Networks
Why Public Wi-Fi Makes You Click A Page First
A captive portal works by deliberately breaking name resolution and redirecting traffic, which is why the sign-in page sometimes refuses to appear at all.

Connecting to Wi-Fi in a café or airport joins the network immediately, then blocks everything until a page appears and you agree to something. The mechanism is an intentional interception.
You are connected but not permitted
Joining the wireless network and receiving an address happens normally. The gateway simply refuses to forward your traffic to the wider internet.
Your device is therefore genuinely on the network. It has neighbours, an address and a route, and only the final hop is withheld.
The portal identifies you by your device's hardware address and network address, and flips a rule once you have satisfied whatever condition it imposes.
Redirection depends on hijacking a request
To show you a page, the network must intercept a request you made and answer it with something else. The usual target is a plain web request or a name lookup.
The gateway answers every name query with its own address, so whatever site you request resolves to the portal. It is a deliberate impersonation of the entire internet.
This works cleanly only for unencrypted requests. An encrypted connection to a real site cannot be redirected without producing a certificate warning, because the interception is exactly what encryption prevents.
Devices probe for the condition on purpose
Operating systems detect these networks by requesting a known address on a server they control and checking whether the expected response comes back.
Anything other than the expected answer means something is intercepting, and the system opens a restricted browser window pointed at whatever was returned.
When that window fails to appear, the probe usually succeeded by accident, often because a cached answer or an encrypted connection hid the interception.
Encrypted name lookups break the trick
Devices increasingly send name queries over encrypted channels to servers of their own choosing, which the gateway cannot read or answer.
The portal then has nothing to hijack, and the connection appears simply broken. Operating systems work around this by disabling encrypted lookups until the portal check passes.
The same friction affects privacy tools and custom resolvers, which is why turning them off temporarily is often the only way onto a hotel network.
The authorisation is weakly bound to you
Because permission is tied to a hardware address that any device can present, these networks provide identification rather than security.
Once past the portal, traffic on most such networks is not isolated between users unless the operator has specifically configured it that way.
The portal's real purpose is usually a terms acceptance, a session timer or a marketing capture. Treating it as a security boundary misreads what it was built to do.
Questions readers ask
Is a mesh system better than a single powerful router?
Only where coverage is the limitation. One well-placed unit serving a small flat will beat three nodes relaying through each other.
Do more nodes always improve things?
No. Each wireless hop costs airtime, and nodes that hear each other well compete for the same channel. Two good positions beat four poor ones.





