Using SecurePass™

The functionality discussed in this article is an optional module of the Smart WiFi Platform. Reach out to your Service Provider if you’re interested in finding out if your hotspot can support SecurePass.

If your Smart WiFi hotspot has SecurePass enabled, guests that purchase a Multi Device Guest Plan will be served a password unique to their Guest Plan that can be used to connect to the SecurePass WiFi network. To configure the SecurePass WiFi network, follow the guide for your compatible hardware below.

Please ensure you report the name of the secure WiFi network to support and that you’re Guest Plans are properly configured so your guests will receive their personal wifi passwords. If the correct network name has not been reported to support, guest’s passwords will not work to connect.

Ruckus SmartZone configuration guide

  1. Login to the SmartZone dashboard
  2. Using the navigation panel to the left, click Services & Profiles > Authentication
  3. Click the Proxy (SZ Authenticator) tab at the top and the click the ‘+ Create’ button
    1. Name: securepass_auth
    2. Service Protocol: RADIUS
    3. Primary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: 1812
      • Shared Secret: You will be provided this by your Service Provider
    4. Secondary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: 1812
      • Shared Secret: You will be provided this by your Service Provider
  4. Using the navigation panel to the left, click Wireless LANs and click the ‘+ Create’ button
    1. General Options
      1. Name: SecurePass (or whatever you wish)
      2. SSID: Enter your desired network name.
        This value must be reported to your Service Provider.
    2. Authentication Options
      1. Authentication Type: Standard usage
      2. Authentication Method: Open
    3. Encryption Options

      1. Encryption Method: WPA2
      2. Algorithm: AES
      3. 802.11w MFP: Disabled
      4. Dynamic PSK: External
    4. Authentication & Accounting Service
      1. Authentication Service: securepass_auth
    5. Options

      1. Wireless Client Isolation: ON
  5. Press OK

Ruckus ZoneDirector configuration guide

  1. Login to your ZoneDirector dashboard
  2. Using the Navigation panel, select Services & Profiles > AAA Servers
    • On the Authentication/Accounting Servers page click the +Create button
      1. Name: securepass_auth
      2. Type: RADIUS
      3. Encryption: Unchecked
      4. Auth Method: CHAP
      5. Backup RADIUS: Checked
      6. First Server-
        • IP Address: You will be provided this by your Service Provider
        • Port: You will be provided this by your Service Provider
        • Shared Secret: You will be provided this by your Service Provider
        • Confirm Secret: You will be provided this by your Service Provider
      7. Second Server
        • IP Address: You will be provided this by your Service Provider
        • Port: You will be provided this by your Service Provider
        • Shared Secret: You will be provided this by your Service Provider
        • Confirm Secret: You will be provided this by your Service Provider
      8. Press OK
    • Back on the Authentication/Accounting Servers page click the +Create button again
      1. Name: securepass_acct
      2. Type: RADIUS Accounting
      3. Encryption: Unchecked
      4. Backup RADIUS: Checked
      5. First Server-
        • IP Address: You will be provided this by your Service Provider
        • Port: You will be provided this by your Service Provider
        • Shared Secret: You will be provided this by your Service Provider
        • Confirm Secret: You will be provided this by your Service Provider
      6. Second Server
        • IP Address: You will be provided this by your Service Provider
        • Port: You will be provided this by your Service Provider
        • Shared Secret: You will be provided this by your Service Provider
        • Confirm Secret: You will be provided this by your Service Provider
      7. Press OK
  3. Using the Navigation panel, select Wireless LANs
  4. Select your desired WLAN Group
  5. Press the +Create button (Or Edit your desired existing WLAN)
    1. General
      • Name: SecurePass(or whatever you wish)
      • ESSID: Enter your desired network name.
        This value must be reported to your Service Provider.
    2. WLAN Usages
      1. Type: Standard Usage
    3. Authentication
      1. Method: Open
      2. Dynamic-PSK: External
      3. DPSK Authentication Server: securepass_auth
    4. Encryption
      1. Method: WPA2
      2. Algorithm: AES
      3. 802.11w MFP: Disabled
    5. Advanced Options
      1. Wireless Client Isolation: Check both boxes
      2. Accounting Server: securepass_acct
      3. Send Interim-Update every: 10 minutes
  6. Press OK

Ruckus Cloud configuration guide

  1. Login to your Ruckus Cloud portal
  2. Using the navigation panel select Network Control> Policies & Profiles
  3. Click on the RADIUS Server tile
  4. Click the ‘Add RADIUS Server’ button
    • Profile Name: securepass_auth
    • Type: Authentication RADIUS Server
    • Primary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
    • Click Add Secondary Server
    • Secondary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
    • Click Add
  5. Click the ‘Add RADIUS Server’ button again
    • Profile Name: securepass_acct
    • Type: Accounting RADIUS Server
    • Primary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
    • Click Add Secondary Server
    • Secondary Server
      • IP Address: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
    • Click Add
  6. Using the navigation panel select Wi-Fi > Wi-Fi Networks List
  7. Click the ‘Add Wi-Fi Network’ button
    1. Network Details
      • Network Name: Enter your desired network name.
        This value must be reported to your Service Provider
      • Network Type: Dynamic Pre-Shared Key
      • Press Next
    2. DPSK Settings
      • Security Protocol: WPA2
      • Use RADIUS Server
      • Authentication Server: securepass_auth
      • Accounting Service: Enabled
      • Accounting Server: securepass_acct
      • Click Show more settings
      • Dynamic VLAN: Disabled
      • Network Control > Client Isolation: Enabled
      • Press Next
    3. Venues
      • Select the venue you would like to enable the SecurePass network
      • Press Next
    4. Summary
      • Review the settings on the page to ensure everything matches this document and then press Add

