Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Windows Defender Firewall and captive portal flow are separate parts of public Wi-Fi access: Windows detects a restricted connection through NCSI, while the router, gateway, access point, or wireless controller normally hosts and enforces the portal. The firewall can block the DNS or HTTP traffic needed for detection, but disabling it is rarely the correct fix.

That distinction explains why a Windows 10 or Windows 11 PC can show “No Internet,” fail to open a hotel or café sign-in page, or browse normally while Windows still reports limited connectivity. The complete path includes Wi-Fi association, DHCP, DNS, NCSI probes, local firewall rules, proxies, upstream firewall policy, portal authentication, and a second connectivity check after sign-in.

Key takeaways

  • Windows Defender Firewall normally does not host or authenticate a captive portal; the portal usually runs on a gateway, router, access point, wireless controller, or cloud-managed network service.
  • Current Windows versions use NCSI web and DNS probes, including www.msftconnecttest.com/connecttest.txt and dns.msftncsi.com, to identify whether a network is restricted.
  • A failed NCSI probe can produce a “No Internet” status even when ordinary websites work, because NCSI tests only its defined Microsoft endpoints.
  • Most client-side troubleshooting should test outbound DNS, HTTP, proxy access, and NCSI activity rather than create an inbound exception or disable Windows Defender Firewall.
  • Microsoft recommends hostname- or service-based NCSI rules instead of fixed IP allowlists because the public NCSI infrastructure can change.

What is the Windows Defender Firewall and captive portal flow?

The Windows Defender Firewall and captive portal flow is a chain in which Windows detects restricted access, but network infrastructure normally performs the restriction and login. Windows joins Wi-Fi, receives network settings, runs NCSI tests, and may open a browser or sign-in window when the gateway replaces the expected test response with a redirect or login page.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

According to Microsoft’s NCSI overview, NCSI is a network-status detection mechanism rather than a captive-portal authentication service. A hotel gateway, airport access controller, café router, school network, or enterprise guest gateway decides whether the device is authorized.

#1 Best Overall
Protectli Vault FW2B - 2 Port, Firewall Micro Appliance/Mini PC - Intel Dual Core, AES-NI, Barebone
  • 【NEWER MODEL AVAILABLE - Protectli Vault V1210】THE VAULT (FW2B): Secure your network with a compact, fanless & silent firewall. Comes with US-based Support & 30-day money back guarantee!
  • CPU: Intel Celeron J3060 Dual Core at 1.6 GHz (Turbo 2.48 GHz), AES-NI hardware support
  • PORTS: 2x Intel Gigabit Ethernet NIC ports, 4x USB 2.0, 2x USB 3.0, 1x RJ-45 COM, 2x HDMI
  • COMPONENTS: Needs RAM & Storage to work! This is a Barebones unit for maximum customizability (no RAM or mSATA). Not all memory is compatible with the Vault! Please research "Vault Hardware Compatibility" before purchasing. coreboot BIOS optional, must be installed by user.
  • COMPATIBILITY: No OS pre-installed. All hardware tested with pfSense, untangle, OPNsense and other popular open-source software solutions.

How does a captive portal work?

A captive portal is a network access-control system that permits limited connectivity until a user accepts terms, enters credentials, pays, or completes another authorization step. The gateway identifies an unauthenticated client and redirects or replaces selected requests with a portal page.

Captive portals are common on hotel, airport, restaurant, university, school, conference, public-transit, guest, and some managed enterprise networks. The portal can identify a client by an IP address, MAC address, VLAN, device identity, user identity, or a combination of those factors.

Windows Defender Firewall is normally only one policy enforcement point in the path. The portal itself is generally upstream, so changing a Windows firewall rule cannot repair a gateway that has broken DNS, failed to redirect HTTP, misconfigured IPv6, or failed to release a client after authentication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens from Wi-Fi connection to portal login?

