Nice idea, but if I disallow access to my LAN, how are the users to get to my internal DNS servers? ๐Ÿ™„
Solved it by setting the Captive Portal to not capture traffic destined for my LAN, and setting some Firewall rules to block that access ๐Ÿ˜†

Cheers, Andy E.