Cambium configuration guide

  1. Login to your CnMaestro dashboard
  2. Using the navigation panel select Configuration > Wi-Fi Profiles
  3. Select the WLANS tab
  4. Click the Add button
    1. WLAN Tab
      • Type: Enterprise Wi-FI
      • Name: SecurePass WiFi(or whatever you wish)
      • Enabled: Checked
      • SSID: Enter your desired network name.
        This value must be reported to your Service Provider
      • Client Isolation: Network Wide
    2. AAA Servers Tab
      • Authentication Server
        • #1. Host: You will be provided this by your Service Provider
        • #1. Secret: You will be provided this by your Service Provider
        • #1 Port: You will be provided this by your Service Provider
        • #2. Host: You will be provided this by your Service Provider
        • #2. Secret: You will be provided this by your Service Provider
        • #2. Port: You will be provided this by your Service Provider
      • Accounting Server
        • #1. Host: You will be provided this by your Service Provider
        • #1. Secret: You will be provided this by your Service Provider
        • #1 Port: You will be provided this by your Service Provider
        • #2. Host: You will be provided this by your Service Provider
        • #2. Secret: You will be provided this by your Service Provider
        • #2. Port: You will be provided this by your Service Provider
        • Accounting Mode: Start-Interim-Stop
        • Accounting Packet: Checked
      • Advanced Settings
        • NAS-Identifier: You will be provided this by your Service Provider
        • Dynamic VLAN: Unchecked
    3. Press Save
  5. Using the navigation panel select Configuration > Wi-Fi Profiles
  6. On the AP Groups tab, select your desired AP Group
    1. Basic Tab
      • Use the Add WLAN button to add the WLAN created in step 4 to the AP Group.
      • Make sure you note what # the WLAN is in the order of your AP Group, as it is used in the next step You will use this in the next step.
    2. User-Defined Overrides tab
      • Paste the text below into the user defined overrides text area. You must replace the # in the text below with the order number of the WLAN in your AP Group as mentioned in the previous step.
        !
        wireless wlan #
        epsk RADIUS
        !

TP-Link Omada Pro configuration guide

  1. Login to your Omada Pro controller
  2. Using the navigation panel select Profiles > RADIUS Profiles
  3. Click the ‘Create New RADIUS Profile’ button
    1. Name: securepass
    2. Authentication Server IP/URL: You will be provided this by your Service Provider
    3. Authentication Port: You will be provided this by your Service Provider
    4. Authentication Password: You will be provided this by your Service Provider
    5. RADIUS Accounting: Checked
    6. Accounting Server IP/URL: You will be provided this by your Service Provider
    7. Accounting Port: You will be provided this by your Service Provider
    8. Accounting Password: You will be provided this by your Service Provider
    9. Press Save
  4. Using the navigation panel select Wireless Networks > WLAN
  5. Click the ‘Create New Wireless Network’ button
    1. Network Name: Enter your desired network name.
      This value must be reported to your Service Provider
    2. Security: PPSK with RADIUS
    3. RADIUS Profile: securepass
    4. Authentication type: Generic RADIUS with unbound MAC
    5. NAS ID: You will be provided this by your Service Provider
    6. Set all other values to best practices
    7. Press Apply

NetExperience configuration guide

  1. Login to the NetExperience customer portal
  2. Using the navigation bar select Configure> Profiles
  3. Click the ‘Add’ button
    1. Type: RADIUS
    2. Profile Name: securepass
    3. Click the ‘Add Authentication Server’ button
    4. Primary Authentication Server
      • Address: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
    5. Secondary Authentication Server
      • Address: You will be provided this by your Service Provider
      • Shared Secret: You will be provided this by your Service Provider
      • Port: You will be provided this by your Service Provider
    6. Click the ‘Add Accounting Server’ button twice
    7. Primary Accounting Server
      • Use the Same Primary Server for Accounting: Checked
      • Port: You will be provided this by your Service Provider
    8. Secondary Accounting Server
      • Use the Same Primary Server for Accounting: Checked
      • Port: You will be provided this by your Service Provider
    9. Click the ‘Add’ button at the top of the page
  4. The portal will redirect you back to the Profiles page after creating the RADIUS Profile. On this page click the ‘Add’ button again.
    1. Type: Wireless Network (SSID)
    2. Profile Name: SecurePass (or whatever you wish)
    3. Mode: WPA2 RADIUS Multi-PSK
    4. RADIUS
      • RADIUS Proxy: Manual
      • RADIUS Profile: securepass
      • RADIUS Accounting Interval: 300
      • NAS ID: Manual
      • Enter NAS ID: You will be provided this by your Service Provider
      • NAS IP: WAN
    5. SSID
      • SSID Name: Enter your desired network name.
        This value must be reported to your Service Provider
      • Broadcast SSID: Show SSID
    6. Network Connectivity
      • Mode: NAT
    7. Set all other values to best practices
    8. Click the ‘Add’ button at the top of the page

Example Guest Experience

  1. When a guest selects a Multi Device Guest Plan to purchase from a hotspot with SecurePass enabled they’ll be presented with options on how to receive their private password.
    The platform can also be configured to require a specific method.
  2. After successfully purchasing the plan regardless of selection devices will be presented an interstitial page displaying key information about the PSK associated to their purchased plan.

 

Updated on February 15, 2024

Was this article helpful?

Related Articles