Skip to main content

HPE Aruba captive portal troubleshooting: redirect, certificate and walled garden checklist

Use this checklist to diagnose a failing HPE Aruba captive portal from the symptom you see: no redirect, a certificate warning or a guest who is never released. You can then trace the fault to DNS, DHCP, the walled garden, the redirect URL, the certificate or RADIUS. Finally, apply the fix on Instant APs, Aruba Central or a mobility controller.

By Tom HackettPublished
📖 9 min read2,136 words3 worked examples12 key definitions

Video overview

Part of our core series: Captive portal guide →

An HPE Aruba captive portal that fails usually has one of five faults. The pre-authentication role blocks DNS or the portal, or walled garden entries are missing. Other common faults are a malformed redirect URL, the controller's default certificate triggering browser warnings, or RADIUS requests that never reach the authentication server. Check DHCP and DNS on the guest VLAN first, then work outwards.

What does an Aruba captive portal that is not working look like?

Most faults show up as one of three symptoms. Naming the symptom correctly saves you an hour of guesswork.

No redirect. The guest joins the open SSID and gets an IP address, but no login page appears. The Captive Network Assistant (CNA), the small browser your phone opens automatically, either never pops up or shows a blank screen.

Certificate warning. The login page loads only after a "Your connection is not private" message. Laptops show this more than phones, because desktop browsers expect HTTPS for any login page.

Never released. The guest completes the splash page but stays stuck in the captive role. They loop back to the login page, or the CNA reports no internet connection.

This guide picks up where your HPE Aruba captive portal setup guide leaves off. It assumes the SSID, external portal profile and RADIUS servers already exist. For the same checklist on Meraki, see Cisco Meraki captive portal troubleshooting: splash page, walled garden and RADIUS checklist.

What usually causes an Aruba captive portal to fail?

A captive portal is a web page the network forces guests through before it grants internet access. On Aruba, five components have to agree for that to work.

Pre-authentication role and walled garden

Every guest starts in a pre-authentication role, also called the initial or captive portal role. That role must allow DHCP, DNS and HTTP/HTTPS to the portal host. Every other destination should be redirected or denied.

The walled garden is the list of destinations a guest can reach before logging in. An external portal needs its own hostname listed there, plus every domain the splash page loads. Fonts, scripts, analytics tags and social login providers count. One missing entry can leave the CNA on a white screen.

Redirect URL and parameters

When the AP intercepts a guest's first HTTP request, it sends the browser to the external portal URL. Aruba appends parameters to that URL, such as the client MAC address, the SSID and the address to post credentials back to.

A wrong URL, a stray trailing character or an HTTP/HTTPS mismatch breaks the handover. The portal then cannot identify the AP or the guest.

Default captive portal certificate

Aruba controllers and virtual controllers ship with a factory certificate for their internal login page. It is not issued for a hostname you own. Browsers therefore flag it as untrusted or mismatched.

Our support article on Cisco WLC captive portal certificate setup describes the same principle on Cisco. The cure is a publicly trusted certificate whose Common Name (CN) matches the hostname the controller presents.

RADIUS authentication and accounting

RADIUS (Remote Authentication Dial-In User Service) is the protocol the controller uses to ask an authentication server whether to admit a client. With Purple, our splash page systems collect the guest's details and issue a one-time login. The controller then passes that login to Purple's RADIUS server to complete authentication, as our captive portal support article explains.

If the request never arrives, or the shared secret is wrong, the guest is never released. Accounting messages report session start and stop. Missing accounting leaves you with gaps in your session data.

DNS and DHCP on the guest VLAN

A VLAN (virtual LAN) separates guest traffic from corporate traffic. If the guest VLAN hands out an unreachable DNS server, the browser cannot resolve the portal hostname. The redirect then never starts. Exhausted DHCP scopes cause the same symptom at busy times.

How do you work out which cause you have?

Work from the client outwards. This decision matrix maps what you see to where you should look first.

