<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[CP&#x2F;pfSense behind another firewall with proxy]]></title><description><![CDATA[<p dir="auto">Hello,</p>
<p dir="auto">we're facing a problem with our pfSense setup for our students at school. We're trying to secure the students wifi with a captive portal. Therefore we use a router with a proxy for content filtering.</p>
<p dir="auto">This is our setup:</p>
<p dir="auto">Internet &lt;–--&gt; Router with firewall and proxy &lt;---&gt; pfSense WAN -- &lt;pfsense&gt;--pfSense student interface &lt;---&gt; (mobile) clients (iOS, Android, Windows/Mac OS)<br />
                              10.10.11.1/24                              10.10.11.2        DHCP                    172.20.0.0/22                        DHCP via pfSense<br />
                                proxy port: 800                                              DNS-Resolver<br />
                                                                                                          CP</p>
<p dir="auto">NAT Portforwarding enabled on WAN interface for students "NET" --- TCP/UDP "any" IP and "any" port to 10.10.11.1:800</p>
<p dir="auto">The proxy is manually set on every device (iOS, Android, ...) We use an non-transparent proxy without authentification</p>
<p dir="auto">iOS: If i connect to the network i get an IP, DNS ... everything looks fine. CP opens, I enter the voucher code and press "Continue" for access. But nothing happens. If I check the status on the cp interface, the client is listed as authenticated. There is no redirection to the url specified in cp settings, neither a "success" from the captive.apple.com<br />
I've found a workaround: Connect to wifi without proxy settings. CP appears, enter login credentials, press "continue", press "Cancel" on captive portal browser (device is listed as athenticated in pfsense)-- "Forget network" -- connect to wifi -- enter proxy settings -- happy internet browsing via proxy ... -.-<br />
If i do the workaround the device is shown in the firewall and the proxy of the router.</p>
<p dir="auto">Android: I connect to the wifi, get an IP, DNS settings, everything looks good. On some devices i get an cp, on some devices I don't get a cp ...-.-</p>
<p dir="auto">I hope you can help us!</p>
<p dir="auto">Thank you<br />
BGS&lt;/pfsense&gt;</p>
]]></description><link>https://forum.netgate.com/topic/108170/cp-pfsense-behind-another-firewall-with-proxy</link><generator>RSS for Node</generator><lastBuildDate>Mon, 09 Mar 2026 16:02:28 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/108170.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 21 Nov 2016 17:07:02 GMT</pubDate><ttl>60</ttl></channel></rss>