always-on vpn fails on hotel wifi captive portal
Gets always-on VPN working through hotel and airport captive portals. Covers portal detection, temporary bypass, and client settings. Use when VPN fails on captive-portal networks. Not for general VPN failures.
TL;DR
The captive portal must be satisfied before the VPN can connect. Open a browser and complete the portal login, then let the VPN connect. If the always-on client blocks the portal page itself, use the client's captive-portal detection or temporarily allow portal bypass per policy.
The error
(Cannot connect to VPN on hotel/airport Wi-Fi; the portal page may or may not load.)Steps
- Open a browser and navigate to a plain HTTP site (not HTTPS). Expected: the captive portal login page appears. HTTPS sites fail silently behind portals; plain HTTP triggers the redirect.
- Complete the portal login (room number, accept terms, etc.). Expected: portal confirms access. The VPN still cannot connect until this is done.
- Let the VPN client retry; most detect portal completion automatically. Expected: tunnel connects within a minute.
- If the always-on client blocks all traffic including the portal: check for a "captive portal detection" or "allow portal" setting in the client. Expected: found and enabled. Some clients pause the tunnel automatically for portals.
- As a last resort per policy, temporarily disable always-on, satisfy the portal, reconnect VPN, then re-enable always-on. Expected: connected. Document the exception; do not leave always-on disabled.
When to use
- VPN fails specifically on hotel, airport, or conference Wi-Fi
- Portal page will not load with VPN trying to connect
When not to use
- VPN fails on all networks (general VPN issue)
- Home Wi-Fi without a portal
Compatibility
- Always-on VPN clients (GlobalProtect, AnyConnect, Zscaler); all OSes
Variants
Portal loads but VPN still fails after login
The portal may do MAC-based auth that expires, or require periodic re-auth. Re-check the portal.
Client has no portal handling
Older clients predate the feature; upgrade the client.
Why it happens
Always-on VPN tries to tunnel everything, but the portal needs untunneled HTTP to authenticate the device first. The two fight until the portal is satisfied, which requires a brief exception.
Edge cases
- Some portals block VPN protocols even after login; the user may need a different network.
- Warn traveling users about this before trips; it is the top travel VPN ticket.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_M9Hh5zAB4XoOLq71dUqhXw
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.