The following instructions outline how to setup a Adtran Bluesocket network for the Marketing4WiFi Platform. This guide covers details such as configuring RADIUS, walled garden entries, and captive portals. This guide assumes that your Bluesocket controller is already operational and on a live network with adopted Access Points. Please make sure any firewall rules, web content filters, and other security measures have been configured to interface with the platform.
Log in to your Bluesocket WLAN controller
At the top click on Configuration and then on the left, under External Authentication click on Accounting
Click on Create Accounting Server and enter the following:
- Name: Acct1
- Enabled: Ticked
- IP Address: Select one
- Port: 1813
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Shared Secret Confirmation: as above
- Timeout: 5
- Retries: 5
- Interim Updates Enabled: Ticked
- Interim Update Interval: 300
Click Create Accounting Server
Click on Create Accounting Server again and enter the following:
- Name: Acct2
- Enabled: Ticked
- IP Address: Select one
- Port: 1813
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Shared Secret Confirmation: as above
- Timeout: 5
- Retries: 5
- Interim Updates Enabled: Ticked
- Interim Update Interval: 300
Click Create Accounting Server
Next, on the left, under External Authentication click on Servers. Click on Create Authentication Server and enter the following:
- Type: RadiusWebAuthServer
- Name: Auth1
- Accounting Server: Acct1
- IP Address: Select one
- Port: 1812
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Shared Secret Confirmation: as above
- Timeout Weight: 1
- Precedence: Highest
- Role: Guest
Click on Create Authentication Server.
Click on Create Authentication Server again and enter the following:
- Type: RadiusWebAuthServer
- Name: Auth2
- Accounting Server: Acct2
- IP Address: Select one
- Port: 1812
- Shared Secret: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Shared Secret Confirmation: as above
- Timeout Weight: 1
- Precedence: Lowest
- Role: Guest
Click on Create Authentication Server.
Next, on the left under Captive Portal, click on Forms. Click Create Login Form and enter the following:
- Name: SmartWiFi
- Allow User Logins: Ticked
- Allow Guest Logins: Unticked
- Redirect Clients to an External URL: Ticked
- Base URL of External Server: Select one
- Clients Access Point MAC Address: ap
- Client’s Access Point Name: ap_name
- vWLAN IP Address: controller
- Client’s Original URL: destination
- Client’s MAC Address: mac
- Client’s IP Address: source
- Client’s Access Point SSID: ssid
- Client’s VLAN ID: vlan
- Double Encoding of URI Parameters: Unticked
- Include RADIUS Option Vendor option: Unticked
Next, on the left, under Role Based Access Control click on Destinations. Click on Create Destination Hostname and enter:
Create a Destination Hostname for all the entries in the Default walled garden entries.
Next, on the left, click on Destination Groups. Click on Create Destination Group.
- Name: SmartWiFi
- Destinations: Click the + sign beside each domain on the right hand list to add all of these to the left list. Be sure not to add the “Any” rule.
Click Create Destination Group
Next, on the left, click on Roles. Click on the Un-registered role. At the bottom, click on Append Firewall Rule and choose:
- Policy: Allow
- Service: Any
- Direction: Both Ways
- Destination: under “Destination Groups” choose SmartWiFi
Next, on the left, click on Roles. Click on the Guest role.
Under the Bandwidth Shaping section, enter:
QoS Rate In: Enter the desired download speed for guests.
QoS Rate Out: Enter the desired upload speed for guests.
Under the Post Login Redirection section, enter:
URL Redirect: Select one
Next, on the left, under Wireless click on SSIDs. Click on Create SSID and enter the following:
Name: Smart WiFi (Or whatever you wish, this is what guests will see when connecting to WiFi)
Broadcast SSID: Ticked
Enable Captive Portal Authentication: Ticked
Authentication: Open System
Cipher: Disabled
Un-registered Role: Un-registered
Login Form: SmartWiFi
Finally, you need to apply this new configuration to your AP’s in the usual way. For example, go to the Status tab at the top and choose Access Points. Highlight the ones you are using and click the Apply button.
Troubleshooting Splash page
- When presenting the splash page guests may see a SSL certificate error. Please see this article regarding Manufacturer SSL certificates.
- If a hotspot deactivated message is presented please ensure all the AP MACs have been properly added as gateways to the correct hotspot.
- If devices are redirected to the splash page URL but the page fails to load please ensure the Destination Group walled garden entries were all added correctly and applied to the correct role.