The connection normally follows this sequence:

  1. Wi-Fi association: The Windows device associates with the access point and completes any wireless security exchange.
  2. DHCP: The network supplies an IP address, default gateway, and DNS configuration. A device without a valid address may never reach the portal.
  3. Network classification: Windows detects the network change through its network-status services.
  4. NCSI testing: Windows resolves known Microsoft probe names and requests a known HTTP resource.
  5. Local policy: Windows Defender Firewall, a VPN, proxy, endpoint security product, or web filter can allow or block the traffic.
  6. Upstream policy: The router, gateway, wireless controller, perimeter firewall, DNS filter, or secure web gateway decides whether the client is authenticated.
  7. Portal interception: Before authentication, the gateway may redirect the HTTP probe or return a login page instead of the expected Microsoft response.
  8. Browser handoff: Windows may open a browser or captive-portal sign-in experience.
  9. Post-login validation: After authentication, NCSI repeats its tests. If Windows receives the expected response, Windows updates the network’s connectivity state.
[Wi-Fi association]
        |
        v
[DHCP address, gateway, DNS]
        |
        v
[Windows network-status services and NCSI]
        |
        +-- DNS query for NCSI host
        +-- HTTP GET to Microsoft Connect Test
        |
        v
[Windows Defender Firewall, VPN, proxy, endpoint filter]
        |
        v
[Router, gateway, controller, or hardware firewall]
        |
        +-- Unauthenticated: redirect or replace response
        +-- Authenticated: return expected probe response
        |
        v
[Windows updates connectivity state and portal experience]

What does NCSI test on Windows?

NCSI tests whether Windows can reach known Microsoft connectivity endpoints and receive the expected result; NCSI does not log the user into the hotel, airport, or café portal. According to Microsoft’s NCSI frequently asked questions, current Windows releases use Microsoft Connect Test web probes and DNS connectivity checks.

The current web-probe process is broadly:

  1. Windows resolves www.msftconnecttest.com.
  2. Windows requests http://www.msftconnecttest.com/connecttest.txt.
  3. Windows checks for an HTTP success response containing Microsoft Connect Test.
  4. Windows performs DNS checks that include dns.msftncsi.com.

Windows 10 version 1607 and later use the Microsoft Connect Test web probe instead of the older www.msftncsi.com/ncsi.txt probe. Windows 11 uses the Network List Service and Network Profile Manager path for network-status handling, while older Windows versions use older Network Location Awareness terminology. Microsoft documents the version and probe differences in its NCSI troubleshooting guidance.

A captive gateway may return an HTTP redirect, HTML login form, empty response, timeout, or another payload. The mismatch tells Windows that the network is not yet unrestricted. Windows may then open a browser or sign-in window, although policy, proxy configuration, default-browser settings, Windows version, and the network’s implementation can change the visible experience.

What is the difference between Windows Defender Firewall and a hardware firewall?

Windows Defender Firewall protects and filters traffic on the Windows endpoint, while a router, gateway, wireless controller, perimeter firewall, or secure web gateway controls traffic and authentication at the network boundary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Function Windows Defender Firewall Router, gateway, controller, or hardware firewall
Where it runs On the Windows endpoint In network infrastructure
Primary control Traffic entering or leaving one Windows device Traffic entering or leaving a network, VLAN, or guest segment
Hosts the captive portal Usually no Usually yes, directly or through a managed portal service
Can block NCSI Yes, through local firewall, proxy, VPN, or security policy Yes, through DNS, HTTP, proxy, filtering, or gateway policy
Performs hotel Wi-Fi authentication No Usually initiates the redirect and validates authentication
Applies profile or identity policy Windows Public, Private, or Domain firewall profile VLAN, MAC, IP, device, user, or gateway policy
Best diagnostic tools wf.msc, PowerShell, Event Viewer, endpoint logs Controller and gateway logs, packet capture, DNS and proxy logs

Microsoft documents Windows firewall administration through Windows Firewall tools, including Windows Firewall with Advanced Security, Group Policy, PowerShell, and command-line tools. Configuration changes require administrative rights.

