Ruckus (SmartZone managed)

IMPORTANT:
Please ensure you are running SmartZone v3.0 or above in order to continue.

1
Start by logging into your SmartZone web interface.
2
Click Services & Profiles > Authentication on the left. Click the Proxy (SZ Authenticator) tab then Create and configure with the following settings:

RADIUS AUTH
Name Guest WiFi
Service Protocol RADIUS
Primary Server Address rad1-eu.captini.net ( 52.19.71.71 )
Port 1812
Shared Secret capt1n1
Confirm Secret as above
Backup RADIUS Enable Secondary Server
Secondary Server Address rad2-eu.captini.net ( 52.210.72.220 )
Port 1812
Shared Secret capt1n1
Confirm Secret as above
3
Click OK to save.
4
Next, click Accounting on the left. Click the Proxy tab then Create and configure with:

RADIUS ACCOUNTING
Name Guest WiFi Acct
Primary Server IP Address rad1-eu.captini.net ( 52.19.71.71 )
Port 1813
Shared Secret capt1n1
Confirm Secret as above
Backup RADIUS Enable Secondary Server
Secondary Server IP Address rad2-eu.captini.net ( 52.210.72.220 )
Port 1813
Shared Secret capt1n1
Confirm Secret as above
5
Click OK to save.
6
Click Hotspots & Portals on the left. Click the Hotspot (WISPr) tab then Create and configure with:


HOTSPOT
Portal Name Guest WiFi
Smart Client Support None
Login URL External
Redirect unauthenticated users to (Primary) https://portal-eu.captini.net
Redirected MAC Format AA-BB-CC-DD-EE-FF
HTTPS Redirect ON
Start Page - Redirect to the following URL https://portal-eu.captini.net
Walled Garden Add the following domains one by one:

*.captini.com
*.captini.net
*.amazonaws.com
*.cloudfront.net
m.facebook.com
*.doubleclick.net
*.doublecick.net
developer.facebook.com
*.doubleclick.com
*.facebook.com
*.fbcdn.net
*.akamaihd.net
connect.facebook.net
*.facebook.net
twitter.com
*.twimg.com
api.twitter.com
*.linkedin.com
platform.linkedin.com
*.licdn.net
*.licdn.com
*.slicdn.com
sr.symcb.com
*.instagram.com
7
Click OK to save.
8
Click Wireless LANs on the left, then click Create. Configure with:

WIRELESS LAN
Under General Options:
Portal Name Guest WiFi
SSID Guest Wi-Fi (or whatever you wish)
Zone Select a zone
WLAN Group Select a group (or default)
Under Authentication Options:
Authentication Type Hotspot (WISPr)
Method Open
Under Encryption Options:
Method None
Under Hotspot Portal:
Hotspot (WISPr) Portal Guest WiFi
Bypass CNA ON - Use Controller as proxy - Guest WiFi
Accounting Service ON - Use Controller as Proxy - Guest WiFi Acct
Send interim update every 2 Minutes
Under RADIUS Options:
NAS ID AP MAC
Delimiter Dash
Single Session ID Accounting ON
Called Station ID AP MAC
9
Click OK to save.
10
Click System > General Settings on the left and then the WISPr Northbound Interface tab. Configure using the following settings:

NORTHBOUND API
Enable Northbound Portal Interface Support ON
User Name api
Password Request from your Captini account manger
SmartZone Public IP Please email this address to your Captini account manager
11
Click OK to save.
12
IMPORTANT: In order for our system to authenticate users, you are required to set up a Port Forward on your firewall/router to allow traffic inbound.

Local/Internal IP Your Smartzone internal LAN IP (e.g. 192.168.0.1) Protocol TCP Destination Port 9080

PORT FORWARDING INFO
Create a new port forward as follows:
Local/Internal IP: Your Smartzone internal LAN IP (e.g. 192.168.x.x)
Protocol: TCP
Destination Port: 9080


The configuration is complete and ready for testing.