The FortinNAC app enables you to easily provide each of your visitors with unique access to your Wi-Fi network.
How does this application work?
When a visitor signs in with Envoy, FortiNAC receives their information and automatically provisions a temporary code to access your Wi-Fi network. Envoy then sends this code to the visitor via email or text message.
Note: For this application to work, you must collect either visitor email addresses or phone numbers at sign-in. Learn more about how to configure your Envoy sign-in fields.
PREREQUISITES
MUST BE ON VERSION 9.4.5 of FortiNAC or higher, a previous API bug was patched on the Fortinet side in this version.
The following IPs must be whitelisted for inbound and outbound communication:
Static IP #1: 18.204.164.109
Static IP #2: 52.6.210.64
Static IP #3: 52.86.90.108
Validate the port configured within FortiNAC and confirm the port is whitelisted alongside the IPs above.
Ex URL: https://domain.com:8443
Create an API key user using the following guide.
Create new User ID with the following name: envoy-api-admin
Under "Allowed Subnets", add Envoy's IPs listed above to allow requests from our system using the FortiAPI.
Endpoints used as part of the integration:
GET/POST/PATCH user
GET user/guest-templates
Ensure permission sets should match the following:
Guest/Contractor Templates -> Access
Users -> Add/Modify
If you run into API key creation, please contact your Fortinet support rep.
Enabling the Envoy + FortiNAC application
Go to Apps > All Apps.
Under Wi-Fi, find Fortinet. Click “Install” and then “Configure”.
Enter your FortiNAC domain and port.
Enter your API key created above as a prerequisite, then click “Next step”. Please ensure that this user has sufficient permissions noted above.
Select your Guest Template from the drop-down, then click “Next Step”. Please ensure this Guest Template has a guest network and portal configured.
Under Visitors configuration:
Required: Select access duration for guest credentials to remain active at creation
Optional: Select Visitor types to block from receiving Wi-Fi credentials.
Optional: Send guest Wi-Fi credentials to hosts. This is useful when visitors do not have easy access to email or text messages or if they are not required to enter their email address or phone number at sign-in.
Optional: Delete guests on sign-out: this will delete the guest accounts for the visitors on sign-out.
Click “Complete setup.”