Skip to content

Aruba Instant On Setup ​

Connect CaptiFi to your HPE Aruba Instant On access points. The guest network uses an external guest portal with CaptiFi's RADIUS server. A guest who joins sees your CaptiFi splash page. When they sign in, CaptiFi hands their browser back to the access point, the access point checks the guest with CaptiFi's RADIUS server, and the guest is online for the session length set for your venue in CaptiFi.

Important

Enter the Portal URL, Redirect URL, RADIUS details and NAS identifier exactly as CaptiFi shows them. A wrong value keeps guests on the splash page.

Prerequisites ​

  • Instant On access points set up and online. The field names in this guide are the ones in Instant On 3.2.
  • Admin access to the Instant On web portal or mobile app.
  • A CaptiFi account at my.captifi.io. Choose Aruba Instant On in the set-up wizard. Its Configure your controller step shows your Portal URL, RADIUS server, ports, shared secret and NAS identifier, each with a copy button, and Copy everything copies the full list including the Redirect URL. After set-up, the same values are on the venue's card under My Locations: click Controller settings.
  • If your firewall restricts outbound traffic, allow UDP 1812 and 1813 from the access points to radius.captifi.io.

Not available on Instant On venues ​

  • WiFi vouchers and Paid WiFi are not available on Aruba Instant On, FortiGate or MikroTik networks. If you try to switch either on for an Instant On venue, my.captifi.io tells you it is not available, and guests always use the standard sign-in page.
  • Scheduled WiFi name changes in the Planner. Instant On has no management API for renaming a network, so rename it in Instant On itself.

Overview ​

  1. Create a guest network.
  2. Turn on the guest portal and set it to External.
  3. Enter the Portal URL and the Redirect URL.
  4. Keep User authentication and add the CaptiFi RADIUS server.
  5. Add the allowed domains.
  6. Test.

Step 1: Create a Guest Network ​

  1. Open the Instant On web portal or app
  2. Go to Networks
  3. Add a network
  4. Configure:
    • Network Name: your guest WiFi name, for example "Free WiFi"
    • Usage: Guest
    • Security: Open

VLAN / Network Isolation

For best security, assign your guest network to a dedicated VLAN and enable network isolation so guest traffic is separated from your internal network. In Instant On this is configured under the network's IP & VLAN settings. This prevents guests from reaching printers, file shares or other internal resources.


Step 2: Turn On the External Guest Portal ​

  1. In the guest network's settings, under Security > Network Options, tick Guest portal
  2. Click Update, then click the View guest portal link. Instant On opens Networks > Guest Portal
  3. Under Type, choose External

Step 3: Enter the Portal URL and Redirect URL ​

FieldValue
Portal URLhttps://app.captifi.io/guest/aruba?site_id=YOUR_SITE_ID/
Redirect URLhttps://app.captifi.io/site/YOUR_SITE_ID/connected

YOUR_SITE_ID is your venue's ID, shown in the Portal URL CaptiFi gives you. Copy both values from CaptiFi rather than typing them.

Keep the trailing / on the Portal URL: some Instant On firmware needs it. The access point adds the guest's details to the Portal URL itself (their MAC address, the network name and the access point's own sign-in address), so enter the address exactly as shown with nothing after it.

The Redirect URL is a CaptiFi page. Once the access point has let a guest online it sends them there, and the page forwards them to the website you set under Redirect after connect in the splash page builder. Set your own website there, not in this field.


Step 4: Authentication and the CaptiFi RADIUS Server ​

  1. Under Authentication, keep User authentication (default). Do not choose Guest portal acknowledgment: CaptiFi signs guests in through RADIUS.
  2. Leave Require RADIUS-Message-Authenticator unticked.
  3. Tick RADIUS Accounting.
  4. Under Primary RADIUS Server, enter:
FieldValue
Server IP address or Domain Nameradius.captifi.io
Shared secretThe shared secret CaptiFi shows for your venue
Server timeoutLeave the default
Retry countLeave the default
Authentication port1812
Accounting port1813
  1. Under Network Access Attributes, enter:
FieldValue
NAS identifierThe NAS identifier CaptiFi shows for your venue, exactly. It is unique to your venue and is how CaptiFi matches the access point's requests to your guests.
NAS IP addressUse device IP (default)
  1. Leave Secondary RADIUS Server unticked

Step 5: Add the Allowed Domains ​

Guests must reach these before they are online, so the splash page, its styling and its fonts load. Under Allowed Domains, click Add and enter each domain:

Domain
app.captifi.io
captifi.io
fonts.googleapis.com
fonts.gstatic.com

You do not need to add the access point's own sign-in address: the access point answers it itself.

Click Apply changes when you are done.


Step 6: Test the Connection ​

  1. Join the guest network with a phone. The CaptiFi splash page opens. If it does not, open a browser and visit any http:// site
  2. Sign in. The page shows Connecting while CaptiFi records the sign-in, then hands the phone to the access point, which puts it online
  3. Confirm the sign-in under Guests on my.captifi.io. While you are still in the wizard, the Check the connection step shows three checks: RADIUS traffic from the controller, a phone reaching the splash page, and a completed sign-in. On Instant On the access point sends its first RADIUS request when a guest signs in, so Controller sending RADIUS traffic turns green only after your first test sign-in. A check that turns Stale means no traffic for 15 minutes

TIP

After a change in Instant On, allow 1 to 2 minutes for it to reach every access point.


Supported Aruba Models ​

All Aruba Instant On access points are supported, including AP11, AP12, AP15, AP22 and AP25.


Troubleshooting ​

IssueSolution
Splash page does not appearCheck Type is External and the Portal URL matches CaptiFi exactly, including the trailing /
Splash page appears without its styling or fontsAdd all four allowed domains from Step 5
Guest signs in but stays offlineCheck Authentication is User authentication, and the RADIUS server, shared secret and NAS identifier match CaptiFi exactly. Check UDP 1812 is allowed out to radius.captifi.io
Controller sending RADIUS traffic stays pending after a test sign-inThe shared secret or NAS identifier differs from CaptiFi, or UDP 1812 and 1813 are blocked
Phone is online but shows an error page after signing inSet the Redirect URL to the CaptiFi value from Step 3 and put your website under Redirect after connect in CaptiFi
Guests dropped after a whileSession length is set in CaptiFi under your venue's Edit site in My Locations
Vouchers or Paid WiFi cannot be switched onNeither is available on Aruba Instant On, FortiGate or MikroTik networks; guests use the standard sign-in page
Settings not applyingWait 2 minutes, then restart the access point from Instant On
Guests see a blank pageClear the browser cache on the test phone, and check the Portal URL has no extra spaces

Next Steps ​


Need Help? ​

Instant On set-ups vary with hardware and firmware version. If you are stuck:

CaptiFi — Guest WiFi Marketing Platform