• Hotel wired jack question

    4
    0 Votes
    4 Posts
    1k Views
    DerelictD
    Just make sure they can't just "choose" to be elected your spanning tree root or something stupid like that. Are your wired and wireless networks on the same layer 2? You might consider separating them else someone who connects wired and wireless at the same time with something like an Airport express in "join a wireless network" mode will create a bridging loop. probably many ways to accomplish that with two ports to the same layer 2 in the same location. (one wireless, one wired). You ought to be able to just use the same CP on both networks.
  • MOVED: No usernames in squid logs when using captive portal

    Locked
    1
    0 Votes
    1 Posts
    505 Views
    No one has replied
  • Captive portal + transparent proxy : Any solution?

    5
    0 Votes
    5 Posts
    2k Views
    D
    No. Not until someone writes proper hooks for ipfw to be used in packages. Cf. https://redmine.pfsense.org/issues/5594
  • IOS 10 not being authenticated on the CP

    3
    0 Votes
    3 Posts
    732 Views
    L
    Thanks will look into it
  • Port 80 open if using squid in transparent mode

    3
    0 Votes
    3 Posts
    585 Views
    H
    @doktornotor: CP and Squid in transparent mode will NOT work. Thank you very much!
  • How to allow captive poral users to change their own passwords?

    8
    0 Votes
    8 Posts
    4k Views
    jimpJ
    FreeRADIUS on pfSense? You can't. If you use it externally, there might be a GUI that lets you do that somewhere, but it's not a pfSense feature, it would be some other bit of software.
  • External MultiCP without FreeRADIUS

    1
    0 Votes
    1 Posts
    595 Views
    No one has replied
  • Delay in Connecting Captive Portal

    10
    0 Votes
    10 Posts
    3k Views
    S
    When trying to connect to WIFI with mobile devices it just hangs in "Connecting WiFi" page and not get redirected to captive portal. During this time shouldn't I be able to connect to captive portal by manually typing the captive portal URL. When I do so on mobile, it says connection refused.
  • Users to access to Captive Portal

    2
    0 Votes
    2 Posts
    612 Views
    D
    Not possible. Anyone with access to page-system-usermanager is effectively root.
  • Portal captive https

    20
    0 Votes
    20 Posts
    8k Views
    DerelictD
    No it didn't. It is simply not possible to get in the middle of an HTTPS connection and not generate a certificate error unless you can mint a certificate for the original destination signed by a CA trusted on the device. And even then you are hampered by certificate pinning, etc. I would love to see the certificate generated by the captive portal that was presented when you tried to go to a regular, global HTTPS site and got the portal instead without a cert error being presented.
  • PfSense 2.2.6 Captive Portal High CPU

    1
    0 Votes
    1 Posts
    494 Views
    No one has replied
  • Nginx: [error] accept4() failed Software caused connection abort

    2
    0 Votes
    2 Posts
    3k Views
    I
    in sys file there is a method like below, in it I set. That method produces nginx config file. function system_generate_nginx_config(…) .... events {     worker_connections  1024;   **  multi_accept on;** } …. When I set "multi_accept on;" will it cause any problem? NOTE: The web sites about nginx saying like below about "multi_accept on;": We've enabled multi_accept which causes nginx to attempt to immediately accept as many connections as it can. The option multi_accept makes the worker process accept all new connections instead of serving on at a time. If multi_accept is disabled, a worker process will accept one new connection at a time. Otherwise, a worker process will accept all new connections at a time.
  • Captive Portal + Squid3 non transparent proxy

    12
    0 Votes
    12 Posts
    11k Views
    C
    @haydin81: Squid3-dev–->"non-transparent", Patch captive portal" checked, "authentication-captive portal" Captive Portal--> enabled, "authentication-radius" checked"disable mac filtering" while state that, 1. if a user open explorer without proxy settings, he can access captive portal login page(of course some firewall rule added) 2. if a user open explorer with proxy settings, he cant open access captive portal and no access to internet (why?) 3. if a user open explorer without proxy settings and login captive portal (note.1), he can access internet with proxy settings explorer. Help me!! Hi, I'm with the same problem. But, pfsense 2.3.2-RELEASE-p1, package squid 0.4.29_1. Has anyone made work non-transparent proxy + captive portal? –- edit I solved the problem editing the error page (/usr/local/etc/squid/errors/.../ERR_ACCESS_DENIED) to redirect to captive portal. But the user needs to access some http page, not https, because the browser blocks https redirection.
  • Android 6.0 Captive Portal Redirect Error

    5
    0 Votes
    5 Posts
    2k Views
    C
    That is a problem in Android. After login  the redirect url will crash right? I have captive portal set on other gateways not pfsense and also do this on Android, It is a known problem.
  • Slow show up captive portal page in iPhone

    1
    0 Votes
    1 Posts
    644 Views
    No one has replied
  • Captive portal do not block unauthorised connections anymore

    8
    0 Votes
    8 Posts
    2k Views
    D
    hi there again, I played around with 2.3.2 in my lab and figured it out. The old cp portal works flawless by adding the allowed ip "192.168.0.0/16", of course the pfSense interface / LAN Subnet my clients are using is in this range. With 2.3.2 a client can access any ip without authentication as soon as the LAN subnet is added unter "allowed ip", which is used by the captive portal clients. in my case: setup all needed subnets manually, and add new one over time add all subnets manually in this range except the one of the captive portal clients
  • Radius + Custom Captive Portal + MYSQL + PHP

    1
    0 Votes
    1 Posts
    799 Views
    No one has replied
  • 0 Votes
    2 Posts
    2k Views
    GertjanG
    @sonidoP: Try URL: http://x.x.x.x:8002/index.php?zone=cp_guest (ref: https://forum.pfsense.org/index.php?topic=110073.30 ) with blank page result. Like that ? Your captive zone 'name' in question is really "cp_guest" ? The port used by pfSense is really "8002" (mine is 8003 for https and 8002 for http - you can't chose them, they are assigned by pfSense when creating portals) If "http://x.x.x.x:8002/index.php?zone=cp_guest" doesn't work, you have two possibilities : You portal doesn't work -> make it work first. Visiting "http://x.x.x.x" (your captive portal address) should redirect you to … as said here : https://forum.pfsense.org/index.php?topic=110073.msg679281#msg679281 Check your port number and zone name - it should be EXACT. @sonidoP: There is little documentation of the Pre-authentication procedure in version 2.3.2-RELEASE-p1, Someone could tell me if the process is correct? As said here https://doc.pfsense.org/index.php/Captive_Portal_Pre-authentication_Redirect and as you might guess, this page isn't really maintained, and rather tricky to use.
  • PHP Warning: Module 'mysql' already loaded in Unknown on line 0

    2
    0 Votes
    2 Posts
    1k Views
    jimpJ
    The file must somehow be listed multiple times in /usr/local/etc/php/extensions.ini
  • Captive portal and wifi routers

    4
    0 Votes
    4 Posts
    4k Views
    DerelictD
    Don't put your wifi users behind routers. Put them behind access points (bridges) so the captive portal sees both the client MAC address and IP address.
Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.