pfSense: Captive Portal
Wednesday, July 22, 2009 at 12:23PM Disclosure: I am not connected with pfSense/BSD Perimeter LLC in any business manner, I am just a user. I created this feature focus for my own reasons but decided to publish it anyway.
Introduction
For the uninitiated pfSense is a standalone firewall/router the is based on FreeBSD which is designed for use on standard PC hardware. It uses the OpenBSD Packet Filter (hence the pf) for the firewall as well as advanced features such as hardware redundancy via CARP, VPN and Load balancing. However I will be talking about an interesting feature called the captive portal on pfSense 1.x and I will also be having a quick look into pfSense 2.0 which is yet to be released.
A captive portal normally sits between the client hosts on the network and the Internet. It normally requires a login from the user before permitting access. This is useful if you wish to allow/deny some people getting online with your wireless at your house party, stop visitors accessing the internet at the office or simply for displaying an acceptable use policy.
Captive portals will normally permit access to a IP/MAC address pair that has been authenticated by the device. As anyone that knows about networking will tell you both MAC and IP address can be easily spoofed by an attacker on a LAN to an already authenticated pair permitting the attackers traffic through the Portal. This weakness is something to keep in mind when thinking of using a captive portal.
Even though a captive portal has this weakness why is a good idea to implement one? It works on any operating system that supports a web browser (Windows, Mac, Linux, BSD, etc) and requires no additional software to be installed on the host computers. These advantages are obviously great from a management perspective by allowing the device to work with any modern operating system and decreasing some administration overhead by not having to manage more software on the client computers.
Services: Captive Portal
All the configuration of the captive portal is done via the Services menu in the web interface. All the standard options are covered such as:
- The network interface that the portal will run on.
- Maximum concurrent connections per user.
- Idle/hard timeout settings.
- Popup logout window so users can end the current session.
Some of the more interesting features that the pfSense portal has to offer are:
- URL redirection.
- Enable/disable concurrent user logins (one IP/MAC pair per user).
- Enable/Disable MAC filtering settings.
- No/Local/RADIUS authentication.
- HTTP/HTTPS (SSL) portal connections.
- Customisable portal pages for legal messages, ASCII art, etc.
Authentication Options
pfSense has a few diffrent authentication options for the captive portal:
- No authentication.
- Local user management.
- RADIUS authentication.
No authentication will allow traffic through the captive portal without authenticating which is useful for the bandwidth limiting feature. The local user management uses the locally stored database to authenticate users, which is handy for smaller networks with small amount of users. RADIUS authentication uses an RADIUS server which is configured separately for more complex environments with many users.
A Pass-through MAC address is an option which allows a configured MAC address to pass through the captive portal without authentication. There is also an option (MAC filtering) that allows you to disable the verification of MAC address which can prove useful if you have routers or other such layer 3 devices in the way of the captive portal and the clients. The 'allowed IP address' is the same idea as the pass-through MAC address but using the IP address instead of MAC address.
The users tab is where all the local accounts that are used for local authentication are managed. The user account controls are basic allowing username, password, full name (not parsed) and account expiration date when creating a new account. Accounts can also be edited and removed from this interface. Pfsense 2.0 will be improving the user account system drastically, for more information see the pfSense 2.0 section below.
HTTPS (SSL) Login
When there is not a HTTPS login option I always feel really uneasy. Thankfully pfSense has such an option if it's not a little tricky to set up. Three things must be there for HTTPS to work, a server name, the certificate (in a X.509 PEM format) and the key (RSA private key PEM format).
The first required step to enabling the SSL login is a server name for checking against the Common Name on the SSL certificate so it doesn't generate a name mismatch error. A certificate and private key must be pasted into the web interface for the SSL connections to be functional. The certificate and key can be easily generated from the tool on the System: Advanced functions page. Please note that a self-signed certificate will display an error message in the client browser unless its set up to trust it.
Customisable Portal Pages
The customisable pages are a nice feature of the portal to help it fit in with a network (e.g. to show a company style login page). The pfSense captive portal allows highly customisable login and error pages by allowing users to upload customised HTML pages with messages about network use or to add company logos (which are managed by the file manager).
