Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Captive Portal fails regularly after upgrading from 2.0.1 to 2.0.2

    Scheduled Pinned Locked Moved Captive Portal
    43 Posts 15 Posters 27.8k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • E Offline
      eri--
      last edited by

      @heper:

      yesterday i've deployed 2.0.3 with a ssl cert from startssl & Radius auth on a Win2K8r2

      i've seen that too:

      Jan 31 19:57:20 	lighttpd[21213]: (connections.c.305) SSL: 1 error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
      Jan 31 19:57:20 	lighttpd[21213]: (connections.c.305) SSL: 1 error:140760FC:SSL routines:SSL23_GET_CLIENT_HELLO:unknown protocol
      

      doesn't seem to affect the portal … i've had +40 portal users all day without complaints

      That's just a warning because it tries to forward anything on tcp to port 80 which has been reduced only to tcp traffic on 2.1 version of pfSense.
      Since the client is trying an https://www.pfsense.org but the firewall redirection sends it to a simple HTTP talking webserver you get the warning.

      1 Reply Last reply Reply Quote 0
      • E Offline
        eri--
        last edited by

        @Abdsalem:

        Running latest snapshot of PRERELEASE-2.0.3 (31/01/2013)

        I can also confirm what the last 2 posters have reported, though it doesnt seem to affect the CP users.

        I am also seeing a lot of the following.

        Jan 31 20:23:57 lighttpd[18696]: (connections.c.137) (warning) close: 25 Connection reset by peer
        Jan 31 20:23:57 lighttpd[18696]: (connections.c.137) (warning) close: 25 Connection reset by peer

        Jan 31 20:02:55 lighttpd[18696]: (request.c.1133) GET/HEAD with content-length -> 400
        Jan 31 20:02:55 lighttpd[18696]: (request.c.1133) GET/HEAD with content-length -> 400

        Jan 31 19:56:03 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'redirurl' (attacker '10.0.0.109', file '/usr/local/captiveportal/index.php')
        Jan 31 19:56:03 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'redirurl' (attacker '10.0.0.109', file '/usr/local/captiveportal/index.php')

        Jan 31 17:55:50 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'info_hash' (attacker '10.0.0.78', file '/usr/local/captiveportal/index.php')
        Jan 31 17:55:50 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'info_hash' (attacker '10.0.0.78', file '/usr/local/captiveportal/index.php')

        Jan 31 17:35:49 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'checklic' (attacker '10.0.0.74', file '/usr/local/captiveportal/index.php')
        Jan 31 17:35:49 lighttpd[18696]: (mod_fastcgi.c.2676) FastCGI-stderr: ALERT - ASCII-NUL chars not allowed within request variables - dropped variable 'checklic' (attacker '10.0.0.74', file '/usr/local/captiveportal/index.php')

        There have been some more fixes after that specifically for this.
        Actually in general you will get better performance from 2.0.[2|3] than 2.0.1 since of a bug in php.

        1 Reply Last reply Reply Quote 0
        • M Offline
          m4st3rc1p0
          last edited by

          hi, its not working for me, im using mac address to pass via portal and its not working, the only thing that works is that when you put the ip address of the said station. Can anyone help ?

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.