• HTTPS doesn't work from Firefox with Captive Portal enabled.

    8
    0 Votes
    8 Posts
    1k Views
    GertjanG
    @Artemiy: https://google.com or https://facebook.com Publish the golden rule for your visitors : never ever use a https site when you are connecting to a unknown (== captive portal) network. Users want a protected one-to-one connection, that is understandable. But you are using the captive portal - so users will be redirected from the site they want to visit, to the site where they have to authenticate first (pFsense). This is against de 'https' rules See it this way : Firefox is right. Users ARE warned that they didn't land on their https … This is another way to protect a users from a "man in de middle attack" - this time its clearly shown by the navigator. If I was visiting https://my-bank-site.tld and another site sghows up instead (even emulating my banks site very well) and my navigator still accepts the connection, I would DITCH these browser.
  • Whitelisting MAC address for a vendor

    2
    0 Votes
    2 Posts
    1k Views
    J
    This is solved. The solution was to segment a DHCP pool that is restricted to a mac vendor (first six). Then set that IP pool to bypass on the captive portal page.
  • Captive portal is enabled and everyone got internet

    6
    0 Votes
    6 Posts
    1k Views
    GertjanG
    Read and check this https://doc.pfsense.org/index.php/Captive_Portal_Troubleshooting Is the nginx running on the portal interface ? Use SSH acces and : ps ax | grep 'nginx' sockstat -4l | grep 'nginx' Btw : being able to access the portal on the WAN NIC ….. well, something is very wrong.
  • 0 Votes
    9 Posts
    2k Views
    GertjanG
    ;D Nice !!!
  • Remote view of Portal Page

    4
    0 Votes
    4 Posts
    1k Views
    T
    Thank you, Skron.  That works perfectly.  :)
  • 0 Votes
    3 Posts
    1k Views
    L
    Hi sir sorry for the late reply. Our problem is that we need to have the list of users in an external database like mysql and in the database the usernames and password where placed there. What are the ways so we can achieved our goal sir? please help us and thank you for replying us.
  • - SOLVED - HTML : How to insert usn/pw/vouch fields into custom page?

    3
    0 Votes
    3 Posts
    825 Views
    E
    I just realized that my big image's button does not redirect me anymore to the intranet site, but just on the "Invalid Credentials Specified" page, as when a wrong voucher/password is entered… There is any way to make both things works?? Inserting voucher code or username plus password = access to the internet Just clicking on the huge image's button= access to the intranet only(NO www) Solution:                 I just put my big button image as the "error's page" and now clicking to it i get redirected to my local host.
  • CP block LAN access

    9
    0 Votes
    9 Posts
    1k Views
    O
    so as far as i see, there is no easy way to dynamically isolate clients until authorized, client isolation is possible, but dynamically is nearly impossible, i think ill get back to the standard AP WPA thing nd get over with it.  :(
  • -SOLVED- Synchronize Voucher Database IP ???

    5
    0 Votes
    5 Posts
    2k Views
    E
    Yes was depending from Mozilla FireFox, even if i have never been ask to save or use those credentials for those 2 fields, it kept putting them there even after having been erased and saved (without  asking, that's weird). Using Google's Chrome fixed the issue, as those 2 fields would come up blank, thanks! :)
  • Captive Portal

    5
    0 Votes
    5 Posts
    2k Views
    E
    An example from Google… [image: tp-link-bandwidth-control-1.jpg] [image: tp-link-bandwidth-control-1.jpg_thumb]
  • - SOLVED- CP redirecting to blank page instead of webserver (CentOS6)

    8
    0 Votes
    8 Posts
    2k Views
    E
    Ok i fixed it. The problem was depending from the fact that i thought the only firewall was "Selinux" (which i disabled), but there was another default firewall still on, so as soon i realize that, i disabled it and now it works, good job OOPF, thank you for helping yourself…. ;D
  • 0 Votes
    1 Posts
    574 Views
    No one has replied
  • Portal Page with CSS -> Browser says: did not parse stylesheet. why?