The file manager speaks for its self really, it's the place you manage the uploaded files for the customised captive portal pages. It's nice to see that there is a way to keep track of the uploaded files and that they aren't just stuck in a directory out of the way.
Other Features
The URL redirection feature works by changing the website that would be loaded after going through the captive portal. This is useful for an intranet site or a hard to remember external domain that everyone should be directed through.
The per-user bandwidth restrictions allows you to limit the upload and download speed per user. This is a very useful feature to stop people taking up all the bandwidth which works well with the no authentication mode selected.![]()
2.0 Alpha-Alpha features
Note: These features are taken from a pre-release alpha build of pfSense 2.0 (2.0-ALPHA-ALPHA, built on Tue Jun 23 08:18:08 EDT 2009) and anything said here could change before final release.
The new 2.0 release will allow you to run the captive portal on more that one interface, previously you could only use one interface at a time. This is a small improvement that will help administrators of larger networks deal with scalability and bandwidth concerns.
The users tab in the Captive portal UI (Services:Captive portal) will be replaced with a Vouchers tab in version 2.0 since the user account management has been made more system wide.
![]()
2.0 User Manager
While this is not directly a captive portal feature the user manager is a heavy dependency for the local authentication used on many smaller networks. The local user management interface has been moved to System:User Manager (in the System menu under User Manager) and has been vastly improved to support more advanced settings like per user SSH Authorized Keys and will be used in a more system wide manner.

Groups will also be implemented in the User manager so system privileges can limited to only what people require which is naturally a good practice. Restrictions that are assigned to groups, users are then added to groups to have the restrictions applied to their accounts. Restrictions include limiting access to web UI pages and shell access.
A LDAP server backend will be available for user authentication with fall back to the internal user/group database incase of the server being unavailable. This fits in with the vastly upgraded user management system and will surely make administrators happy.
Conclusion
I like to use the captive portal that pfSense provides to allow the use of computers without internet access and allowing other authorised users internet access. I also have used it on a wireless AP (with WPA) to keep some people off the internet while allowing a trusted few at a house party.
The UI on pfSense has a good layout and helpful detailed descriptions for most options which never makes you feel like you need to look up a manual. I have used the pfSense captive portal personally for about 3 months without any stability issues and would be happy to recommend it.


Reader Comments (65)
Nice post, thanks for promoting the project!
i am a user of pfsense and i have notice that when u setup a user and his/her time expires pfsense deletes the account whats with that. i don't know if u have noticed that and if u can help on how to solved that problem
any help will be appreciated TenQ
hassankiara: That's just the way it currently is with pfSense, it deletes the account. It's a shame, I know.
more power to you sir! same with me here, im using pfsense for my office network still at version 1.2.2
The information is very usefull, tahnk you !
Although the ratings of Sunday's CBS Tony telecast might not detect a seismic shift,Tory Burch shoes theater is in danger of becoming popular. Newsweek dubbed this the Mormon moment, but the truth is apparently a lot hammier: It looks like we've all been Tory Burch sale infected by the shameless sparkle of Glee fandom.To no one's surprise, the juggernaut of the season The Book of Mormon held sway.
In this time cheap ed hardy stores.Ed hardy something are very popular. Our shop Wholesale Ed hardy and retail this .We have ed hardy mens clothing sale.Ed hardy T, Ed hardy shoes,Ed Hardy Women Clothing.belt and more I believe Ed Hardy Accessories sales online.you will like it so much In holiday we also retail discount ed hardy women skirt.Ed hardy and you can go here to choose Ed Hardy Womensand buy. Last good luck with you.
I appreciate for your post! I hope you will keep it on. I also want to make friends with you and share my favorite replica to you. I am focus on you.-cheapest Vacheron Constantin Kalla Rome watches
An excellent article to improve people's quality, enhance the knowledge of the grade, I really like this article, and thank you for sharing.P90x Workout Schedule
P90x Dvd
You post is very good!
