TP-Link Omada - Passpoint Configuration
Configure Passpoint (Hotspot 2.0) on TP-Link Omada SDN Controller and EAP series access points to enable automatic WiFi authentication through IronWifi's cloud RADIUS service. This eliminates manual network selection and provides WPA2/WPA3-Enterprise security across your wireless infrastructure.
Supported Platforms
- Omada Controller - Hardware, software, or cloud
- Omada EAP Series - Enterprise access points (EAP660 HD, EAP670, etc.)
Prerequisites
In TP-Link Omada:
- Omada Controller 5.x or later
- Omada EAP access points with Hotspot 2.0 support (Wi-Fi 6 models recommended)
- Network connectivity to IronWifi RADIUS servers
In IronWifi Console (complete these first):
- Log in to IronWifi Management Console
- Navigate to Networks > select your network
- Enable Passpoint
- Note the following:
- Primary RADIUS Server IP
- Secondary RADIUS Server IP
- RADIUS Secret
- NAI Realm (e.g.,
ironwifi.com) - Roaming Consortium OIs
Important Note
Passpoint/Hotspot 2.0 support varies by Omada AP model and firmware version. Verify your specific model supports Hotspot 2.0 before proceeding.
Omada Controller Configuration
Omada Controller Setup
Step 1: Configure RADIUS Profile
- Log in to Omada Controller
- Navigate to Settings > Authentication > RADIUS Profile
- Click Create New RADIUS Profile
- Configure:
- Name: IronWifi
- Authentication Server:
- IP Address: IronWifi RADIUS IP
- Port: 1812
- Shared Secret: Your RADIUS secret
- Accounting Server:
- IP Address: IronWifi RADIUS IP
- Port: 1813
- Shared Secret: Your RADIUS secret
- Click Create
Step 2: Create Wireless Network
- Go to Settings > Wireless Networks
- Click Create New Wireless Network
- Configure basic settings:
- Name: Passpoint-Network
- SSID: Passpoint
- Security Mode: WPA2-Enterprise
- RADIUS Profile: IronWifi
- Click Apply
Step 3: Enable Hotspot 2.0
- In the wireless network settings, find Advanced Settings
- Locate Hotspot 2.0 section
- Enable Hotspot 2.0
Step 4: Configure Hotspot 2.0 Settings
Interworking Settings:
- Access Network Type: Free public network
- Internet: Enabled
- ASRA: Disabled
- ESR: Disabled
- UESA: Disabled
Venue Information:
- Venue Group: Business
- Venue Type: Unspecified Business
- Venue Name: Your Location (Language: eng)
Step 5: Configure Domain Name
- In Hotspot 2.0 settings, find Domain Name List
- Click Add
- Enter:
ironwifi.net
Step 6: Configure Roaming Consortium
- Find Roaming Consortium List
- Add Organization Identifiers:
- Click Add
- Enter OI:
5A03BA0000 - Click Add
- Enter OI:
004096
Step 7: Configure NAI Realm
-
Find NAI Realm List
-
Click Add NAI Realm
-
Configure:
- NAI Realm:
ironwifi.com - EAP Method: EAP-TTLS
- Inner Authentication: PAP
- NAI Realm:
-
Save all settings
Per-Site Configuration
For multi-site deployments:
Site-Level Settings
- Select target site in Omada Controller
- Go to Settings > Wireless Networks
- Configure Passpoint network per site
- Adjust settings as needed per location
Venue-Specific Configuration
Customize venue information per site:
| Setting | Example Values |
|---|---|
| Venue Group | Business, Residential, Educational |
| Venue Type | Hotel, Restaurant, Coffee Shop |
| Venue Name | "Site Name (eng)" |
Advanced Configuration
WAN Metrics
If available in your firmware:
- Find WAN Metrics in Hotspot 2.0 settings
- Configure:
- Link Status: Up
- Symmetric Link: Yes
- Downlink Speed: 100000 (kbps)
- Uplink Speed: 50000 (kbps)
Connection Capability
Define available network services:
| Protocol | Port | Status |
|---|---|---|
| ICMP | - | Closed |
| TCP | 80 | Open |
| TCP | 443 | Open |
| TCP | 5060 | Open |
| UDP | 5060 | Open |
3GPP Cellular Information
For carrier integration (if supported):
- MCC/MNC pairs for carrier identification
- Enables carrier WiFi offload
Omada Cloud Controller
Cloud Configuration
If using Omada Cloud Controller:
- Log in to omada.tplinkcloud.com
- Select your controller
- Follow the same configuration steps
- Configuration syncs to local controller/APs
Limitations
Cloud controller may have:
- Delayed configuration sync
- Limited advanced Hotspot 2.0 options
- Check local controller for full feature set
Verification
Check Configuration
- Go to Devices > select an AP
- View Configuration tab
- Verify Passpoint settings applied
Monitor Clients
- Go to Clients
- Filter by SSID: Passpoint
- Check connection status
Verify RADIUS
- Go to Insights > Events
- Filter for authentication events
- Verify successful authentications
Troubleshooting
Network Not Discovered
-
Verify Hotspot 2.0 Enabled
- Check WLAN settings
- Ensure HS2.0 toggle is on
-
Check AP Support
- Verify AP model supports Hotspot 2.0
- Update firmware if needed
-
Verify Client Support
- Ensure device has Passpoint enabled
- Check device supports Passpoint
Authentication Failures
-
Test RADIUS Connectivity
- Check network path to RADIUS server
- Verify firewall allows UDP 1812/1813
-
Verify Credentials
- Check RADIUS secret matches
- Verify NAI realm configuration
-
Review Logs
- Check Omada Controller logs
- Review IronWifi authentication logs
Common Issues
| Issue | Solution |
|---|---|
| AP doesn't show HS2.0 option | Update firmware or check model support |
| Clients don't connect automatically | Verify roaming consortium and NAI realm |
| Authentication timeout | Check RADIUS server connectivity |
| Intermittent failures | Check for IP conflicts or network issues |
Debug Steps
-
Controller Logs
- Go to System > Logs
- Filter for wireless/authentication events
-
AP Status
- Check AP is online
- Verify configuration adopted
-
Client Diagnostics
- Check client supplicant logs
- Verify certificate if using EAP-TLS
Firmware Requirements
Minimum Versions
| Component | Minimum Version |
|---|---|
| Omada Controller | 5.0.0 |
| EAP660 HD | 1.0.0 |
| EAP670 | 1.0.0 |
| EAP615-Wall | Check release notes |
Recommended
- Use latest stable firmware
- Check TP-Link release notes for Hotspot 2.0 fixes
- Test after firmware updates
Best Practices
- Verify AP Support: Not all Omada APs support Hotspot 2.0
- Keep Updated: Use latest controller and AP firmware
- Test Thoroughly: Test with multiple Passpoint-capable devices
- Monitor: Set up alerts for authentication failures
- Documentation: Document your configuration for support
- Redundancy: Configure backup RADIUS servers