Flex H - Camtive portal

Options
Sartoretto_2025
Sartoretto_2025 Posts: 2 image  Freshman Member

We verified a configuration that the customer requested, which was to define only certain PCs on the LAN that would be restricted via captive portal. We contacted Zyxel support, and they confirmed that, as with the ATP series, it's not possible to specify an IP range excluded from the captive portal feature managed on the same network. Only individual IPs, interfaces, or services can currently be excluded. This limitation is very frustrating and limits the functionality often used on the ATP series.

All Replies

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,263 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Sartoretto_2025

    Could you describe more details with us? The specific LAN has lots of devices, like printer, IP phone, IoT devices, PCs, and you want only PCs need to authenitcation by captive portal?

    Zyxel Melen


  • Zyxel_Melen
    Zyxel_Melen Posts: 4,263 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Sartoretto_2025

    The next firmware, V1.36, will support selecting an address or address group in the source address for specific interface.

    image.png

    Does this match your requirement?

    Zyxel Melen


  • mjr
    mjr Posts: 39 image  Freshman Member
    First Comment Friend Collector Seventh Anniversary

    Hello!

    How can I select Incoming "WAN" as source for the captive portal?

    Best regards,

    MJR

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,263 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @mjr

    Captive portal is a gatekeeper positioned between clients and the internet. You cannot freely access the internet until you complete the actions it requires. If you want to access LAN from WAN, what you should configure is the security policy/firewall rule. Or, connect the remote access VPN.

    Zyxel Melen


  • mjr
    mjr Posts: 39 image  Freshman Member
    First Comment Friend Collector Seventh Anniversary

    with the Usg flex (pre H) it was possible to configure a security policy/firewall rule/NAT (access LAN from WAN), which was bound to a specific user/user group. the user had to logon to the firewall (via webinterface), authenticate and afterwards the connection was allowed.

  • Lucas_Wilson
    Lucas_Wilson Posts: 5 image  Freshman Member
    Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    @Zyxel_Melen I'd also really like this feature to be added to the H Series, as @mjr says, it was available on the legacy USG Flex series.

    Our issue is that some of our customers would like 2FA (via google authenticator or otherwise) for VPN clients, we've even seen some cyber insurance companies requesting 2FA as a requirement for remote VPN access. Currently on the USG Flex H series there is no way to redirect VPN clients to a captive portal before granting them access to the network.

    I think this would be a fantastic feature to add in, and would definitely increase the security of the H series devices.

  • mjr
    mjr Posts: 39 image  Freshman Member
    First Comment Friend Collector Seventh Anniversary
  • Lucas_Wilson
    Lucas_Wilson Posts: 5 image  Freshman Member
    Zyxel Certified Network Engineer Level 1 - Nebula First Comment Friend Collector

    To clarify, I'm aware that the 2FA feature comes with the licence-based (paid) SecuExtender client, and upon connection the user is then redirected to the firewall for 2FA, but I feel as though this should be available with the native Windows or Mac VPN clients. If the IKE VPN could be selected as an incoming interface for captive portal, I feel as though this would solve the problem.

  • Zyxel_Melen
    Zyxel_Melen Posts: 4,263 image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @Lucas_Wilson

    The native VPN clients doesn't support auto-redirect/auto-popout 2FA authentication page. And the captive portal is to recognize the user when accessing specific zone/interface/subnet, not for authentication part of remote access VPN connecting. These are different scenarios.

    Zyxel Melen