<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Setup a Captive portal for PON Network]]></title><description><![CDATA[<p dir="auto">Hi all,</p>
<p dir="auto">Currently, I setup a topology which is using the PON architecture, as the picture below:<br />
<img src="/assets/uploads/files/1692873684442-3088822c-4f4a-4890-a1a1-97dd5f74e43e-image.png" alt="3088822c-4f4a-4890-a1a1-97dd5f74e43e-image.png" class=" img-fluid img-markdown" /></p>
<p dir="auto">I've had some trouble:</p>
<ol>
<li><strong>When enable Captive portal:</strong></li>
</ol>
<ul>
<li>The WAN interface in ONT can't get the IP from DHCP server</li>
<li>Captive portal doesn't work, not redirect to other page (Login or Accept) for accessing Internet</li>
</ul>
<ol start="2">
<li><strong>The WAN connection of pfSense is unstable</strong>: The WAN interface still gets the IP but I can't access WEB GUI and ping to internet from WAN interface. So, I need to do some CLI to config the IP for WAN interface to get the IP, and then it's normal</li>
</ol>
<p dir="auto">Do you have the performance review for pfSense? I want to deploy this model in the real site for serving around 200-500 users. If you have, please share something with me.</p>
<p dir="auto">Be thankful for any your recommendation!</p>
]]></description><link>https://forum.netgate.com/topic/182400/setup-a-captive-portal-for-pon-network</link><generator>RSS for Node</generator><lastBuildDate>Sat, 18 Apr 2026 13:59:20 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/182400.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 24 Aug 2023 10:48:56 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Tue, 05 Sep 2023 09:16:26 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122669">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">I know this isn't what you want to achieve, but a captive portal 'wants' to use/see the actual client IP and MAC addresses.<br />
A captive portal, on the pfSense side, is just a set of firewall rules. And these need these two, as there is not else to handle upon.</p>
</blockquote>
<p dir="auto">Hi Gertjan,<br />
I've done to setup the whole system, and it worked.<br />
However, now I consider to use a separate DHCP server, not rely on pfSense. Could I deploy this model? And How to setup network connection between DHCP server &lt;--&gt; pfSense &lt;--&gt; AP?</p>
<p dir="auto">Thank you!</p>
]]></description><link>https://forum.netgate.com/post/1124020</link><guid isPermaLink="true">https://forum.netgate.com/post/1124020</guid><dc:creator><![CDATA[huyhieu9900]]></dc:creator><pubDate>Tue, 05 Sep 2023 09:16:26 GMT</pubDate></item><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Mon, 28 Aug 2023 05:43:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huyhieu9900">@<bdi>huyhieu9900</bdi></a> said in <a href="/post/1122495">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">Just connected direct the AP/ client to pfSense and then Captive portal is ready?</p>
</blockquote>
<p dir="auto">Like</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">use dedicated pfSense interface, a cable, a big switch, more switches, and access points.</p>
</blockquote>
<p dir="auto">I know this isn't what you want to achieve, but a captive portal 'wants' to use/see the actual client IP and MAC addresses.<br />
A captive portal, on the pfSense side, is just a set of firewall rules. And these need these two, as there is not else to handle upon.</p>
]]></description><link>https://forum.netgate.com/post/1122669</link><guid isPermaLink="true">https://forum.netgate.com/post/1122669</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Mon, 28 Aug 2023 05:43:34 GMT</pubDate></item><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Sat, 26 Aug 2023 13:59:13 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122289">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">In short: when you use a router in the captive portal network, pfSense (the captive portal) can't "see" the portal user's MAC anymore.</p>
</blockquote>
<p dir="auto">I see, the pfSense has just seen the MAC of router/ONT WAN. not client from router/ONT. So how can I deploy? Just connected direct the AP/ client to pfSense and then Captive portal is ready?</p>
<p dir="auto">Thank you!</p>
]]></description><link>https://forum.netgate.com/post/1122495</link><guid isPermaLink="true">https://forum.netgate.com/post/1122495</guid><dc:creator><![CDATA[huyhieu9900]]></dc:creator><pubDate>Sat, 26 Aug 2023 13:59:13 GMT</pubDate></item><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Fri, 25 Aug 2023 08:53:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huyhieu9900">@<bdi>huyhieu9900</bdi></a> said in <a href="/post/1122287">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">but the basic issue is pfSense didn't allow internet access when enabling CP.</p>
</blockquote>
<p dir="auto">In short: when you use a router in the captive portal network, pfSense (the captive portal) can't "see" the portal user's MAC anymore.</p>
<p dir="auto">The captive protal <em>can</em> work without the MAC information (of every connected client), but that leaves only the IP of the client as a client-identification.</p>
