SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
HTTP New Added 28 August 2026

511 Network Authentication Required

A captive portal (hotel, airport or corporate guest Wi-Fi) is intercepting traffic and requires sign-in. The response comes from the network, not from the server you addressed.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# Confirm it is interception, not the origin
curl -sI http://neverssl.com | head -3
curl -sI https://example.com | head -3   # HTTPS usually fails to connect instead

# Open the portal
# macOS/iOS: connect and wait for the captive portal sheet
# Linux:     xdg-open http://captive.apple.com

# Applications should treat 511 as 'not my server' and not cache the response.

How to diagnose HTTP errors

HTTP status codes are a first classification, not a diagnosis. The essential split: 4xx means the request was wrong (fix the client), 5xx means the server failed to fulfil a valid request (fix the server). The subtlety is that reverse proxies and CDNs generate their own 5xx responses. A 502 or 504 from nginx tells you about nginx's relationship with the upstream, not about your application code.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Capture the full exchange with curl -v or curl -sD - -o /dev/null. Response headers frequently name the component that generated the error (Server:, Via:, X-Cache:).
  2. Determine whether the response came from your application or from something in front of it. Add a unique header in your app and check whether it survives; if it is missing, a proxy answered.
  3. For 502/504, check the upstream directly, bypassing the proxy. If the upstream is healthy, the problem is proxy timeouts, buffer sizes, or DNS re-resolution.
  4. Follow redirects explicitly with curl -IL to catch loops. A redirect loop is usually an HTTPS-terminating proxy that does not forward X-Forwarded-Proto.
  5. Correlate the request with server logs using a request ID. Guessing from the status code alone is the slowest way to debug HTTP.

Tools worth reaching for

  • curl -v / -IL
  • browser devtools Network tab
  • access logs
  • tcpdump / Wireshark
  • httpstat

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

developer.mozilla.org

Related HTTP errors

See all 49 HTTP errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.