ISP Radius Hotspot: captive portals, vouchers, and sessions
Configure NAS devices, profiles, portals, hotspot accounts and voucher batches, then monitor authentication and expiry.
Last updated: 2026-08-19
Architecture and setup order
ISP Radius Hotspot manages Wi-Fi access through Radius accounts, captive portals, and vouchers. Prepare the Radius server, NAS devices, profiles, general state rules, and one of the three portal experiences before creating accounts or voucher batches.
The portal authenticates against Radius. Correct branding and a rendered login page do not prove that the NAS source, shared secret, selected profile, and accounting packets work.
NAS and security
Register every controller, access point, or gateway using the source IP actually seen by Radius, a recognizable name and description, vendor type, normally port 1812, the same shared secret on both sides, and any required server or community values. With NAT, register the observed source rather than the management address.
Allow authentication and accounting only from the intended network, protect the secret, and inspect requests and sessions after saving. Avoid duplicate NAS entries with ambiguous addresses.
Profiles and state-based switching
Profiles group supported Radius attributes for time limits, bandwidth, simultaneous use, vendor policy, and other access rules. Operators and dictionaries must match the NAS. A profile edit can affect every linked account.
General settings can automatically move suspended or terminated customers to dedicated profiles. Create and test those profiles first and verify the real restriction. The profile switch does not replace the authoritative commercial state.
Three separate captive portals
The module keeps independent configurations for credentials, passwordless access, and vouchers. For each portal select a real identifier, default profile, generated filename or API name, two colors, logo, background, and Privacy Policy content.
Do not reuse the same default profile automatically for identified customers, guests, and voucher users. Save and test the generated URL, smartphone layout, privacy text, authentication, and logout on an isolated network.
Hotspot accounts
An account stores customer or guest reference, contacts, city, profile, optional static IP, username, password, lifecycle state, and notes. Voucher accounts additionally record first use and validity days; zero or empty may mean unlimited duration according to the configured workflow.
Active, Suspended, and Terminated states must agree with the profile and linked service. Protect passwords, keep them out of screenshots, and perform a real controlled authentication after creation.
Voucher groups and generation
Groups generate batches of credentials with common profile and duration and produce printable voucher PDFs. Define group name, quantity, profile, validity, SSID or portal instructions, and layout before generation; verify unique usernames and passwords.
A voucher PDF is access material. Control distribution, record batches, and destroy unused copies. Do not regenerate an entire batch only to repair layout without invalidating or reconciling the previous credentials.
Dashboard and online users
Standard and complete dashboards summarize accounts, sessions, and operational state within the user’s authorized scope. Online Users shows current accounting sessions; the complete view is reserved for roles with wider visibility.
Always inspect accounting timestamp and freshness before declaring that a person is currently connected. A stale session may indicate missing Stop accounting rather than active use.
Access requests and session history
Access Requests records Radius attempts and outcomes, helping separate bad credentials, unsupported profile, unknown NAS, and policy rejection. Session History retains start, stop, address, NAS, traffic, and termination cause when available.
These records can reveal identity and connection habits. Restrict permissions, time ranges, exports, and retention according to the applicable policy.
Service, Customer Area, and billing
The service instance links the Hotspot account to the commercial relationship. Administration can open the portal and show state or sessions; Customer Area exposes only the information and actions explicitly intended for the account holder.
Technically active but unbilled accounts belong in the reconciliation queue. Resolve account, customer, service, and document linkage instead of disabling access without understanding the cause.
Automatic voucher expiry
The scheduled process calculates expiry from first use and configured validity days. Accounts without a finite duration remain unlimited; expired accounts follow the module lifecycle. Verify timezone, first-use timestamp, duration, and restriction profile before distributing a batch.
The printed or expected date does not enforce access by itself. Monitor scheduler execution, errors, and resulting account state.
Checklist
- Register actual NAS sources and matching secrets
- Use supported profile attributes
- Create and test suspended and terminated profiles
- Keep credential, passwordless, and voucher portals separate
- Publish readable privacy information and branding
- Test portal and logout on a phone
- Protect account credentials and voucher PDFs
- Review requests and accounting timestamps
- Link accounts to services and billing
- Monitor voucher-expiry automation
- Limit access to session data and exports