Symptom Most likely cause Check first Fix
No IP address, or a self-assigned one DHCP scope exhausted or guest VLAN not trunked DHCP server leases and AP uplink VLAN tagging Extend the scope or shorten the lease, then tag the VLAN on the switch port
IP address, but no redirect DNS blocked in pre-auth role, or HTTPS-only first request Client role in the AP or Central client details Allow DNS in the pre-auth role, then test with neverssl.com
Redirect starts, blank page Missing walled garden entries Browser developer tools on a test laptop Add every blocked domain to the walled garden
Portal says it cannot identify the network Malformed redirect URL or missing parameters Full redirect URL captured on a test device Correct the external portal URL in the profile
"Your connection is not private" Default controller certificate or CN mismatch Certificate details in the browser padlock Install a publicly trusted certificate matching the portal hostname
Login completes, guest loops back RADIUS reject, timeout or shared secret mismatch RADIUS server logs and AP authentication logs Match the secret, permit the source address, confirm the server is reachable
Online, but session data incomplete Accounting disabled or blocked RADIUS accounting logs Enable accounting on the server profile

What to check in the client logs

Start with the CNA. Android shows a "you may need to log in" notification and closes the CNA once it detects authentication. If the CNA is skipped, open a browser and go to neverssl.com. That site stays on plain HTTP, so the AP can intercept the request without an SSL error.

On a laptop, the browser developer tools show which requests failed during page load. Each blocked domain is a missing walled garden entry.

What to check in the AP and controller logs

Look at the client's current role first. A guest still in the pre-auth role after login points to RADIUS. A guest in no role at all points to association or DHCP. Then read the authentication debug logs for the client's MAC address. A RADIUS timeout means the packets are not leaving or not arriving. An Access-Reject means the server received them and refused.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.

How do you fix it on Instant AP, Aruba Central and controllers?

The concepts are the same across all three platforms. Where you change them differs. The detailed values for Purple are in our captive portal support article. Use those, not values copied from another venue.

Aruba Instant external captive portal

On Instant, the virtual controller holds the external portal profile, the walled garden and the RADIUS server definitions. Confirm which address your RADIUS traffic comes from. With dynamic RADIUS proxy enabled, requests arrive from the virtual controller address. Without it, each AP sends its own requests. The RADIUS server and any firewall in between must allow whichever source you use.

Aruba Central guest portal troubleshooting

In Aruba Central, the WLAN's splash page type must be set to external. Check that the portal profile points at the right URL. Central's client view shows each guest's role, VLAN and authentication events in one place. That makes it the quickest way to tell a DNS fault from a RADIUS fault across many sites.

Controller-based deployments

On a mobility controller, check three objects: the initial role, the captive portal profile and the AAA profile. The initial role's access policy must allow DNS, DHCP and the portal host. The captive portal profile must reference the correct server certificate. The controller's portal hostname must also resolve on the guest VLAN.

What does a fix look like in a live venue?

These worked examples show how the checklist plays out. They are illustrative, not named customer case studies.

A 180-room hotel on Instant APs. Guests on iPhones saw a blank CNA after a splash page redesign. The new page loaded fonts and a social login button from domains missing from the walled garden. The IT manager listed the failed requests in browser developer tools and added each domain. Completed logins in the portal rose from about 40 a day to more than 250 within a week. For more on guest connectivity in this sector, see Hotels.

A 40-store fashion chain on Aruba Central. Shoppers on laptops reported "unsafe network" warnings, generating about 25 helpdesk tickets a month. The virtual controllers were still presenting the default certificate. The team installed a publicly trusted certificate with a CN matching the portal hostname, then confirmed that name resolved on the guest VLAN. Tickets fell to two the following month. See Retail for how guest access supports stores.

A council-run conference centre on a mobility controller. Attendees completed the splash page but looped back to it. The authentication logs showed RADIUS timeouts. A new perimeter firewall rule had blocked the controller's source address. After the address was re-allowed, release from login to online fell from never to under five seconds.

