Cambium Networks cnPilot Enterprise AP

  • Updated
Important: You will need firmware version 3.1 or above in order to continue.

Logging in

Log in to your AP web interface and on the left menu choose Configure > WLAN. Click Create Wireless LAN at the top right.

Enter a WLAN ID (1 or above, whatever you have available). Configure with the following:

Basic Configuration

On the Basic tab:

Enable Enabled
SSID Guest WiFi (or whatever you wish)
VLAN 1 (or whatever you require)
Security Open
Radios 2.4GHz and 5GHz
Max Clients 200
Client Isolation Enabled

Click Save

Radius Server Configuration

On the Radius Server tab:

Authentication Server 1 Host *insert radius_server here*
Authentication Server 1 Secret *insert radius_secret here*
Authentication Server 1 Port 1812
Authentication Server 2 Host *insert radius_server2 here*
Authentication Server 2 Secret *insert radius_secret here*
Authentication Server 2 Port 1812
Accounting Server 1 Host *insert radius_server here*
Accounting Server 1 Secret *insert radius_secret here*
Accounting Server 1 Port 1813
Accounting Server 2 Host *insert radius_server2 here*
Accounting Server 2 Secret *insert radius_secret here*
Accounting Server 2 Port 1813
Accounting Mode start-interim-stop
Server Pool Mode Failover
Interim Update Interval 120

Click Save

Guest Access Configuration

On the Guest Access tab:

Enable Enabled
Portal Mode External Hotspot
Access Policy Radius
Redirect Mode http
External Page URL *insert access_url here*
Success Action Redirect user to External URL
Redirect URL *insert redirect_url here*
Session Timeout 86400
Inactivity Timeout 1800

Click Save

White List Configuration

Next, under the Add White List header, add the required domains one at a time by clicking the Save button. Please refer to this list.

The configuration is now complete.

SecurePass Note: To enable our SecurePass WiFi solution please complete the steps below. This enables a secure, seamless WiFi connection for repeat users.

Secure WiFi - Purple

RADIUS Server Configuration

Log in to your cnMaestro dashboard. Navigate to Wi-Fi Profiles > WLAN > WLANs and click Add WLAN

Configure with:

WLAN

Name Purple-SecurePass
Wi-Fi Offload Custom
SSID Enable Yes
SSID Purple SecurePass
Security WPA2-Enterprise (802.1x)

AAA Servers

Authentication Server

1. Host rad1-secure.purple.ai
1. Secret *insert radius_secret here*
1. Port 1812
1. Realm securewifi.purple.ai
2. Host rad2-secure.purple.ai
2. Secret *insert radius_secret here*
2. Port 1812
2. Realm securewifi.purple.ai

Accounting Server

1. Host rad1-secure.purple.ai
1. Secret *insert radius_secret here*
1. Port 1813
2. Host rad2-secure.purple.ai
2. Secret *insert radius_secret here*
2. Port 1813
Accounting Mode Start-Interim-Stop
Sync Accounting Records Enabled
Interim Update Interval 240

Advanced Settings

NAS-Identifier AP HOSTNAME
Dynamic VLAN Enabled
Called Station ID AP-MAC:SSID

Passpoint

Enable Yes
Access Network Type Free Public
Internet Yes
Venue Group Business
Venue Type Professional Office
Roaming Consortium

Click Add New and create these two entries:

5A03BA0000
004096

Domain Names

Click Add New and enter:

securewifi.purple.ai

NAI Realm List

Click Add New and enter:

NAI List: 1
Name: securewifi.purple.ai

Under Add New EAP:


EAP: 1
Method: EAP TTLS
Authentication 1: Non EAP Innter Auth:PAP


Click Save

Operator Friendly Names

Click Add New and enter:

Language Code: eng
Operator Name: Purple

Click Save and deploy your changes.The configuration is now complete.

Share online:
Was this article helpful?
0 out of 0 found this helpful