Problem with captive portal on a non-nated interface
-
I am trying to set up a captive portal on an interface that does not have nat
it use routable addressi am using the 1.2.3 RC1 version.
if i set the portal on OPT1 (a nated interface) everything works fine.
if i switch frome OPT1 to OPT2 (a non-nated interace). the portal web page
appear and i can loggin to it (i see my user in status page), but i cannot go any furtheri tried to run ipfw show, and i see automatic rule created for my IP, and i can see traffic
going thru those rule (not blocked by the 19904 rule) but nothing come back to my internal
machinesi have searched the forum and web site. for similar case. but did not find any
Is the captive portal compatible with non-nated interface? has anyone succeeded in a
similar configuration ?i will try different version, in a vmware lab i am setting up. but i was wondering if anybody knew
something about this problemThank for your reply
Math -
Give more detials.
This is just telling nothing! -
Thanks for your interest.
I was just wondering if my problem was a "known limitation" or
if i have hit a bug\misconfiguration.the firewall is sort of a departemental-firewall, the organisation use a large
10.x.y.z network. and the departement is a subnet of that large network.
i cannot use NAT for that firewall.my WAN is a large 10.x.y.z
my LAN is a 192.168.x.y (for testing with NAT activated)
my OPT1 is a subnet of the large 10.x.y.zi started by setting up the captive portal on the LAN "testing" network
and it worked fine.
than i switched from LAN to OPT1 "production" network
and all my traffic was blocked.this is firewall is now in production (without the portal) so i cannot do many test on it
i will settup a test lab to reproduce the problem -
So i did set up a lab
and the captive portal works well with non-nated interface
it is probably a misconfiguration on my part, i still dont know why
it is not working in the production firewall. but i know it is possible.i will probably have to redo the whole configuration from scratch.
thanks for your interrest
Math