<p dir="auto">See also captive portal issues : <a href="https://docs.netgate.com/pfsense/en/latest/troubleshooting/captiveportal.html" target="_blank" rel="noopener noreferrer nofollow ugc">Troubleshooting Captive Portal</a> which uses a friendly language to tell you you broke 'DNS' <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /><br />
Well, yeah, you shouldn't do that.</p>
]]></description><link>https://forum.netgate.com/post/1122289</link><guid isPermaLink="true">https://forum.netgate.com/post/1122289</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Fri, 25 Aug 2023 08:53:32 GMT</pubDate></item><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Fri, 25 Aug 2023 08:17:55 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">The first issue says 'nothing after LAN works'.<br />
That includes 'captive portal'. Even a PC (world's most simple connection) with a LAN cable won't work.</p>
</blockquote>
<p dir="auto">Yes, in the LAN site, connected by LAN cable, client can receive IP from DHCP server of pfSense, but still can't access internet and redirect to the portal page</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">As already discussed earlier this week, don't put 'routers' in a "captive portal" network.</p>
</blockquote>
<p dir="auto">You mean the ONT. We can't replace ONT because customer requires ONT for accessing internet by Wi-Fi</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">Btw : in the past we always started 'simple' : a WAN, a switch, one or two devices and we build up from there.</p>
</blockquote>
<p dir="auto">I know, the popular topology deploys in the AON infrastructure. But currently, customer has a demand for deploying in the GPON infrastructure. So I need to test based on GPON topology</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">Noop.<br />
Here in France, I've seen a mid size airport hooked (2 million passengers a year) up to a dual HA pfSense. A double 6100. These are running in circles doing close 'nothing'. Hundreds of portal users.<br />
Thousands have been mentioned here for other sides.<br />
Entire schools.</p>
</blockquote>
<p dir="auto">Thank you for your information!</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/gertjan">@<bdi>Gertjan</bdi></a> said in <a href="/post/1122283">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">That's not done anymore ?<br />
I did step-by-step, but the basic issue is pfSense didn't allow internet access when enabling CP.</p>
</blockquote>
]]></description><link>https://forum.netgate.com/post/1122287</link><guid isPermaLink="true">https://forum.netgate.com/post/1122287</guid><dc:creator><![CDATA[huyhieu9900]]></dc:creator><pubDate>Fri, 25 Aug 2023 08:17:55 GMT</pubDate></item><item><title><![CDATA[Reply to Setup a Captive portal for PON Network on Fri, 25 Aug 2023 07:32:04 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huyhieu9900">@<bdi>huyhieu9900</bdi></a> said in <a href="/post/1122087">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<pre><code>When enable Captive portal:

The WAN interface in ONT can't get the IP from DHCP server
Captive portal doesn't work, not redirect to other page (Login or Accept) for accessing Internet
</code></pre>
</blockquote>
<p dir="auto">The first issue says 'nothing after LAN works'.<br />
That includes 'captive portal'. Even a PC (world's most simple connection) with a LAN cable won't work.</p>
<p dir="auto">As already discussed earlier this week, don't put 'routers' in a "captive portal" network.<br />
It's possible, but there is a price to pay.<br />
And you have to face the portal gods .... experts might consider doing this, but no one came back with the 'how it went' story.</p>
<p dir="auto">So : captive portal ? =&gt; Ok, use dedicated pfSense interface, a cable, a big switch, more switches, and access points. Live will be easy.</p>
<p dir="auto">Btw : in the past we always started 'simple' : a WAN, a switch, one or two devices and we build up from there.<br />
The keyword was step-by-step.<br />
That's not done anymore ? <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f60a.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--blush" style="height:23px;width:auto;vertical-align:middle" title=":blush:" alt="😊" /></p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/huyhieu9900">@<bdi>huyhieu9900</bdi></a> said in <a href="/post/1122087">Setup a Captive portal for PON Network</a>:</p>
<blockquote>
<p dir="auto">Do you have the performance review for pfSense?</p>
</blockquote>
<p dir="auto">Noop.<br />
Here in France, I've seen a mid size airport hooked (2 million passengers a year) up to a dual HA pfSense. A double 6100. These are running in circles doing close 'nothing'. Hundreds of portal users.<br />
Thousands have been mentioned here for other sides.<br />
Entire schools.</p>
<p dir="auto">And if things go heavy : take the sledge hammer method : TNSR - and use a dedicated Portal 'server'.</p>
]]></description><link>https://forum.netgate.com/post/1122283</link><guid isPermaLink="true">https://forum.netgate.com/post/1122283</guid><dc:creator><![CDATA[Gertjan]]></dc:creator><pubDate>Fri, 25 Aug 2023 07:32:04 GMT</pubDate></item></channel></rss>