it would need building and testing on a FortiGate with a FortiAP. VoqadoWiFi has not done that, and there is no date.
If you are choosing hardware now, the TP-Link Omada setup guide and the Ubiquiti UniFi setup guide show exactly what VoqadoWiFi needs. If you are keeping your current hardware, its own options above work today without us.
FortiGate and FortiAP questions
Can a FortiGate SSID use an external captive portal?
security captive-portal, external-web to the portal address without the protocol, and selected-usergroups.How does the portal tell the FortiGate to let the guest in?
https://<FGT_IP>:1000/fgtauth with magic, username and password, which the FortiGate checks against the selected user groups.Can a FortiGate collect guest emails on its own?
Does VoqadoWiFi work with Fortinet?
Sources
Every Fortinet fact on this page comes from these official pages, read on 7 October 2026. Menus and features change between releases, so check them against your own version.
Keep reading
Fortinet, FortiGate, FortiAP and FortiWiFi are trademarks of Fortinet. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by Fortinet.