Does the captive portal need an inbound Windows Firewall exception?

Usually, no. A Windows client normally initiates outbound DNS and HTTP or HTTPS connections, and the portal’s response returns through that established outbound flow. The main diagnostic targets are outbound DNS, outbound HTTP, proxy access, NCSI service traffic, and the upstream captive-portal policy.

An inbound rule that allows broad access does not make a gateway redirect the client. Creating an inbound exception can increase exposure on an untrusted public network while leaving the actual DNS, proxy, HTTP, or gateway problem untouched.

Rank #2
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.

Why does the portal open in a browser?

Windows may open a browser or captive-portal sign-in window after NCSI detects that the network returned something other than the expected Microsoft probe response. Microsoft describes that browser-opening behavior for public and corporate networks in its connectivity and public-network troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows does not always open the portal automatically. A disabled active probe, enterprise policy, proxy authentication, VPN, endpoint security filter, unsupported portal design, default-browser setting, or failure in the gateway’s redirect can prevent the expected handoff. A user may also need to sign in to Windows locally first; Microsoft’s captive-portal guidance states that captive-portal functionality is not supported at the Windows sign-in screen.

Why does an HTTPS website often fail to trigger a captive portal?

Many captive portals historically rely on intercepting plain HTTP, while HTTPS traffic is protected by TLS and cannot normally be replaced with a portal page without certificate errors or a specialized operating-system captive-portal flow.

For diagnosis, a plain HTTP request such as the Microsoft Connect Test request is more informative than opening an HSTS-enabled HTTPS website. An HTTPS test can time out, show a certificate warning, or fail without displaying the portal. Do not bypass certificate warnings or install an untrusted certificate merely to make a public Wi-Fi sign-in page work. TLS inspection by a hardware firewall or proxy can also create certificate-validation failures and portal loops.

Does changing the Windows network profile fix a captive portal?

Changing a network from Public to Private usually does not remove the gateway’s captive-portal requirement. Public, Private, and Domain profiles determine which local Windows firewall rules apply; they do not authenticate the client with the hotel, café, school, or enterprise gateway.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Keep a public Wi-Fi network classified as Public unless the network is genuinely trusted. Changing the profile to Private can enable local discovery and sharing rules and may unnecessarily expose services to other devices. During network recategorization, Windows can briefly use firewall quarantine behavior while the correct filters are applied; Microsoft documents that transition in its Windows Firewall quarantine documentation.

How can you troubleshoot a captive portal without disabling the firewall?

Use the following sequence to identify whether the failure occurs at Wi-Fi, DHCP, DNS, TCP, HTTP, NCSI, proxy, endpoint security, or gateway authentication. Run ordinary inspection commands as a standard user; use administrative changes only when a controlled test proves they are necessary.

1. Test another device on the same network

If every device fails, investigate the access point, DHCP service, DNS, gateway, portal, wireless controller, or upstream firewall. If only one Windows device fails, investigate the endpoint firewall, VPN, proxy, DNS cache, security software, or local policy. If websites work but Windows says “No Internet,” focus on NCSI instead of assuming that general Internet access is unavailable.

2. Confirm the Windows network profile and connectivity state

Get-NetConnectionProfile

Review Name, InterfaceAlias, NetworkCategory, IPv4Connectivity, and IPv6Connectivity. Do not change NetworkCategory just to force portal access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

3. Check Windows Firewall profiles

Get-NetFirewallProfile |
    Format-Table Name, Enabled, DefaultInboundAction, DefaultOutboundAction

This command shows whether each Windows firewall profile is enabled and whether the default inbound or outbound action is allow or block. Open the graphical console with:

