• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Pfsense, No internet when it is said "You are connected".

Scheduled Pinned Locked Moved Captive Portal
168 Posts 34 Posters 54.8k Views
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D
    dhmyess @Gertjan
    last edited by Dec 4, 2019, 8:02 PM

    @Gertjan Yes, I've ready apply this patch and then edited the file /etc/inc/system.inc but no changes.

    Am I use wrong patch??

    sorry for slow respon, I have to wait for users not using the network to work, I do not want to get complaints from them because of my trial.

    For freezing issues it's probably due to motherboard problems or bios bugs, because other machines aren't affected.

    1 Reply Last reply Reply Quote 0
    • G
      Gertjan
      last edited by Dec 4, 2019, 9:07 PM

      First solve "motherboard problems or bios bugs" - then post back concerning portal problems.

      I'm using the patch sited above :

      364ef71e-7e8d-48cc-9ec9-11ffb125172a-image.png

      and also edited /etc/inc/system.inc - for the sole reason that when I restart pfSense the "connected user database" should be deleted.
      Note that I rarely reboot pfSense ... so that "^$g" patch is not very important.

      I even don't need the " https://github.com/pfsense/pfsense/compare/RELENG_2_4_4...Augustin-FL:fix-reconfig-for-2-4-4.diff " because I never edit portal settings ... why should I ? It up and running for years now.

      I do have an entire hotel - about 20 people are connected daily - and all works well.
      https://www.test-domaine.fr/munin/brit-hotel-fumel.net/pfsense.brit-hotel-fumel.net/portalusers.html

      No "help me" PM's please. Use the forum, the community will thank you.
      Edit : and where are the logs ??

      D 1 Reply Last reply Dec 5, 2019, 7:44 PM Reply Quote 1
      • D
        dhmyess @Gertjan
        last edited by Dec 5, 2019, 7:44 PM

        @Gertjan apparently I used the wrong patch, after i use patch
        https://github.com/pfsense/pfsense/compare/RELENG_2_4_4...Augustin-FL:fix-reconfig-for-2-4-4.diff
        it works!!!
        problem solved, I am very very grateful for your help

        1 Reply Last reply Reply Quote 0
        • M
          MacUsers
          last edited by MacUsers Dec 31, 2019, 10:05 PM Dec 31, 2019, 10:04 PM

          Hi there,
          First time Captive Portal user: following this video tutorial and the login page came up right away the moment I logged into GUEST network/WiFi and then straight way presented with "You are connected" but no Internet access, just like every one else reported here (hence, reading this page). Also updated this patch, as suggested but still no joy yet. I'm on the latest v2.4.4-RELEASE-p3 and using only the Voucher based access. Could any one help me out with any suggestions and stuff pls?

          -San

          1 Reply Last reply Reply Quote 0
          • M
            MacUsers
            last edited by MacUsers Jan 1, 2020, 3:28 PM Jan 1, 2020, 1:38 PM

            I figured out a different thing for me: It started working after I added this rule in Firewall/NAT/Outbound:

            140243f1-53e2-4cfd-8434-6907188d7b95-image.png

            (192.168.60.x is my GUEST network)
            It's working okay for me now. Probably the patch upgraded also contributed to the success??

            -S

            1 Reply Last reply Reply Quote 0
            • J
              johnpoz LAYER 8 Global Moderator
              last edited by Jan 1, 2020, 2:58 PM

              Well if you had dicked with outbound nat and turned if off automatic, then yeah you going to have all kinds of problems!! With no outbound nat..

              An intelligent man is sometimes forced to be drunk to spend time with his fools
              If you get confused: Listen to the Music Play
              Please don't Chat/PM me for help, unless mod related
              SG-4860 24.11 | Lab VMs 2.8, 24.11

              M 1 Reply Last reply Jan 1, 2020, 3:27 PM Reply Quote 0
              • M
                MacUsers @johnpoz
                last edited by Jan 1, 2020, 3:27 PM

                @johnpoz said in Pfsense, No internet when it is said "You are connected".:

                Well if you had dicked with outbound nat and turned if off automatic, then yeah you going to have all kinds of problems!! With no outbound nat..

                Yeah, I had to switch to Manual Outbound NAT couple of yrs. ego, which I completely forgotten about it. Wanted to mentioned here just in case anyone else did the same mistake as me.

