Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I've just noticed a slight issue with the guest wireless I've setup recently. After going around the houses with Unifi captive portal not working on separate VLANs I decided to setup a separate captive portal using OPNSense. This works great on Android and iOS as option 114 on DHCP sets the captive portal page to https://domain.name:8000. However, for Windows devices they don't read option 114 so it relies on http/https redirection.

I realise my error when I look at the routes. In order for the traffic to be filtered the DNS and gateway addresses are pointing to the Smoothwall. If I change it and point to the OPNSense box I can get it to work with a rule in place to intercept traffic and redirect it to the captive portal page. It'll try to load msftconnecttest and redirect to https://domain.name:8000 (which is great). However I need to recreate this on the Smoothwall so the traffic is filtered. From what I've worked out it's the NAT that does the job, redirecting all traffic through to the portal as shown in: Captive portal & GuestNET — OPNsense documentation

The Smoothwall sits behind OPNSense with a bridge acting as a bump between for captive portal. It doesn't need to do any typical firewall stuff as once it's passed the traffic over the Smoothwall handles the firewall. Any ideas how I can do this with a Smoothwall NAT?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...