The following Access Control Rules are added when you enable an
                internal captive portal. The rules are removed when you disable the captive
                    portal.
                    - Blacklist. This
                        rule quarantines any MAC address that is part of the Blacklist group. This
                        is always the first rule in the Rules
                        List.
 
                    - Default
                        Catchall. This rule applies the Default Auth Policy to any MAC Address. It
                        is always the final rule in the Rules
                        List.
 
                    - Unregistered: This rule is a
                        catchall, and will always be listed immediately before the Default Catchall.
                        Users who do not match any other rule will match Unregistered, and they will
                        be presented with the captive portal. 
 
                    - Registered Guests: Users who
                        complete registration through the Guest captive portal will match this rule,
                        which checks for end-system MAC addresses in the Registered Guests
                            group.

Note   
This rule is
                            only present when Guest Registration or Guest Web Access is enabled.
                        
 
 
                    - Web Authenticated Users:
                        Users who complete registration through the Authenticated captive portal
                        will match this rule, which checks for end-system MAC addresses in the Web
                        Authenticated Users group.

Note   
This rule is only present
                            when Authenticated Registration or Authenticated Web Access is enabled.