You must change the default password before continuing.

At least 8 characters.

RADIUS Platform

waiting for approval

unknown on the network · BYOD enrollments submitted — until approved they cannot reach the network.

Dashboard

Endpoints

Active sessions

Pending approvals

Network devices

Sites

Recent rejects

Recent auth events

View all →
TimeIdentityMethodResultVLANReason
No auth events yet

Clients

NameStatusCreatedActions
No clients yet

Sites

UniFi Scope

Every network and SSID this client's UniFi key can see, and which of them authenticate against us.

Wi-Fi not assigned to a site

These apply across the whole client. Edit one to pin it to a site.

No sites yet — a site holds its VLANs, network devices and Wi-Fi

Network Devices

NameTypeRADIUS Client IPNAS-IdentifierVendorAPIActions

No network devices yet

Endpoints

Showing devices for
HostnameTypeUserVLANCertificateStatusAccessDescriptionActions

No endpoints yet

Pending approvals

Device Enrollments — employees self-enrolling a personal device

No device enrollments awaiting approval

Unknown Devices — seen on the network without a known identity

No pending approvals

VLAN assignment

PriorityMatch typeMatch valueResultVLANActions

No access policies yet

Alerts

SeverityTypeAlertSeenStatusActions

No alerts — everything looks healthy.

Notification channels

Add a channel

Which events go to this channel

Uncheck anything this channel should stay quiet about.

Nothing checked — this channel would never fire. Pick at least one.

NameTypeDestinationEventsLast deliveryActions

No channels yet — add one above to be notified by email, Slack, Microsoft Teams, or your SIEM when devices are waiting.

API tokens

New token — copy it now, it won't be shown again:

Create a token

Use as a Bearer token: Authorization: Bearer rdp_.... It authenticates as you; a scoped token is limited to one client.

NamePrefixScopeLast usedExpiresActions

No API tokens yet.

Activity

Export applies the filters above but is not limited to the row count shown on screen (up to 50,000 rows).

TimeEventWhoDeviceWhereNetworkDetail
No activity in this window

Whether each of your network devices is reaching the server and being answered.

No network devices registered for this client yet.

Guest portal configuration

Configure captive portal branding, Stripe payment, pricing plans, and guest access behavior.

Preview portal

RADIUS server public endpoint

Use this as the RADIUS server address in UniFi/MikroTik.

Auth / Accounting / CoA

/ /

UDP 1812/1813 inbound required; UDP 3799 if using CoA disconnect.

RADIUS client IP reminder

Each network device's RADIUS client IP is the source IP this server sees from the client site (its public WAN or VPN/RadSec tunnel IP). Do not enter the RADIUS server's own IP unless the device is on the same LAN as the server.

Guest captive portal URL (for this client)

Set this as the external/captive portal URL on the client’s UniFi or MikroTik. The AP appends the guest MAC automatically. Click Preview to test it now.

Portal branding & access methods

logo

Stripe

Stripe webhook URL: https:///api/guest/stripe-webhook

Add pricing / access plan

Current guest plans

NameMethodDurationPriceVLANActions
No guest plans configured yet

Recent guest sessions

MACStatusMethodGuestVLANExpires
No guest sessions yet

Certificates & PKI

Manage certificate authorities and issue EAP-TLS client/server certificates.

No certificate authority yet. Create one to enable EAP-TLS.

Certificates —

Showing certificates for
Subject CNSerialStatusExpiresActions
No certificates issued from this CA yet No certificates for this device

WiFi Networks

Define SSIDs and push them to UniFi / MikroTik equipment.

No WiFi networks defined yet.

Enrollment tokens

Generate self-service links so users can onboard devices and download certificates.

Self-service enrollment link Active Off

One link you can share with employees. They confirm their email, then request a personal device — each request lands here for your approval. No sign-in or prior network access required.

Currently allows:

New enrollment link — copy it now, the full token is shown only once:

TokenPurposeUsesExpires
No enrollment tokens yet

Users

BYOD enrollment link Active Off

Share this with users so they can enroll their own devices — or use "+ Add user" to invite them directly.

Manage →

Synced directory users and local accounts — sign-in source, groups, and devices.

User Sign-in Groups Devices Status
No synced users yet — sync an identity provider on the Identity & Groups page.

Identity providers

Connect Entra ID / OIDC to pull users and groups. Use "Sync now" to refresh from the directory.

No identity providers connected yet.

Group → VLAN mappings

Map a synced directory group to a VLAN. Members of a mapped group also get self-service portal access.

GroupVLANPriorityActions
No group mappings yet

Identity & groups

Connect Microsoft Entra ID / OAuth and map directory groups to VLANs.

Identity providers

No identity providers configured

Group → VLAN mappings

GroupVLANPriorityActions
No group mappings yet

Client setup wizard

Guided onboarding — from organization to a verified RADIUS deployment in 8 steps.

Team & Access

Manage internal/admin users, their roles, and per-client access.

platform_owner Full control, incl. billing & user management
platform_admin Manage all clients & users
client_admin Full control of assigned client(s)
client_operator Day-to-day changes, no user management
client_auditor Read-only access
UserScopeRolesStatusActions
No users yet

Diagnostics

Is each device's traffic reaching the server and being answered — and what the service sees, live.

Settings

Global platform configuration. Changes apply immediately — no restart. Values feed the dashboard, RadSec bundles, and setup guides.

Branding — white-label the selected client's portal & workspace

VLAN fallbacks — for the selected client only

Read only when the authenticating site has no VLAN of the matching purpose (BYOD also accepts a Guest VLAN; Corporate also accepts a Data VLAN). Sites that already have one ignore these boxes entirely — see the note under each field. Leave blank to inherit the platform value.

Two-factor authentication (TOTP)

Protects local password logins (SSO admins get MFA from their identity provider). Enabled.Not enabled.

Public RADIUS endpoint

What client sites (UniFi/MikroTik) point at. The hostname is preferred for RadSec/TLS; the IP is the fallback.

Preferred. Baked into every RadSec bundle, appliance .env, and the UniFi guide.

Sites will be told to use:

Ports

Defaults are standard; change only if your firewall/NAT remaps them.

Branding

logo

PNG/JPEG/GIF/WebP, max 2 MB. Shown in the dashboard header.

Device onboarding (NAC)

One SSID: devices with an Intune-deployed certificate auto-join the corporate network via EAP-TLS. Devices without a cert fall back to username/password and land on the BYOD network.

Where password-auth (no cert) devices go, for tenants with no override of their own. Precedence: the site's VLAN with purpose "byod" (or "guest") → the client's VLAN fallback (card above) → this value. Sites that define their own BYOD/Guest VLAN never reach either fallback.

Email (SMTP)

Powers email alerts & notifications. Password is encrypted; leave blank to keep the current one.

Source:

Note: the RadSec/EAP server TLS certificate is separate — if you change the hostname, re-issue the server cert with the new name (see the RadSec docs) so certificate validation still matches.