I’m trying to apply the Captive Portal over a VPN (Host-to-LAN) link, but it passthrough. This VPN is made from the internal interface, and I use the Source NAT routing method. It’s possible?
How to assign more than a class of IP on VPNs? How to assign a specific IP for a user determined on VPN?
The VPNs L2TP/IPSec for Road Warrior connections use point-to-point interfaces and at the moment it is not possible to apply the captive portal to these interfaces. I don’t understand why you want to protect the VPNs host-to-LAN with the il web login. The VPNs are already authenticated by x.509 certificates and Kerberos passwords.
I use this in a small ISP. It would be useful since my customers are not trustworthy and I want to limit its accesses for only one PC. About the others two questions?