Kiwire 3.0 Administrator - Device & Controller Setup Guide
Kiwire 3.0 Administrator - Device & Controller Setup Guide
Cambium Networks Configuration for Kiwire Hotspot
Cambium Networks Configuration for Kiwire Hotspot
Prerequisites
Before integrating the controller with Kiwire, it is necessary that the controller and access point:
-
are connected to the Internet
-
are reachable on the network
-
have an IP address assigned to the a through DHCP or static
Note:
-
Kiwire-hostname or Kiwire-ip can be obtain by contacting our technical support for our cloud customer. For enterprise client the ip will be on premises Kiwire ip address.
-
Social network hostname list can be obtained from Social network whitelist guide
Part 1: Cambium cnMaestro configuration
-
Login to your Cambium cnMaestro controller
-
Go to WLANs > Configuration > AAA Servers
-
Authentication Server
-
Host: Kiwire-hostname or Kiwire-Ip
-
Secret: create a secret pass phrase
-
Port: 1812
-
Timeout: 3 seconds
-
Attempts: 1
-
-
Accounting Server
-
Host: Kiwire-hostname or Kiwire-ip
-
Secret: secret same as authentication server
-
Port: 1813
-
Timeout: 3 seconds
-
Attempts: 1
-
Accounting Mode: Start-Interim-Stop
-
Accounting Packet: ticked
-
Interim Update Interval: 1800 seconds
-
-
Advanced Settings
-
NAS-Identifier: AP MAC address with capital letters and colon
-
Dynamic Authorization: ticked
-
Dynamic VLAN: ticked
-
Called Station ID: AP-MAC:SSID
-
-
Omaya 3.0 Administrator > Quick Setup > Dashboard
Documentation
Kiwire 3.0 Administrator > Setting up the Wi-Fi Hardware & Configuration > Ruckus Virtual
Kiwire 3.0 Administrator - Device & Controller Setup Guide
Ruckus Virtual SmartZone configuration for Kiwire hotspot
1. Enable the WISPr Northbound Interface.
-
Go to administrator > External services > Wispr Northbound interface
-
Enable the northbound portal interface
-
Set a username and password for the northbound interface
-
Click OK to save
2. Create the hotspot zone.
-
Go to network > Wireless > Access points.
-
Select domain for the hotspot
-
Click Add New Icon to create the zone
-
Choose the type ‘zone’.
-
Give a name to the zone.
-
Insert the controller/northbound interface username and password.
-
Click OK to save.
3. Create hotspot portal.
-
Go to Services > Hotspot & Portal > Hotspot (Wispr)
-
Select the hotspot zone created before.
-
Click create icon.
5. Create portal name
-
Provide a Portal name
-
Smart client support → None
-
Login URL → External
-
Redirect unauthorized → Kiwire Hostname or ip with sub url of
/login/ruckus_vsz
ex : https://129.205.194.224/login/ruckus_vsz -
Redirect mac format → select the format of capital letters with “-“
-
Https redirect → On
-
Under walled Garden, Add new entry
-
Add the wallgarden list from network wallgarden guide to enable
social login
4. Create authentication server.
-
Go to Security > Authentication > Non proxy(AP Authenticator)
-
Select hotspot zone
-
Click on create icon
-
Name → Kiwire-authentication
-
Type → Radius
-
IP Address → Kiwire ip address
-
Port → 1812
-
Secret key → assign anything shared secret key
5. Create accounting server
-
Go to Security > Accounting > NonProxy
-
Select the hotspot zone name created.
-
Click create.
-
Name → Kiwire-accounting
-
Type→Radius
-
IP Address → Kiwire ip address
-
Port→1813
-
Shared Secret: use the same shared key create at authentication
-
process.
6. Create SSIDs.
-
Go to Network > Wireless > Wireless LANs
-
Select the hotspot zone.
-
Click Create.
-
Name → your SSID name
-
SSID → your SSID
-
Authentication type → Hotspot ( WISPr)
-
Method→Open
-
Encryption option → None
-
Hotspot(WISPr) → Select Hotspot portal created
-
Bypass CNA → Off
-
Authentication service → Off , select Kiwire-authentication
-
Accounting Service → Off, select Kiwire-accounting
-
NasID → APMac
-
Delimiter → Dash
-
Called Station ID → AP Mac
-
Single Session ID accounting → On
7. Disable encrypt-mac-ip and encrypt-zone-name from the CLI
-
Login to Putty Ruckus Controller terminal
-
Enable EN
-
Config
-
No encrypt-mac-ip
-
No encrypt-zone-name.
Kiwire Configuration for Ruckus Virtual SmartZone
-
Navigate to Devices > Add Device
-
Device Type → Controller
-
Vendor → Ruckus VSZ
-
Identity → controller mac address (delimiter colon and small letter format eg : 0c:51:aa:52:e4)
-
Ip Address → Ruckus controller ip address or host
-
Address → optional
-
Username → controller username set at northbound interface
-
Password → controller password set at northbound interface
-
Shared Secret Key → Secret key phrase set at ruckus controller setup
(Accounting / Authentication) -
COA Port → 3799)
-
Description → optional
-
Monitoring Method → optional
-
Community → optional
-
Snmp version → optional
-
Create→ to save