Skip to main contentSkip to search
Skip to main content

Cambium Networks

Cambium Networks cnPilot and Xirrus access points authenticate WiFi clients against IronWiFi cloud RADIUS using WPA2-Enterprise (802.1X), with an optional external captive portal for guest networks. RADIUS server, shared secret, and splash page URL are configured per-WLAN in cnMaestro or the device web UI.

Prerequisites

In IronWiFi Console (complete these first):

  1. Create a Network in IronWiFi Console
  2. Create a Captive Portal with the appropriate vendor
  3. Note your RADIUS settings and Splash Page URL

In Cambium Networks:

  • Administrative access to Cambium device
  • Network connectivity to IronWiFi RADIUS servers

Device Configuration

RADIUS Settings

Configure your device with:

SettingValue
Primary Server
{Primary IP from IronWiFi}
Auth Port
{AUTH_PORT}
Acct Port
{ACCT_PORT}
Shared Secret
{Your shared secret}

Captive Portal

warning

Ensure the external portal URL uses the exact splash page URL from IronWiFi Console. A mismatched URL will cause authentication failures even if the portal page appears to load.

  1. Enable external captive portal
  2. Set splash page URL from IronWiFi
  3. Configure walled garden to include
    107.178.250.42

Walled Garden

Add these entries for pre-authentication access:

Required for IronWiFi:

  • 107.178.250.42
    (IronWiFi splash page)
  • DNS servers

Authentication Provider Domains:

If using social login providers, add the following domains to your walled garden:

ProviderRequired Entries
Google
*.google.com
,
*.googleapis.com
,
*.gstatic.com
,
accounts.google.com
Facebook
*.facebook.com
,
*.fbcdn.net
,
connect.facebook.net
,
facebook.com
Twitter
*.twitter.com
,
*.twimg.com
,
twitter.com
LinkedIn
*.linkedin.com
,
*.licdn.com
Microsoft
*.microsoft.com
,
*.microsoftonline.com
,
*.live.com
,
login.live.com

WPA-Enterprise

tip

Before testing WPA2-Enterprise, ensure a user account exists in IronWiFi with the correct credentials. Use the authentication testing tool to verify RADIUS connectivity independently from the access point.

For 802.1X authentication:

  1. Set security to WPA2-Enterprise
  2. Configure RADIUS server details
  3. Test with a known user

Troubleshooting

IssuePossible CauseSolution
Portal not appearingWalled garden misconfiguredCheck walled garden includes
107.178.250.42
and splash URL is correct
Authentication failingRADIUS settings incorrectVerify RADIUS IP, ports, and shared secret match IronWiFi Console
No internet after authFirewall or VLAN issueCheck firewall rules and VLAN settings
Authentication works but internet access is blockedWalled garden or accounting issueCheck walled garden settings and verify RADIUS accounting is enabled
Users are disconnected after a short timeSession timeout misconfiguredCheck session timeout settings in IronWiFi groups and verify RADIUS accounting port configuration
Captive portal page does not loadHTTPS redirect or splash URL issueVerify HTTPS redirect settings and check that the splash page URL is correctly configured in cnMaestro

Getting Help

For device-specific questions:

Vendor-Specific Notes

tip

Cambium cnPilot and XV series APs use the cnMaestro cloud management platform. RADIUS settings are configured per WLAN profile under Configure > WLANs > Security. Ensure firmware version 6.0+ for full Hotspot 2.0 and Passpoint support.

For this vendor

Shared configuration

Was this page helpful?