Nexudus Integration with IronWiFi – Detailed FAQ

Nexudus Integration with IronWiFi – Detailed FAQ

Nexudus Integration with IronWiFi – Detailed FAQ


1. How does authentication between IronWiFi and Nexudus work?

Captive Portal:

  • Users connect to an open SSID and are redirected to a captive portal page.

  • They enter their Nexudus credentials or voucher code.

  • IronWiFi sends these credentials to Nexudus via API for validation and returns approval/rejection in real time.

  • No dependency on IronWiFi’s local database in this flow.

WPA2-Enterprise (Passpoint) Authentication:

  • Devices use stored credentials (from a Passpoint profile or Wi-Fi profile).

  • IronWiFi verifies the stored credentials against Nexudus in real time but depends on its local database as well.

  • Any profile updates in Nexudus are pushed to IronWiFi to maintain synchronization.

2. How often does Nexudus sync with IronWiFi?

  • Nexudus updates user data (new attributes, expired memberships, disabled accounts) in IronWiFi’s database regularly.

  • These updates typically occur in real time or near real time, ensuring that IronWiFi has up-to-date information for accurate access decisions.

3. What are the most common authentication issues?

  • Certificate Trust Issues:
    Devices may fail to connect if they don’t trust the RADIUS server’s certificate.

  • Account Status:
    If the user account in Nexudus is disabled or expired, IronWiFi’s real-time verification will fail.

  • Mismatched Configurations:
    Captive portal vs. enterprise authentication can lead to confusion if not properly configured.

  • Sync Delays:
    Rarely, updates may not be immediately reflected due to API timeouts or temporary network issues.

  • Passpoint Profile and Nexudus credentials desynch

           If the user changed / reset their PIN they will need to delete and re-install their passpoint profiles via captive portal, as the credentials are stored within the Passpoint profile

  1. Device Limit Reached:
          When trying to log in, you are getting an error saying "You can't register a new device. Please contact the administrator."  Delete some devices from Nexudus panel, or increase device limit.

4. How does the captive portal method work in practice?

  • SSID Setup:
    The Wi-Fi network is set to open (no WPA2 password).

  • Portal Login:
    Users enter Nexudus credentials or a voucher code on a branded IronWiFi login page.

  • Validation:
    IronWiFi sends credentials to Nexudus, which verifies the login and sends back an approval or rejection.

  • Access Grant:
    Upon approval, IronWiFi grants temporary or permanent network access (MAC address whitelisting, etc.).

5. What’s the process for WPA2-Enterprise / Passpoint deployments?

  • Profile Installation:
    Members receive a Passpoint profile that includes credentials (username, password, or certificate).

  • Secure Connection:
    Devices connect using the profile (SSID is encrypted with WPA2/WPA3 Enterprise).

  • Real-Time Validation:
    IronWiFi checks credentials stored in its database and synchronizes them with Nexudus updates.

  • Fallback:
    If authentication fails, fallback to captive portal can be considered, but it’s not ideal for secure networks.

  • Mixing these methods can cause confusion because:

    • Captive portal directly talks to Nexudus and bypasses local database checks.

    • Enterprise relies on local data + real-time checks.

  • If the local database is out of sync, WPA2-Enterprise might fail even if captive portal works.

7. How can I troubleshoot authentication failures?

  • Check IronWiFi Logs:

    • Logs show authentication attempts, success/failure, and error codes (e.g., password incorrect, certificate untrusted).

  • Review Change Logs:

    • IronWiFi’s admin console logs Nexudus updates to show if user data was recently changed (like disabled accounts or updated profiles).

  • Test with Known Working Credentials:

    • Use test accounts to isolate issues (credentials vs. network config).

  • Verify Certificate Trust:

    • For enterprise connections, ensure devices trust the RADIUS certificate chain.

8. How are voucher codes handled?

  • Creation:Nexudus admins create voucher codes for day passes, promotions, or visitor access.

  • Login Flow:
    Users enter the voucher code on the captive portal.

  • Verification:
    IronWiFi requests Nexudus API to confirm the voucher’s validity (usage limits, expiry).

  • Access Grant:
    If valid, the device is allowed on the network for the specified duration.

9. What best practices ensure a smooth Nexudus integration?

Test in Staging First:
Validate Passpoint profiles and captive portal login with test accounts.
Separate Guest & Enterprise SSIDs:
Use different SSIDs for visitors vs. members.
Monitor Logs & Changelogs:
Track authentication issues and recent Nexudus updates.
Educate Users:
Instruct them on profile installation, especially for WPA2-Enterprise.
Document Everything:
Keep configuration details, user guides, and logs organized.

10. What hardware or OS limitations should I consider?

    • Related Articles

    • Zapier & IronWiFi integration

      Zapier allows you to automate tasks in our console such as user creation or voucher generation. There are thousands of applications that you can seamlessly connect with IronWiFi without the need to write a single line of code. The integration is ...
    • IronWiFi and Nexudus Integration

      IronWiFi enables you to track members' time in the office, data consumption, and much more. After configuring your Access Point to use our authentication services, your members will be presented with a login page (Captive Portal), where they need to ...
    • Nexudus Integration

      IronWiFi enables you to track members' time in the office, data consumption and much more. After configuring your Access Point to use our authentication services, your members will be presented with a login page (Captive Portal), where they need to ...
    • OfficeRnd Integration

      OfficeRnD’s integration with IronWiFi enables the connection between your Memberships management system (OfficeRnD) and your Radius-based Network. Once the integration is active, you can get the following benefits: Unified Authentication – OfficeRnD ...
    • Okta (SAML)

      This page explains the configuration of Okta (SAML) in conjunction with IronWiFi Captive Portal. OKTA Console Settings 1. Navigate to admin Okta console https://login.okta.com/ 2. Go to the Applications > Applications -> Browse App Catalog -> search ...