Put visitors on a secured WPA-Enterprise network

Create a Visitor WiFi entry for Cisco Meraki, UniFi, TP-Link, Ruckus or any standard access point, point the access point at Offision's RADIUS server, and have visitors join with the username and password on their badge.

Updated 20 Aug 2026

Done looks like this: a test visitor checks in, joins your guest SSID with the username and password on their badge, and is refused after checking out.

1. Add the network entry

Open Visitor WiFi, choose Add, and pick the brand that matches your controller from the menu — Cisco, Ruckus, TP-Link, Unifi, or Generic for any standard RADIUS access point. The brand cannot be changed after the entry is created.

Open Visitor WiFi
The Visitor WiFi page — one row per guest network.

The Visitor WiFi page — one row per guest network.

The Marketplace also carries a tile per vendor under Visitor WiFi; a tile opens this same list with the brand already chosen.

2. Fill in the Basic page

Name the entry, decide the sign-in rules — Username type and Password type — and, if this network is for one site only, link its buildings.

A RADIUS entry's Basic page — the sign-in rules, and no network-name field.

A RADIUS entry's Basic page — the sign-in rules, and no network-name field.

Every field is explained in the settings reference. There is no network-name field on this page: a secured network is named on your controller, and its security comes from the per-visitor sign-in, not a shared password.

3. Copy the RADIUS values into your controller

Open RADIUS settings, the second page of the dialog. Everything on it is generated for you: Host IP or FQDN, Auth port, Secret, and the NAS identifier.

The RADIUS settings page — values to copy into the controller.

The RADIUS settings page — values to copy into the controller.

Two brands differ:

  • Unifi authenticates by access point instead: enter your access points’ MAC addresses, one per line, rather than a NAS identifier.
  • Cisco shows the same values arranged as a step-by-step Meraki guide.

4. Create the SSID on your controller

On the controller, create a WPA-Enterprise (802.1X) guest SSID pointing at the values from step 3. Offision’s RADIUS server answers PAP, EAP-TTLS/PAP and PEAP/MSCHAPv2 — the methods phones and laptops use out of the box.

5. Check it worked

Invite yourself, check in at reception, and join the SSID with the username and password printed on your badge. Then check out — and confirm the same details are now refused. Both results matter: the second one is the security story.

When it goes wrong

What you seeUsual cause
Sign-in refused for a real visitorThey have not checked in yet, or their visit period has ended
Every sign-in refusedThe entry has no Visitor WiFi Integration license, or the controller’s shared secret no longer matches — regenerating the Secret without updating the controller does this
The controller never reaches OffisionThe NAS identifier (or a Unifi MAC address) is missing or mistyped on the access points, so requests cannot be matched to the entry
The badge prints no WiFi detailsExpected for RADIUS brands — see what the badge can print