The design spec is solid, but in practicality it doesn't seem work properly which is the problem.  If I turn on "Block all access until sign-on is complete", I will start getting calls from our employees that their personal devices and customer devices can't surf the Internet on guest Wi-Fi.  In theory, the phones should reach out to an HTTP url and redirect to the portal, but some devices just don't behave properly.  So, I either get lots of support tickets, or I allow non-HTTP traffic prior to sign in.  Neither option is good. 
						
					
					... View more