The following instructions outline how to setup a Aruba Instant network for the Marketing4WiFi Platform. This guide covers details such as configuring RADIUS, walled garden entries, and captive portals. This guide assumes that your Aruba Instant is already operational and on a live network with adopted Access Points. Please make sure any firewall rules, web content filters, and other security measures have been configured to interface with the platform.
To configure via Aruba Central
- Log in to your Aruba Central account at https://portal.central.arubanetworks.com
- Under Wireless Configuration choose Networks
- Click on Create New and configure with the following
- Type: Wireless
- SSID: Smart WiFi (or whatever you wish)
- Primary Usage: Guest
- Click Next and configure with the following
- Client IP Assignment: Virtual Controller Assigned
- Click Next and configure with the following
- Splash Page Type: External
- Captive Portal Profile: Click new and configure with
- Name: Smart WiFi
- Type: Radius Authentication
- IP or Hostname: Select oneUS-A Hostname
https://splash.4wifi.net
US-B Hostnamehttps://splash.4wifi-e2.net
- URL: /hotspotlogin.php
- Port:80
- Use HTTPS: No
- Captive Portal Failure: Deny Internet
- Automatic URL Whitelisting: Unchecked
- Redirect URL: Select oneUS-A Redirect URL
https://splash.4wifi.net/hotspotlogin.php?res=success
You can confirm your platform environment under Operator Customizations.
US-B Redirect URLhttps://splash.4wifi-e2.net/hotspotlogin.php?res=success
You can confirm your platform environment under Operator Customizations.
- Click Save
- WISPr: Disabled
- Encryption: Disabled
- MAC Authentication: Disabled
- Authentication Server 1: Choose New and configure with:
- Name: SmartWiFi1
- Select oneUS-A Radius 1 IP
52.23.46.139
You can confirm your platform environment under Operator Customizations.
US-B Radius 1 IP3.132.31.3
You can confirm your platform environment under Operator Customizations.
- Shared Key: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Retype Key: Same as above
- All other values left at default
- Click Save
- Authentication Server 2: Choose New and configure with:
- Name: SmartWiFi2
- Select oneUS-A Radius 2 IP
52.207.192.243
You can confirm your platform environment under Operator Customizations.
US-B Radius 2 IP3.18.137.68
You can confirm your platform environment under Operator Customizations.
- Shared Key: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Retype Key: Same as above
- All other values left at default
- Click Save
- Load Balancing: Disabled
- Reauth Interval: 24 hours
- Accounting: Enabled
- Accounting Mode: Authentication
- Accounting Interval: 3 min
- Blacklisting: Disabled
- Walled Garden: Click on 0 blacklist, 0 whitelist and configure with:
- Add each of the wildcard default walled garden entries to the whitelist.
- Press Ok to add each entry. The walled garden must be added one at a time.
- Click on Next
- Add each of the wildcard default walled garden entries to the whitelist.
- Access Rules: Role Based
- Under Role click on New and enter SmartWiFi as the name. Click OK to add.
You will need to add a new rule one by one for each of the wildcard default walled garden entries.
Example: Access Control / Network/ Any/ Allow/ To a Domain Name: *.4wifi.net - Press Ok save to each entry until all are listed.
- Create one more rule with the settings Access Control / Network / Any / Deny / To All Destinations.
- Under Role click on New and enter SmartWiFi as the name. Click OK to add.
- Under Role on the left, choose default_wired_port_profile, check the “Assign Pre-authentication role” box and select Smart WiFi.
- Click Save.
To configure via Aruba virtual controller
- Log in to your master IAP
- Under Network, Click New
- Configure with:
- SSID: Smart WiFi (or whatever you wish)
- Primary Usage: Guest
- Click Next and configure with:
- Client IP Assignment: Virtual Controller managed
- Client VLAN assignment: Default(unless you have a VLAN configured)
- Click Next and configure with:
- Name: Smart WiFi
- Type: Radius Authentication
- IP or hostname: Select oneUS-A Radius 1 IP
52.23.46.139
You can confirm your platform environment under Operator Customizations.
US-B Radius 1 IP3.132.31.3
You can confirm your platform environment under Operator Customizations.
- URL: /hotspotlogin.php
- Port: 80
- Use https: disabled
- Captive portal failure: Deny internet
- Automatic URL whitelisting: Disabled
- Redirect URL: Select oneUS-A Radius 2 IP
52.207.192.243
You can confirm your platform environment under Operator Customizations.
US-B Radius 2 IP3.18.137.68
You can confirm your platform environment under Operator Customizations.
- Click OK to save
- Auth server 1: Click the dropdown, select new and configure with:
- Type: RADIUS
- Name: Smart WiFi1
- IP Address:
- Select oneUS-A Radius 1 IP
52.23.46.139
US-B Radius 1 IP3.132.31.3
- Auth Port: 1812
- Acct Port: 1813
- Shared Key: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Retype Key: Same as above
- Click OK to save
- Auth server 2: Click the dropdown, select new and configure with:
- Type: RADIUS
- Name: Smart WiFi2
- IP Address:
- Select oneUS-A Radius 2 IP
52.207.192.243
US-B Radius 2 IP3.18.137.68
- Auth Port: 1812
- Acct Port: 1813
- Shared Key: Available in the Edit Hotspot page in the Marketing4WiFi dashboard, called RADIUS Secret in the dashboard.
- Retype Key: Same as above
- Click OK to save
- Reauth Interval: 24 hours
- Accounting: Enabled
- Accounting Mode: Authentication
- Accounting Interval: 3 min
- Blacklisting: Disabled
- Walled Garden: Click on 0 blacklist, 0 whitelist and configure with:
- Add each of the wildcard default walled garden entries to the whitelist.
- Press Ok to add each entry. The walled garden must be added one at a time.
- Click on Next
- Add each of the wildcard default walled garden entries to the whitelist.
- Access Rules: Role Based
- Under Role click on New and enter SmartWiFi as the name. Click OK to add.
You will need to add a new rule one by one for each of the wildcard default walled garden entries.
Example: Access Control / Network/ Any/ Allow/ To a Domain Name: *.4wifi.net
Press Ok save to each entry until all are listed. - Create one more rule with the settings Access Control / Network / Any / Deny / To All Destinations.
- Under Role click on New and enter SmartWiFi as the name. Click OK to add.
- Under Role on the left, choose default_wired_port_profile, check the “Assign Pre-authentication role” box and select Smart WiFi.
- Click Finish to complete the set up.