waiting for approval
unknown on the network · BYOD enrollments submitted — until approved they cannot reach the network.
Dashboard
Endpoints
Active sessions
Pending approvals
Network devices
Sites
Recent rejects
Recent auth events
View all →| Time | Identity | Method | Result | VLAN | Reason |
|---|---|---|---|---|---|
Clients
| Name | Status | Created | Actions |
|---|---|---|---|
Sites
UniFi Scope
Every network and SSID this client's UniFi key can see, and which of them authenticate against us.
Our RADIUS is matched on address:
Some SSIDs are mirrored across consoles and are counted once per console.
Wireless
| SSID | Security | VLAN | RADIUS profile | Auth server | Authenticates via |
|---|---|---|---|---|---|
| (disabled) |
Wired 802.1X
Port control: ·
RADIUS selection for wired is site-wide in UniFi; port profiles only toggle enforcement.
Networks / VLANs
| VLAN | Name | Purpose | Subnet | DHCP |
|---|---|---|---|---|
| Tag | Name | Purpose | Actions |
|---|---|---|---|
No VLANs at this site yet.
Network Devices
| Name | Type | RADIUS client IP | NAS-Identifier | API | Actions |
|---|---|---|---|---|---|
| not set | — |
No network devices at this site — nothing here can authenticate yet.
Wi-Fi networks
| SSID | Security | Status | Actions |
|---|---|---|---|
No SSIDs assigned to this site.
Guest Portal
No guest portal configured yet — set one up here, or once for the whole client under Guest portal.
Wi-Fi not assigned to a site
These apply across the whole client. Edit one to pin it to a site.
No sites yet — a site holds its VLANs, network devices and Wi-Fi
Network Devices
| Name | Type | RADIUS Client IP | NAS-Identifier | Vendor | API | Actions |
|---|---|---|---|---|---|---|
| not set | not connected |
No network devices yet
Endpoints
Pending approvals
Device Enrollments — employees self-enrolling a personal device
Unknown Devices — seen on the network without a known identity
VLAN assignment
| Priority | Match type | Match value | Result | VLAN | Actions |
|---|---|---|---|---|---|
No access policies yet
Alerts
| Severity | Type | Alert | Seen | Status | Actions |
|---|---|---|---|---|---|
No alerts — everything looks healthy.
Notification channels
Add a channel
Which events go to this channel
Uncheck anything this channel should stay quiet about.
Nothing checked — this channel would never fire. Pick at least one.
| Name | Type | Destination | Events | Last delivery | Actions |
|---|---|---|---|---|---|
| everything |
No channels yet — add one above to be notified by email, Slack, Microsoft Teams, or your SIEM when devices are waiting.
API tokens
New token — copy it now, it won't be shown again:
Create a token
Use as a Bearer token: Authorization: Bearer rdp_.... It authenticates as you; a scoped token is limited to one client.
| Name | Prefix | Scope | Last used | Expires | Actions |
|---|---|---|---|---|---|
| revoked |
No API tokens yet.
Activity
Export applies the filters above but is not limited to the row count shown on screen (up to 50,000 rows).
| Time | Event | Who | Device | Where | Network | Detail |
|---|---|---|---|---|---|---|
|
· port
|
VLAN | · ↓ ↑ session opened |
Whether each of your network devices is reaching the server and being answered.
·
RadSec sessions (s):
Guest portal configuration
Configure captive portal branding, Stripe payment, pricing plans, and guest access behavior.
RADIUS server public endpoint
Use this as the RADIUS server address in UniFi/MikroTik.
Auth / Accounting / CoA
/ /
UDP 1812/1813 inbound required; UDP 3799 if using CoA disconnect.
RADIUS client IP reminder
Each network device's RADIUS client IP is the source IP this server sees from the client site (its public WAN or VPN/RadSec tunnel IP). Do not enter the RADIUS server's own IP unless the device is on the same LAN as the server.
Guest captive portal URL (for this client)
Set this as the external/captive portal URL on the client’s UniFi or MikroTik. The AP appends the guest MAC automatically. Click Preview to test it now.
Portal branding & access methods
Stripe
Stripe webhook URL: https:///api/guest/stripe-webhook
Add pricing / access plan
Current guest plans
| Name | Method | Duration | Price | VLAN | Actions |
|---|---|---|---|---|---|
Recent guest sessions
| MAC | Status | Method | Guest | VLAN | Expires |
|---|---|---|---|---|---|
Certificates & PKI
Manage certificate authorities and issue EAP-TLS client/server certificates.