                -S

                1 Reply Last reply Reply Quote 0
                • J
                  johnpoz LAYER 8 Global Moderator
                  last edited by Jan 1, 2020, 3:38 PM

                  @MacUsers said in Pfsense, No internet when it is said "You are connected".:

                  Yeah, I had to switch to Manual Outbound NAT couple of yrs. ego

                  Highly unlikely to be honest... Why did you have to switch to manual exactly? Because some vpn service guide said to? You were routing some network behind pfsense that didn't need nat at all?

                  Hybrid is normally better choice when you need to do something out of norm with outbound nat for some vpn client connection your routing traffic through.

                  An intelligent man is sometimes forced to be drunk to spend time with his fools
                  If you get confused: Listen to the Music Play
                  Please don't Chat/PM me for help, unless mod related
                  SG-4860 24.11 | Lab VMs 2.8, 24.11

                  M 1 Reply Last reply Jan 1, 2020, 5:17 PM Reply Quote 0
                  • M
                    MacUsers @johnpoz
                    last edited by Jan 1, 2020, 5:17 PM

                    @johnpoz, I'm actually now trying to think why did I do that. I don't use any external VPN service but that time I was new to pfSense and probably was following some of the guides.
                    Actually trying to clean up the collected junks from my config. So you saying just simply switch to Hybrid and remove all of the manually added rules?

                    -S

                    1 Reply Last reply Reply Quote 0
                    • J
                      johnpoz LAYER 8 Global Moderator
                      last edited by johnpoz Jan 1, 2020, 5:47 PM Jan 1, 2020, 5:45 PM

                      You should be able to switch to just full auto.. If your not using a vpn connection to some vpn service - I to be honest off the top of my head can not think of why you would not just be full auto for outbound nat..

                      Do you have more than 1 wan connection, where you would want to determine which clients get natted to which wan?

                      Really if you are just plain jane out of the box type of setup, wan and lan(s) on your pfsense then yeah auto is all that would be needed, and is default out of the box.

                      Even if you were doing downstream router with transit to pfsense, etc. auto works there too, etc. It really should be rare that you need to switch from auto to hybrid, or even rarer manual.. There would have to be something unique to your network.

                      An intelligent man is sometimes forced to be drunk to spend time with his fools
                      If you get confused: Listen to the Music Play
                      Please don't Chat/PM me for help, unless mod related
                      SG-4860 24.11 | Lab VMs 2.8, 24.11

                      1 Reply Last reply Reply Quote 0
                      • S
                        stephenw10 Netgate Administrator
                        last edited by Jan 1, 2020, 8:17 PM

                        Yeah if you need to add custom rules switching to hybrid is generally better as you still auto rules to avoid exactly this sort of thing.
                        If it was a long while back there may not have been the hybrid mode option. At one time there was just auto or manual.

                        Steve

                        1 Reply Last reply Reply Quote 0
                        • J
                          johnpoz LAYER 8 Global Moderator
                          last edited by Jan 1, 2020, 10:46 PM

                          @stephenw10 said in Pfsense, No internet when it is said "You are connected".:

                          At one time there was just auto or manual.

                          And what version was that, 1, 2.0 ?? I do not recall that at all.

                          An intelligent man is sometimes forced to be drunk to spend time with his fools
                          If you get confused: Listen to the Music Play
                          Please don't Chat/PM me for help, unless mod related
                          SG-4860 24.11 | Lab VMs 2.8, 24.11

                          1 Reply Last reply Reply Quote 0
                          • S
                            stephenw10 Netgate Administrator
                            last edited by Jan 2, 2020, 2:15 AM

                            It was added in 2.2 so it would have to be pretty old install. But possible! 😉

                            1 Reply Last reply Reply Quote 0
                            • J
                              johnpoz LAYER 8 Global Moderator
                              last edited by Jan 2, 2020, 3:08 AM

                              Yeah would of been over 5 years ago to be pre 2.2..

                              That there are still copies out there running such old versions is on one a good testimony to pfsense... On the other hand - WTF people!!! And we wonder why people have issues when they don't update their security software in over 5 years ;)

                              An intelligent man is sometimes forced to be drunk to spend time with his fools
                              If you get confused: Listen to the Music Play
                              Please don't Chat/PM me for help, unless mod related
                              SG-4860 24.11 | Lab VMs 2.8, 24.11

                              1 Reply Last reply Reply Quote 0
                              • M
                                MacUsers
                                last edited by Jan 2, 2020, 7:00 PM

                                I think I started using pfSence on WatchGuard around 2014 and I do recall there was no hybrid option during that time; probably that config is hanging around since then. The thing I can remember, all of my devices (TV, AV receivers etc.) in a separate VLAN and I didn't want outbound connections for those devices - I think that was main reason ☺
                                -S

                                1 Reply Last reply Reply Quote 0
                                • M
                                  MacUsers
                                  last edited by MacUsers Jan 2, 2020, 7:10 PM Jan 2, 2020, 7:10 PM

                                  anyway, going back to captive-portal thing again, is there a way to allow fonts.googleapis.com from the portal, before logging in? I'm working on a custom login page and wish to use some fonts from there in the CSS (i.e. @import url(//fonts.googleapis.com/css?family=Open+Sans);). So I allowed fonts.googleapis.com in the Allowed Hostnames but it's not being imported. Anything else I need to do to make it working? Or is it possible at all?
                                  -S

                                  F 1 Reply Last reply Jan 2, 2020, 7:19 PM Reply Quote 0
                                  • F
                                    free4 Rebel Alliance @MacUsers
                                    last edited by Jan 2, 2020, 7:19 PM

                                    @MacUsers font.googleapis.com itself is calling other domains

                                    0a73f3c0-3ec2-4df7-85a7-70da6e54e7c7-image.png

                                    M 1 Reply Last reply Jan 2, 2020, 7:51 PM Reply Quote 1
                                    • M
                                      MacUsers @free4
                                      last edited by MacUsers Jan 2, 2020, 8:57 PM Jan 2, 2020, 7:51 PM

                                      @free4 said in Pfsense, No internet when it is said "You are connected".:

                                      @MacUsers font.googleapis.com itself is calling other domains

                                      Interesting!! Haven't noticed that at all.
                                      It started working straight away the moment I also allowed fonts.gstatic.com. Thanks a lot for pointing out!!
                                      -S

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        stephenw10 Netgate Administrator
                                        last edited by stephenw10 Jan 2, 2020, 11:04 PM Jan 2, 2020, 11:03 PM

                                        Yes you should be able to define hosts that are allowed before logging in there.

                                        Can you reach https://fonts.googleapis.com/css?family=Open+Sans directly from a client before logging in?

                                        Edit: Missed replies on next page. 🙄

                                        Steve

                                        1 Reply Last reply Reply Quote 0
                                        • A
                                          andresense
                                          last edited by Jan 23, 2020, 2:08 PM

                                          Hello,

                                          I don't know if my problem is the same as that being listed on this list but ...

                                          I'm having it when pfsense returns from a restart. Users who had authenticated before the restart cannot navigate or authenticate after the restart of the restart pfsense ...

                                          I performed the patch above but nothing

                                          Debug:

                                          [2.4.4-RELEASE][root@pfSense.localdomain]/root: ipfw table portal_test_auth_up list
                                          --- table(portal_test_auth_up), set(0) ---
                                          [2.4.4-RELEASE][root@pfSense.localdomain]/root: ipfw table portal_test_auth_down list
                                          --- table(portal_test_auth_down), set(0) ---

                                          sqlite3 /var/db/captiveportalportal_teste.db --line "select * from captiveportal"
                                          allow_time = 1579787905
                                          pipeno = 2000
                                          ip = 10.2.0.4
                                          mac = a1:dd:aa:6b:bb:cc
                                          username = helmet
                                          sessionid = b4d27f77b0c2b79a
                                          bpassword =
                                          session_timeout =
                                          idle_timeout =
                                          session_terminate_time =
                                          interim_interval =
                                          traffic_quota =
                                          authmethod = Local Auth
                                          context = first

                                          Patch can NOT be applied cleanly (detail):

                                          /usr/bin/patch --directory=/ -t -p2 -i /var/patches/5e29a0f922717.patch --check --forward --ignore-whitespace

                                          Hmm... Looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/etc/inc/captiveportal.inc b/src/etc/inc/captiveportal.inc
                                          |index 453b4f02950..152effd9243 100644
                                          |--- a/src/etc/inc/captiveportal.inc

