This article will describe how to configure your Peplink to enable the Cloudi-Fi's Captive Portal
You will need admin access to the Pepwave router to continue.
Testing environment
Validated with MAX BR2 IP55 and Firmware 8.2.0 build 5066
Summary:
1) Get Cloudi-Fi required URL and RADIUS secret
Location URL: this URL is used to configure an External Captive Portal
-
Cloudi-Fi administration Locations Click on the menu button of the location and select Copy Splash page URI
-
Transform the URI as follows

Company Key :
-
Go to Settings Company Account and copy the Cloudi-Fi Public Key
Radius Server Information
-
Use the chatbot interface and ask for the RADIUS & SYSLOG servers and secret.
2) Guest Network configuration
Go to Network Network Settings and create a new LAN
-
IP Address: Provide a Guest Subnet
-
Name: Cloudi-Fi-Guest
-
VLAN ID: Provide a VLAN for your Guests
-
DHCP Server: Enabled
-
IP Range: Provide a DHCP Scope for your Guests
-
Lease Time: Amount of time your Guests can use an IP Address
-
DNS Servers: Enable Assign DNS server automatically or provide your own DNS servers
Save

3) Radius Configuration
Go to Advanced Misc. Settings Radius Server and add a new Radius
-
Name: Cloudi-Fi-Primary-Radius
-
Host: Radius IPs
-
Port: 1812
-
Secret: Shared Secret provided by the Cloudi-Fi Support team via Chat
Save

Do the same with the Secondary Radius Server.
4) Captive Portal Profile Configuration
Go to Network Captive Portal and create a new LAN
-
Name: Cloudi-Fi-Captive-Portal
-
Enable: Select the LAN you’ve created for the Guests.
-
Hostname: guest.3wi.fi
Note that guest.3wi.fi is a domain name owned by Cloudi-Fi.
You could use this FQDN if you use the Cloudi-Fi public certificate.
If you prefer to use your domain and certificate,
replace guest.3wi.fi by your domain. -
Access Mode: User Authentication
-
Authentication Profile: Select the Cloudi-Fi's Primary Server and Cloudi-Fi's Secondary Server
-
Accounting Interim Interval: 600
-
NAS-Identifier: Your Cloudi-Fi Public Key
-
Allowed Networks: cloudi-fi.net (If you are using Social Network authentication, also add those domains)
-
Splash Page: Paste your captive portal URL
Save

5) SSID Configuration
Go to AP AP Wireless SSID and add a new SSID
-
SSID: Your Guest SSID Name
-
VLAN: Select your Guest VLAN
-
Broadcast SSID: Enabled
-
Security Policy: Open (No Encryption)
Save

6) Configure an SSL Certificate (Optional)
A public certificate has to be deployed on the router to bring up a secured channel between the guest device and the Pepwave router. Without this certificate, guests will receive “Untrusted Certificate” error messages after they authenticate on the Cloudi-Fi portal.
Go to Advanced Misc. Settings Certificate Manager Captive Portal SSL
-
Private Key: Your Certificate Private Key
-
Local Public Key Certificate: Paste the following certificate parts in this order:
-
Server Certificate
-
Intermediate CA
-
Root CA
Save
-

Go to Network LAN Network Settings and add a new Local DNS Record
-
Host Name: guest.3wi.fi
-
IP Address: 192.168.1.1 (Your LAN IP Address)

Apply Changes
If you have any questions, don't hesitate to get in touch with us - How to contact your support?