Another Fact:
Apple Devices first of all try to contact the
www.apple.com Website. They need a reply from
www.apple.com after that, they go to the next Step and get the Captive Portal.
I mean, they get the Captive Portal, but who knows what for "Security Features" Apple has as well...
Maybe the first contact to Apple.com ist OK...then they move through the Building and after that there are issues between Apple.com contact and Captive Portal.
I have created a DNS Whitelist with
www.apple.com as Entry. maybe it is a possible reason...