Captive Portal IPv6 Support
11–20 of 57 posts
Re: Captive Portal IPv6 Support
#12Earlier quoted context omitted.
You’re going to have to explain that one. I don’t see how CGNAT does anything but allow easier access to attacks (using private ip space outside of the local network)
All the details can be found in the EUROPOL publications begging for it to be banned.
Re: Captive Portal IPv6 Support
#13Earlier quoted context omitted.
You’re going to have to explain that one. I don’t see how CGNAT does anything but allow easier access to attacks (using private ip space outside of the local network)
All the details can be found in the EUROPOL publications begging for it to be banned.
It's nearly 8 years later, we haven't moved to IPv6, and they stopped making noise so I'm left to assume they either got more source port logging or found some other method?
Re: Captive Portal IPv6 Support
#14As much as we need infrastructure to move us all the way to IPv6 (no more CGNAT please!), I'm not sure I want more captive portals in the world. I'd much rather an addition to the WiFi standard to support interactive login, though I suppose that would be hard pressed to come by now.
Something like a DHCP option or NDP option ends up being a lot more natural: "Hey, here's your IP along with the information needed to access the network" is already a function of that layer. Some devices (e.g. macOS/iOS/iPadOS, Windows, Android) take a similar approach in the reverse by probing for a specific test url. That's also a bit hacky and unreliable (e.g. it can falsely trigger) but some minor standardization of it to e.g. a well known DNS name could be another good option.
Re: Captive Portal IPv6 Support
#15Earlier quoted context omitted.
Just give internet access directly. Or do not offer internet access at all. People carry their own already-connected devices anyway.
What if legal wants to show a TOS page, or you want finer grained authentication than a shared key? >Or do not offer internet access at all. People carry their own already-connected devices anyway. Travelers don't typically have gigabytes of bandwidth to spare. I for one like having unmetered internet access even when there's theoretically internet access available through roaming (absurdly expensive) or esims (expen…
The reality is that nobody wants to bother with any of that.
Either just connect me to the internet without extra steps, or don't at all. Don't waste my time.
Re: Captive Portal IPv6 Support
#16As much as we need infrastructure to move us all the way to IPv6 (no more CGNAT please!), I'm not sure I want more captive portals in the world. I'd much rather an addition to the WiFi standard to support interactive login, though I suppose that would be hard pressed to come by now.
It's really a business problem. IMO you shouldn't have to solve this just because you've gone indoors – you already pay a carrier for connectivity – but many carriers don't want to own that responsibility.
Re: Captive Portal IPv6 Support
#17Earlier quoted context omitted.
Just give internet access directly. Or do not offer internet access at all. People carry their own already-connected devices anyway.
What if legal wants to show a TOS page, or you want finer grained authentication than a shared key? >Or do not offer internet access at all. People carry their own already-connected devices anyway. Travelers don't typically have gigabytes of bandwidth to spare. I for one like having unmetered internet access even when there's theoretically internet access available through roaming (absurdly expensive) or esims (expen…
Configure your access points to use RADIUS or SAML for auth?
Re: Captive Portal IPv6 Support
#18Earlier quoted context omitted.
What if legal wants to show a TOS page, or you want finer grained authentication than a shared key? >Or do not offer internet access at all. People carry their own already-connected devices anyway. Travelers don't typically have gigabytes of bandwidth to spare. I for one like having unmetered internet access even when there's theoretically internet access available through roaming (absurdly expensive) or esims (expen…
>What if legal wants to show a TOS page? The reality is that nobody wants to bother with any of that. Either just connect me to the internet without extra steps, or don't at all. Don't waste my time.
I don't either, but for IT departments in large organizations, ignoring the legal department isn't an option.
Re: Captive Portal IPv6 Support
#19Earlier quoted context omitted.
What if legal wants to show a TOS page, or you want finer grained authentication than a shared key? >Or do not offer internet access at all. People carry their own already-connected devices anyway. Travelers don't typically have gigabytes of bandwidth to spare. I for one like having unmetered internet access even when there's theoretically internet access available through roaming (absurdly expensive) or esims (expen…
> or you want finer grained authentication than a shared key? Configure your access points to use RADIUS or SAML for auth?
Re: Captive Portal IPv6 Support
#20Earlier quoted context omitted.
What if legal wants to show a TOS page, or you want finer grained authentication than a shared key? >Or do not offer internet access at all. People carry their own already-connected devices anyway. Travelers don't typically have gigabytes of bandwidth to spare. I for one like having unmetered internet access even when there's theoretically internet access available through roaming (absurdly expensive) or esims (expen…
>What if legal wants to show a TOS page? The reality is that nobody wants to bother with any of that. Either just connect me to the internet without extra steps, or don't at all. Don't waste my time.