Rank #3
200pcs Rubber Grommet 7 Sizes Sheet Metal Auto Body Firewall Hole Plug Cap
  • Package Include: 200 Pcs Round Rubber Grommets, 7 Different Size, Fits Drill Hole: 9/32", 3/8", 1/2", 5/8", 3/4", 7/8", 1"
  • Size and Quantity: M7.14 x 80pcs, M9.53 x 40pcs, M12.07 x 30pcs, M15.88 x 20pcs, M19.05 x 10pcs, M22.23 x 10pcs, M25.4 x 10pcs, Material: Black Rubber
  • Product Names: Sheet Metal Hole Plug, Auto Body Hole Plug, Firewall Grommet, Firewall Hole Plug, Plug for Drill Hole, Cable Wire Hole Plug, Electrical Appliance Hole Plug, Plumbing Hole Plug, Round Rubber Grommet, Round Rubber Hole Plug, Closed Rubber Grommet, Rubber Hole Plug, Closed Hole Plug, Drill Hole Plug, Rubber Cable Hole Plug, Firewall Solid Closed Hole Plug, Electrical Wire Gasket, Electrical Firewall Gasket, Wire Electrical Appliance Plumbing Hole Plug, Automotive Hole Plug
  • Application: Used for Sheet Metal, Auto Body, Firewall, Drill hole, Plumbing, Electric Appliance, Automotive and Boat, Metal Panels, Electrical Cabinet, Box Outlet Protection Seal, Wall Hole, Spray, Cylinder, Valve, Garages, General Plumbers, Workshop, Door, Window, Bearing, Pump, Drain Plugs, Chemical Pipe, Water Pipe, etc.
  • Other Names: Closed Grommet, Drill Hole Grommet, Rubber Cable Grommet, Cable Wire Grommet, Firewall Solid Closed Grommet, Electrical Wire Grommet, Electrical FirewallGrommet, Sheet Metal Grommet, Auto Body Hole Grommet, Wire Electrical Appliance Plumbing Grommet, Electrical Appliance Grommet, Automotive Grommet
wf.msc

Look for organization-managed rules, outbound blocks, logging configuration, and rules that apply only to a particular network profile. Also consider third-party security products that install Windows Filtering Platform providers or web filters.

4. Test DNS independently

Resolve-DnsName www.msftconnecttest.com
Resolve-DnsName dns.msftncsi.com
Resolve-DnsName ipv6.msftconnecttest.com

DNS failure points toward the local resolver, DHCP-provided DNS, VPN, proxy, DNS filter, or upstream network. Successful DNS does not prove that TCP or HTTP traffic is permitted, and it does not prove that the portal will redirect correctly.

5. Test TCP reachability

Test-NetConnection www.msftconnecttest.com -Port 80
Test-NetConnection www.msftconnecttest.com -Port 443
Test-NetConnection ipv6.msftconnecttest.com -Port 80

A failed port-80 test can indicate Windows Firewall, endpoint filtering, a proxy requirement, or gateway policy. A successful TCP test only proves that a TCP connection was established; it does not prove that the correct HTTP content will be returned.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

6. Request the Microsoft HTTP probe

Invoke-WebRequest `
  -Uri "http://www.msftconnecttest.com/connecttest.txt" `
  -UseBasicParsing

On an unrestricted connection, the response should be an HTTP success containing Microsoft Connect Test. A redirect, HTML login form, unexpected status, empty response, or timeout has a different meaning:

Observed result Most likely interpretation Next check
DNS cannot resolve the host Resolver, DHCP, VPN, DNS filter, or upstream DNS failure Check DNS settings, VPN, and gateway DNS logs
TCP port 80 fails Local firewall, endpoint filter, proxy, or gateway is blocking TCP Inspect outbound rules and upstream policy
HTTP redirect or login HTML The captive portal is intercepting the request Complete authentication and retest
Expected “Microsoft Connect Test” content NCSI sees an unrestricted probe response Investigate other applications, proxy, or delayed status updates if Windows still says offline
Timeout after successful TCP HTTP filtering, proxy behavior, gateway failure, or portal malfunction Check proxy and gateway logs
Unexpected success or content The portal may be returning a false success or altering the probe Ask the network operator to check captive-portal behavior

Microsoft describes the expected host, path, and response content in its NCSI troubleshooting guidance.

