• Reverse Captive Portal?

    5
    0 Votes
    5 Posts
    3k Views
    C

    I'm not sure this is the only way  although it does work.

    I don't really understand what the initial problem is neither what additional authentication will bring but if this is what you want to deploy, why not looking at reverse proxy  ???
    I don't know what pfSense reverse proxy package provides (in term of feature) but the is a lot of reverse proxy implementations (Nginx, HAproxy Vulture) that may solve your problem, kind of  ;)

    Reverse proxy will prompt user for authentication. Most of then will allow you to select among various kind of authentication mechanisms and some will also add capability to create tunnelling and encryption  8)

    What I really mean here is that captive portal wording is meaningless here (to me) as there is nothing captive. User may decide to access or not your interface.

  • Captive portal voucher code authentication invalid credentials

    2
    0 Votes
    2 Posts
    946 Views
    GertjanG

    Create temporary a user+password using the Local User Manager (or use the admin account).
    Use the default html login page, where you can both enter a user+password or voucher code (both work at the same time).
    Login should work right away.

    A first attempt that doesn't work, and a second attempt that does work means that the voucher code is ok. There might be some 'html' or posting error.
    Mention what YOU changed from default … settings, etc.

    edit: You are aware that the current pfSEnse is 2.2.2 ? Using 2.1.4 means you are dealing with known bugs, and is normally reserved for experts who know how to deal with these.

  • Captive Portal can access my private network? Help

    2
    0 Votes
    2 Posts
    587 Views
    DerelictD

    Put rules blocking anything you don't want them to access before the pass rules on the interface captive portal is on.  This has nothing to do with the portal, but with your basic firewall rules.

  • Captive Portal PfSense Network

    5
    0 Votes
    5 Posts
    1k Views
    E

    Yes your DNS was wrong. Use pfSense as DNS server for your clients.

    For your current problem check your firewall logs.

  • Is it possible to redirect https-Traffic to the Captive-Portal-Login Page?

    10
    0 Votes
    10 Posts
    4k Views
    W

    Just this moment I tried to verify this with windows 8 and it works very well: As soon as i got connected to the pfsense-network, a Browser opens automatically with the Captive Portal site.

  • Captive portal and freeradius setup

    2
    0 Votes
    2 Posts
    771 Views
    GertjanG

    Strange …..

    Looking at this forum : pfSense Forum » pfSense English Support » Captive Portal (that is the forum where you posted !) there is a post named PFsense 2.1 MultiCP and https with Windows Radius Guide 
    There is also this : https://doc.pfsense.org/index.php/FreeRADIUS_2.x_package#Using_the_FreeRADIUS_2_Package:_Basics
    Even more : https://doc.pfsense.org/index.php/Using_Captive_Portal_with_FreeRADIUS

    More then enough to get you started.

    And when you install Google first, you even find more : Google : pfsense radius

  • Force manually expired voucher to renew dhcp lease

    11
    0 Votes
    11 Posts
    3k Views
    GertjanG

    The issue has been solved https://github.com/pfsense/pfsense/commit/ea6cbc390bba86336bf5a173922b20f0b3416c89

  • No redirection to captiveportal login page with CARP

    6
    0 Votes
    6 Posts
    1k Views
    R

    I don't know why but this doesn't seems to work for me.

    I don't see any answer from the CP (tcpdump on the network interface with port 8003 only shows clients requesting the vip).

  • Using DNS Resolver with CP

    3
    0 Votes
    3 Posts
    699 Views
    GertjanG

    Added to that:
    A Portal should be on its own interface.
    So, its has its own firewall - which should enable Internet access, and forbid any access the private lans or any  other interfaces.

  • Captive Portal for IPSec-connected guest network

    2
    0 Votes
    2 Posts
    773 Views
    S

    Hi,

    i am seeking for the same solution too, can you find any solution for this?

    thanks
    serhan

  • Cannot use WAN interface

    3
    0 Votes
    3 Posts
    834 Views
    M

    Have you set your pfSense to act as DNS proxy/forwarder and are your clients using the pfSense's LAN address as their primary DNS? Unless your clients can resolve external addresses you won't be redirected to the CP landing page.

  • How can i use remote location's pfsense captive portal from local?

    2
    0 Votes
    2 Posts
    1k Views
    S

    Hi, do you have any experience about reaching the captive portal through ipsec vpn?

    local - cyberoam –-----ipsec vpn----------------pfsense in cloud

    when an unauthenticated user wants to go to the internet, we want to pfsense's captive portal comes to this user, is it possible, how can i do this?

    i wrote a policy in cyberoam, which asked pfsense's radius the users credentials, in cyberoam's captive portal, which asked the credentials to the pfsense, the user can logon correctly, and internet opened, and than,  i tried to redirect pfsense's ghost's url instead of cyberoam's captive portal, but the user can not be authenticated with this way, the mechanism is not the same.

    i need a solution to popup the pfsense's captive portal in front of the unauthenticated users through ipsec vpn.

    Thanks
    serhan

  • Slow CP page and general throughput.

    11
    0 Votes
    11 Posts
    2k Views
    L

    There are 6 separate APs, spread around the two buildings.  I would not expect to see more than 20 or so users per unit (I have logged into them when busy).  I am generally not onsite when it's busy which is difficult.  2 APs are on one interface and 4 on the other.

    I am not fixated on the CP max users as such, I was just wondering what happens when several people try to connect at once, and the max is reached.  I understand it's not the amount of users that can pass through, just the amount that view the login screen, but at times, looking at the logs, several people do login in quick succession.

    iPhones recently do not seem to throw up the captive portal login when you connect the AP any longer.  They used to.  I wonder if this could be causing users problems, as they assume they are connected when they're not?  Many these days don't even open browsers, it's straight to FB, email, twit etc.

    Need to find some time to update to the latest version I guess, but will see how things go now squid is disabled.

    Ubiquiti AP's are supposed to be very good in terms of number of users?  I have used a few of them poreviously, and thinking of replacing with these.  They also allow roaming between APs, although I think this is software based, and not too sure how it works.  Need to have a closer look.

    Thanks.

  • 0 Votes
    11 Posts
    3k Views
    V

    Same problem on 2.2.2. Empty radacct table

  • Activated CP and the internet stopped working

    4
    0 Votes
    4 Posts
    618 Views
    D

    @teekaypapa:

    i am using LAN for the Portal

    Good luck  ::)

    (P.S. DNS servers must be allowed through the CP or nothing works.)

  • 0&0 for inputoctets & outputoctets in idle-timeout

    4
    0 Votes
    4 Posts
    758 Views
    D

    @new_in_pf:

    pfsense 2.1-release  i386

    Perhaps you could try with something uptodate…

  • MOVED: Captive Portal Reports

    Locked
    1
    0 Votes
    1 Posts
    548 Views
    No one has replied
  • Config Pf Sense to show only captive portal page.

    15
    0 Votes
    15 Posts
    2k Views
    S

    yap you right…not a professional like you guys...but try to find short cut and learn something new!! Thanks for reply

  • New feature request option "pass users if radius fails"

    4
    0 Votes
    4 Posts
    785 Views
    E

    Creating master master replication is way easier then creating some RADIUS monitoring script.

  • 0 Votes
    3 Posts
    619 Views
    perikoP

    Got it, thanks for your input.

Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.