## TL;DR
The captive portal must be satisfied before the VPN can connect. Open a browser and complete the portal login, then let the VPN connect. If the always-on client blocks the portal page itself, use the client's captive-portal detection or temporarily allow portal bypass per policy.

## The error
```text
(Cannot connect to VPN on hotel/airport Wi-Fi; the portal page may or may not load.)
```

## Steps
1. Open a browser and navigate to a plain HTTP site (not HTTPS). Expected: the captive portal login page appears. HTTPS sites fail silently behind portals; plain HTTP triggers the redirect.
2. Complete the portal login (room number, accept terms, etc.). Expected: portal confirms access. The VPN still cannot connect until this is done.
3. Let the VPN client retry; most detect portal completion automatically. Expected: tunnel connects within a minute.
4. If the always-on client blocks all traffic including the portal: check for a "captive portal detection" or "allow portal" setting in the client. Expected: found and enabled. Some clients pause the tunnel automatically for portals.
5. As a last resort per policy, temporarily disable always-on, satisfy the portal, reconnect VPN, then re-enable always-on. Expected: connected. Document the exception; do not leave always-on disabled.

## When to use
- VPN fails specifically on hotel, airport, or conference Wi-Fi
- Portal page will not load with VPN trying to connect

## When not to use
- VPN fails on all networks (general VPN issue)
- Home Wi-Fi without a portal

## Compatibility
- Always-on VPN clients (GlobalProtect, AnyConnect, Zscaler); all OSes

## Variants
### Portal loads but VPN still fails after login
The portal may do MAC-based auth that expires, or require periodic re-auth. Re-check the portal.
### Client has no portal handling
Older clients predate the feature; upgrade the client.

## Why it happens
Always-on VPN tries to tunnel everything, but the portal needs untunneled HTTP to authenticate the device first. The two fight until the portal is satisfied, which requires a brief exception.

## Edge cases
- Some portals block VPN protocols even after login; the user may need a different network.
- Warn traveling users about this before trips; it is the top travel VPN ticket.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_M9Hh5zAB4XoOLq71dUqhXw
