| IMPORTANT: Your device must be running AOS 7.1 firmware or above to continue. |
Start by logging into your AP web interface.
Step 1 - External Radius
Click Security > External RADIUS on the left. Configure with:
| RADIUS Attribute Formatting | Ethernet-MAC |
| Station MAC Format | UC-hyphenated (XX-XX-XX-XX-XX-XX) |
| Accounting | On |
| Accounting Interval | 120 |
Click Save changes to flash at the top right.
Step 2 - SSID
Click SSID > SSID Management on the left. Underneath the current SSIDs, enter Guest WiFi (or whatever you wish) and click Create. Configure this new SSID with:
| SSID | Enabled |
| Brdcst | Enabled |
| Encryption | None/Open (remove the Global checkbox) |
| WPR | Ticked |
Next, scroll down the page and under Web Page Redirection Configuration, configure with:
| Landing Page URL | *insert redirect_url here* |
| Server | External Login |
| Redirect URL | *insert access_url here* |
| Redirect Secret | *insert uam_secret here* |
Next, under WPR Whitelist Configuration, add the required domains one by one. Please refer to this list.
Next, under Authentication Service Configuration configure with:
| Authentication Server | External Radius |
Under Primary:
| Host / IP Address | *insert radius_server here* |
| Port | 1812 |
| Shared Secret | *insert radius_secret here* |
| Verify Secret | as above |
| Accounting | Enabled |
Under Secondary:
| Host / IP Address | *insert radius_server2 here* |
| Port | 1812 |
| Shared Secret | *insert radius_secret here* |
| Verify Secret | as above |
Under Primary (Accounting):
| Host / IP Address | *insert radius_server here* |
| Port | 1813 |
| Shared Secret | *insert radius_secret here* |
| Verify Secret | as above |
Under Secondary (Accounting):
| Host / IP Address | *insert radius_server2 here* |
| Port | 1813 |
| Shared Secret | *insert radius_secret here* |
| Verify Secret | as above |
| Interval | 120 |
Click Save changes to flash at the top right to commit your changes.
Configuration Complete
The configuration is now complete.