Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Create Captive Portal for company

    Scheduled Pinned Locked Moved Captive Portal
    24 Posts 3 Posters 6.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W Offline
      wallabybob
      last edited by

      By default, pfSense will NAT on LAN to WAN connections but that can be disabled.

      I manage one of my pfSense boxes by accessing it through it WAN interface.

      1 Reply Last reply Reply Quote 0
      • G Offline
        goran81
        last edited by

        I'm not sure I follow. I am very new to this so forgive me. So do I need to disable something then from the setup you recommend? Also, can you please give me a scenario that I want to achieve with ip's and gateway addresses? I think it will register better if I see visually what you prefer me to do.

        1 Reply Last reply Reply Quote 0
        • W Offline
          wallabybob
          last edited by

          @goran81:

          I'm not sure I follow. I am very new to this so forgive me. So do I need to disable something then from the setup you recommend?

          Since you are new to this I would highly recommend you start with a very basic configuration and get that working. Then tweak it one step at a time so when it stops working you can more easily go back to a working configuration and you have only a small number of steps to analyse to see what broke.

          @goran81:

          Also, can you please give me a scenario that I want to achieve with ip's and gateway addresses? I think it will register better if I see visually what you prefer me to do.

          I am not prepared to guess the details of your existing network configuration. Help me to help you by giving more details about your network. For a start, give me a network diagram and address my assumptions.

          1 Reply Last reply Reply Quote 0
          • G Offline
            goran81
            last edited by

            ISP–--ASA5510-----Cisco2811/Router------3 Cisco switches-----computers. my current lan ip scheme is 10.10.1.1/24 and I want to give my wireless clients and ip of 192.168.5.x/24. Do I need to give a static ip to my WAN connection on my pfsense box? like 10.10.1.2? and my wireless a static of 192.168.5.x?

            1 Reply Last reply Reply Quote 0
            • G Offline
              goran81
              last edited by

              Can anyone please help me with my initial setup? I would appreciate it.

              Thanks

              1 Reply Last reply Reply Quote 0
              • W Offline
                wallabybob
                last edited by

                @goran81:

                Do I need to give a static ip to my WAN connection on my pfsense box? like 10.10.1.2?

                If you don't have a suitable DHCP server, yes and yes.

                @goran81:

                and my wireless a static of 192.168.5.x?

                Yes, WiFi interface in pfSense should be a static IP in 192.168,5,x/24  (static so you can enable DHCP server).

                1 Reply Last reply Reply Quote 0
                • G Offline
                  goran81
                  last edited by

                  What about the gateway addresses for both WAN and LAN?

                  1 Reply Last reply Reply Quote 0
                  • G Offline
                    goran81
                    last edited by

                    Anyone?

                    1 Reply Last reply Reply Quote 0
                    • G Offline
                      goran81
                      last edited by

                      Just wanted to say thanks for your help. I configured pfsense and captive portal. it seems to work pretty well. I am going to get familiar with it and maybe post some more questions later on.

                      Thank you so much

                      1 Reply Last reply Reply Quote 0
                      • G Offline
                        goran81
                        last edited by

                        How do I make it so that I can access the web GUI just through my WAN connection? I have placed a rule on my LAN interface just to have internet access and not be able to access my internal LAN which is my WAN connection on my box.

                        1 Reply Last reply Reply Quote 0
                        • G Offline
                          goran81
                          last edited by

                          Anyone please?

                          1 Reply Last reply Reply Quote 0
                          • W Offline
                            wallabybob
                            last edited by

                            @goran81:

                            How do I make it so that I can access the web GUI just through my WAN connection?

                            Have you tried it? If so and it "doesn't work" please post what the browser reports when you attempt it.

                            1 Reply Last reply Reply Quote 0
                            • G Offline
                              goran81
                              last edited by

                              I have not tried it. I need help configuring it

                              1 Reply Last reply Reply Quote 0
                              • W Offline
                                wallabybob
                                last edited by

                                I expect you will need a firewall rule on the WAN interface to allow access and a firewall rule on the LAN interface to block access.

                                Step 1. Try access  from both WAN interface and LAN interface and report the outcome.

                                1 Reply Last reply Reply Quote 0
                                • G Offline
                                  goran81
                                  last edited by

                                  When I am on the WAN it will not open up the web gui but when I am on the lan it will open. What rule do I need to place to make this work?

                                  Thanks for your help.

                                  1 Reply Last reply Reply Quote 0
                                  • G Offline
                                    goran81
                                    last edited by

                                    These are the current rules I have. I know I have to uncheck the block private networks but what else do I need to do.

                                    Thanks

                                    WAN.png_thumb
                                    WAN.png
                                    LAN.png
                                    LAN.png_thumb

                                    1 Reply Last reply Reply Quote 0
                                    • W Offline
                                      wallabybob
                                      last edited by

                                      I think you will at least need to replicate on the WAN interface the Anti lockout rule on the LAN interface EXCEPT the destination Address in the new rule will be WAN Address rather than LAN address.

                                      Then you should go to Diagnostics -> States, click on the Reset States tab, read the explanation and click on the Reset button.

                                      1 Reply Last reply Reply Quote 0
                                      • G Offline
                                        goran81
                                        last edited by

                                        You know what I figured it out.

                                        Thanks,

                                        1 Reply Last reply Reply Quote 0
                                        • First post
                                          Last post
                                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.