Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lan users cant connect to internet

    Scheduled Pinned Locked Moved Captive Portal
    19 Posts 7 Posters 3.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mido2500
      last edited by

      Thanks
      But i need to know if i need any rules at firewall to get internet working

      1 Reply Last reply Reply Quote 0
      • pttP
        ptt Rebel Alliance
        last edited by

        https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#Firewall.2FRules

        If you want "specific" answers, you need to "show" (screenshots) how have "configured" your pfSense

        1 Reply Last reply Reply Quote 0
        • DerelictD
          Derelict LAYER 8 Netgate
          last edited by

          You do not need to add any rules for basic internet access from LAN in a basic, default installation.

          Chattanooga, Tennessee, USA
          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
          Do Not Chat For Help! NO_WAN_EGRESS(TM)

          1 Reply Last reply Reply Quote 0
          • M
            mido2500
            last edited by

            OK tomorrow when go to work i will upload an attachment Thanks

            1 Reply Last reply Reply Quote 0
            • M
              mido2500
              last edited by

              This an attachment for case .i am waiting for help

              1.png
              1.png_thumb
              2.png
              2.png_thumb
              3.png
              3.png_thumb
              4.png
              4.png_thumb
              5.png
              5.png_thumb
              6.png
              6.png_thumb
              7.png
              7.png_thumb

              1 Reply Last reply Reply Quote 0
              • H
                heper
                last edited by

                you don't need a lan gateway

                uncheck "Block private networks and loopback addresses" on interfaces–>wan

                1 Reply Last reply Reply Quote 0
                • M
                  mido2500
                  last edited by

                  i disabled lan gateway ,and iam not checked any option for wan gateway ,i cant go internet also

                  1 Reply Last reply Reply Quote 0
                  • M
                    mido2500
                    last edited by

                    i found the problem ,when i enabled captive portal internet is not working ,when disabled internet working on lan users ,the question how can i enabled captive portal with access internet at users have mobile or tablet

                    1 Reply Last reply Reply Quote 0
                    • johnpozJ
                      johnpoz LAYER 8 Global Moderator
                      last edited by

                      "how can i enabled captive portal with access internet at users have mobile or tablet"

                      Well set it up and have them auth…

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • M
                        mido2500
                        last edited by

                        first i enabled the captive portal and create user at user manager and when access internet from lan not working (internet not working )

                        1 Reply Last reply Reply Quote 0
                        • DerelictD
                          Derelict LAYER 8 Netgate
                          last edited by

                          Get it working without captive portal first.

                          Chattanooga, Tennessee, USA
                          A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                          DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                          Do Not Chat For Help! NO_WAN_EGRESS(TM)

                          1 Reply Last reply Reply Quote 0
                          • M
                            mido2500
                            last edited by

                            working without it .how can i work with it plz

                            1 Reply Last reply Reply Quote 0
                            • M
                              mido2500
                              last edited by

                              Any solution plz

                              1 Reply Last reply Reply Quote 0
                              • johnpozJ
                                johnpoz LAYER 8 Global Moderator
                                last edited by

                                Dude what is your not understanding about the configuration of captive portal.. So your not using anything else like proxy or snort.  You just have out of the box clean install of pfsense, dhcp clients using pfsense as their gateway, lan rules any any.  clients using pfsense for dns while dns is just using unbound as resolver.

                                And everything works - but when you turn on CP it doesn't work?  This really is click click..

                                Here I enabled cp on 1 of my wifi networks, on the wlan interface in pfsense, created a user gave it captive portal permissions

                                The really only thing other than selecting enable in captive portal and picking the interface(s) you want it to listen on is picking the auth.. So here I set it to use local users, created a local user and gave it permissions to use cp.  I then tried to go to www.cnn.com on box on that network and get redirected to login page.  I auth, you can see pfsense shows it authed, and on the client I get my website I originally asked for.

                                If it takes you say more than 30 seconds to get a basic cp up and running and tested your doing something WRONG..  But without knowing what you did and what is happening or not happening its impossible to help you find what that something is.

                                captiveportalsetup.jpg
                                captiveportalsetup.jpg_thumb

                                An intelligent man is sometimes forced to be drunk to spend time with his fools
                                If you get confused: Listen to the Music Play
                                Please don't Chat/PM me for help, unless mod related
                                SG-4860 24.11 | Lab VMs 2.8, 24.11

                                1 Reply Last reply Reply Quote 0
                                • I
                                  itchy
                                  last edited by

                                  so the firewall rules should not block anything. What is happening exactly when a CP user tries to connect to the internet? Can you provide some more details?

                                  1 Reply Last reply Reply Quote 0
                                  • DerelictD
                                    Derelict LAYER 8 Netgate
                                    last edited by

                                    ipfw (not pf) is placed in the stream and it redirects connections to any:80 to cp_interface:8002 where an nginx instance returns the portal page.

                                    Upon successful login an IP/MAC pair is placed in an ipfw table (Status / Captive Portal / testcp image above) that passes traffic so it is no longer redirected to the portal page.

                                    After that, normal pf LAN rules apply.

                                    Chattanooga, Tennessee, USA
                                    A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                    DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                    Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                    1 Reply Last reply Reply Quote 0
                                    • GertjanG
                                      Gertjan
                                      last edited by

                                      @itchy:

                                      Can you provide some more details?

                                      This has been taken care of a long time ago.
                                      https://doc.pfsense.org/index.php/Captive_Portal_Troubleshooting
                                      The firewall rules "ipfw" redirect all http requests to the internal web sever that displays the login page IF the user's device hasn't been granted access already.

                                      If a user's device has been granted access, the firewall rules accessible in the GUI determine what happens.

                                      edit : great : I'm actually saying the same thing as Derelict.

                                      No "help me" PM's please. Use the forum, the community will thank you.
                                      Edit : and where are the logs ??

                                      1 Reply Last reply Reply Quote 0
                                      • First post
                                        Last post
                                      Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.