Ruckus SmartZone
Prerequisites
This guide applies to the version 5.0.0 or later of the Controller.
The following products are supported:
SCG
vSCG
SZ
vSZ
vSZ-D
Device configuration
Configuring Wireless LANs Group:
In the panel go to the following directory: Network->Wireless LANs->Create
This example is for the Wlan Group Default, you can choose a different one if you already have your own WLAN group setup for this purpose.
In the pop-up window enter the following:
Name | Your network name |
SSID | Your network name |
WLAN Group | default |
Authentication Type | Hotspot (WISPr) |
Authentication Method | Open |
Now, in the "Hotspot (WISPr) Portal" field create a new profile by clicking "+"
Portal Name | aiwifi |
Logon URL | External |
Redirect unauthenticated user | Primary: |
Redirected MAC Format | AA:BB:CC:DD:EE:FF |
Start Page | redirect to the following URL: |
Session Timeout | 1440 |
Grace Period | 60 |
Leave the HTTPS redirect option as OFF (disabled) this will prevent SSL errors on the captive portal when being launched by the controller.
The, scroll down and add Walled Garden/Traffic Class Profile configuration:
Add the following domains:
captive.aiwifi.iostorage1-prod-media.s3.us-east-2.amazonaws.comapi.aiwifi.iosentry.iocloudfront.comlr-ingest.iodoubleclick.netfbsbx.com
After setting up "aiwifi" hotspot, please click "+" and add Authentication Server profile: ``
In the pop-up window enter the following:
Name | swauth |
Type | RADIUS |
IP Address | 3.135.4.246 |
Port | 1812 |
Share Secret | Aiwifi support will provide this |
Confirm Secret | Copy above |
When finished, press OK.
Then, add an "Accounting Server" by clicking "+"
In the pop-up window enter the following:
Name | aiwifiaccount |
Type | RADIUS Accounting |
IP Address | 3.135.4.246 |
Port | 1813 |
Shared Secret | Aiwifi support will provide this |
Confirm Secret | Copy above |
When finished, press OK.
Now, save the changes and go to: Network->Access Points
Enter the Access Point configuration panel following the marks. Set up your AP Name and go to the: Band/Spectrum Configuration. Then turn the "WLAN Group" on and choose the "default" profile.
This example is for the Wlan Group Default, you can choose a different one if you already have your own WLAN group setup for this purpose.
Disabling MAC address encryption
By default, MAC address encryption is enabled on Ruckus SZ devices and will cause Aiwifi to malfunction. In order to disable it, you will need to access your controller CLI via SSH, enable privileged commands, enter config mode, then execute the command “no encrypt-mac-ip”:\
Example:
Copy
ruckus> enableruckus# configruckus(config)# no encrypt-mac-ip
It might be the case that you have a firewall that blocks traffic between the WiFi device and the controller. You might either have explicit blocking rules on the firewall, or simply have separate VLANs for the guests and the controller and the traffic between them might be blocked as well. In this case you have to unlock specific ports. For example:
8090 TCP
8099 TCP
9997 TCP
9998 TCP