Where can I get cheap christian louboutin shoes?I know Discount Christian Louboutin are the world well-known brand and really well-liked with stars specially Hollywood
stars and are essentially the most top-level shoe brand. Speaking bluntly, I also appreciate the red sole high heels.
louboutin pas cherlouboutin pas cher
Sandale Christian LouboutinSandale Christian Louboutin
Escarpins LouboutinEscarpins Louboutin
Botte LouboutinBotte Louboutin
De soirée Christian Louboutin shoesDe soirée Christian Louboutin shoes
Christian Louboutin Mary JanesChristian Louboutin Mary Janes
Christian Louboutin avec cale soldesChristian Louboutin avec cale soldes
Christian Louboutin Plats soldesChristian Louboutin Plats soldes
Ed Hardy SaleEd Hardy Sale
ed hardy men clothinged hardy men clothing
ed hardy mens shirtsed hardy mens shirts
ed hardy men shoesed hardy men shoes
ed hardy mens swim trunksed hardy mens swim trunks
mens ed hardy polosmens ed hardy polos
Christian Louboutin ShoesChristian Louboutin Shoes
louboutin pumpslouboutin pumps
christian louboutin wedgeschristian louboutin wedges
louboutin sandalslouboutin sandals
louboutin bootslouboutin boots
Thousands of Factory Audited China Suppliers, China Manufacturers, China Products are seeking Trusted Importers and Exporters on tradetuber.com .wholesale lingerie | wholesale costume | clubwear wholesale | wholesale swimwear | wholesale corset | wholesale Panties | Led Corn Light
Buy $10 Replica Designer Sunglasses with 3-day FREE SHIPPING. At fashion-world4u you find Imitation ,Inspired ,MEN designer Sunglasses and Women Replica Sunglass at cheap discount price. Sunglasses | Replica Sunglasses | Sunglass | Designer Sunglasses
Best Quality Magnetic Jewelry and Magnet Therapy Products - Over 1300 Items that are good for Health as well as Beauty - Free Worldwide Shipping. magnetic jewelry | magnetic therapy | magnetic products | magnetic bracelets | beaded bracelet | bead bracelet
iphone case
iphone cover
iphone cases
iphone covers
iphone 4 case
iphone 4 cover
iphone 3GS case
iphone 4 cases
ipad case
ipad 2 case
ipad 2 cover
Shox pas cher
Basket Nike Pas cher
Air Max pas cher
Nike Air Max pas cher
Air Max 90 pas cher
Nike Air Max 90 Pas cher
Nike pas cher
Air Max 90 pas cher
Chaussures Nike pas cher
ED Hardy Clothing
Christian Audigier
ED Hardy Bags
ED Hardy Handbags
ED Hardy Shoes
ED Hardy T shirts
ED Hardy bikini
Cheap Ed Hardy
ED Hardy
Nike pas cher
Air Max 90 pas cher
Nike Air Max 90 pas cher
Nike Air Max pas cher
Nike Shox pas cher
Basket Nike Pas Cher
Air Max pas cher
Air Max 90
Nike Air Max 90
Nike Air Max
Nike Air Max 95
Air Max
Brian Atwood
Atwood Brian
Brian Atwood Shoes
Atwood Pumps
Brian Atwood Pumps
freelance writer
jingruizm <p>Dispatch of louis vuitton outletNeteaselouis vuitton outlet stores science and louis vuitton outlet onlinetechnology authentic louis vuitton outleton July 26 message, louis vuitton outlet store onlinethe United louis vuitton 2011States pointslouis vuitton outlets to big 3 low.louis vuitton wallets Chinese concept louis vuitton speedymajority drops. Giant network louis vuitton for men(NYSE:GA) goes against louis vuitton shoulder bagcity to go up 0.61 dollars, original louis vuittongo up greatly 8.33% , louis vuitton damierthe newspaper closes at 7.93 dollars. </p><p>Giant network is made the same score almost now, after rising quickly genuine louis vuittonafter open quotation, arrange, appear again when midday one small rises, concussion is arranged louis vuitton cheapafternoon, sign up forauthentic louis vuitton 7.93 dollars finally, achieve went out from louis vuitton suitcase
June first since new tall. Interval of wave motion of giant network share price is 7.31-7.97 dollar now, and 52 weeks fluctuant interval was 6.03-9.45 dollar in the past. (Chi Zhi)</p><p>(Article origin: Report of Netease science and technology)
In the Herve Leger outlet online store, there are coming in many Herve Leger New dresses, they are fashionable,On one
dress of Herve Leger wherever you are you will be the focus.That is why many
Hollywood famous stars choose to. Herve Leger bandage is always binding up with the shining:
Herve Leger Dresses Herve Leger Dresses;
Herve Leger Cheap Herve Leger Cheap;
Herve Leger On Sale Herve Leger On Sale;
Leger Dress Leger Dress;
Herve Leger Outlet Herve Leger Outlet;
Herve Leger Bandage Herve Leger Bandage;
herve leger skirts herve leger skirts;
Herve Leger Swimsuit Sale Herve Leger Swimsuit Sale;
zentai catsuit zentai catsuit;
zentai bodysuitzentai bodysuit;
lycra suit lycra suit;
spandex catsuits spandex catsuits;
spiderman suit spiderman suit;
Christian Louboutin Replica Christian Louboutin Replica;
Christian Louboutin Sale Christian Louboutin Sale;
Cheap Christian Louboutin Cheap Christian Louboutin;
Christian Louboutin Knockoffs Christian Louboutin Knockoffs;
Christian Louboutin Discount Christian Louboutin Discount;
Christian Louboutin Replica Christian Louboutin Replica.