7. Inspect NCSI events

Open Event Viewer and navigate to:

Applications and Services Logs
  > Microsoft
  > Windows
  > NCSI
  > Operational

Review events around the time of the connection attempt. The log can show active-probe activity and help distinguish failed resolution, altered responses, policy restrictions, and repeated connectivity checks.

8. Check active-probe configuration

Microsoft documents NCSI settings under:

HKLMSYSTEMCurrentControlSetServicesNlaSvcParametersInternet

Relevant values include:

EnableActiveProbing
ActiveWebProbeHost
ActiveWebProbePath
ActiveWebProbeContent
ActiveDnsProbeHost
PassivePollPeriod
WebTimeout
CaptivePortalTimer

If EnableActiveProbing is 0, Windows may not actively test the connection or automatically recognize the portal. That setting can be intentional because of privacy requirements, enterprise policy, or a security baseline. Do not change registry values casually; record the original state and follow organizational change control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

9. Check proxy and VPN behavior

A browser can work through a proxy while the NCSI service cannot, or NCSI can work while a browser is blocked. Applications may use different proxy paths, credentials, DNS behavior, or VPN routes. Inspect the Windows proxy settings, VPN state, automatic detection, DNS-over-HTTPS policy, third-party web filtering, and TLS inspection.

netsh winhttp show proxy

An authenticated enterprise proxy may allow browser traffic while preventing the Windows connectivity service from completing its expected probe. A proxy architecture must account for NCSI’s service context and the organization’s security policy.

10. Isolate the endpoint firewall only under controlled conditions

If the evidence points to Windows Defender Firewall, record the current state, perform one controlled test on a trusted lab or disposable network, and immediately restore the firewall. Compare firewall logs and endpoint-security logs before creating a narrow, documented rule.

Rank #4
Glovary Firewall Mini PC J3710 Quad Core, 4 x i225V 2.5GbE LAN Fanless OPNsense Appliance, 8GB RAM 128GB SSD, Micro Router Computer Hardware, AES-NI, HD+DP Dual Display, Console, 2USB3.0, SPK/MIC
  • Quad Core J3710 Processor: F3 firewall hardware with Pentium J3710 Processor, 4 Cores 4 Threads, 2M Cache, up to 2.64 GHz, TDP 6.5 W. Compatible with OPNsense, Linux, ESXi, Proxmox
  • 4 x i225V 2.5GbE LAN: J3710 mini pc with 4 x i225V 2500Mbps LAN, can monitor network data, improve network security, powerful and widely used
  • DDR3 RAM mSATA Slot: J3710 firewall pc with 1 x DDR3L SO-DIMM memory, 1 x mSATA SSD slot, 1 x SATA 3.0 slot(SATA Cable included), 1 x Mini-PCIe Slot
  • HD DP Dual Display: Micro firewall appliance J3710 integrated HD Graphics, HD + DP dual display interfaces improve work efficiency
  • Fanless Mini Size: Firewall appliance J3710 with aluminium alloy body, fanless quiet running without noise. Size only 11 x 10 x 3.5 cm

Do not leave Windows Defender Firewall disabled on public Wi-Fi. Do not use a broad “allow everything outbound” rule as a permanent solution. A controlled firewall test is diagnostic evidence, not a recommended configuration.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What should a help desk conclude from each test?

The following decision tree keeps the investigation at the layer where the failure is observed:

Does the device receive an IP address?
 ├─ No → Check Wi-Fi association, DHCP, VLAN, or access control.
 └─ Yes
     |
     Does DNS resolve NCSI hosts?
      ├─ No → Check DNS, VPN, proxy, DHCP, or upstream filtering.
      └─ Yes
          |
          Can TCP 80 reach the probe host?
           ├─ No → Check Windows Firewall, endpoint filter, proxy, or gateway.
           └─ Yes
               |
               Does HTTP return "Microsoft Connect Test"?
                ├─ Yes → NCSI sees unrestricted Internet.
                ├─ Redirect/login HTML → Captive portal is detected.
                ├─ Timeout → Check filtering, proxy, gateway, or portal failure.
                └─ Unexpected content → Portal or intermediary may be misconfigured.

