Ubiquiti Unifi - Passpoint Configuration

In this guide we describe how to configure your Ubiquiti UniFi controller to work with Passpoint / HS2.0

Prerequisites

This guide is for Network version 8.4.x ONLY. Ubiquiti has recently reintroduced Passpoint feature into their codebase, at the moment available only from the Early Release channel. You have to enable Early Release in your UI accounts settings before being able to select it in the Unifi Controller. You also need to upgrade your AP firmware to the firmware from Early Release channel. As this is the pre-release / testing branch some bugs might be present.

Further information about Unifi and  Passpoint can be found on the Unifi website:

Unifi Passpoint

  1. Access to the Ubiquiti Dashboard as a user with administrative privileges.
  2. Information about the assigned RADIUS servers - Server IP address, port numbers, shared secrets - available from IronWiFi Management Console - Sign in or Open Account

About this guide

This guide describes how to set up and test your Ubiquiti UniFi environment so you can use it with IronWiFi Passpoint:  

  • Log in to the Ubiquiti UniFi dashboard as a user with administrative privileges.
  • Update Ubiquiti UniFi access points to firmware that supports Hotspot 2.0 (Early Release)
  • Configure a secure RADIUS connection.
  • Configure the wireless LAN.

Log in to the Ubiquiti UniFi Dashboard

To start the configuration process, log in to the Ubiquiti UniFi Dashboard as admin (https://unifi.ui.com/dashboard).  For existing environments with additional users, log in as a user with administrative privileges.

There are a number of options you can set. Only the options that require your input are shown. Default values are used for options that don’t need adjustment.

Update the access point firmware

Before starting the Hotspot 2.0 (HS 2.0) configuration, update the access points (APs) with firmware that supports Hotspot 2.0.  

Ubiquiti recommends that the UniFi access points run firmware version 7.0.63/6.6.75/6.6.76 or newer.

Configure the RADIUS Profile

Navigate to Settings -> Profiles -> Radius, click Create New

Fill in the fields, clicking Add after adding each server, tick Wireless Networks, Accounting and set Interim Update Interval

Screenshot 2024-08-06 at 14.02.00

Click Apply Changes when done.

Configure Wireless Network

Click on WiFi, click Create New

Fill in name, click Manual next to Advanced, switch HotSpot2.0 to Passpoint option.

Add Venue Information accordingly, add ironwifi.net as NAI Realm, select EAP-TTLS and add PAP and MSCHAP v2, save.

In the Roaming Consortium List add ironwifi.net as Name and AA146B0000 as the Organization ID.

Add ironwifi.net as Domain Name and add Operator Friendly Name [this setting is overwritten with the input from the generated profile]

 

Select the remaining option according to your requirements, select correct RADIUS Profile and click Apply Changes