Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login
    Introducing Netgate Nexus: Multi-Instance Management at Your Fingertips.

    Captive Portal using domain name not working

    Scheduled Pinned Locked Moved Captive Portal
    5 Posts 2 Posters 1.9k Views 2 Watching
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • R Offline
      richardsago
      last edited by

      Good day. Please let me know where my mistakes are. When I setup captive portal to use domain name of pfsense it's not working but if I deactivate domain name in captive portal it works.

      A. This is when captive portal is set to use domain name of pfsense and will not work:

      Services > Captive Portal > Configuration > Login [enable]. I think "HTTPS server name" is one of the mistakes but I don't know what value to replace it. Its current value is the "hostname" + "domain" that is found in System > "General Setup" and with working acme certificate. And opening pfsense in a browser using this hostname and domain is working
      ff6f1913-1df6-4fd8-bc34-f1853c4b4ccb-image.png

      Connect the computer to the captive portal WFi, then open a browser and then click "Open network login page"
      ebb75e7a-3491-4849-a9ad-1573ef64e9e6-image.png

      It will not go to the captive portal webpage:
      eb7185f2-0100-41af-b290-6eb42903ef14-image.png

      B. This is when captive portal is set to use IP address of pfsense and will work:

      Services > Captive Portal > Configuration > Login [disable]
      b894efd6-9108-4e4a-87c4-68aa841e75b9-image.png

      Connect the computer to the captive portal WFi, then open a browser and then click "Open network login page"
      2d0213a2-1ea9-4e40-91a9-0fe4ebefebff-image.png

      The captive portal will be displayed
      537ea5b8-dd23-4062-812c-1ed689b614cf-image.png

      After a correct voucher code is entered then the device will be connected to the internet
      71f4e76c-5e38-462f-bca6-1e4774259d10-image.png

      C. These are screenshots of other settings that may be helpful in diagnosing:

      System > "General Setup" > hostname + domain is the value used in Services > Captive Portal > Configuration > "HTTPS server name"
      499f5c55-0e3e-4c7e-b16e-439ed75df37b-image.png

      System > Advanced > "Admin Access" > "SSL/TLS Certificate" is the value used in Services > Captive Portal > Configuration > "SSL/TLS Certificate"
      cfc29340-c420-46b3-bd9f-a23389ec2970-image.png

      The acme certificate is working:
      7bbe496a-84e5-45ad-9947-406441eeb588-image.png

      Did not add "hostname" + "domain" of System > "General Setup" to System > Advanced > "Admin Access" > "Alternate Hostnames" because opening pfsense using hostname + domain is already working
      2a8f4109-9eb6-408c-8b03-3ffc385fad66-image.png

      Also did not add pfsense's hostname and domain in Services > "DNS Resolver" > "General Settings" > "Host Overrides" and "Domain Overrides" because opening pfsense using hostname + domain is already working
      ba6437e7-da3c-4bac-8dc9-59505172e744-image.png

      GertjanG 1 Reply Last reply Reply Quote 0
      • GertjanG Online
        Gertjan @richardsago
        last edited by Gertjan

        @richardsago

        Your Captive portal is using the pfSense LAN as it's interface ?
        Normally, the pfSense LAN is a trusted network, you connect your own trusted devices, and you use LAN to access the pfSense GUI for administration etc.
        A captive portal is by nature a non-trusted network, so this can't be the LAN, but some other OPTx interface. This interface will contain firewall rules that apply to your portal visitors.

        I'm not saying that the captive portal network can't be LAN, but it's a bit 'strange'.

        Can you test this : connect your device to the portal network - no need to login. Can you show this :

        ipconfig /all
        

        Remember : DHCP and DNS should work.

        edit :
        @richardsago said in Captive Portal using domain name not working:

        After a correct voucher code is entered then the device will be connected to the internet

        If you don't user 'users' and 'password', you can remove this part :

        aa80af02-1f6a-4856-9e02-270e2d1677fe-image.png

        so only

        a23fa2b7-c766-4e33-97f3-9fa27d4be1c6-image.png

        shows up.

