Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lan users cant connect to internet

    Captive Portal
    7
    19
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mido2500
      last edited by

      hi
      iam new to pfsense ,i have aproblem .i have 2 card on server pfsense wan and lan ,pfsense go to internet Done but lan users no ,i need to know why and when finished from this problem i want users have mobile and tablet use captive portal authentication ,users can this or no

      • lam connected to switch and wan connected to router ,dhcp is on on lan card,user gw is lan card
      1 Reply Last reply Reply Quote 0
      • pttP
        ptt Rebel Alliance
        last edited by

        Check: https://doc.pfsense.org/index.php/Connectivity_Troubleshooting

        1 Reply Last reply Reply Quote 0
        • M
          mido2500
          last edited by

          Thanks
          But i need to know if i need any rules at firewall to get internet working

          1 Reply Last reply Reply Quote 0
          • pttP
            ptt Rebel Alliance
            last edited by

            https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#Firewall.2FRules

            If you want "specific" answers, you need to "show" (screenshots) how have "configured" your pfSense

            1 Reply Last reply Reply Quote 0
            • DerelictD
              Derelict LAYER 8 Netgate
              last edited by

              You do not need to add any rules for basic internet access from LAN in a basic, default installation.

              Chattanooga, Tennessee, USA
              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
              Do Not Chat For Help! NO_WAN_EGRESS(TM)

              1 Reply Last reply Reply Quote 0
              • M
                mido2500
                last edited by

                OK tomorrow when go to work i will upload an attachment Thanks

                1 Reply Last reply Reply Quote 0
                • M
                  mido2500
                  last edited by

                  This an attachment for case .i am waiting for help

                  1.png
                  1.png_thumb
                  2.png
                  2.png_thumb
                  3.png
                  3.png_thumb
                  4.png
                  4.png_thumb
                  5.png
                  5.png_thumb
                  6.png
                  6.png_thumb
                  7.png
                  7.png_thumb

                  1 Reply Last reply Reply Quote 0
                  • H
                    heper
                    last edited by

                    you don't need a lan gateway

                    uncheck "Block private networks and loopback addresses" on interfaces–>wan

                    1 Reply Last reply Reply Quote 0
                    • M
                      mido2500
                      last edited by

                      i disabled lan gateway ,and iam not checked any option for wan gateway ,i cant go internet also

                      1 Reply Last reply Reply Quote 0
                      • M
                        mido2500
                        last edited by

                        i found the problem ,when i enabled captive portal internet is not working ,when disabled internet working on lan users ,the question how can i enabled captive portal with access internet at users have mobile or tablet

                        1 Reply Last reply Reply Quote 0
                        • johnpozJ
                          johnpoz LAYER 8 Global Moderator
                          last edited by

                          "how can i enabled captive portal with access internet at users have mobile or tablet"

                          Well set it up and have them auth…

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                          1 Reply Last reply Reply Quote 0
                          • M
                            mido2500
                            last edited by

                            first i enabled the captive portal and create user at user manager and when access internet from lan not working (internet not working )

                            1 Reply Last reply Reply Quote 0
                            • DerelictD
                              Derelict LAYER 8 Netgate
                              last edited by

                              Get it working without captive portal first.

                              Chattanooga, Tennessee, USA
                              A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                              DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                              Do Not Chat For Help! NO_WAN_EGRESS(TM)

                              1 Reply Last reply Reply Quote 0
                              • M
                                mido2500
                                last edited by

                                working without it .how can i work with it plz

                                1 Reply Last reply Reply Quote 0
                                • M
                                  mido2500
                                  last edited by

                                  Any solution plz

                                  1 Reply Last reply Reply Quote 0
                                  • johnpozJ
                                    johnpoz LAYER 8 Global Moderator
                                    last edited by

                                    Dude what is your not understanding about the configuration of captive portal.. So your not using anything else like proxy or snort.  You just have out of the box clean install of pfsense, dhcp clients using pfsense as their gateway, lan rules any any.  clients using pfsense for dns while dns is just using unbound as resolver.

                                    And everything works - but when you turn on CP it doesn't work?  This really is click click..

                                    Here I enabled cp on 1 of my wifi networks, on the wlan interface in pfsense, created a user gave it captive portal permissions

                                    The really only thing other than selecting enable in captive portal and picking the interface(s) you want it to listen on is picking the auth.. So here I set it to use local users, created a local user and gave it permissions to use cp.  I then tried to go to www.cnn.com on box on that network and get redirected to login page.  I auth, you can see pfsense shows it authed, and on the client I get my website I originally asked for.

                                    If it takes you say more than 30 seconds to get a basic cp up and running and tested your doing something WRONG..  But without knowing what you did and what is happening or not happening its impossible to help you find what that something is.

                                    captiveportalsetup.jpg
                                    captiveportalsetup.jpg_thumb

                                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                                    If you get confused: Listen to the Music Play
                                    Please don't Chat/PM me for help, unless mod related
                                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                                    1 Reply Last reply Reply Quote 0
                                    • I
                                      itchy
                                      last edited by

                                      so the firewall rules should not block anything. What is happening exactly when a CP user tries to connect to the internet? Can you provide some more details?

                                      1 Reply Last reply Reply Quote 0
                                      • DerelictD
                                        Derelict LAYER 8 Netgate
                                        last edited by

                                        ipfw (not pf) is placed in the stream and it redirects connections to any:80 to cp_interface:8002 where an nginx instance returns the portal page.

                                        Upon successful login an IP/MAC pair is placed in an ipfw table (Status / Captive Portal / testcp image above) that passes traffic so it is no longer redirected to the portal page.

                                        After that, normal pf LAN rules apply.

                                        Chattanooga, Tennessee, USA
                                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                        1 Reply Last reply Reply Quote 0
                                        • GertjanG
                                          Gertjan
                                          last edited by

                                          @itchy:

                                          Can you provide some more details?

                                          This has been taken care of a long time ago.
                                          https://doc.pfsense.org/index.php/Captive_Portal_Troubleshooting
                                          The firewall rules "ipfw" redirect all http requests to the internal web sever that displays the login page IF the user's device hasn't been granted access already.

                                          If a user's device has been granted access, the firewall rules accessible in the GUI determine what happens.

                                          edit : great : I'm actually saying the same thing as Derelict.

                                          No "help me" PM's please. Use the forum, the community will thank you.
                                          Edit : and where are the logs ??

                                          1 Reply Last reply Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.