Behind the "Captive Portal NIC", there shouldn't be any device that acts as a router.
(Some special VLAN cases might be an exception here)
'Router mode' should be deactivated on Wifi Access Points.
I protect my AP's with a firewall, so no connection is accepted coming from clients on "Captive Portal OPT1", except those coming from pfSEnse, so I can manage my AP's.