Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Use pfsense as a wifi captive portal

    Scheduled Pinned Locked Moved Problems Installing or Upgrading pfSense Software
    3 Posts 2 Posters 1.7k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sandman42
      last edited by

      Hi,

      I'd like to use pfsense as a wifi captive portal: authorised users may connect to it via an external access point and go to internet

      Therefore I have installed it with two nics: one on the WLAN network, say 192.168.2.x and one on the LAN network, say 192.168.1.x.

      WLAN network has an access point (192.168.2.253) that handles Wi-fi connection, LAN has internet connection, i.e. there is a firewall and a router to internet.
      What I'd like to do is assign a daily ticket to a user, so this user connects to wifi, is forced to authenticate, and only after that is allowed to use internet, i.e. I have to allow some sort of routing (I think) between 192.168.2 and 192.168.1.254 (the internet firewall on LAN).

      My question is: how can I do that? Is it correct to do that? Can you point me to a correct solution???

      Thanks

      1 Reply Last reply Reply Quote 0
      • P
        phil.davis
        last edited by

        The routing stuff seems straightforward:
        The WLAN side is your pfSense LAN 192.168.2.0/24
        Your LAN is the pfSense WAN 192.168.1.0/24
        On the pfSense WAN you could:
        a) specify a WAN interface IP that is not used in 192.168.1.0/24 - e.g. 192.168.1.253/24 - and set the WAN gateway to 192.168.1.254 and DNS server to whatever; or
        b) use DHCP on WAN and your real internet firewall at 192.168.1.254 can give you an IP, gateway and DNS.
        If you can modify your real internet gateway to add a route back to 192.168.2.0/24 then you can turn off NAT on the pfSense - no need to end up with "double NAT" if you don't have to.

        As the Greek philosopher Isosceles used to say, "There are 3 sides to every triangle."
        If I helped you, then help someone else - buy someone a gift from the INF catalog http://secure.inf.org/gifts/usd/

        1 Reply Last reply Reply Quote 0
        • S
          sandman42
          last edited by

          It works.

          Thanks!!! :)

          1 Reply Last reply Reply Quote 0
          • First post
            Last post
          Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.