Cisco WLC - Passpoint Configuration
Configure Passpoint (Hotspot 2.0) on Cisco AireOS WLC or Catalyst 9800 wireless controllers to enable automatic WiFi authentication through IronWiFi's cloud RADIUS service. This provides seamless WPA2/WPA3-Enterprise connections without manual network selection or splash pages.
Supported Platforms
- Cisco AireOS WLC - 5520, 8540, 3504, vWLC
- Cisco Catalyst 9800 - 9800-40, 9800-80, 9800-CL
- Cisco Embedded Wireless Controller
Prerequisites
In Cisco WLC:
- Cisco WLC with AireOS 8.5+ or IOS-XE 17.x+
- Access points supporting Hotspot 2.0 (Wave 2 or later)
- Network connectivity to IronWiFi RADIUS servers
In IronWiFi Console (complete these first):
- Log in to IronWiFi Management Console
- Navigate to Networks > select your network
- Enable Passpoint
- Note the RADIUS details and Passpoint configuration:
- RADIUS Server IP
- RADIUS Secret
- Authentication Port: Customer Authentication Port
- Accounting Port: Customer Accounting Port
AireOS WLC Configuration
Web Interface Configuration
Step 1: Configure RADIUS Server
-
Log in to WLC web interface
-
Go to Security > AAA > RADIUS > Authentication
-
Click New
-
Configure:
- Server Index: 1
- Server IP Address: IronWiFi RADIUS IP
- Shared Secret: Your RADIUS secret
- Port Number: Customer Authentication Port
- Server Status: Enabled
-
Click Apply
-
Go to Accounting and add accounting server:
- Same IP, customer accounting port
Step 2: Create WLAN
- Go to WLANs
- Click Create New
- Configure:
- Profile Name: Passpoint
- SSID: Passpoint
- ID: Select available ID
- Click Apply
Step 3: Configure WLAN Security
- Edit the new WLAN
- Go to Security > Layer 2:
- Layer 2 Security: WPA+WPA2
- WPA2 Policy: Enabled
- WPA2 Encryption: AES
- Auth Key Mgmt: 802.1X
- Go to Security > AAA Servers:
- Authentication Servers: Select IronWiFi server
- Accounting Servers: Select IronWiFi server
Step 4: Enable Hotspot 2.0
- Go to Advanced tab
- Find Hotspot 2.0 section
- Enable Hotspot 2.0
- Configure:
General:
- Hotspot 2.0 Enable: Enabled
- DGAF Disable: Disabled
Step 5: Configure 802.11u
- Go to Wireless > 802.11u
- Enable 802.11u
- Configure:
Network Settings:
- Internet Access: Enabled
- Network Type: Free public network
- ASRA: Disabled
Venue Information:
- Venue Group: Business
- Venue Type: Unspecified
- Venue Name: Your Location (Language: eng)
Step 6: Configure Roaming Consortium
- In 802.11u settings, find Roaming Consortium
- Add OIs:
Step 7: Configure NAI Realm
- Go to NAI Realm section
- Add realm:
- NAI Realm: ironwifi.com
- EAP Method: EAP-TTLS
- Inner Auth: PAP
Step 8: Configure Domain
- In Hotspot 2.0 settings
- Add Domain Name:
ironwifi.net
AireOS CLI Configuration
Catalyst 9800 Configuration
Web Interface (WebUI)
Configure RADIUS
- Go to Configuration > Security > AAA
- Click Servers/Groups > RADIUS
- Add server:
- Name: IronWiFi
- IP Address: IronWiFi RADIUS IP
- Key: Your shared secret
- Auth Port: Customer Authentication Port
- Acct Port: Customer Accounting Port
Create Server Group
- Go to Server Groups
- Create new group
- Add IronWiFi server to group
Configure Policy Profile
- Go to Configuration > Tags & Profiles > Policy
- Create new policy profile
- Configure AAA settings to use IronWiFi
Configure WLAN
-
Go to Configuration > Tags & Profiles > WLANs
-
Create new WLAN:
- Profile Name: Passpoint
- SSID: Passpoint
- Status: Enabled
-
In Security tab:
- Layer 2: WPA2
- Auth Key Management: 802.1X
-
In Advanced tab:
- Enable Hotspot 2.0
Configure Hotspot 2.0
- Go to Configuration > Wireless > Hotspot 2.0
- Create HS2.0 Profile:
General Settings:
- Profile Name: IronWiFi-Passpoint
- Internet Access: Enabled
- Network Type: Free public
Venue:
- Venue Group: Business
- Venue Type: Unspecified
Domain:
- Add:
ironwifi.net
Roaming Consortium:
- Add:
5A03BA0000 - Add:
004096
NAI Realm:
- Realm: ironwifi.com
- EAP Method: EAP-TTLS
- Inner Auth: PAP
- Assign profile to WLAN
Catalyst 9800 CLI Configuration
Troubleshooting
Common Issues
Network Not Discovered
- Verify Hotspot 2.0 is enabled on WLAN
- Check 802.11u configuration
- Verify GAS/ANQP frames are being sent
- Check client Passpoint support
Authentication Failures
- Test RADIUS connectivity
- Verify NAI realm configuration
- Check IronWiFi logs for details
- Verify EAP method configuration
Debug Commands (AireOS)
Debug Commands (Catalyst 9800)
Best Practices
- Use Wave 2 APs: Ensure APs support Hotspot 2.0
- Firmware: Keep WLC and APs on supported versions
- Testing: Test with multiple device types
- Monitoring: Monitor authentication success rates
- Redundancy: Configure backup RADIUS servers
Related Topics
Same vendor
Standards & reference
Was this page helpful?