After portal login, request the probe again. If the response now contains Microsoft Connect Test, Windows should eventually update its connectivity status. If the response remains a redirect, login page, timeout, or altered payload, the gateway has not released the client or NCSI remains blocked or modified.

What firewall rules are appropriate?

The safest approach is to allow the required NCSI traffic through the organization’s intended proxy and firewall architecture, using the required hostnames or service context where supported, the necessary protocols and ports, and the correct Windows network profile.

Microsoft advises against relying on fixed NCSI IP addresses because public NCSI infrastructure can change. A historical IP allowlist can become obsolete even when the hostname remains valid. Use Microsoft’s current NCSI guidance when designing enterprise rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Allowing the NCSI host alone does not automatically allow the captive portal’s own login assets. The portal may require DNS, a portal hostname, identity or payment services, content-delivery hosts, proxy access, and post-authentication gateway release. A rule must be narrow enough for the organization’s architecture but complete enough for the actual login flow.

Rules and fixes to avoid

  • Do not allow all inbound traffic to make the portal appear.
  • Do not permanently disable Windows Defender Firewall.
  • Do not allow all outbound traffic indefinitely as a workaround.
  • Do not hard-code a historical Microsoft NCSI IP address.
  • Do not redirect HTTPS indiscriminately.
  • Do not return the expected Microsoft Connect Test content before the client is authenticated.
  • Do not assume that allowing NCSI also allows every portal dependency.
  • Do not bypass certificate warnings or install an untrusted portal certificate.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should network operators configure a captive portal?

A network operator should redirect restricted requests consistently until authentication succeeds, allow the minimum DNS and portal resources required for login, and return the expected NCSI response only after the client has been released.

Microsoft’s captive-portal guidance cautions against inconsistent combinations of redirects, dropped requests, and false-success responses. A portal that sometimes redirects, sometimes times out, and sometimes returns the normal Microsoft probe text can produce loops, false “Internet available” states, or a portal that never appears.

Network operators should also test IPv4 and IPv6 separately. A dual-stack client can reach the Internet over one protocol while the portal interception or release logic works only over the other. IPv4 and IPv6 should have equivalent authentication behavior, or the network should avoid advertising a path that the portal cannot correctly control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Common failure scenarios and the correct response

The portal never opens

First test whether the device has an IP address, can resolve the NCSI host, can reach TCP port 80, and receives a redirect or login HTML response. If the HTTP request times out, inspect Windows Firewall, endpoint filters, proxy settings, and the gateway. If the request returns the expected Microsoft text before login, the gateway may be bypassing or misconfiguring its captive policy.

Best Value
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

The browser opens, but login loops

A login loop usually means the gateway cannot preserve the client’s authentication state, one of the portal’s required assets is blocked, DNS or cookies are failing, IPv6 bypasses the authenticated path, or the gateway does not release the client after successful login. Check the portal and controller logs rather than disabling the Windows firewall.

Windows says “No Internet,” but websites work

This situation is commonly an NCSI false negative or a deliberate block of Microsoft probe endpoints. Browser traffic may use a proxy, VPN route, cached DNS result, or application-specific path that differs from the NCSI service. Re-run the HTTP probe and inspect the NCSI Operational log before changing firewall settings.

Only one Windows computer fails

Compare the failing device with a working device on the same SSID. Focus on local firewall rules, VPN, proxy, DNS configuration, active probing policy, third-party endpoint security, stale network state, and IPv6 behavior. A network-wide gateway problem is less likely when several other devices complete the portal flow.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The portal works over IPv4 but not IPv6

An advertised IPv6 path may not have equivalent portal interception or authentication. Test both www.msftconnecttest.com and ipv6.msftconnecttest.com and compare gateway behavior. Do not assume that successful IPv4 login proves the dual-stack path is correctly released.

