This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Clients not connecting to Captive Portal behind RED60 with bridge to VLAN

Hello,

We have a RED60 with several VLANs tagged. One of these VLANs is for external WiFi users.

The APX320's are managed in Sophos Central. The AP's management IP's are in a different VLAN so the AP cannot directly communicate with the client or vice versa.

The SSID has a password and bridges into the VLAN and Hotspot is enabled so client isolation is also automatically enabled.

The external users know the WiFi password for the SSID and the password for the Hotspot and we want them to agree to our rules of usage. Thats all.

The Problem is, the clients authenticate to the SSID and then are not redirected to the captive portal. If they try to access a website the request times out.

In packet capture on our firewall I see positive DNS requests for the websites, e.g. google.com but the devices do not seem to try to access any captive portal page.

I found this old thread, but I hope after 3 years, there is a fix or this is about an other issue..

Hotspot Captive Portal not working with VLAN tagging

Any hint for me what to look for?



This thread was automatically locked due to age.
  • This is what such a client does right when it connects to Guest WiFi and tries to access google
    192.0.0.1 = RED IP in this VLAN
    192.0.0.2 = Client IP in this VLAN received by DHCP Server on the RED/XG Firewall ant HQ.

    Fullscreen
    1
    2
    3
    4
    5
    6
    7
    8
    9
    10
    11
    12
    13
    14
    15
    16
    17
    18
    19
    20
    21
    1 11:02:50,012432 EndpointMACAddress ARP 62 Who has 192.0.0.1? Tell 192.0.0.2
    2 11:02:50,012432 EndpointMACAddress ARP 58 Who has 192.0.0.1? Tell 192.0.0.2
    3 11:02:50,012440 RedMACAddress ARP 44 192.0.0.1 is at RedMACAddress
    4 11:02:50,020323 192.0.0.2 192.0.0.1 DNS 60330 53 95 Standard query 0x704c A connectivitycheck.gstatic.com
    5 11:02:50,020323 192.0.0.2 192.0.0.1 DNS 60330 53 91 Standard query 0x704c A connectivitycheck.gstatic.com
    6 11:02:50,020389 192.0.0.1 192.0.0.2 DNS 53 60330 107 Standard query response 0x704c A connectivitycheck.gstatic.com A 216.58.206.3
    7 11:02:50,023867 EndpointMACAddress ARP 62 Who has 192.0.0.1? Tell 192.0.0.2
    8 11:02:50,023867 EndpointMACAddress ARP 58 Who has 192.0.0.1? Tell 192.0.0.2
    9 11:02:50,023873 RedMACAddress ARP 44 192.0.0.1 is at RedMACAddress
    10 11:02:50,046589 192.0.0.2 192.0.0.1 DNS 22702 53 80 Standard query 0x59b5 A www.google.com
    11 11:02:50,046589 192.0.0.2 192.0.0.1 DNS 22702 53 76 Standard query 0x59b5 A www.google.com
    12 11:02:50,046687 192.0.0.1 192.0.0.2 DNS 53 22702 92 Standard query response 0x59b5 A www.google.com A 172.217.23.100
    13 11:02:50,072500 192.0.0.2 192.0.0.1 DNS 25713 53 108 Standard query 0xfd5a A epdg.epc.mnc001.mcc262.pub.3gppnetwork.org
    14 11:02:50,072500 192.0.0.2 192.0.0.1 DNS 25713 53 104 Standard query 0xfd5a A epdg.epc.mnc001.mcc262.pub.3gppnetwork.org
    15 11:02:50,072618 192.0.0.1 192.0.0.2 DNS 53 25713 200 Standard query response 0xfd5a A epdg.epc.mnc001.mcc262.pub.3gppnetwork.org A 109.237.187.225 A 109.237.187.129 A 109.237.187.130 A 109.237.187.226 A 109.237.187.131 A 109.237.187.227
    16 11:02:50,093047 192.0.0.2 192.0.0.1 DNS 16633 53 82 Standard query 0xeecc A mtalk.google.com
    17 11:02:50,093047 192.0.0.2 192.0.0.1 DNS 16633 53 78 Standard query 0xeecc A mtalk.google.com
    18 11:02:50,093147 192.0.0.1 192.0.0.2 DNS 53 16633 123 Standard query response 0xeecc A mtalk.google.com CNAME mobile-gtalk.l.google.com A 64.233.167.188
    19 11:02:50,164626 192.0.0.2 192.0.0.1 DNS 12922 53 87 Standard query 0x4b9a A alt8-mtalk.google.com
    20 11:02:50,164626 192.0.0.2 192.0.0.1 DNS 12922 53 83 Standard query 0x4b9a A alt8-mtalk.google.com
    21 11:02:50,179226 192.0.0.1 192.0.0.2 DNS 53 12922 134 Standard query response 0x4b9a A alt8-mtalk.google.com CNAME alt8.mobile-gtalk4.l.google.com A 173.194.201.188
    XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX