Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Captive Portal PAT (Port Address Translation) support

    Scheduled Pinned Locked Moved Captive Portal
    2 Posts 2 Posters 1.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • T
      Tanker
      last edited by

      Hi all

      We have the next scenario. An VPN private Network with access sites with routers wifi. The users have an IP address of local LAN via DHCP server configured in access router. Then the access router translate de N:1 IP addresses of the users to unique IP address of the wan interface (PAT).

      [[          Access Site                ]]  [[          PRIVATE NETWORK      ]]  [[              CENTRAL SITE                    ]]

      Users Wifi ))))  (((( router wifi (AP) <–----> MPLS VPN network <-----> router HQ <--> Captive Portal <--> Firewall -->> INTERNET

      LAN 192.168.1.0/24    PAT N:1  10.100.10.1/32  ---> CORE --->    !!PROBLEM!! with identifing users due to PAT in router access site.

      Because of this, when the traffic reaches the captive portal, all users are using the same IP address, the IP address of the interface WAN of the router access, and the Captive Portal is not able to identify sessions or connections of different users.

      Does anyone know if the captive portal is able to identify connections or user sessions under these conditions, via cookies or something
      like this?

      Thank you very much
      Regards
      TanKer

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Disable NAT on the wifi router and create a static route pointing to the ip of the wifi router for the wifi subnet.
        Basically convert the setup into a routed network instead of a NATed setup.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • First post
          Last post
        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.