Skip to main contentSkip to search
Skip to main content

SonicWall

SonicWall TZ, NSa, and NSsp firewalls (with SonicWave access points or built-in wireless) authenticate WiFi clients against IronWiFi cloud RADIUS using WPA2-Enterprise (802.1X), with an optional external Lightweight Hotspot Messaging (LHM) captive portal for guest networks. RADIUS servers are configured under Users > Settings > Authentication, and the splash page is set per Guest Zone.

Prerequisites

In IronWiFi Console (complete these first):

  1. Create a Network in IronWiFi Console
  2. Create a Captive Portal with the appropriate vendor
  3. Note your RADIUS settings and Splash Page URL

In SonicWall:

  • Administrative access to SonicWall device
  • Network connectivity to IronWiFi RADIUS servers

Device Configuration

Step 1: Access SonicWall Management Interface

Log in to the SonicWall management interface.

SonicWall management interface login

Step 2: Configure RADIUS Server

Navigate to the RADIUS server settings and add the IronWiFi RADIUS server.

SonicWall RADIUS server configuration

RADIUS Settings

Configure your device with:

SettingValue
Primary Server
{Primary IP from IronWiFi}
Auth Port
{AUTH_PORT}
Acct Port
{ACCT_PORT}
Shared Secret
{Your shared secret}

SonicWall RADIUS server IP and shared secret settings

Step 3: Configure Captive Portal

Set up the external captive portal with the IronWiFi splash page URL.

SonicWall captive portal configuration

Captive Portal

  1. Enable external captive portal
  2. Set splash page URL from IronWiFi
  3. Configure walled garden to include
    107.178.250.42

SonicWall external captive portal URL settings

Walled Garden

Add these entries for pre-authentication access:

Required for IronWiFi:

  • 107.178.250.42
    (IronWiFi splash page)
  • DNS servers

SonicWall walled garden allowed addresses

Authentication Provider Domains:

If using social login providers, add the following domains to your walled garden:

ProviderRequired Entries
Google
*.google.com
,
*.googleapis.com
,
*.gstatic.com
,
accounts.google.com
Facebook
*.facebook.com
,
*.fbcdn.net
,
connect.facebook.net
,
facebook.com
Twitter
*.twitter.com
,
*.twimg.com
,
twitter.com
LinkedIn
*.linkedin.com
,
*.licdn.com
Microsoft
*.microsoft.com
,
*.microsoftonline.com
,
*.live.com
,
login.live.com

WPA-Enterprise

For 802.1X authentication:

  1. Set security to WPA2-Enterprise
  2. Configure RADIUS server details
  3. Test with a known user

SonicWall WPA2-Enterprise wireless security settings

Troubleshooting

IssuePossible CauseSolution
Portal not appearingWalled garden misconfiguredCheck walled garden includes
107.178.250.42
and splash URL is correct
Authentication failingRADIUS settings incorrectVerify RADIUS IP, ports, and shared secret match IronWiFi Console
No internet after authFirewall or VLAN issueCheck firewall rules and VLAN settings

Getting Help

For device-specific questions:

Shared configuration

Was this page helpful?