- Purple
- Captive portals: a complete guide
- Grandstream GWN and guest WiFi: captive portal setup with Purple
Grandstream GWN and guest WiFi: captive portal setup with Purple
How Grandstream GWN access points work with Purple guest WiFi: an external splash page, RADIUS and a walled garden, with a link to Purple's step-by-step setup guide for the exact configuration.
Video overview
Listen to this guide
View podcast transcript
Part of our core series: Captive Portal Guide →
Grandstream GWN and Purple WiFi configuration generator
Generate exact external captive portal parameters, RADIUS authentication endpoints, and walled garden allowlists for Grandstream GWN access points integrated with Purple guest WiFi.
=== GRANDSTREAM GWN + PURPLE GUEST WIFI SPECIFICATION ===
Controller Architecture: GWN Cloud (Hosted)
Target Access Point Series: Grandstream GWN7664 (Wi-Fi 6 (802.11ax) 4x4:4 MU-MIMO)
Firmware Baseline: v1.0.21.15 or newer
Guest SSID VLAN: 50
Client Bandwidth Rate Limit: 15 Mbps Downstream
Session Re-Authentication Timeout: 4 Hours (240 Minutes)
--- 1. PORTAL & REDIRECTION CONFIGURATION ---
Portal Type: External Splash Page
Splash Page URL: https://login.purplewifi.net/
Redirect Method: HTTP/HTTPS GET 302 Redirection
Apple Captive Network Assistant (CNA) auto-pop: Expected (OS probe hosts kept out of the walled garden)
--- 2. RADIUS SERVER SETTINGS ---
Primary RADIUS Authentication Server:
Host / IP: radius.purplewifi.net
Port: 1812 (UDP)
Shared Secret: YourPurpleRadiusSecretKey
Secondary RADIUS Authentication Server:
Host / IP: radius-backup.purplewifi.net
Port: 1812 (UDP)
Shared Secret: YourPurpleRadiusSecretKey
Primary RADIUS Accounting Server:
Host / IP: radius.purplewifi.net
Port: 1813 (UDP)
Shared Secret: YourPurpleRadiusSecretKey
Interim Accounting Interval: 300 seconds
Secondary RADIUS Accounting Server:
Host / IP: radius-backup.purplewifi.net
Port: 1813 (UDP)
Shared Secret: YourPurpleRadiusSecretKey
--- 3. WALLED GARDEN DOMAINS (13 rules) ---
- *.purplewifi.net
- login.purplewifi.net
- *.purple.ai
- *.facebook.com
- *.fbcdn.net
- *.google.com
- accounts.google.com
- *.twitter.com
- *.x.com
- *.twimg.com
- *.linkedin.com
- *.licdn.com
- appleid.apple.com
Deploy Purple guest WiFi across Grandstream GWN in minutes
Whether you are managing a 5-AP hospitality venue or a 500-AP campus on GWN Cloud, Purple turns guest connectivity into first-party marketing data, automated compliance, and footfall intelligence.
Grandstream GWN access points are managed from the cloud through GWN Cloud. Purple adds the guest layer on top: the captive portal your visitors see, the sign-in journey, and the first-party data you collect. It does not replace any of your Grandstream hardware.
How Grandstream GWN works with Purple guest WiFi
Purple is a cloud overlay. Your GWN access points keep running the WiFi; Purple runs the guest experience through features GWN Cloud already supports.
- External splash page. In GWN Cloud's captive portal policy you set the splash page to external and choose Purple as the platform. A new device is redirected to your Purple splash page, the visitor signs in, and control returns to GWN.
- RADIUS. GWN checks each sign-in against Purple's RADIUS service on the standard ports, 1812 for authentication and 1813 for accounting. The accounting data is what powers your visitor analytics.
A walled garden, a short allow-list of addresses a device can reach before it signs in, set as pre-authentication rules, lets the splash page load and any payment or social-login steps complete.
That is the whole model: GWN moves the packets, Purple owns the sign-in and the data. Because it runs on standard external web authentication and RADIUS, it works the same way across Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Purple is hardware-agnostic by design.
What you need
- Grandstream GWN access points on firmware v1.0.7.12 or above, managed through GWN Cloud.
- A Purple venue with your splash page and sign-in journey set up.
- Your Purple splash server, RADIUS details and pre-authentication domains, from your Purple dashboard.
Set it up with Purple
The exact settings, the captive portal policy, the external splash server, the RADIUS authentication and accounting servers, and the pre-authentication rules, are documented step by step in Purple's support guide, with the precise values to enter.
