Mist (Juniper) - Passpoint Configuration
Configure Passpoint (Hotspot 2.0) on Juniper Mist AI-driven access points to enable automatic WiFi authentication through IronWifi's cloud RADIUS service. This eliminates manual network selection and provides WPA2/WPA3-Enterprise security across your wireless infrastructure.
Supported Platforms
- Mist Cloud - Cloud-managed wireless
- Mist AP Series - AP12, AP32, AP33, AP34, AP41, AP43, AP45, AP61, AP63
Prerequisites
In Mist:
- Mist organization with APs deployed
- Mist APs with firmware supporting Hotspot 2.0
- Network connectivity to IronWifi RADIUS servers
In IronWifi Console (complete these first):
- Log in to IronWifi Management Console
- Navigate to Networks > select your network
- Enable Passpoint
- Note the following:
- Primary RADIUS Server IP
- Secondary RADIUS Server IP
- RADIUS Secret
- NAI Realm (e.g.,
ironwifi.com) - Roaming Consortium OIs
Mist Cloud Configuration
Mist Dashboard Configuration
Step 1: Configure RADIUS Server
- Log in to Mist Dashboard (manage.mist.com)
- Navigate to Organization > WLAN Templates or Site > WLANs
- Go to RADIUS Servers section
- Click Add Server
- Configure Authentication Server:
- IP Address: IronWifi RADIUS IP
- Port: 1812
- Secret: Your RADIUS secret
- Add Accounting Server:
- IP Address: IronWifi RADIUS IP
- Port: 1813
- Secret: Your RADIUS secret
Step 2: Create WLAN
- Go to Site > WLANs (or WLAN Template)
- Click Add WLAN
- Configure:
- SSID: Passpoint
- Security: WPA2/WPA3-Enterprise (802.1X)
- RADIUS Authentication: Select IronWifi servers
- RADIUS Accounting: Enable and select servers
Step 3: Enable Hotspot 2.0
- In WLAN settings, find Hotspot 2.0 section
- Toggle Enable Hotspot 2.0
Step 4: Configure Hotspot 2.0 Settings
Network Information:
- Internet Access: Yes
- Network Type: Free public network
- Additional Step Required: No (or as needed)
Venue Information:
- Venue Group: Business
- Venue Type: Unspecified Business
- Venue Name: Your Location Name
Operator Information:
- Operator Friendly Name: Your Organization
- Language: English (eng)
Step 5: Configure Domain
- In Hotspot 2.0 settings, find Domain Name
- Add:
ironwifi.net
Step 6: Configure Roaming Consortium
- Find Roaming Consortium section
- Add OIs:
5A03BA0000(OpenRoaming Settled)004096(OpenRoaming Settlement-Free)
Step 7: Configure NAI Realm
-
Find NAI Realm List section
-
Click Add NAI Realm
-
Configure:
- NAI Realm:
ironwifi.com - Encoding: UTF-8
- EAP Method: EAP-TTLS
- Authentication: Credentials (Username/Password)
- Inner Authentication: PAP
- NAI Realm:
-
Save the WLAN configuration
Advanced Configuration
3GPP Cellular Information
For carrier WiFi integration:
- In Hotspot 2.0 settings, find 3GPP Cellular Network Information
- Add MCC/MNC pairs:
MCC: 310, MNC: 410
MCC: 311, MNC: 480
WAN Metrics
Configure WAN link characteristics:
- Enable WAN Metrics
- Configure:
- Link Status: Up
- Symmetric Link: Yes
- At Capacity: No
- Downlink Speed: 100 Mbps
- Uplink Speed: 50 Mbps
- Downlink Load: 0
- Uplink Load: 0
Connection Capability
Define available network services:
| Protocol | Port Number | Status |
|---|---|---|
| TCP | 80 | Open |
| TCP | 443 | Open |
| TCP | 5060 | Open |
| UDP | 5060 | Open |
| ESP | - | Open |
Operating Class
Configure supported frequencies:
- Find Operating Class
- Enable classes for your deployment:
- Class 81: 2.4 GHz
- Class 115: 5 GHz (channels 36-48)
- Class 121: 5 GHz (channels 100-140)
- Class 124: 5 GHz (channels 149-161)
OpenRoaming Configuration
Enable OpenRoaming
For full OpenRoaming support:
-
In Hotspot 2.0 settings
-
Add both OpenRoaming OIs:
5A03BA0000 (Settled)
004096 (Settlement-Free) -
Configure NAI realm for OpenRoaming:
- Realm:
ironwifi.com - EAP Method: EAP-TTLS or EAP-TLS
- Realm:
RCOI Configuration
If using specific Roaming Consortium:
- Add your organization's RCOI
- Configure matching realm
WLAN Template Configuration
For multi-site deployments:
Create Template
- Go to Organization > WLAN Templates
- Click Create Template
- Configure Passpoint WLAN as above
- Save template
Apply to Sites
- Go to Organization > Site Configuration
- Select sites
- Apply WLAN template
- Push configuration
Troubleshooting
Network Not Discovered by Devices
-
Verify Hotspot 2.0 Status
- Check WLAN settings show HS2.0 enabled
- Verify AP firmware supports Passpoint
-
Check GAS/ANQP
- Devices should query ANQP
- APs should respond with configuration
-
Client Requirements
- Device must support Passpoint
- Passpoint must be enabled on device
Authentication Failures
-
RADIUS Connectivity
- Verify AP can reach RADIUS server
- Check firewall rules for UDP 1812/1813
-
Credential Issues
- Verify NAI realm matches
- Check EAP method configuration
- Review IronWifi logs
-
Certificate Issues (for EAP-TLS)
- Verify certificate is valid
- Check CA trust chain
Mist Dashboard Diagnostics
- Go to Insights > Client Events
- Filter by client or WLAN
- Look for:
- Association events
- Authentication events
- RADIUS responses
AP Diagnostics
- Select AP in dashboard
- Go to Utilities > AP Troubleshoot
- Run packet capture for RADIUS traffic
- Check AP logs for errors
Monitoring
Mist Analytics
Track Passpoint usage:
-
SLE (Service Level Expectations)
- Monitor authentication success rate
- Track connection times
-
Client Insights
- View Passpoint client associations
- Check device types and capabilities
-
RADIUS Analytics
- Monitor authentication requests
- Track failure reasons
IronWifi Monitoring
- Log in to IronWifi Console
- Navigate to Logs > Authentication
- Filter by network/realm
- Review success and failure events
Best Practices
- Use Templates: For consistent multi-site deployment
- Test Thoroughly: Verify with multiple device types
- Monitor SLEs: Track authentication success rates
- Firmware Updates: Keep APs on latest firmware
- Redundancy: Configure multiple RADIUS servers
- Documentation: Document your Passpoint configuration