Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    External (Reverse?) Captive Portal

    Scheduled Pinned Locked Moved Captive Portal
    5 Posts 3 Posters 3.4k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      tacabana
      last edited by

      I have the current setup.

      ISP
            |
        DMZ Subnet
            |
        IPSEC VPN Hardware
            |
        VPN Subnet
            |
      Mail Server

      I have been asked to allow access to the corporate mail server's web interface from the Internet without requiring VPN software for each user, however I don't want to have to move the mail server from the VPN subnet.  Could a Captive Portal be used to provide access to authenticated users from the Internet (SSL VPN)?  If so, how?  A WAN link (routable interface) can't be chosen for a captive portal.

      IE.

      ISP
            |
        DMZ Subnet
            |    |–--------------------
            |                                    |
        IPSEC VPN Hardware      SSL Captive Portal
            |                                    |
            |                                    |
        VPN Subnet-------------------
            |
      Mail Server

      Notes:
      DMZ is routable /27 subnet using Proxy Arp.
      Using pfSense 1.0.1

      1 Reply Last reply Reply Quote 0
      • S
        sullrich
        last edited by

        That is not currently possible, unfortunately.

        1 Reply Last reply Reply Quote 0
        • H
          hoba
          last edited by

          This is more suitable for your needs: http://sourceforge.net/projects/sslexplorer/

          1 Reply Last reply Reply Quote 0
          • T
            tacabana
            last edited by

            SSL-Explorer looks to be just the ticket.  Didn't know this project existed…

            Thanks to all for the very quick responses.

            1 Reply Last reply Reply Quote 0
            • H
              hoba
              last edited by

              sslexplorer even has a built in java vpn client. It's pretty cool. Just forward the configured port to the ssl exporer and configure your users/apps there. I tested this at our office. works great.

              1 Reply Last reply Reply Quote 0
              • First post
                Last post
              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.