Back

Networking ·2025 · Live

pfSense captive portal with vouchers

Migrated a WPA2-Enterprise (802.1X / RADIUS) WiFi to an open network with a captive portal, reusing the existing RADIUS as the user store and adding guest vouchers.

The WiFi ran WPA2-Enterprise with RADIUS. It worked, but it locked out guests and every device that could not speak 802.1X.

The migration moved the network to open + pfSense captive portal while keeping the same RADIUS server as the user store, so nobody had to change their password.

Guests got a voucher system with expiry, and the portal pages (login, error and logout) were hand-written so the experience would not look like a router form.

Highlights

  • Authentication against the existing RADIUS, no credential migration
  • Expiring vouchers for guests
  • Custom responsive login, error and logout pages
  • Works with devices that cannot do 802.1X (IoT, consoles, TVs)

Stack

  • pfSense
  • FreeRADIUS
  • 802.1X
  • HTML
  • CSS
  • Redes WiFi

Private repository — Code available on request

Sections

Actions