Back
Networking ·2025 · Live
pfSense captive portal with vouchers
Migrated a WPA2-Enterprise (802.1X / RADIUS) WiFi to an open network with a captive portal, reusing the existing RADIUS as the user store and adding guest vouchers.
The WiFi ran WPA2-Enterprise with RADIUS. It worked, but it locked out guests and every device that could not speak 802.1X.
The migration moved the network to open + pfSense captive portal while keeping the same RADIUS server as the user store, so nobody had to change their password.
Guests got a voucher system with expiry, and the portal pages (login, error and logout) were hand-written so the experience would not look like a router form.
Highlights
- Authentication against the existing RADIUS, no credential migration
- Expiring vouchers for guests
- Custom responsive login, error and logout pages
- Works with devices that cannot do 802.1X (IoT, consoles, TVs)
Stack
- pfSense
- FreeRADIUS
- 802.1X
- HTML
- CSS
- Redes WiFi
Private repository — Code available on request