The following document explains how to configure the Wireless Social captive portal service when using a Meraki MX device.
If you do not have a Guest VLAN created, the below instructions explain how to configure this. If you already have this configured, you can skip to Access Control set up steps.
VLAN Configuration
π Note: This section is to be used when non-Meraki access points are in use to create the Guest Only WiFi network.
β οΈ Important: You must match the SSID VLAN with the VLAN set up in this section.
Go to Security & SD-WAN.
Configure the Deployment Settings with the following:
Mode: Routed.
Client Tracking: MAC Address.
Now, under the Routing section, click Add VLAN. Configure with the following:
VLAN name: e.g. Guest.
VLAN ID: your preferred VLAN ID.
Group Policy: New Group Policy.
New Group: e.g. Guest Group.
Click Next.
Configure the IPv4 Config settings with your chosen IP subnet.
Disable IPv6 set up.
Click Preview to view the settings. If correct, click Update to apply.
Now that your VLAN is created, you can trunk the MX ports to allow traffic with your Guest VLAN through. To do this, follow the below steps:
Click the ports you wish to trunk and then click edit.
Add your Guest VLAN into the Allowed VLANs box.
Click Update to apply.
Access Control
To configure the guest WiFi, please follow the steps below:
Go to Security & SD-WAN and click Access Control under the Configure section.
Choose the VLAN you wish to edit and configure with the following:
Under the Network Access section, set the Splash page to Sign-on with my RADIUS server.
Enter the following RADIUS for Splash Page settings:
Host:
Europe: radius1-eu.wireless-social.com
Americas: radius1-us.wireless-social.com
π Note: Choose the relevant server for your location.
Port: 1812.
Secret: Please contact Support.
β οΈ Important: Ensure that there are no spaces before and after the secret.
Click Add a Server again and add:
Host:
Europe: radius2-eu.wireless-social.com
Americas: radius2-us.wireless-social.com
π Note: Choose the relevant server for your location.
Port: 1812
Secret: Please contact Support.
β οΈ Important: Ensure that there are no spaces before and after the secret.
Failover policy: Deny Access.
Captive portal strength: Block all access until sign-on is complete.
Walled Garden: Walled Garden is enabled.
Walled Garden ranges: Add all of the following walled garden domains. There may also be other relevant regional accounts if your venue is outside of the UK or US that you will need to add.
Splash Page Configuration
To configure the splash page, please follow the below steps:
Go to Security & SD-WAN and under the Configure section click Splash Page.
Choose the relevant VLAN from the dropdown and then configure with the following settings:
Custom splash URL: add the following URL:
π Note: Choose the relevant server for your location.
Where should users go after the splash page? Select A Different URL and add:
π Note: Choose the relevant server for your location.
Click Save changes to finish.
π€ Tip: If you would like to change the frequency of how often your customers see the splash page, you can amend the Splash Frequency setting.
