Does the controller use inter-vlan routing to Nat traffic to a L3 captive portal page hosted on a clearpass server? Do I need a L3 IP address on the controller. My guest wifi is using GRE tunnel to DMZ network out though our firewalls. Our firewall has NAT on it from guest to our clearpass. Last week I disabled inter-vlan rouing on the guest vlan thinking didn't need it now captive portal stopped re-directing at least that is my thorey haven't been back to test if that fixed it this is a test enviroment for Version 8. I'm able to get to the web login by typing the URL into a browser and DNS is working. I assumed that our firewall would handle the NAT since the gateway is there not on the controller.