Appearance
Aruba Instant On Setup
Connect CaptiFi to your Aruba Instant On access points. Aruba integrates with CaptiFi using an external guest portal plus RADIUS authentication: guests see your CaptiFi splash page, and CaptiFi's RADIUS server tells your access points when to let each guest online.
Important
The portal URL, RADIUS details, and shared secret must be entered exactly as shown in your CaptiFi dashboard. Incorrect values will prevent the captive portal from working.
Prerequisites
- Aruba Instant On access point(s) configured and online
- Aruba Instant On mobile app or web portal access
- Admin access to the Aruba Instant On management interface
- CaptiFi account at my.captifi.io with an Aruba site created — CaptiFi will provide your site ID, RADIUS shared secret, and NAS identifier (contact support@captifi.io if you don't have these)
Overview
The Aruba Instant On integration involves five steps:
- Create a Guest Network — Set up a dedicated guest WiFi SSID
- Configure the Guest Portal — Point the external portal to CaptiFi
- Add the CaptiFi RADIUS server — So guests actually get online after signing in
- Walled Garden — Allow pre-authentication access to CaptiFi domains
- Test — Verify everything is working
Step 1: Create a Guest Network
- Open the Aruba Instant On app or web portal
- Go to Networks
- Tap + Add Network
- Configure:
- Network Name: Your guest WiFi name (e.g., "Free WiFi")
- Usage: Guest
- Security: Open
VLAN / Network Isolation
For best security, assign your guest network to a dedicated VLAN and enable network isolation so guest traffic is separated from your internal network. In Aruba Instant On this is configured under the network's IP & VLAN settings. This prevents guests from accessing printers, file shares, or other internal resources.
Step 2: Configure the Guest Portal
- In the guest network settings, open Captive Portal / Guest Portal
- Set the portal type to External
- Enter the CaptiFi portal URL, replacing
YOUR_SITE_IDwith the site ID from your CaptiFi dashboard:https://app.captifi.io/guest/aruba?site_id=YOUR_SITE_ID/
Keep the trailing slash
The URL must end with a trailing / — removing it causes errors on some Aruba firmware versions. Your access point automatically appends the guest's details (MAC address, SSID, etc.) when redirecting, so do not add anything else to the URL.
Step 3: Add the CaptiFi RADIUS Server
Aruba puts guests online using RADIUS. After a guest completes your splash page, the access point checks with CaptiFi's RADIUS server — without this step guests will see the splash page but never get internet access.
- In the guest portal settings, create a new RADIUS profile (e.g., "CaptiFi RADIUS")
- Configure:
| Setting | Value |
|---|---|
| Server Address | radius.captifi.io |
| Authentication Port | 1812 |
| Accounting Port | 1813 |
| Shared Secret | Shown in your CaptiFi dashboard's Aruba setup guide (or provided by support) |
| NAS Identifier | Shown in your CaptiFi dashboard (unique to your site) |
- Two settings to double-check:
- "Require RADIUS Message-Authenticator" must NOT be selected
- "Use Device IP" should be enabled
- Save and apply
Step 4: Configure Walled Garden / Allowed Domains
Before guests authenticate, they need access to CaptiFi's servers to load the splash page. Add the following to Allowed Domains (also called Walled Garden) in your guest network settings:
| Domain |
|---|
app.captifi.io |
captifi.io |
- Open your guest network settings in Aruba Instant On
- Go to Security → Allowed Domains (or Walled Garden)
- Add each domain listed above
- Save and apply
TIP
If your splash page uses paid WiFi or external resources, you may need extra entries — see the Paid WiFi guide for the Stripe domains.
Step 5: Test the Connection
- Connect to the guest WiFi with a test device
- The CaptiFi splash page should appear automatically
- If on mobile, you may need to open a browser and visit any HTTP site
- Complete a test login — you should get internet access within a few seconds
- Confirm the login appears in Guest Visits on your CaptiFi dashboard
TIP
After making changes in the Aruba portal, it may take 1-2 minutes for settings to propagate to all access points.
Supported Aruba Models
All Aruba Instant On access points are supported, including AP11, AP12, AP15, AP22, and AP25.
Troubleshooting
| Issue | Solution |
|---|---|
| Splash page not appearing | Verify the portal type is External and the portal URL matches your dashboard exactly, including the trailing / |
| "Cannot reach portal" error | Ensure the AP has internet access and the walled garden includes app.captifi.io |
| Guests can't get online after login | Check Step 3: the CaptiFi RADIUS server (radius.captifi.io, ports 1812/1813) must be configured with the correct shared secret and NAS identifier |
| "Access denied" after login | The RADIUS shared secret doesn't match — copy and paste it directly from your CaptiFi dashboard |
| Guests dropped after a while | Session length is controlled by CaptiFi — adjust it under your venue's settings in My Locations |
| Settings not applying | Wait 2 minutes for propagation, then reboot the AP from the Instant On app |
| Splash page loads but login fails | Ensure "Require RADIUS Message-Authenticator" is NOT selected and "Use Device IP" is enabled |
| Guests see a blank page | Clear the browser cache on the test device, and verify the portal URL has no extra spaces |
Next Steps
Need Help?
Aruba Instant On setups can vary depending on your hardware and firmware version. If you're stuck:
- Email: hello@captifi.io
- Live Chat: Available on captifi.io