    7
    0 Votes
    7 Posts
    3k Views
    F
    Maybe you misunderstood me: The captiveportal works fine with the css, if someone connect via interface. It just not load the css files if i watch the portal page over the pfsense webconfigurator. attached file: That "view" button i press. Files on pfsense: [2.3.1-RELEASE][root@fw.int]/root: ls -la /usr/local/captiveportal/ total 40 drwxr-xr-x  2 root  wheel  1024 Jun 30 13:42 . drwxr-xr-x  15 root  wheel    512 May 20 12:01 .. lrwxr-xr-x  1 root  wheel    39 Jun 29 15:23 captiveportal-bg.jpg -> /var/db/cpelements/captiveportal-bg.jpg lrwxr-xr-x  1 root  wheel    43 Jun 29 15:28 captiveportal-custom.css -> /var/db/cpelements/captiveportal-custom.css lrwxr-xr-x  1 root  wheel    44 Jun 29 15:24 captiveportal-fitlogo.png -> /var/db/cpelements/captiveportal-fitlogo.png lrwxr-xr-x  1 root  wheel    56 Jun 29 15:24 captiveportal-fontawesome-webfont.ttf -> /var/db/cpelements/captiveportal-fontawesome-webfont.ttf lrwxr-xr-x  1 root  wheel    57 Jun 29 15:24 captiveportal-fontawesome-webfont.woff -> /var/db/cpelements/captiveportal-fontawesome-webfont.woff lrwxr-xr-x  1 root  wheel    53 Jun 29 15:24 captiveportal-jquery-1.11.1.min.js -> /var/db/cpelements/captiveportal-jquery-1.11.1.min.js lrwxr-xr-x  1 root  wheel    45 Jun 30 13:42 captiveportal-success.html -> /var/db/cpelements/captiveportal-success.html lrwxr-xr-x  1 root  wheel    41 Jun 30 13:05 captiveportal-test.css -> /var/db/cpelements/captiveportal-test.css lrwxr-xr-x  1 root  wheel    49 Jun 29 15:27 captiveportal-uikit.active.css -> /var/db/cpelements/captiveportal-uikit.active.css lrwxr-xr-x  1 root  wheel    42 Jun 29 15:25 captiveportal-uikit.css -> /var/db/cpelements/captiveportal-uikit.css lrwxr-xr-x  1 root  wheel    45 Jun 29 15:25 captiveportal-uikit.min.js -> /var/db/cpelements/captiveportal-uikit.min.js lrwxr-xr-x  1 root  wheel    44 Jun 29 15:25 captiveportal-wa_logo.png -> /var/db/cpelements/captiveportal-wa_logo.png -rw-r--r--  1 root  wheel  10454 May 16 23:22 index.php -rw-r--r--  1 root  wheel  10434 May 16 23:22 radius_accounting.inc -rw-r--r--  1 root  wheel  6862 May 16 23:22 radius_authentication.inc ![Screen Shot 2016-06-30 at 16.23.28.png](/public/imported_attachments/1/Screen Shot 2016-06-30 at 16.23.28.png) ![Screen Shot 2016-06-30 at 16.23.28.png_thumb](/public/imported_attachments/1/Screen Shot 2016-06-30 at 16.23.28.png_thumb)
  • Captive Portal Allowing other devices after first user login

    4
    0 Votes
    4 Posts
    891 Views
    GertjanG
    Can you mention : The IP the "CP" of pfsense is using. The mask The DHCP range activated on the CP NIC. The IP your AP is using. The IP / Gateway / DNS the visitor(s) device(s) got from the DHCP server on pfsense (running on CP). Did you saw the DHCP log entries for this lease on pfsense (you should recognize the MAC).
  • CP appear but when i put user name and password return me again

    5
    0 Votes
    5 Posts
    1k Views
    C
    Your login page is sane. The error page is just another login page though, so you'll go back to the login upon an authentication failure. Status>System logs, Portal Auth should show why authentication is failing.
  • Open new browser window when accepted by the portal

    4
    0 Votes
    4 Posts
    1k Views
    GertjanG
    No. I just suggest that you shouldn't 'code' a solution that doesn't work an "any visitors device". This means basically : keep it simple - and don't do what you self don't what to see elsewhere.
  • PfSense CP + MS-AD

    4
    0 Votes
    4 Posts
    1k Views
    F
    One other thing: pfSense 2.3.1 i386 my CP custom login page no longer works unless I remove, the information that you said is needed - $PORTAL_ACTION$ $PORTAL_REDIRURL$ $PORTAL_ZONE$ none of the above variables work. eg: <title>C-NAME Wireless Internet Access Point</title> ![](captiveportal-test.jpg) ## C-NAME Wireless Internet Access Point Welcome! Please supply **Either** your Username & Passowrd **Or** your Voucher Number below. <form method="post" action="$PORTAL_ACTION$"> | **Username:** | | | **Password:** | | | **Voucher Number:** | | |   | |     | </form> this is the code that works: <title>C-NAME Wireless Internet Access Point</title> ![](captiveportal-test.jpg) ## C-NAME Wireless Internet Access Point Welcome! Please supply **Either** your Username & Passowrd **Or** your Voucher Number below. <form method="post" action="http://10.10.1.1:8002/index.php?zone=C-NAME"> | **Username:** | | | **Password:** | | | **Voucher Number:** | | |   | |     | </form> Please fix this problem.
  • [pfsense-2.3] captive portal not working - single interface (WAN)

    11
    0 Votes
    11 Posts
    8k Views
    GertjanG
    @solidus: Yes of course, I understand that this is a very serious issue So, if someone has an https home page set and is not sufficiently smart to change the https into an http at the beginning of the URL, what could be a simple solution/workaround? Well …. A visitor that want to have the page https://www.google.com instructs his browser that he want to see https://www.google.com - and nothing else - no matter what. That's what https (ssl) is known about. It guarantees this need. It doesn't need much thinking that other destinations or ruled out. If the connections gets incercepted (redirected), the returned certificate will NOT say its "google.com" but "myportal.net" => the browser will jell. So, the visitor will start to understand that something is up ... He should know that he is behind a "captive portal" (more and more people are using this kind of Internet access more and more. The captive portal login page isn't, of course "https://www.google.com" so .... Basic rule : a connection should be build before secure connections are possible. With others words : use http://..... first and if ok, use https://..... @solidus: How much is feasible to put in the DNS resolver configuration, maybe using the "domain override" option, a domain like "log.me" that triggers the captive page? DOMAIN : log.me    –--  IP Address : pfsense LAN IP It would be easy to say to someone that is blaming browsing issues to digit "log.me" in the browser address bar ;D This has been done already. Search the forum (nad pfSEnse doc) for the examples. Instruct the local DNS that log.me == the IP of the Captive portal and your close.
  • Setting Correct date format for captive portal calendars

    8
    0 Votes
    8 Posts
    2k Views
    I
    ah now thats service! TYVM i will look forward to the new release.
  • (Found a bug) Can't name captive portal starting with a number

    3
    0 Votes
    3 Posts
    635 Views
    J
    You're very welcome.  I love you guys!  Keep up being awesome.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.