Deploying a Guest WLAN

You can customize the guest wireless networks in terms of how users connect and what access privileges are given once connected.
Complete the following steps to deploy a guest WLAN.
  1. Go to Wi-Fi Networks > Create.
  2. Enter a name for the guest WLAN.

    Creating a New Guest WLAN

  3. For Usage Type, select Guest Access.
  4. In Onboarding Portal, select whether to allow guests the option to register their devices on your internal (non-guest) WLANs using the Onboarding Portal. For more information, refer to Using the BYOD Onboarding Portal.
  5. For Guest Authentication, select Guest Pass and Social Login (allows social media login and Guest Pass), Social Login only (social media login only), or None (no password required).
  6. For Guest Password, if you selected Guest Pass and Social Login for Guest Authentication, select one of the following options:
    • Unique password for each guest: Guest Passes must first be generated, in batch or individually, for each visitor before they will be able to log in using a Guest Pass. For more information, refer to Working with Guest Passes.
    • Single shared password among all guests: This option allows you to skip the Guest Pass requirement, and simply provide a single password for all visitors.

    Selecting a Single Shared Password or Unique Password for Each Guest

  7. For Guest Friendly Key, select Enable to include only numbers in the guest-friendly key.
    Note: By default, the guest-friendly key is enabled when a user creates a new WLAN with guest access (Guest Authentication is set to Guest pass and Social login).
    Note: The guest-friendly key is disabled in the guest access WLAN during migration.
  8. For Grace Period, enter a value in minutes to allow users to reconnect without re-authentication. Clear the check box to disable the grace period.
  9. For Authentication Method, Open is the only option available for Guest WLAN and is selected by Default.
    • Open: No authentication method is used. Open authentication allows the use of WPA2, WPA3, WPA2/WPA3-Mixed, OWE, or no encryption. Open authentication + WPA2 encryption (also known as WPA-PSK) is the most common type of WLAN encryption method and should be the default configuration if there are no special requirements for authentication or encryption.
  10. For Encryption Method, select one of the following options:
    • WPA2: Encrypts wireless traffic with WPA2 encryption. If this option is selected, users will still be required to enter the WPA2 passphrase to access the open guest WLAN, even with None selected as the guest authentication type.
    • WPA3: Announced in January 2018, the WPA3 standard replaces WPA2 with several security enhancements.
    • WPA2/WPA3-Mixed: Allows mixed networks of WPA2- and WPA3-compliant devices.
    • OWE: Opportunistic Wireless Encryption (OWE) provides encrypted communications for open networks.
    • None: Without encryption, anyone can access this WLAN with no passphrase or Guest Pass login required. (Guests may still be required to visit a captive portal landing page, if configured.)
  11. For Accounting Server, select an accounting server from the list or click the + icon to create a new RADIUS accounting server entry.
  12. (Optional) Click Show Advanced Options, and configure any advanced options, such as restricted subnet access, WLAN priority, access controls, application visibility, and so on. Refer to Advanced WLAN Configuration for more information.
  13. Click Next.
  14. Customize the guest WLAN by configuring the following options:

    Configuring the Guest WLAN

    • Social Media Logins: Allow users to log in using their social media accounts. Refer to Social Media WLANs.
    • Guest Pass Self-Service: Allow users to self-authenticate their clients to your guest WLAN using a Guest Pass generated automatically for each guest user. For more information, refer to Guest Pass Self-Service.
    • Validity Period: Click Effective from first use to make the Guest Pass valid on first use or click Effective from the creation time to make the Guest Passes valid from the time they are created. If you select Effective from first time, enter a value for the number of days after which the Guest Passes will expire if not used.
    • User Redirection URL: Click Redirect to website user intends to visit to redirect to the website the user intended to visit after successful login or click Redirect user to this website to redirect the user to a specified URL. If you select Redirect user to this website, enter the URL of the website in the field.
    • Terms and Conditions: Choose whether to display the terms and conditions before guests can access your network. You can also edit the default terms and conditions by clicking Edit, and replacing the default text with any text you choose.
    • Guest Portal Language: Select your preferred guest portal language for guest WLAN configuration.
      Note: The default language is the same as the system language. The guest portal preview page and the guest portal page will follow the guest portal language in the WLAN. The guest portal language will not work on customized text.
      Note: The portal language is not applicable for the following two types of guest WLANs:
      • A Facebook login for the guest WLAN only.
        Note: The portal language is supported if the Facebook login method is combined with other login options.
      • A no-authentication guest WLAN without Terms and Conditions and Customize Captive Portal.
    • Language Switch: This option is available only when the selected guest portal language is not English and this option is selected by default. Only when the Language Switch option is selected, the English (EN) toggle switch will be displayed in the guest portal page. You can change the portal language between the default language and English.
    • Insert WiFi4EU Snippet: Select the check box to insert a WiFi4EU snippet in the head tag of the web authentication portal page. This allows the WLAN to be used by members of the WiFi4EU "digital single market" for EU member states.

      Inserting a WiFi4EU Snippet

    • Customize Captive Portal: Click the edit icons to customize the banner, background image, background color, logo, welcome message, and opacity level. Click Preview to choose the preview device and dimensions of the preview screen and click OK to save your changes.
  15. Click OK to save your changes on the Create WLAN screen.

    The Share Wi-Fi QR Code pop-up appears. You can save or print the QR code to share it with your users. Close the pop-up if you prefer to view the QR code later (Wi-Fi Networks > More > Show QR Code). Refer to Using a QR Code to Join a Wi-Fi Network for more information.

  16. The next screen prompts you to begin the configuration for email and SMS delivery of Guest Passes. Click Yes to configure email and SMS settings, or click No to skip this step.

    You can configure these settings later from the Admin & Services page, if you prefer. Refer to Configuring Email Server Settings for more information.

    Configuring Email and SMS Delivery Settings

    After completing the email and SMS server settings, the Guest Pass Management page is displayed as shown.

    Creating a Guest Pass Now

  17. If you select Create Guest Pass now and click OK, you are redirected to the Guest Pass Generation page. You can create Guest Passes by clicking Create in the Admin Generated Guest Passes section. Refer to Generating a Guest Pass for more information.

    Admin-Generated Guest Passes

  18. If you select Create a Guest Pass Operator to manage and click OK, you must configure the Guest Pass operator role settings. Refer to Creating a Guest Pass Operator for more information.