Integrations / Aruba Instant

Aruba Instant configuration

RADIUS, walled garden, captive portal.

Operator setup for Aruba Instant on the Marketing4WiFi Platform used by Easy Smart WiFi. Two tracks: Aruba Central, or the Instant Virtual Controller on the master IAP.

  • Splash: External, port 80, HTTPS No
  • RADIUS names SmartWiFi1 / SmartWiFi2
  • Credentials stay “You will receive this”

What is this Aruba Instant guide for?

The following instructions outline how to setup a Aruba Instant network for the Marketing4WiFi Platform. This guide covers details such as configuring RADIUS, walled garden entries, and captive portals. This guide assumes that your Aruba Instant is already operational and on a live network with adopted Access Points. Please make sure any firewall rules, web content filters, and other security measures have been configured to interface with the platform. The Aruba IAP’s can be configured through the Aruba web user interface that exists on the IAP itself as well as through Aruba’s cloud based service Aruba Central.

Aruba Central

Cloud path at portal.central.arubanetworks.com. Use this if Central already manages the Instant APs.

Instant Virtual Controller

On-box path on the master IAP web UI. Use this if the cluster is managed from the Instant Virtual Controller.

What you are not guessing

RADIUS IPs, hostnames, shared keys, and redirect URLs are issued for the location. Paste them where this guide says You will receive this.

Before you start

Prerequisites

  • Aruba Instant is already operational on a live network with adopted access points.
  • Firewall rules, web content filters, and other security measures allow the Marketing4WiFi / Easy Smart WiFi platform.
  • You have the RADIUS IP or hostname, shared key, and redirect URL Easy Smart WiFi sent for this location. Those values are not published here.
  • You know whether this site is managed in Aruba Central or on the master IAP Instant Virtual Controller. Follow only that track.
  • Keep a hardware support agreement with Aruba. Controllers and GUIs change; this page is a general reference. Easy Smart WiFi can help with limited troubleshooting. Some listed companies may only be integrated with the platforms and not official partners.

Related hardware guides: Ubiquiti UniFi and EnGenius Cloud. Full vendor list: WiFi marketing integrations.

Both tracks

Walled garden domains

Add each of the wildcard default walled garden entries to the whitelist. Press OK to add each entry. The walled garden must be added one at a time. Example: Access Control / Network / Any / Allow / To a Domain Name: *.4wifi.net.

Easy Smart WiFi does not publish a separate Aruba wildcard sheet on this site. The platform default splash and authorization hostnames are documented on the UniFi configuration guide as Allowed Authorization Access. Use that list plus the wildcard default list supplied with your credentials. Replace your_white_label_splash_domain with the splash hostname you were given.

  • twitter.com
  • twimg.com
  • abs.twitter.com
  • crl3.digicert.com
  • crl4.digicert.com
  • sr.symbc.com
  • linkedin.com
  • licdn.com
  • l-msedge.net
  • facebook.com
  • facebook.net
  • developer.facebook.com
  • fbcdn.net
  • doubleclick.net
  • connect.facebook.net
  • splash.4wifi.net
  • splash.4wifi-e2.net
  • assets.smartwifiplatform.com
  • ads.ads4wifi.com
  • assets.ads4wifi.com
  • d49qral3g92qa.cloudfront.net
  • your_white_label_splash_domain
Track 1

Aruba Central

To configure via Aruba Central. Portal: https://portal.central.arubanetworks.com.

  1. Log in to your Aruba Central account at https://portal.central.arubanetworks.com.

  2. Under Wireless Configuration choose Networks.

  3. Click on Create New and configure with the following:

    • Type: Wireless
    • SSID: Smart WiFi (or whatever you wish)
    • Primary Usage: Guest
  4. Click Next and configure with the following:

    • Client IP Assignment: Virtual Controller Assigned
  5. Click Next and configure with the following:

    • Splash Page Type: External
    • Captive Portal Profile: Click new and configure with:
    • Name: Smart WiFi
    • Type: Radius Authentication
    • IP or Hostname: You will receive this
    • URL: /hotspotlogin.php
    • Port: 80
    • Use HTTPS: No
    • Captive Portal Failure: Deny Internet
    • Automatic URL Whitelisting: Unchecked
    • Redirect URL: You will receive this

    Click Save.

  6. Set the following:

    • WISPr: Disabled
    • Encryption: Disabled
    • MAC Authentication: Disabled
  7. Authentication Server 1: Choose New and configure with:

    • Name: SmartWiFi1
    • You will receive this
    • Shared Key: You will receive this
    • Retype Key: Same as above
    • All other values left at default

    Click Save.

  8. Authentication Server 2: Choose New and configure with:

    • Name: SmartWiFi2
    • You will receive this
    • Shared Key: You will receive this
    • Retype Key: Same as above
    • All other values left at default

    Click Save.

  9. Set the following:

    • Load Balancing: Disabled
    • Reauth Interval: 24 hours
    • Accounting: Enabled
    • Accounting Mode: Authentication
    • Accounting Interval: 3 min
    • Blacklisting: Disabled
  10. Walled Garden: Click on 0 blacklist, 0 whitelist and configure with:

    • Add each of the wildcard default walled garden entries to the whitelist.
    • Press Ok to add each entry. The walled garden must be added one at a time.
    • Example domain: *.4wifi.net. See Walled garden domains.
  11. Click on Next.