How do you stop the Aruba captive portal failing again?

  • Version-control the walled garden. Treat every splash page change as a network change, and update the walled garden in the same release.
  • Set certificate renewal reminders. A lapsed public certificate brings back the warning overnight. Diarise renewal at least 30 days before expiry.
  • Test with three devices. After any change, test on an iPhone, an Android phone and a Windows laptop. Each handles the CNA differently.
  • Monitor RADIUS. Alert on rising Access-Reject or timeout counts, not just on server availability.
  • Keep the guest SSID open. Purple recommends an open SSID for guest access because it reduces friction. If you also run WPA3 elsewhere, read WPA3 transition mode connection failures: a deployment checklist for Cisco Meraki, HPE Aruba and Ruckus.

Purple's Guest WiFi runs as a cloud overlay on HPE Aruba, alongside Cisco Meraki, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Across 80,000+ live venues, Purple handled 440 million logins in 2024, according to Purple's own data.

Frequently asked questions

Does Purple work with Aruba Instant, Aruba Central and controller-based deployments?

Yes. Purple's Guest WiFi integrates with HPE Aruba through an external captive portal and RADIUS, so it works on Instant APs, Aruba Central and mobility controllers. The controller redirects guests to Purple's splash page and then passes the one-time login to Purple's RADIUS server. You keep your existing access points and switching, and you configure the portal profile, walled garden and RADIUS servers to Purple's published values.

Do I need to buy a public SSL certificate for my Aruba controller?

Yes, if you want guests to avoid browser warnings. The default certificate on an Aruba controller or virtual controller is not issued for a hostname you own, so desktop browsers flag it. A publicly trusted certificate whose Common Name matches the portal hostname removes the warning. Standard domain-validated certificates from any public certificate authority are suitable, and you renew them on the issuer's schedule.

Will moving our Aruba guest portal to Purple need new hardware?

No. Purple is hardware-agnostic and runs as a cloud overlay on the HPE Aruba access points and controllers you already own. The change is configuration: a new external portal URL, updated walled garden entries and Purple's RADIUS servers. Most of the effort goes into testing on phones and laptops at a pilot site before you roll the profile out across the estate.

Is Purple's Aruba captive portal GDPR compliant?

Yes. Purple holds ISO 27001 certification and operates in line with GDPR and CCPA. Guests give conscious-choice opt-ins on the splash page, so marketing consent is recorded at the point of login. Your Aruba network handles traffic, while Purple stores the first-party data under your control. You set retention and consent wording to match your own privacy policy.

How is Purple's Guest WiFi licensed for an Aruba estate?

Purple licenses Guest WiFi through three plans: Connect, Capture and Engage. Connect covers secure guest access, while Capture and Engage add data collection and marketing capability on top. The plan you choose does not change the Aruba configuration, because every plan uses the same external portal and RADIUS integration. Your Purple account team can quote by venue count and plan.

How long does it take to fix a broken Aruba captive portal?

Most faults take under a day to fix once you identify the symptom. Walled garden and DNS issues often take under an hour after you capture the failed requests. Certificate replacement depends on how quickly your certificate authority validates the domain. RADIUS faults caused by firewall changes usually need a change request, so plan for your own approval window.

Should we use Aruba ClearPass or an external portal like Purple for guests?

Choose an external portal like Purple if you want guest data, marketing consent and analytics without running extra on-premises servers. ClearPass is an on-premises policy manager that suits complex staff access control. Purple runs in the cloud with 99.999% uptime and handles the splash page, RADIUS and data capture together. Many venues keep ClearPass for staff and use Purple for guests.

Key Definitions

Captive portal

A web page the network forces a client through before granting internet access. The IETF describes the architecture in RFC 8952, covering the enforcement device, the portal server and how clients detect captivity.

On Aruba, the captive portal only works when the pre-auth role, walled garden, redirect URL, certificate and RADIUS all agree. A fault in any one of the five produces the symptoms in this checklist.

