Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Lan users cant connect to internet

    Captive Portal
    7
    19
    3.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • pttP
      ptt Rebel Alliance
      last edited by

      https://doc.pfsense.org/index.php/Connectivity_Troubleshooting#Firewall.2FRules

      If you want "specific" answers, you need to "show" (screenshots) how have "configured" your pfSense

      1 Reply Last reply Reply Quote 0
      • DerelictD
        Derelict LAYER 8 Netgate
        last edited by

        You do not need to add any rules for basic internet access from LAN in a basic, default installation.

        Chattanooga, Tennessee, USA
        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
        Do Not Chat For Help! NO_WAN_EGRESS(TM)

        1 Reply Last reply Reply Quote 0
        • M
          mido2500
          last edited by

          OK tomorrow when go to work i will upload an attachment Thanks

          1 Reply Last reply Reply Quote 0
          • M
            mido2500
            last edited by

            This an attachment for case .i am waiting for help

            1.png
            1.png_thumb
            2.png
            2.png_thumb
            3.png
            3.png_thumb
            4.png
            4.png_thumb
            5.png
            5.png_thumb
            6.png
            6.png_thumb
            7.png
            7.png_thumb

            1 Reply Last reply Reply Quote 0
            • H
              heper
              last edited by

              you don't need a lan gateway

              uncheck "Block private networks and loopback addresses" on interfaces–>wan

              1 Reply Last reply Reply Quote 0
              • M
                mido2500
                last edited by

                i disabled lan gateway ,and iam not checked any option for wan gateway ,i cant go internet also

                1 Reply Last reply Reply Quote 0
                • M
                  mido2500
                  last edited by

                  i found the problem ,when i enabled captive portal internet is not working ,when disabled internet working on lan users ,the question how can i enabled captive portal with access internet at users have mobile or tablet

                  1 Reply Last reply Reply Quote 0
                  • johnpozJ
                    johnpoz LAYER 8 Global Moderator
                    last edited by

                    "how can i enabled captive portal with access internet at users have mobile or tablet"

                    Well set it up and have them auth…

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    • M
                      mido2500
                      last edited by

                      first i enabled the captive portal and create user at user manager and when access internet from lan not working (internet not working )

                      1 Reply Last reply Reply Quote 0
                      • DerelictD
                        Derelict LAYER 8 Netgate
                        last edited by

                        Get it working without captive portal first.

                        Chattanooga, Tennessee, USA
                        A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                        DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                        Do Not Chat For Help! NO_WAN_EGRESS(TM)

                        1 Reply Last reply Reply Quote 0
                        • M
                          mido2500
                          last edited by

                          working without it .how can i work with it plz

                          1 Reply Last reply Reply Quote 0
                          • M
                            mido2500
                            last edited by

                            Any solution plz

                            1 Reply Last reply Reply Quote 0
                            • johnpozJ
                              johnpoz LAYER 8 Global Moderator
                              last edited by

                              Dude what is your not understanding about the configuration of captive portal.. So your not using anything else like proxy or snort.  You just have out of the box clean install of pfsense, dhcp clients using pfsense as their gateway, lan rules any any.  clients using pfsense for dns while dns is just using unbound as resolver.

                              And everything works - but when you turn on CP it doesn't work?  This really is click click..

                              Here I enabled cp on 1 of my wifi networks, on the wlan interface in pfsense, created a user gave it captive portal permissions

                              The really only thing other than selecting enable in captive portal and picking the interface(s) you want it to listen on is picking the auth.. So here I set it to use local users, created a local user and gave it permissions to use cp.  I then tried to go to www.cnn.com on box on that network and get redirected to login page.  I auth, you can see pfsense shows it authed, and on the client I get my website I originally asked for.

                              If it takes you say more than 30 seconds to get a basic cp up and running and tested your doing something WRONG..  But without knowing what you did and what is happening or not happening its impossible to help you find what that something is.

                              captiveportalsetup.jpg
                              captiveportalsetup.jpg_thumb

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                              1 Reply Last reply Reply Quote 0
                              • I
                                itchy
                                last edited by

                                so the firewall rules should not block anything. What is happening exactly when a CP user tries to connect to the internet? Can you provide some more details?

                                1 Reply Last reply Reply Quote 0
                                • DerelictD
                                  Derelict LAYER 8 Netgate
                                  last edited by

                                  ipfw (not pf) is placed in the stream and it redirects connections to any:80 to cp_interface:8002 where an nginx instance returns the portal page.

                                  Upon successful login an IP/MAC pair is placed in an ipfw table (Status / Captive Portal / testcp image above) that passes traffic so it is no longer redirected to the portal page.

                                  After that, normal pf LAN rules apply.

                                  Chattanooga, Tennessee, USA
                                  A comprehensive network diagram is worth 10,000 words and 15 conference calls.
                                  DO NOT set a source address/port in a port forward or firewall rule unless you KNOW you need it!
                                  Do Not Chat For Help! NO_WAN_EGRESS(TM)

                                  1 Reply Last reply Reply Quote 0
                                  • GertjanG
                                    Gertjan
                                    last edited by

                                    @itchy:

                                    Can you provide some more details?

                                    This has been taken care of a long time ago.
                                    https://doc.pfsense.org/index.php/Captive_Portal_Troubleshooting
                                    The firewall rules "ipfw" redirect all http requests to the internal web sever that displays the login page IF the user's device hasn't been granted access already.

                                    If a user's device has been granted access, the firewall rules accessible in the GUI determine what happens.

                                    edit : great : I'm actually saying the same thing as Derelict.

                                    No "help me" PM's please. Use the forum, the community will thank you.
                                    Edit : and where are the logs ??

                                    1 Reply Last reply Reply Quote 0
                                    • First post
                                      Last post
                                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.