Skip to main content

Configure your Ruckus SmartZone managed access points.

User guide for configuring the Guest WiFi service on your Ruckus SmartZone managed access points

S
Written by Stephanie Desveaux
Updated over 4 weeks ago

⚠️ Important: Please ensure you are running SmartZone v3.0 or above to continue.

Guest WiFi configuration

To configure the Guest WiFi via Ruckus SmartZone log in to your SmartZone web interface, then follow each of the sections below in order.

RADIUS server set up

To configure your RADIUS servers, follow the steps below:

  1. Click Services & Profiles and then click Authentication on the left.

  2. Click the Proxy (SZ Authenticator) tab then Create and configure with:

    • Name: Guest RADIUS.

    • Service Protocol: RADIUS.

    • Primary Server IP Address: 18.168.231.87.

    • Port: 1812.

    • Shared Secret: Please contact Support.

    • Confirm Secret: Please contact Support.

      • ⚠️ Important: Ensure that there are no spaces before and after the RADIUS secret.

    • Backup RADIUS: Enable Secondary Server.

    • Secondary Server IP Address: 18.134.223.213.

    • Port: 1812.

    • Shared Secret: Please contact Support.

    • Confirm Secret: Please contact Support.

      • ⚠️ Important: Ensure that there are no spaces before and after the RADIUS secret.

  3. Click OK to save.

  4. Next, click Accounting on the left. Click the Proxy tab then Create and configure with:

    • Name: Guest RADIUS Acct.

    • Primary Server IP Address: 18.168.231.87.

    • Port: 1813.

    • Shared Secret: Please contact Support.

    • Confirm Secret: Please contact Support.

      1. ⚠️ Important: Ensure that there are no spaces before and after the RADIUS secret.

    • Backup RADIUS: Enable Secondary Server.

    • Secondary Server IP Address: 18.134.223.213.

    • Port: 1813.

    • Shared Secret: Please contact Support.

    • Confirm Secret: Please contact Support.

      • ⚠️ Important: Ensure that there are no spaces before and after the RADIUS secret.

  5. Click OK to save.

Hotspot and walled garden set up

To configure the guest hotspot, follow the steps below:

  1. Click Hotspots & Portals on the left. Click the Hotspot (WISPr) tab then click Create and configure with:

  2. Scroll to the Walled Garden section and add all of the following walled garden domains. There may also be other relevant regional accounts if your venue is outside of the UK or US that you will need to add.

  3. Click Ok to save.

Wireless LAN set up

To configure your WLAN, follow the steps below:

  1. Click Wireless LANs on the left, then click Create.

  2. Under General Options, configure with:

    • Name: Guest Wi-Fi.

    • SSID: e.g. _Venue Name Guest Wi-Fi - or whatever you wish.

    • Zone: Select a zone.

    • WLAN Group: Select a group or default.

  3. Under the Authentications Options section, configure with:

    • Authentication Type: Hotspot (WISPr).

    • Method: Open.

  4. Under the Encryption Options section, configure with:

    1. Method: None.

  5. Under the Hotspot Portal section, configure with:

    • Hotspot (WISPr) Portal: Guest WiFi.

    • Bypass CNA: Off.

    • Authentication Service: ON - Use Controller as proxy

    • From the dropdown select the RADIUS profile previously configured - i.e. Guest RADIUS.

    • Accounting Service: ON - Use Controller as Proxy -

    • From the dropdown select the RADIUS Accounting profile previously configured - i.e. Guest RADIUS Acct.

    • Send interim update: every 2 Minutes.

  6. Under the RADIUS Options section, configure with

    • NAS ID: AP MAC

    • Delimiter: Dash

    • Single Session ID Accounting: ON

    • Called Station ID: AP MAC

  7. Click Ok to save.

Northbound API set up and port forwarding

You will now need to set up the Northbound API. Follow the below steps:

  1. Click System and then select General Settings on the left.

  2. Click the WISPr Northbound Interface tab. Configure as follows:

    1. Enable Northbound Portal Interface Support: ON

    2. Username: api

    3. Password: enter any password you choose

  3. Click Ok to save.

📌 Note: Our default username is api. If you are using a different multiple zones and have an alternative username set up, please notify Support.

⚠️ Important: To complete the set up you will need to provide us with your SmartZone Public IP and the Northbound Password that you chose above and email them to Wireless Social Support.

This allows our system to talk to the SmartZone for authenticating users and is a mandatory step.

Port forward set up

In order for our system to authenticate users you are required to set up a Port Forward on your firewall/router to allow traffic inbound. Follow the below instructions:

  1. Please create a new port forward with one of the following rules:

    1. If you are using SSL use:

      • Local/Internal IP: Your SmartZone internal LAN IP (e.g. 192.168.0.1)

      • Protocol: TCP

      • Destination Port: 9443

    2. If you are using HTTP use:

      • Local/Internal IP: Your SmartZone internal LAN IP (e.g. 192.168.0.1)

      • Protocol: TCP

      • Destination Port: 9080

📌 Note: You only need one forwarding rule 9443 uses SSL, 9080 uses HTTP). Please let us know which port you are using.

If you have an existing forwarding rule to your SmartZone northbound API interface, please let us know the port and if the destination is using http or https.

All requests to the SmartZone server will come from a restricted list of IP addresses, these are listed below in case you need to restrict inbound traffic to your SmartZone:

  • 18.134.235.222

  • 18.134.223.213

  • 18.168.231.87

  • 188.39.31.210


Insights Plus Ruckus location services set up

There are two steps to this process; the initial step adds the Wireless Social MQTT broker to the SmartZone and sets this up. The second step enables this for the zone in question which then pushes out the configuration to the Access Points. Follow the instructions below to complete:

  1. On SmartZone click System Menu, then select General Settings and the Location Services tab.

  2. Click on Create and you will see a new menu box Create LBS Server. Enter the below details:

    • Venue Name: v6a

      • Server Address: rx1-proxy.wireless-social.com

      • Port: 8883

    • Password: ruckusws2022

  3. Press OK to save the details.

To deploy the settings to your Zone, follow the steps below:

  1. Go to Access points in the left-hand menu and click Access Points.

  2. Choose the zone to deploy to - e.g. the Default one if your controller does not have multiple zones.

  3. Choose Configuration and press configure.

  4. Scroll down to the bottom – and click on Advanced to open extra options.

  5. Scroll down to Location Based Services and choose V6a - this is the venue identifier entered in the first steps.

  6. Save your changes.

⚠️ Important: It's important not to change the venue name, or the password – these must match the ones on our systems for data to be processed.

Notify Support once you have completed the configuration and we can monitor for data coming in.

Your login and Insights Plus presence data will appear in the Insights portal within 24 hours.

Did this answer your question?