Cambium - Passpoint Configuration
Configure Passpoint (Hotspot 2.0) on Cambium Networks cnPilot access points to enable automatic WiFi authentication through IronWifi's cloud RADIUS service. This eliminates manual network selection and provides WPA2/WPA3-Enterprise security across your wireless infrastructure.
Supported Platforms
- cnMaestro - Cloud management platform
- Cambium cnPilot - Enterprise access points
- Cambium XV Series - Outdoor access points
Prerequisites
In Cambium:
- Cambium access points with Hotspot 2.0 support
- cnMaestro account or on-premises controller
- Firmware version 6.x or later
In IronWifi Console (complete these first):
- Log in to IronWifi Management Console
- Navigate to Networks > select your network
- Enable Passpoint
- Note the following:
- RADIUS Server IP addresses
- RADIUS Secret
- NAI Realm (e.g.,
ironwifi.com) - Roaming Consortium OIs
cnMaestro Cloud Configuration
cnMaestro Configuration
Step 1: Configure RADIUS Server
- Log in to cnMaestro
- Navigate to Configure > WLAN > AAA Servers
- Click Add AAA Server
- Configure:
- Name: IronWifi-RADIUS
- Type: RADIUS
- Host: IronWifi RADIUS IP
- Authentication Port: 1812
- Accounting Port: 1813
- Shared Secret: Your RADIUS secret
- Click Save
Step 2: Create WLAN Profile
- Go to Configure > WLAN > WLANs
- Click Add WLAN
- Configure basic settings:
- WLAN Name: Passpoint-Secure
- SSID: Your SSID name
- Security: WPA2-Enterprise
- AAA Server: IronWifi-RADIUS
Step 3: Enable Hotspot 2.0
- In the WLAN configuration, find Hotspot 2.0 section
- Enable Hotspot 2.0
- Configure the following:
Network Settings:
- Internet Access: Enabled
- Network Type: Free Public Network
- Network Authentication: Not required
Venue Information:
- Venue Group: Business
- Venue Type: Unspecified Business
Domain Configuration:
- Domain Name:
ironwifi.net
Operator Information:
- Operator Friendly Name: Your Organization Name
- Language Code: eng
Step 4: Configure Roaming Consortium
- In Hotspot 2.0 settings, find Roaming Consortium
- Add Organization Identifiers (OIs):
5A03BA0000
004096
Step 5: Configure NAI Realm
- Find NAI Realm section
- Add realm configuration:
- Realm:
ironwifi.com - EAP Method: EAP-TTLS
- Inner Authentication: PAP, MSCHAPv2
- Realm:
- Save the configuration
Step 6: Apply to Access Points
- Go to Configure > AP Groups
- Select target AP group
- Assign the Passpoint WLAN profile
- Push configuration to devices
cnPilot On-Premises Configuration
Web Interface Configuration
Configure RADIUS
- Access AP web interface
- Go to Configuration > Security > RADIUS
- Add RADIUS server:
- Server IP: IronWifi RADIUS IP
- Port: 1812
- Secret: Your shared secret
- Accounting: Enable, port 1813
Configure Hotspot 2.0
- Go to Configuration > Wireless > WLAN
- Create or edit WLAN
- Enable Hotspot 2.0
- Configure:
Hotspot 2.0: Enabled
Internet: Yes
Network Type: Free Public
Venue: Business - Unspecified
Domain: ironwifi.net
Operator: Your Organization (eng)
Roaming Consortium: 5A03BA0000, 004096
NAI Realm: ironwifi.com, EAP-TTLS
CLI Configuration
# Configure RADIUS
radius-server host 1.2.3.4 key your-secret
# Create WLAN with Hotspot 2.0
wlan passpoint
ssid "Passpoint"
security wpa2-enterprise
radius-server IronWifi
hotspot20 enable
hotspot20 internet enable
hotspot20 network-type free-public
hotspot20 venue-group business
hotspot20 venue-type unspecified
hotspot20 domain-name ironwifi.net
hotspot20 operator-name eng "IronWifi"
hotspot20 roaming-consortium 5A03BA0000
hotspot20 roaming-consortium 004096
hotspot20 nai-realm ironwifi.com eap-ttls pap
Advanced Configuration
3GPP Cellular Network Information
For carrier integration:
- In Hotspot 2.0 settings, find 3GPP Cellular Network
- Add MCC/MNC pairs for supported carriers:
MCC: 310, MNC: 410 (AT&T)
MCC: 311, MNC: 480 (Verizon)
WAN Metrics
Configure WAN link information:
- Enable WAN Metrics
- Configure:
- Link Status: Up
- Symmetric Link: Yes
- Downlink Speed: 100000 (kbps)
- Uplink Speed: 50000 (kbps)
Connection Capability
Define available services:
| Protocol | Port | Status |
|---|---|---|
| ICMP | - | Closed |
| TCP | 80 | Open |
| TCP | 443 | Open |
| TCP | 5060 | Open |
| UDP | 5060 | Open |
Troubleshooting
Passpoint Network Not Visible
- Verify Hotspot 2.0 is enabled on WLAN
- Check firmware supports Hotspot 2.0
- Ensure client device has Passpoint enabled
- Verify ANQP responses are being sent
Authentication Failures
- Test RADIUS connectivity from AP
- Verify shared secret matches
- Check NAI realm configuration
- Review IronWifi authentication logs
Debug Commands
# Show Hotspot 2.0 status
show wlan hotspot20
# Show RADIUS statistics
show radius statistics
# Show connected clients
show clients
# Debug ANQP
debug hotspot20 anqp
cnMaestro Diagnostics
- Go to Monitor > Clients
- Check Passpoint association status
- Review authentication events
- Check AP connectivity status
Best Practices
- Firmware Updates: Keep APs on latest firmware for best Passpoint support
- Testing: Test with multiple Passpoint-capable devices
- Monitoring: Set up alerts for authentication failures
- Documentation: Document your OI and realm configuration
- Redundancy: Configure backup RADIUS servers