                                          +++ b/src/etc/inc/captiveportal.inc
                                          Patching file etc/inc/captiveportal.inc using Plan A...
                                          Ignoring previously applied (or reversed) patch.
                                          Hunk #1 ignored at 235.
                                          Hunk #2 ignored at 600.
                                          Hunk #3 ignored at 645.
                                          Hunk #4 ignored at 697.
                                          Hunk #5 ignored at 747.
                                          Hunk #6 ignored at 755.
                                          Hunk #7 ignored at 786.
                                          Hunk #8 ignored at 1310.
                                          Hunk #9 ignored at 1441.
                                          Hunk #10 ignored at 1924.
                                          Hunk #11 ignored at 1941.
                                          Hunk #12 ignored at 1981.
                                          Hunk #13 ignored at 1992.
                                          Hunk #14 ignored at 2003.
                                          Hunk #15 ignored at 2014.
                                          Hunk #16 ignored at 2450.
                                          16 out of 16 hunks ignored while patching etc/inc/captiveportal.inc
                                          Hmm... The next patch looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/etc/inc/system.inc b/src/etc/inc/system.inc
                                          |index 6d6f33161cb..7e4deb8b326 100644
                                          |--- a/src/etc/inc/system.inc

                                          +++ b/src/etc/inc/system.inc
                                          Patching file etc/inc/system.inc using Plan A...
                                          Hunk #1 succeeded at 2180 with fuzz 2 (offset 60 lines).
                                          Hmm... The next patch looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/usr/local/captiveportal/index.php b/src/usr/local/captiveportal/index.php
                                          |index d5459a80976..44bf0879b32 100644
                                          |--- a/src/usr/local/captiveportal/index.php

                                          +++ b/src/usr/local/captiveportal/index.php
                                          Patching file usr/local/captiveportal/index.php using Plan A...
                                          Ignoring previously applied (or reversed) patch.
                                          Hunk #1 ignored at 198.
                                          1 out of 1 hunks ignored while patching usr/local/captiveportal/index.php
                                          done

                                          Patch can be reverted cleanly (detail):

                                          /usr/bin/patch --directory=/ -f -p2 -i /var/patches/5e29a0f922717.patch --check --reverse --ignore-whitespace

                                          Hmm... Looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/etc/inc/captiveportal.inc b/src/etc/inc/captiveportal.inc
                                          |index 453b4f02950..152effd9243 100644
                                          |--- a/src/etc/inc/captiveportal.inc

                                          +++ b/src/etc/inc/captiveportal.inc
                                          Patching file etc/inc/captiveportal.inc using Plan A...
                                          Hunk #1 succeeded at 235.
                                          Hunk #2 succeeded at 573 (offset -27 lines).
                                          Hunk #3 succeeded at 618 (offset -27 lines).
                                          Hunk #4 succeeded at 670 (offset -27 lines).
                                          Hunk #5 succeeded at 716 (offset -27 lines).
                                          Hunk #6 succeeded at 724 (offset -27 lines).
                                          Hunk #7 succeeded at 755 (offset -27 lines).
                                          Hunk #8 succeeded at 1298 (offset -4 lines).
                                          Hunk #9 succeeded at 1406 (offset -27 lines).
                                          Hunk #10 succeeded at 1912 (offset -4 lines).
                                          Hunk #11 succeeded at 1906 (offset -27 lines).
                                          Hunk #12 succeeded at 1965 (offset -4 lines).
                                          Hunk #13 succeeded at 1953 (offset -27 lines).
                                          Hunk #14 succeeded at 1987 (offset -4 lines).
                                          Hunk #15 succeeded at 1975 (offset -27 lines).
                                          Hunk #16 succeeded at 2421 (offset -17 lines).
                                          Hmm... The next patch looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/etc/inc/system.inc b/src/etc/inc/system.inc
                                          |index 6d6f33161cb..7e4deb8b326 100644
                                          |--- a/src/etc/inc/system.inc

                                          +++ b/src/etc/inc/system.inc
                                          Patching file etc/inc/system.inc using Plan A...
                                          Hunk #1 succeeded at 2126 with fuzz 2 (offset 6 lines).
                                          Hmm... The next patch looks like a unified diff to me...
                                          The text leading up to this was:

                                          |diff --git a/src/usr/local/captiveportal/index.php b/src/usr/local/captiveportal/index.php
                                          |index d5459a80976..44bf0879b32 100644
                                          |--- a/src/usr/local/captiveportal/index.php

                                          +++ b/src/usr/local/captiveportal/index.php
                                          Patching file usr/local/captiveportal/index.php using Plan A...
                                          Hunk #1 succeeded at 198.
                                          done
                                          F 1 Reply Last reply Jan 23, 2020, 4:16 PM Reply Quote 0
                                          • First post
                                            Last post
                                          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.
                                            This community forum collects and processes your personal information.
                                            consent.not_received