Grandstream GWN Series AP setup guide
Follow that guide for the configuration. This page explains how the pieces fit together, so you know what each step is doing.
What you get
Once guests sign in through Purple, every visit becomes verified, conscious-choice opt-in first-party data: who visited, how often, and how to reach them with permission. That is the difference between WiFi that connects people and WiFi that builds a marketing audience you own. Purple is CCPA/CPRA-aligned and ISO 27001 certified, with 99.999% uptime across more than 80,000 live venues.
Key Definitions
Captive portal
The sign-in page a visitor sees before they get online. Purple hosts and runs it; GWN redirects devices to it.
The guest experience layer Purple adds on top of your GWN WiFi.
External splash page
A GWN captive portal setting that sends un-authenticated devices to Purple's externally hosted sign-in page.
How GWN Cloud hands the guest to Purple.
RADIUS
A standard protocol for checking sign-ins and recording session data, on ports 1812 (authentication) and 1813 (accounting).
How GWN validates each guest against Purple and feeds analytics.
Walled garden
A short allow-list of addresses, set as pre-authentication rules, a device can reach before it has signed in.
Lets the splash page, payments and social login load pre-authentication.
GWN Cloud
Grandstream's cloud dashboard for managing GWN access points, including the captive portal policy and RADIUS settings.
Where Grandstream GWN access points are configured.
Frequently asked questions
How do Grandstream GWN access points integrate with Purple guest WiFi?
Grandstream GWN access points integrate with Purple as a cloud overlay using native GWN features. In GWN Cloud or GWN Manager, you configure an external captive portal policy pointing to Purple splash page URLs and authenticate connecting devices against Purple cloud RADIUS servers on UDP ports 1812 and 1813. The physical access points manage RF wireless connectivity, while Purple handles the guest onboarding experience, CRM consent capture, and footfall analytics without requiring local hardware changes.
What RADIUS configuration is required for Grandstream GWN and Purple?
Grandstream GWN requires a primary RADIUS authentication server at radius.purplewifi.net on port 1812 (UDP) and a primary RADIUS accounting server at radius.purplewifi.net on port 1813 (UDP), alongside a secondary backup server at radius-backup.purplewifi.net. You enter your unique shared secret provisioned in your Purple management portal and configure interim accounting updates (typically every 300 seconds) to ensure real-time visitor presence reporting.
Which domains must be added to the Grandstream GWN walled garden allowlist?
The Grandstream walled garden (pre-authentication allowlist) must include *.purplewifi.net, login.purplewifi.net, and *.purple.ai so guests can load the captive portal. If you enable social logins (Google, Facebook, LinkedIn, Apple ID) or paid tiers (Stripe, PayPal), their corresponding authentication API and CDN endpoints must also be allowed before authentication.
What firmware version is required on Grandstream GWN access points?
Grandstream GWN access points require firmware version 1.0.7.12 or above to support external splash page redirection and cloud RADIUS accounting. For current Wi-Fi 6 models such as the GWN7660, GWN7664, and GWN7664LR, firmware version 1.0.21.15 or newer is recommended for optimal captive network assistant (CNA) browser handling on modern iOS and Android devices.
Does Purple work with both GWN Cloud and on-premises GWN Manager?
Yes. Purple guest WiFi is fully compatible with GWN Cloud, GWN Manager (software controller running on Linux or VM), and embedded Master AP deployments. Because the captive portal policy and RADIUS settings use standard RFC-compliant network protocols, the configuration steps are identical across cloud-managed and locally-hosted Grandstream architectures.
Continue reading in this series
Mikrotik RouterOS and guest WiFi: captive portal setup with Purple
How Purple's cloud guest WiFi sits on top of MikroTik devices running RouterOS, using the built-in Hotspot and RADIUS, and where to find the exact setup steps.
Captive portal for Ruckus Cloud: set it up with Purple guest WiFi
How to run a Purple captive portal on Ruckus Cloud (Ruckus One): a third-party WISPr captive portal, an integration key and a walled garden, with a link to Purple's step-by-step setup guide for the exact configuration.
Captive portal for HPE Aruba: set it up with Purple guest WiFi
Setting up a guest captive portal on HPE Aruba Instant access points with Purple, using an external captive portal, RADIUS and an allowlist, through Aruba Central or the Virtual Controller.
Got questions about your specific setup?
Our team works with venue operators, IT managers, and network engineers across 80,000 venues. Book a 20-minute call and we will show you how others like you solved it.