Guest WiFi WLAN Configuration
To configure your via HPE Aruba access points via HPE Aruba Networking Central interface, log in to your Aruba Central account, then follow each of the sections below in order.
SSID configuration
To configure your Guest SSID, follow the below steps:
Select the required Access Point to configure, and click Device.
Under the WLANs tab, click Add SSID.
Enter the name of your SSID - e.g. _Venue Name Free WiFi.
Click Next.
VLAN configuration
Below are the default VLAN configuration settings, you can amend these as preferred.
Configure your preferred VLAN settings. The default settings are as follows:
Client IP Assignment: External DHCP server assigned.
Client VLAN Assignment: Native VLAN.
Click Next.
Security settings
To configure the security settings, please follow the below steps:
Click the Security tab, then set the Security Level to Visitor.
In the Access Network section, from the Type list, select External Captive Portal.
Click the plus
icon next to Captive Portal Profile and enter the following details: Name: guestwifi
Authentication: RADIUS Authentication
IP or hostname:
Europe: wifi.wireless-social.com
Americas: wifi-us.wireless-social.com
URL: /login/aruba/central
Port: 443
Use HTTPS: ON
Captive Portal Failure: Deny Internet
Automatic URL Allow Listing: OFF
Server Offload: OFF
Prevent Frame Overlay: OFF
Use VC IP in Redirect URL: OFF
Redirect URL: Choose the relevant server for your location.
Click OK to save and exit.
To configure the Primary Server, click the plus
icon and create a new RADIUS server. Use the following details: Server Type: RADIUS.
Name: Radius_Server1.
IP Address/FQDN: 18.168.231.87.
Shared Key: Please contact Support.
โ ๏ธ Important: Ensure that there are no spaces before and after the RADIUS secret.
Auth Port: 1812.
Accounting Port: 1813.
All other settings should be left as default.
Click Ok to save.
To configure the Secondary Server, click the plus
symbol and use the details below: Server Type: RADIUS.
Name: Radius_Server2.
IP Address/FQDN: 18.134.223.213.
Shared Key: Please contact Support.
โ ๏ธ Important: Ensure that there are no spaces before and after the RADIUS secret.
Auth Port: 1812.
Accounting Port: 1813.
All other settings should be left at their defaults.
Click Ok to save.
Disable Load balancing, then from the Key Management list, select Open.
Click Advanced Settings, then configure the following settings:
Reauth Interval: 24 Hrs
Accounting: Use authentication Servers
Accounting Interval: 3 min
Click Next to proceed to the next screen.
Access rules
You will now need to configure the Access Rules, to do this, follow the below steps:
Under the Access tab, set the Access Rules to Role Based.
Under Role, click Add Role. Name it PreAuth then click Ok.
Under Access Rules for Selected Roles, click Add Rule then configure with the below rule:
Rule Type: Access Control.
Service: Network Any.
Action: Deny.
Destination: To All Destinations.
Click Ok.
Still under Access Rules for Selected Roles, click Add Rule and enter the below:
Rule Type: Access Control.
Source: Network Any.
Action: Allow.
Destination: To a Domain Name.
Domain Name: wireless-social.com.
Click OK.
๐ Note: You'll need to repeat these steps one by one for each of the following walled garden domains. There may also be other relevant regional accounts if your venue is outside of the UK or US that you will need to add.
Click Add Rule and and enter the below:
Rule Type: Access Control.
Service: Network Any.
Action: Deny.
Destination: To AP IP.
Click Ok.
Scroll down to and enable the Assign Pre-Authentication role.
In the list that appears, select the role you just created.
Click Next.
You'll see a summary of the SSID configuration.
Click Finish to complete the setup.
Insights Plus configuration
To collect data for Insights Plus, you will need to configure the Real Time Locating System settings. Follow these steps:
Within the Access Point menu, click on the Services tab.
Scroll down and click Real Time Locating System, enter the below settings:
Aruba RTLS: Tick.
IP: 18.134.187.121.
Port: 4000.
Passphrase: Secret provided by Wireless Social Technical support - contact us on [email protected]
Update Every: 30.
Include Unassociated Stations: (Enabled).
Server Compatibility: (enabled).
Click Save Settings to complete.
Notify Support once you have completed the configuration and we can monitor for data coming in.
Your login and Insights Plus presence data will appear in the Insights portal within 24 hours.