Captive Network Assistant (CNA)

The small browser a phone or laptop operating system opens automatically when it detects a captive network. iOS and Android each implement their own detection and close the CNA once they sense authentication.

A CNA that never appears or shows a blank screen is the first clue. If it is skipped, browse to neverssl.com, which stays on plain HTTP so the AP can intercept the request.

Pre-authentication role

The Aruba user role, also called the initial or captive portal role, applied to a client before login. Its access policy is a set of firewall rules defining which traffic is permitted, redirected or denied.

The role must allow DHCP, DNS and HTTP/HTTPS to the portal host. A guest still in this role after login points to a RADIUS fault rather than a portal fault.

Walled garden

The allow-list of hostnames and domains a client may reach before authentication, enforced by the AP or controller alongside the pre-authentication role.

An external portal needs its own hostname listed, plus every domain the splash page loads: fonts, scripts, analytics tags and social login providers. One missing entry can leave the CNA on a white screen.

Redirect URL

The external portal address an Aruba AP sends the browser to after intercepting its first HTTP request, with parameters appended such as the client MAC address, the SSID and the address to post credentials back to.

A wrong URL, a stray trailing character or an HTTP/HTTPS mismatch stops the portal identifying the AP or the guest. Capture the full URL on a test device to check it.

Common Name (CN)

The subject attribute in an X.509 certificate, profiled for internet use in RFC 5280, that names the host the certificate was issued for. Browsers reject certificates whose name does not match the hostname presented.

Aruba controllers ship with a factory certificate not issued for a hostname you own. Installing a publicly trusted certificate with a matching CN removes the 'Your connection is not private' warning.

RADIUS

Remote Authentication Dial-In User Service, the client-server protocol specified in RFC 2865 for authenticating network access. A shared secret protects exchanges, and the server answers with Access-Accept or Access-Reject.

With Purple, the controller passes the guest's one-time login to Purple's RADIUS server. A wrong shared secret or a blocked source address leaves the guest unreleased.

RADIUS accounting

The RADIUS extension specified in RFC 2866, in which the network device sends Accounting-Request messages to report session start, interim updates and session stop.

If accounting is disabled or blocked, guests still get online but you lose session data. Enable accounting on the server profile and check the accounting logs.

Access-Reject

The RADIUS response packet defined in RFC 2865 that a server returns when it has received a request but refuses access, for example because credentials or attributes fail its checks.

In the AP authentication logs, an Access-Reject shows the server received the request, whereas a timeout shows packets are not leaving or not arriving. That distinction tells you where to look next.

VLAN

A virtual LAN, defined by IEEE 802.1Q, which tags Ethernet frames to separate logical networks on shared switching infrastructure.

The guest VLAN must be trunked to the AP uplink and hand out a reachable DNS server. An exhausted DHCP scope or untagged VLAN produces no IP address and no redirect.

Dynamic RADIUS proxy

An Aruba Instant setting that makes the virtual controller forward RADIUS requests on behalf of every AP, so they arrive from the virtual controller address rather than each AP's own address.

Your RADIUS server and any firewall in between must allow whichever source address you use. A mismatch causes timeouts and guests who loop back to the login page.

Conscious-choice opt-ins

Purple's consent capture on the splash page, where guests actively choose marketing permissions, aligned with the consent requirements of GDPR (Regulation (EU) 2016/679, Articles 6 and 7).

Consent is recorded at the point of login, and Purple stores the first-party data under your control. You set retention and consent wording to match your own privacy policy.

Worked Examples

A 180-room hotel on Aruba Instant APs redesigned its splash page. Afterwards, guests on iPhones saw a blank Captive Network Assistant and could not log in.

The new page loaded fonts and a social login button from domains that were missing from the walled garden. The pre-authentication role blocked those requests, so the CNA rendered a white screen. The IT manager opened browser developer tools on a test laptop and listed every failed request during page load. Each blocked domain was added to the walled garden on the virtual controller. Completed logins in the portal rose from about 40 a day to more than 250 within a week. The lesson is to treat every splash page change as a network change and update the walled garden in the same release.

