investigation revealed that iOS CNA just requires https 443, not the 8000–8002 OPNsense captive portal ports.
https://forum.netgate.com/topic/188402/captive-portal-not-working-on-ios-devices-only-dhcp-114 blox fruits
https://forum.netgate.com/topic/188402/captive-portal-not-working-on-ios-devices-only-dhcp-114 blox fruits
"