  12. Access Rules: Role Based. Under Role click on New and enter SmartWiFi as the name. Click OK to add.

    • You will need to add a new rule one by one for each of the wildcard default walled garden entries.
    • Example: Access Control / Network / Any / Allow / To a Domain Name: *.4wifi.net
    • Press Ok save to each entry until all are listed.
    • Create one more rule with the settings Access Control / Network / Any / Deny / To All Destinations.
  13. Under Role on the left, choose default_wired_port_profile, check the “Assign Pre-authentication role” box and select Smart WiFi.

  14. Click Save.

Track 2

Aruba Instant Virtual Controller

To configure via Aruba virtual controller. Log in to your master IAP.

  1. Log in to your master IAP.

  2. Under Network, Click New. Configure with:

    • SSID: Smart WiFi (or whatever you wish)
    • Primary Usage: Guest
  3. Click Next and configure with:

    • Client IP Assignment: Virtual Controller managed
    • Client VLAN assignment: Default (unless you have a VLAN configured)
  4. Click Next and configure with:

    • Name: Smart WiFi
    • Type: Radius Authentication
    • IP or hostname: You will receive this
    • URL: /hotspotlogin.php
    • Port: 80
    • Use https: disabled
    • Captive portal failure: Deny internet
    • Automatic URL whitelisting: Disabled
    • Redirect URL: You will receive this

    Click OK to save.

  5. Auth server 1: Click the dropdown, select new and configure with:

    • Type: RADIUS
    • Name: Smart WiFi1
    • IP Address: You will receive this
    • Auth Port: 1812
    • Acct Port: 1813
    • Shared Key: You will receive this
    • Retype Key: Same as above

    Click OK to save.

  6. Auth server 2: Click the dropdown, select new and configure with:

    • Type: RADIUS
    • Name: Smart WiFi2
    • IP Address: You will receive this
    • Auth Port: 1812
    • Acct Port: 1813
    • Shared Key: You will receive this
    • Retype Key: Same as above

    Click OK to save.

  7. Set the following:

    • Reauth Interval: 24 hours
    • Accounting: Enabled
    • Accounting Mode: Authentication
    • Accounting Interval: 3 min
    • Blacklisting: Disabled
  8. Walled Garden: Click on 0 blacklist, 0 whitelist and configure with:

    • Add each of the wildcard default walled garden entries to the whitelist.
    • Press Ok to add each entry. The walled garden must be added one at a time.
    • Example domain: *.4wifi.net. See Walled garden domains.
  9. Click on Next.

  10. Access Rules: Role Based. Under Role click on New and enter SmartWiFi as the name. Click OK to add.

    • You will need to add a new rule one by one for each of the wildcard default walled garden entries.
    • Example: Access Control / Network / Any / Allow / To a Domain Name: *.4wifi.net
    • Press Ok save to each entry until all are listed.
    • Create one more rule with the settings Access Control / Network / Any / Deny / To All Destinations.
  11. Under Role on the left, choose default_wired_port_profile, check the “Assign Pre-authentication role” box and select Smart WiFi.

  12. Click Finish to complete the set up.

Aruba Instant setup FAQ

Where do RADIUS IPs, shared keys, and redirect URLs come from?

Easy Smart WiFi provides the RADIUS IP or hostname, shared key, and redirect URL for your location. Enter those values wherever this guide says “You will receive this.” Do not guess IPs, hostnames, or keys, and do not copy another site’s credentials.

Why is the splash page on port 80 with HTTPS set to No?

For Aruba Instant with Easy Smart WiFi, Splash Page Type is External, the captive portal URL is /hotspotlogin.php, the port is 80, and Use HTTPS is No. Set those values as written. Do not change the portal to port 443 or enable HTTPS on this profile unless Easy Smart WiFi issues a different captive portal profile.

What do I add to the Aruba walled garden whitelist?

Add each wildcard default walled garden entry to the whitelist one at a time, then press OK after every entry. An example domain name is *.4wifi.net. Create a matching role-based Allow-to-domain rule for each entry, then add a final Access Control / Network / Any / Deny / To All Destinations rule. Hostnames documented on the UniFi configuration guide are the platform’s default splash and authorization list; use the wildcard list supplied with your credentials.

Should I use Aruba Central or the Instant Virtual Controller?

Aruba Instant APs can be configured in Aruba Central at https://portal.central.arubanetworks.com or on the master IAP Instant Virtual Controller. Use the controller that already manages your live network. Splash, RADIUS servers SmartWiFi1 and SmartWiFi2, reauth, accounting, and walled garden are configured on both paths. Some field labels differ, including Virtual Controller Assigned versus Virtual Controller managed.

What happens if the captive portal fails?

Set Captive Portal Failure to Deny Internet. Guests do not receive open internet access if the splash page cannot complete.

Is Aruba an official Easy Smart WiFi partner?

Aruba is listed as hardware Easy Smart WiFi integrates with. Some listed companies may only be integrated with the platforms and not official partners. Brand names and logos identify compatible hardware. They do not imply endorsement.

Do I need a new Aruba Instant network for this setup?

No. This guide assumes Aruba Instant is already operational on a live network with adopted access points. Keep the existing IAPs. Configure the guest SSID, RADIUS, walled garden, and captive portal so Easy Smart WiFi can present the splash page.

Need the RADIUS values, or a different vendor?

Credentials are issued with the location. Thirty days free. No setup cost. Cancel anytime. Starting at $50/mo per location. Call (954) 696-0882.

© 2024 WiFiMarketing.tech / Easy Smart Wifi

All trademarks, logos and brand names are the property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, trademarks and brands does not imply endorsement.

 

Skip to content