Nice Nike Dunk SBpost. I willnike dunks
Dunk Shoes keep visiting this bloDunk SB
cheap shoesg very often. Thanks for sharing the useful information….Regards,
For seven seasons, Entourage fans have followed the triumphs and trials in the life of <A href="http://www.toryburch.name/products_all.html">Tory Burch shoes</A> Vincent Chase as the movie star character and his pals conquered Hollywood and lived the good life in Los Angeles. In doing so, fiction has altered real life <A href="http://www.toryburch.name/specials.html">Tory Burch sale</A> of Adrian Grenier, who plays Vince. I was a brooding pretentious artist before I met Vince, and I now I'm somewhere in between having mildly good <A href="http://www.toryburch.name/tory-burch-flats-c-1.html">Tory Burch flats</A> taste and being able to just let down your guard and have fun,he actor, 35, told PEOPLE of how his character has changed him. It's all coming to an end, <A href="http://www.toryburch.name/tory-burch-reva-c-9.html">Tory Burch reva</A> though, as Entourage begins its final season on Sunday. Before the curtain draws to a close on the HBO hit, Grenier gives some insight into what to expect <A href="http://www.toryburch.name/tory-burch-sandals-c-5.html">Tory Burch sandals</A> in the final eight episodes, as well as the future of the franchise. Vince Is Clean: In season 7, Vince found himself entangled with a porn star <A href="http://www.toryburch.name/tory-burch-sandals-c-5.html">Tory Burch Miller sandals</A> girlfriend Sasha Grey, and he developed a cocaine habit. Though better now, "he's got to prove that he's over his little snafu with drugs and <A href="http://www.toryburch.name/tory-burch-flats-c-1.html">Tory Burch flat shoes</A> porn stars,Grenier said while hosting a party at Las Vegass Chateau on Friday. I don't think people realize that Vince isn't out of control. On paper <A href="http://www.toryburch.name/tory-burch-reva-c-9.html">Tory Burch reva flats</A> it may seem that way, but I think he was just having a bad week or a bad couple episodes.Have Tissues Nearby: Be prepared for an emotional ending <A href="http://www.toryburch.name/tory-burch-handbags-c-7.html">Tory Burch handbags</A> not just because the show is coming to an end. It's a tear jerker,Grenier said of the series finale. We all end in a very good place but were all <A href="http://www.toryburch.name/tory-burch-boots-c-8.html">Tory Burch boots</A> completely transformed.
iphone case
iphone cover
iphone cases
iphone covers
iphone 4 case
iphone 4 cover
iphone 3GS case
iphone 4 cases
ipad case
ipad 2 case
ipad 2 cover
Shox pas cher
Basket Nike Pas cher
Air Max pas cher
Nike Air Max pas cher
Air Max 90 pas cher
Nike Air Max 90 Pas cher
Nike pas cher
Air Max 90 pas cher
Chaussures Nike pas cher
ED Hardy Clothing
Christian Audigier
ED Hardy Bags
ED Hardy Handbags
ED Hardy Shoes
ED Hardy T shirts
ED Hardy bikini
Brian Atwood Pumps