Expires
No certificate authority yet. Create one to enable EAP-TLS.
Certificates —
| Subject CN | Serial | Status | Expires | Actions |
|---|---|---|---|---|
WiFi Networks
Define SSIDs and push them to UniFi / MikroTik equipment.
No WiFi networks defined yet.
Enrollment tokens
Generate self-service links so users can onboard devices and download certificates.
Self-service enrollment link Active Off
One link you can share with employees. They confirm their email, then request a personal device — each request lands here for your approval. No sign-in or prior network access required.
Currently allows:
New enrollment link — copy it now, the full token is shown only once:
| Token | Purpose | Uses | Expires |
|---|---|---|---|
Users
BYOD enrollment link Active Off
Share this with users so they can enroll their own devices — or use "+ Add user" to invite them directly.
Synced directory users and local accounts — sign-in source, groups, and devices.
| User | Sign-in | Groups | Devices | Status |
|---|---|---|---|---|
CC: Edit → |
|
Identity providers
Connect Entra ID / OIDC to pull users and groups. Use "Sync now" to refresh from the directory.
Last sync:
Group → VLAN mappings
Map a synced directory group to a VLAN. Members of a mapped group also get self-service portal access.
| Group | VLAN | Priority | Actions |
|---|---|---|---|
Identity & groups
Connect Microsoft Entra ID / OAuth and map directory groups to VLANs.
Identity providers
Last sync:
Group → VLAN mappings
| Group | VLAN | Priority | Actions |
|---|---|---|---|
Client setup wizard
Guided onboarding — from organization to a verified RADIUS deployment in 8 steps.
You can add this later under Identity & Groups. Group→VLAN mappings are configured there after the first sync.
A private Certificate Authority will be created for , used to issue EAP-TLS Wi-Fi certificates. Devices trust it automatically once enrolled — no cost, no public CA needed.
Defaults to your organization name. Leave as-is unless you have a reason to change it.
Tip: the RADIUS Client IP is the source IP this server sees from the site (its public WAN or VPN/RadSec tunnel IP) — not the RADIUS server's own IP.
Generated FreeRADIUS clients.conf (preview):
Deployment packages:
Test command:
Team & Access
Manage internal/admin users, their roles, and per-client access.
| User | Scope | Roles | Status | Actions |
|---|---|---|---|---|
| none |
Diagnostics
Is each device's traffic reaching the server and being answered — and what the service sees, live.
· · any-IP
RadSec sessions (s):
Unregistered senders — traffic being DROPPED
RadSec sources (NAT / roaming — matched by certificate, not IP)
Live server log
Settings
Global platform configuration. Changes apply immediately — no restart. Values feed the dashboard, RadSec bundles, and setup guides.
Branding — white-label the selected client's portal & workspace
VLAN fallbacks — for the selected client only
Read only when the authenticating site has no VLAN of the matching purpose (BYOD also accepts a Guest VLAN; Corporate also accepts a Data VLAN). Sites that already have one ignore these boxes entirely — see the note under each field. Leave blank to inherit the platform value.
Two-factor authentication (TOTP)
Protects local password logins (SSO admins get MFA from their identity provider). Enabled.Not enabled.
Add this secret to your authenticator app, then enter a 6-digit code to confirm:
Public RADIUS endpoint
What client sites (UniFi/MikroTik) point at. The hostname is preferred for RadSec/TLS; the IP is the fallback.
Preferred. Baked into every RadSec bundle, appliance .env, and the UniFi guide.
Ports
Defaults are standard; change only if your firewall/NAT remaps them.
Branding
PNG/JPEG/GIF/WebP, max 2 MB. Shown in the dashboard header.
Device onboarding (NAC)
One SSID: devices with an Intune-deployed certificate auto-join the corporate network via EAP-TLS. Devices without a cert fall back to username/password and land on the BYOD network.
Where password-auth (no cert) devices go, for tenants with no override of their own. Precedence: the site's VLAN with purpose "byod" (or "guest") → the client's VLAN fallback (card above) → this value. Sites that define their own BYOD/Guest VLAN never reach either fallback.
Email (SMTP)
Powers email alerts & notifications. Password is encrypted; leave blank to keep the current one.
Note: the RadSec/EAP server TLS certificate is separate — if you change the hostname, re-issue the server cert with the new name (see the RadSec docs) so certificate validation still matches.