A 40-store fashion chain on Aruba Central received about 25 helpdesk tickets a month from shoppers on laptops reporting 'unsafe network' warnings.

The virtual controllers were still presenting Aruba's default captive portal certificate. That certificate is not issued for a hostname the chain owns, so desktop browsers flagged it as untrusted. The team installed a publicly trusted certificate with a Common Name matching the portal hostname. They then confirmed that hostname resolved on the guest VLAN, because a certificate only helps if the name it covers can be reached. Tickets fell to two the following month. To keep the warning from returning, diarise certificate renewal at least 30 days before expiry.

Attendees at a council-run conference centre on an Aruba mobility controller completed the splash page but looped straight back to it.

The looping symptom pointed past the portal to RADIUS, because guests stayed in the pre-authentication role after login. The authentication debug logs for affected MAC addresses showed RADIUS timeouts rather than Access-Rejects. Timeouts mean packets are not leaving or not arriving, so the team checked the network path. A new perimeter firewall rule had blocked the controller's source address. After the address was re-allowed, release from login to online fell from never to under five seconds. Alerting on rising timeout counts, not just server availability, would catch this sooner.

Frequently asked questions

Does Purple work with Aruba Instant, Aruba Central and controller-based deployments?

Yes. Purple's Guest WiFi integrates with HPE Aruba through an external captive portal and RADIUS, so it works on Instant APs, Aruba Central and mobility controllers. The controller redirects guests to Purple's splash page and then passes the one-time login to Purple's RADIUS server. You keep your existing access points and switching, and you configure the portal profile, walled garden and RADIUS servers to Purple's published values.

Do I need to buy a public SSL certificate for my Aruba controller?

Yes, if you want guests to avoid browser warnings. The default certificate on an Aruba controller or virtual controller is not issued for a hostname you own, so desktop browsers flag it. A publicly trusted certificate whose Common Name matches the portal hostname removes the warning. Standard domain-validated certificates from any public certificate authority are suitable, and you renew them on the issuer's schedule.

Will moving our Aruba guest portal to Purple need new hardware?

No. Purple is hardware-agnostic and runs as a cloud overlay on the HPE Aruba access points and controllers you already own. The change is configuration: a new external portal URL, updated walled garden entries and Purple's RADIUS servers. Most of the effort goes into testing on phones and laptops at a pilot site before you roll the profile out across the estate.

Is Purple's Aruba captive portal GDPR compliant?

Yes. Purple holds ISO 27001 certification and operates in line with GDPR and CCPA. Guests give conscious-choice opt-ins on the splash page, so marketing consent is recorded at the point of login. Your Aruba network handles traffic, while Purple stores the first-party data under your control. You set retention and consent wording to match your own privacy policy.

How is Purple's Guest WiFi licensed for an Aruba estate?

Purple licenses Guest WiFi through three plans: Connect, Capture and Engage. Connect covers secure guest access, while Capture and Engage add data collection and marketing capability on top. The plan you choose does not change the Aruba configuration, because every plan uses the same external portal and RADIUS integration. Your Purple account team can quote by venue count and plan.

How long does it take to fix a broken Aruba captive portal?

Most faults take under a day to fix once you identify the symptom. Walled garden and DNS issues often take under an hour after you capture the failed requests. Certificate replacement depends on how quickly your certificate authority validates the domain. RADIUS faults caused by firewall changes usually need a change request, so plan for your own approval window.

Should we use Aruba ClearPass or an external portal like Purple for guests?

Choose an external portal like Purple if you want guest data, marketing consent and analytics without running extra on-premises servers. ClearPass is an on-premises policy manager that suits complex staff access control. Purple runs in the cloud with 99.999% uptime and handles the splash page, RADIUS and data capture together. Many venues keep ClearPass for staff and use Purple for guests.

Got questions about your specific setup?

Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.