The browser works, but Windows services report no connectivity

Browser and NCSI traffic can use different proxy settings, credentials, VPN split-tunnel routes, DNS resolvers, and security filters. Check WinHTTP proxy configuration, enterprise proxy authentication, endpoint filtering, and whether active probing is disabled by policy.

The user is still offline after portal authentication

The gateway may have authenticated the user but failed to release the client, or the gateway may allow ordinary browsing while blocking or altering NCSI. Request the probe again after login and inspect the gateway’s client state and release logs.

What should you never do on public Wi-Fi?

Do not disable Windows Defender Firewall, change a Public network to Private merely to obtain a portal, bypass HTTPS certificate warnings, install untrusted certificates, or create broad permanent allow rules. These actions can conceal the failing layer and reduce protection on a network that is specifically untrusted.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Windows Defender Firewall is built into supported Windows editions and is normally the first endpoint tool to inspect. Paid endpoint-management products may help organizations enforce and audit firewall policy centrally, but a paid endpoint firewall cannot repair a hotel gateway’s broken portal, DNS service, IPv6 path, proxy configuration, or post-authentication release.

Final diagnostic checklist

  • Confirm whether other devices can use the same Wi-Fi network.
  • Confirm that Windows received an IP address, gateway, and DNS configuration.
  • Run Get-NetConnectionProfile and record the network category and IPv4/IPv6 status.
  • Review Windows Firewall profiles with Get-NetFirewallProfile and inspect wf.msc.
  • Resolve www.msftconnecttest.com, dns.msftncsi.com, and, where relevant, ipv6.msftconnecttest.com.
  • Test TCP port 80 separately from port 443.
  • Request http://www.msftconnecttest.com/connecttest.txt.
  • Look for the expected Microsoft Connect Test response after authentication.
  • Inspect the NCSI Operational event log.
  • Check WinHTTP, Windows proxy, VPN, DNS filtering, TLS inspection, and third-party security software.
  • Check whether EnableActiveProbing is disabled by policy.
  • Ask the network operator to verify redirect consistency, portal dependencies, IPv4/IPv6 parity, and client release.
  • Restore any temporary diagnostic changes immediately.

Frequently Asked Questions

Does Windows Defender Firewall host a captive portal?

No. Windows Defender Firewall filters traffic on the Windows device, while a captive portal normally runs on a router, gateway, access point, wireless controller, or managed network service. Windows detects the restricted state through NCSI and may open the portal experience.

Should I disable Windows Defender Firewall when hotel Wi-Fi will not open the login page?

No. Disabling Windows Defender Firewall is not a general captive-portal fix and increases risk on public Wi-Fi. Test DNS, TCP port 80, the Microsoft HTTP probe, proxy and VPN settings, NCSI events, and the gateway’s portal policy instead.

Why does Windows show No Internet when web browsing works?

Windows may show “No Internet” when NCSI cannot reach its defined Microsoft probe endpoints or receives an unexpected response, even though ordinary websites work. A proxy, VPN, firewall rule, DNS policy, endpoint filter, or intentionally disabled active probing can cause the mismatch.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does allowing www.msftconnecttest.com make the captive portal work?

Not necessarily. Allowing the NCSI endpoint may let Windows test connectivity, but the portal also needs working DNS, portal-host access, authentication dependencies, proxy handling, and a gateway rule that releases the client after login. Microsoft also recommends avoiding fixed IP allowlists for NCSI.

The Bottom Line

Windows Defender Firewall and a captive portal solve different problems. NCSI detects whether Windows receives the expected Microsoft connectivity response; the upstream gateway normally redirects unauthenticated traffic and performs the login. Diagnose the flow layer by layer—IP address, DNS, TCP, HTTP, proxy, NCSI, and gateway release—then make the narrowest documented change. Do not turn off the firewall or trust an untrusted certificate to force a portal page.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.