Captive Portal Re-authentication
Captive Portal Re-authentication
- Free voucher:
- rate limited 1500Kbs,
- unlimited for usage.
- Duration by time: 9999 days, so it never expires.
- Special Voucher:
- rate limited 6Mbs,
- limited online users 1,
- Duration by time: 1 day.
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
When you are authenticated, you will not be asked to authenticate again before the time has expired. You must go to hotspot management and log the user out of the portal if you want to be authenticated again before the time you have set has expired. The users should probably have one of the profiles so it is probably not a problem, but if you are going to test, log yourself out of the hotspot portal,
- Copy Link
- Report Inappropriate Content
@MR.S , so there is no way for a user to log themselves out, in order to use a faster voucher?
pfSense for example allows for user to be auto logged off, if idle for a set amount of time. It does not mean their voucher is invalid, they can log in again and continue using it. This makes sense when a voucher is time based where time only counts as user is connected.
In my case I would have customers connect to free voucher, only later decide they want faster speed, maybe to watch netflix or something. That can only be accomplished, if they have a way to log off somehow or the voucher expires. The normal "portal.tplink.net/portal/logout" does not appear to be working for new EAP625 APs, as such my customers have no way to log off and switch vouchers.
Are their API commands I can use from a remote host on the same subnet that can be used to send a log off signal on behalf of the customer?
Thanks for your reply...much appreciated.
- Copy Link
- Report Inappropriate Content
Followup reply.... I updated my EAP625 to latest firmware, turns out they do support logout command, however after logging into port and then visiting " portal.tplink.net/portal/logout " it does not work. I assume I need to change this URL to actually hit my OC200 controller. Any info on how to do that? Allowing a way to logoff of the free voucher would allow my customers a quick way to re-auth for faster speed vouchers.
- Copy Link
- Report Inappropriate Content
Hi @Swicago
Is your EAP625-outdoor HD?
We don't need to change that URL, normally, clients should be able to logout via the URL portal.tplink.net/portal/logout
What will happen when clients access to that URL?
BTW, we have a pre-release version for OC200, you may update it and see if that helps.
Hardware Controller (Built-in Omada SDN Controller V5.15.6.25) Pre-release
One more thing, only certain EAP with the latest firmware support Portal logout. For those clients that connecting to these EAPs, it won't take effective either.
- Copy Link
- Report Inappropriate Content
Yes, it is EAP625-outdoor HD, hardware version v1.6 on latest 1.3.1 Build 20240929 Rel. 44649
OC200 is running latest stabile 2.17.6 Build 20241101 Rel.44787
The URL portal.tplink.net/portal/logout does nothing, even though it is enabled in the voucher.
I even made sure firewall has given full access to clients connected to EAP-625, to rule it out. I confirmed by being able to load the OC200 config page from my connected client, andriod.
Per OC200 my EAP625 should support the feature. It is not listed as the unsupported per the Devices->Configuration Results->Incompatable section. It was before the firmware updates.
Is there a direct URL for the logout page? Like a direct URL to the portal page? OC200_IPADDRESS:8088/portal/logout ??? This URL does not work, so it must be something else.
Is there a way to change to URL on the OC200? tplink.net is a real domain and redirects to /www.aerial.net/shop/ .. Maybe that is the issue, Once logged into portal, the DNS sees this as a real domain. DNS is not controlled by Omada, but by a pfSense router. Per OC200 config page under voucher, it says the URL can be changed in omada.properties, but how. is there an SSH login for OC200 to change the URL? Seems pretty bad to have left out an easy way to change this url to a custom branded one.
As for visiting the URL, it does nothing. Chrome just says the following
Hmm. We’re having trouble finding that site.
We can’t connect to the server at portal.tplink.net.
If you entered the right address, you can:
-
Try again later
-
Check your network connection
-
Check that Firefox has permission to access the web (you might be connected but behind a firewall)
Let me know what else I can try? You mention a beta OC200 firmware, can I roll back to stabil if it does not work? If so what are the instructions for that?
Thanks, much appreciated
- Copy Link
- Report Inappropriate Content
Hi @Swicago
We were testing this issue and have some clues.
To answer your questions:
1. To change the logout URL, we added an option on the controller interface on controller 5.15.24, please kindly wait.
2. We can manually downgrade the firmware of the OC200, below is the guide:
How to Upgrade or Downgrade Omada SDN ControllerHow to Upgrade or Downgrade Omada SDN Controller
As for the logout URL not working issue, we would like to know the following:
1. What kind of clients are connecting to the portal network?
2. What kind of web browsers are these clients using?
3. Does the logout URL never work on your side? It sometimes works in our local lab.
- Copy Link
- Report Inappropriate Content
I just got back from holiday. I have upgraded the OC200 formware to 2.18.5 Build 20241211 Rel.56161 (Beta)
There is still no where a place to change the portal logout URL. It is still stuck with portal.tplink.net/portal/logout and a message stating "You can change the default URL by editing portal.logout.domain in the omada.properties file. Some devices may require firmware update to support Portal Logout. Please refer to Configuration Result for details." However, there is no where on the OC200 I can doanload or upload omada.properties
And the URL portal.tplink.net/portal/logout does not work, even though ,my AP ( EAP625-Outdoor HD(US) v1.0 ) running latest firmware 1.3.1 Build 20240929 Rel. 44649 says it supports portal logout.
I even tried direct IP to logout, but it either says cannot access page or just hangs
Tried the following {CONTROLLER_IP}:8088/portal/logout
{CONTROLLER_IP}:8843/portal/logout
Ports are not blocked, for testing I allowed full acces across all tcp/udp for IPs coming from AP and was able to load controller page via {CONTROLLER_IP}, so nothing is preventing me from reaching the controller.
Portal signin and voucher system works fine, I just cannot log out, which I need to work.
Thanks
- Copy Link
- Report Inappropriate Content
Hi @Swicago
Thanks for your reply.
Can you please answer questions below:
1. What kind of clients are connecting to the portal network?
2. What kind of web browsers are these clients using?
3. Does the logout URL never work on your side? It sometimes works in our local lab.
- Copy Link
- Report Inappropriate Content
Vincent-TP wrote
Hi @Swicago
Thanks for your reply.
Can you please answer questions below:
1. What kind of clients are connecting to the portal network?
2. What kind of web browsers are these clients using?
3. Does the logout URL never work on your side? It sometimes works in our local lab.
1) Android clients using latest Andriod OS
2) Chrome for Andriod using latest version
3) Never works, ever.
Not really a good system, if even your local lab only sometimes works.
Again, is there no way to use a direct link to the controller???
{controller_IP:PORT}/portal/logout
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 366
Replies: 13
Voters 0
No one has voted for it yet.