        No "help me" PM's please. Use the forum, the community will thank you.

        R 1 Reply Last reply Reply Quote 0
        • R Offline
          richardsago @Gertjan
          last edited by

          Thank you @Gertjan for the reply. Here is the output of ipconfig /all
          294e4673-869a-47bb-8b60-10b58300d04e-image.png

          The captive portal is set to VLAN 70. How do I get around to making captive portal work using domain name, without using pfSense LAN?

          GertjanG 1 Reply Last reply Reply Quote 0
          • GertjanG Online
            Gertjan @richardsago
            last edited by

            Ok, the image shows that the gateway == the DNS. That's good.

            @richardsago said in Captive Portal using domain name not working:

            The captive portal is set to VLAN 70

            That's can be an additional source of issues.
            Before activating pfSense you have to be sure that the VLAN setup works. This means that the VLAN setup of pfSense matches the VLAN setup of your VLAN capable switch.
            Or, you use VLAN capable access points.
            VLAN settings need to be tested and validated before activating the portal.

            @richardsago said in Captive Portal using domain name not working:

            How do I get around to making captive portal work using domain name, without using pfSense LAN?

            That's what I use : a dedicated interface for the portal.
            I didn't have a choice as my captive portal is used by 'unknown' strangers that 'I don't trust'. I use the captive portal for what it was meant to be used (why it was created) : I use the portal for a hotel, so my hotel clients use the hotel portal (wifi) access.

            You actually mentioned already all the needed steps.

            I picked a local network interface (and called PORTAL) for the captive portal :

            3d388b4e-0a9d-43d9-88f9-1a2799a550b1-image.png

            Btw : my pfSense certificate is a wildcard certificate.
            As I own (rent actually) the domain name :
            0d69a77a-5e9f-4575-b555-5290ee304413-image.png

            I set up acme.sh to get a wildcard *.my-hotel-domain.tld certificate.
            My pfSense GUI uses this certificate, so pfsense.my-hotel-domain.tld which already resolves to 192.168.1.1 (and the IPv6 equivalent) will work just fine.

            For the portal, I used this :

            1b0cfcb7-4e04-4d78-98ab-1ca79c57fec4-image.png

            and selected of course the same certificate to be used.

            https is URL or host name based**, so I have to tell pfSense, the resolver, what IP "portal.my-hotel-domain.tld" is.
            easy, you've said so yourself : I created a Host Overrides (resolver settings page) so from now on, when a web browser uses portal.my-hotel-domain.tld it will find 192.168.2.1 (my PORTAL pfSense IPv4).

            ** I think - check first, that you can now also add IPv4 as a SAN for the certificate. But for me, it's way better the client sees portal.my-hotel-domain.tld - showing IPs in an URL can be considered 'scarry'.

            For testing purposes, set up a pass all firewall rule on the PORTAL interface.

            2ad00fc8-bdbc-4baf-8760-d7494524fff8-image.png
            You can change it later, add more rules, for more control.

            Don't forget to set up the DHCP server for the portal interface and give it a big pool like 192.168.2.10 -> 192.168.2.254.

            Have a look at the pfSense /etc/hosts file.

            No "help me" PM's please. Use the forum, the community will thank you.

            R 1 Reply Last reply Reply Quote 1
            • R Offline
              richardsago @Gertjan
              last edited by

              Thank you @Gertjan for the reply. I followed your guide and it works after these steps:

              1. Add a new SAN for the portal in acme
              2. Generate updated acme certificate that now includes the portal SAN
              3. Add this new portal in System > "DNS Resolver" > "General Settings" > "Host Overrides" pointing to the portal IP
              4. Change Services > "Captive Portal" > "HTTPS server name" to point to the new portal SAN
              1 Reply Last reply Reply Quote 1
              • R richardsago referenced this topic
              • First post
                Last post
              Copyright 2026 Rubicon Communications LLC (Netgate). All rights reserved.