When Rule-based Redirection is disabled, denied HTTP(S) traffic from an non-authenticated client is automatically redirected to the External Captive Portal by the AP. To control network access after authentication, configure roles that have an Access Control of deny and specify that role under Virtual Networks > General.
To configure default roles that deny network access after authentication: