Captive Portal (CNA) Troubleshooting

When a guest connects to a WiFi network that requires authentication, the device will usually detect the captive portal automatically and open the Splash Page.

This automatic login window is commonly referred to as a Captive Network Assistant (CNA) or captive portal login window.

The exact behavior is controlled by the guest device and operating system, not by WiFi Hotspot. Apple, Android, and Windows all include their own mechanisms for detecting networks that require captive portal authentication.

What Is a Captive Network Assistant?

A CNA is a simplified browser window opened by the operating system when it detects that a WiFi network requires additional authentication before full Internet access is available.

The typical process is:

  1. The guest connects to the WiFi network.

  2. The device checks whether Internet access is available.

  3. The network requires authentication.

  4. The operating system detects the captive portal.

  5. A login window opens and displays the WiFi Hotspot Splash Page.

  6. The guest completes the login process.

  7. Full Internet access becomes available.

Android uses a dedicated captive portal login component together with its network monitoring system, while Windows uses Network Connectivity Status Indicator (NCSI) to determine whether a connection has Internet access or is behind a captive portal.

The Operating System Controls the Popup

WiFi Hotspot provides the captive portal and authentication process, but the decision to automatically open a login window is made by the client operating system.

Different devices may therefore behave differently on the same WiFi network.

For example:

  • A phone may immediately open the Splash Page.

  • Another device may display a Sign in to WiFi network notification.

  • A laptop may open its default browser.

  • Some devices may require the user to open a browser manually.

This does not necessarily indicate a problem with the Splash Page.

If the Splash Page Does Not Open Automatically

First verify the basic network configuration.

Check that:

  • The device successfully connected to the guest WiFi SSID.

  • The device received a valid IP address.

  • The guest network has working DNS.

  • The hotspot is configured correctly.

  • The user is not already authenticated.

  • The correct Splash Page is assigned.

  • Captive portal traffic is not being bypassed by the walled garden or firewall.

  • The device does not already have an active WiFi Hotspot session.

If these checks are correct, disconnect and reconnect the guest device.

Open the Splash Page Manually

If the operating system does not automatically display the captive portal:

  1. Connect to the guest WiFi network.

  2. Open a regular browser such as Safari, Chrome, Edge, or Firefox.

  3. Navigate to a website.

  4. The request should trigger the captive portal and display the Splash Page.

  5. Complete the normal login process.

If necessary, try a plain HTTP page instead of an HTTPS-only destination.

Modern HTTPS security can prevent a browser from transparently redirecting certain encrypted requests before authentication.

iPhone and iPad

Apple devices normally display the captive network login screen after the user selects a captive WiFi network.

Apple also provides Auto-Join and Auto-Login settings that can affect how a previously used captive network behaves.

If the Splash Page does not appear:

  1. Open Settings → Wi-Fi.

  2. Select the information button next to the guest network.

  3. Verify that Auto-Join is enabled.

  4. Disconnect and reconnect to the WiFi network.

  5. If necessary, use Forget This Network and connect again.

  6. Wait for the captive login screen to appear.

  7. If it still does not appear, open Safari and try to access a website.

Apple notes that turning off Auto-Login can also cause the Welcome screen to be shown again the next time the device connects.

Android

Android contains built-in network monitoring and a dedicated captive portal login application.

When Android detects that Internet access is restricted by a captive portal, it can display a notification or captive portal login window. This functionality is part of Android's Network Stack and may also receive updates independently of the full operating system.

If the Splash Page does not appear:

  1. Disconnect from the guest WiFi.

  2. Reconnect to the network.

  3. Check for a Sign in to WiFi network notification.

  4. Tap the notification when displayed.

  5. If no notification appears, open Chrome or another browser.

  6. Navigate to a website to trigger the captive portal manually.

Exact behavior can vary between Android versions and device manufacturers.

Windows

Windows uses Network Connectivity Status Indicator (NCSI) to determine whether a network has Internet connectivity or requires captive portal authentication.

On supported Windows versions, NCSI performs connectivity checks and can open the browser when a network requires hotspot sign-in.

If the Splash Page does not appear:

  1. Disconnect and reconnect to the guest WiFi network.

  2. Check the network icon for a sign-in or limited connectivity notification.

  3. Select the notification when available.

  4. Open Edge or another browser if the login page does not open automatically.

  5. Navigate to a website to trigger captive portal authentication.

Do Not Disable NCSI

Do not disable Windows NCSI active probing as a standard captive portal troubleshooting procedure.

Microsoft specifically recommends against disabling active probing because Windows components and applications rely on NCSI to correctly determine network connectivity.

Check the Walled Garden

Incorrect walled garden configuration is a common cause of captive portal detection problems.

Before authentication, only services required for the login process should be accessible.

Avoid broad rules such as entire provider domains or large wildcard domain groups unless they are specifically required.

For example, Social Login may require access to selected authentication services before the guest is logged in. However, allowing overly broad provider domains may also allow operating-system connectivity checks to bypass the captive portal.

Use only the domains required by the feature or integration you are using.

Social Login and Captive Portal Detection

Social Login creates a special requirement because the selected social provider must be reachable before the guest receives full Internet access.

Configure the walled garden according to the requirements of:

  • The selected social provider

  • Your router or WiFi controller

  • The Social Login configuration

Avoid copying old domain lists from legacy documentation.

Authentication providers and operating systems can change the services and domains they use over time.

Welcome Page and Redirect Behavior

Captive portal login windows are controlled by the operating system and are designed primarily to complete network authentication.

After successful authentication, some devices may automatically close the captive portal window once Internet access is detected.

For this reason, a configured Welcome Page or redirect destination may not always remain visible when the guest logs in through the operating system's CNA.

When a post-login destination is important, test the complete workflow on the operating systems and devices commonly used at your location.

Test Without an Existing Session

When testing captive portal detection, always use a device that does not already have an active authenticated session.

A useful test procedure is:

  1. Disconnect the device from guest WiFi.

  2. Confirm that any previous WiFi Hotspot session has ended when necessary.

  3. Forget the WiFi network if you want to simulate a first-time connection.

  4. Reconnect to the guest SSID.

  5. Wait for captive portal detection.

  6. Complete the Splash Page login.

  7. Confirm that Internet access becomes available.

Test with more than one device when investigating a problem.

If one device displays the Splash Page correctly and another does not, the issue may be related to the client operating system rather than the hotspot configuration.

Troubleshooting Checklist

If guests report that the Splash Page does not appear, verify:

  • Guest SSID connectivity

  • DHCP and IP assignment

  • DNS operation

  • Hotspot configuration

  • Splash Page assignment

  • Existing authenticated sessions

  • Walled garden rules

  • Firewall rules

  • Social Login whitelist configuration

  • Captive portal behavior on another device

If automatic detection still does not occur, ask the guest to open a regular browser and access a website to trigger the Splash Page manually.

Keep Captive Portal Configuration Current

Captive portal detection is implemented by Apple, Google/Android, Microsoft, and other operating-system vendors.

These mechanisms can change through operating-system and network-component updates. Android, for example, maintains captive portal detection and login functionality as part of its updatable Network Stack.

Avoid relying on permanent lists of connectivity-test domains or old operating-system workarounds.

When device-specific captive portal behavior changes, use the current official documentation from the operating-system provider together with the WiFi Hotspot configuration guide for your router or controller.