Skip to main content

How to Configure Guest WiFi and Captive Portals on Ruijie Networks

This technical guide details the configuration of guest WiFi and captive portals on Ruijie Networks hardware, covering both native cloud portals and external RADIUS integrations. It provides IT managers and network architects with actionable steps for VLAN isolation, walled garden setup, and third-party platform integration to drive analytics and revenue.

📖 6 min read📝 1,432 words🔧 2 worked examples3 practice questions📚 8 key definitions

Listen to this guide

View podcast transcript
How to Configure Guest WiFi and Captive Portals on Ruijie Networks A Purple Technical Briefing - Approximately 10 minutes INTRODUCTION AND CONTEXT - 1 minute Welcome to the Purple Technical Briefing. I am your host, and over the next ten minutes we are going to cover everything you need to know about configuring guest WiFi and captive portals on Ruijie Networks hardware. If you are an IT manager, network architect, or venue operations director at a hotel, retail chain, stadium, or conference centre, and you have Ruijie kit on-site or you are evaluating it, this briefing is for you. Ruijie Networks is one of the fastest-growing enterprise wireless vendors globally. Their RG-WS series controllers, Reyee EG gateways, and cloud-managed access points are now deployed across thousands of venues in Europe, the Middle East, Asia, and beyond. But getting guest WiFi right on Ruijie hardware - specifically the captive portal piece - requires understanding a few architectural decisions upfront. Get those decisions wrong and you end up with a portal that breaks on iOS, guests who cannot authenticate, and a network that is either too open or too locked down. Let us fix that. TECHNICAL DEEP-DIVE - 5 minutes First, the architecture. Ruijie gives you three distinct deployment models for guest WiFi, and choosing the right one depends on your scale and your management approach. Model one is the Ruijie Cloud or JaCS managed portal. This is the native, built-in option. You log into Ruijie Cloud, navigate to Device Config, then Basic, create or edit your guest SSID, enable the Authentication toggle, and select Captive Portal as the mode. Ruijie's JaCS platform, which is their hospitality-focused management system, supports Hotel and Other scenarios and gives you a drag-and-drop portal builder with login options including one-click access, voucher codes, and account-based login. This is the right choice for smaller deployments - a single hotel, a boutique retail site, or a conference centre that wants a quick, branded splash page without external dependencies. Model two is the external captive portal via WISPr and RADIUS. This is the enterprise-grade approach, and it is what you need when you want to integrate Ruijie with a third-party guest WiFi intelligence platform - like Purple. Here, you navigate to Auth and Account in the Ruijie interface, select Captive Portal, set the Policy Mode to External, and point the Portal Server URL at your external platform. You then configure a RADIUS server group with the credentials your platform provides. The WISPr protocol handles the redirect and authentication handshake between the Ruijie gateway and the external portal. This model scales across hundreds of sites, gives you centralised analytics, and lets you run GDPR-compliant data capture workflows. Model three is standalone AP mode. Ruijie's Reyee access points running ReyeeOS version 1.219 or later can run a local captive portal without a gateway, which is useful for temporary deployments or small sites without an EG router. Now, the critical piece that most guides skip: VLAN isolation. When you create a guest SSID on Ruijie, you have two forwarding options - NAT mode and VLAN mode. NAT mode is simpler. The gateway assigns guest devices addresses from a dedicated pool, typically 192.168.23.0 slash 24 by default, and all guest traffic is NATted to the internet. This works, but it gives you less control. VLAN mode is the right choice for any serious deployment. You assign the guest SSID to a dedicated VLAN - say VLAN 100 - and use ACLs on the gateway to block guest traffic from reaching your corporate VLAN. The CLI command pattern looks like this: you create an extended access list, deny IP traffic from your guest subnet to your corporate subnet, permit everything else, and apply that access list inbound on the guest BVI interface. This is the same principle you would apply on Cisco Meraki, HPE Aruba, or Ruckus - Ruijie just has its own CLI syntax. Security standards matter here. Ruijie supports WPA3-Personal and WPA2/WPA3 mixed mode on guest SSIDs. For a guest network where you want zero-friction access, you typically run an open SSID with captive portal authentication rather than a pre-shared key. The captive portal becomes your authentication layer. If you need stronger security - say for a healthcare or financial services environment - you can layer IEEE 802.1X on top, using EAP-TLS or PEAP with a RADIUS server for certificate-based or credential-based authentication. Ruijie's RG-WS series controllers support full 802.1X with dynamic VLAN assignment, meaning you can push different VLANs to different user groups based on RADIUS attributes. The walled garden - or allowlist - is another area that trips people up. Before a guest authenticates through the captive portal, their device can only reach domains you explicitly whitelist. At minimum, you need to allow your portal platform's domain and IP address, any social login providers you are using, and Apple's captive portal detection endpoint, which is captive.apple.com. Miss that last one and iOS devices will show a broken portal experience. You configure the allowlist in Ruijie Cloud under Auth and Account, then Allowlist. IMPLEMENTATION RECOMMENDATIONS AND PITFALLS - 2 minutes Let me give you the four decisions that determine whether your Ruijie guest WiFi deployment succeeds or fails. Decision one: native portal versus external platform. If you are running more than five sites, or if you need to capture first-party data for marketing, use an external platform. Purple, for example, operates as a hardware-agnostic cloud overlay across 80,000-plus live venues. You point your Ruijie gateway at Purple's portal URL, configure the RADIUS credentials, and you get centralised analytics, GDPR-compliant data capture, and CRM integrations - all without touching the Ruijie hardware again. Purple has processed 440 million logins in 2024 alone and holds ISO 27001 certification, so the compliance piece is handled. Decision two: NAT versus VLAN. Always use VLAN mode for production deployments. NAT mode is fine for a proof of concept, but VLAN mode gives you proper Layer 3 isolation, easier firewall policy management, and the ability to apply QoS policies per VLAN. Decision three: bandwidth management. Ruijie's EG gateways have built-in QoS controls. Set per-user download and upload limits on the guest SSID - typically two to five megabits per second download for a standard guest network. This prevents a single guest streaming 4K video from degrading the experience for everyone else. If you are using an external platform, disable Client Escape on the Ruijie side to ensure the platform's bandwidth controls take effect correctly. Decision four: session timeout and re-authentication. Set a sensible session timeout - eight to 24 hours for hospitality, shorter for retail or events. Ruijie lets you configure this per portal policy. Pair it with a post-login redirect URL so guests land on your venue's website or a promotional page after connecting. The most common pitfall I see is teams deploying a captive portal without testing it on iOS and Android simultaneously. Apple and Google both have captive portal detection mechanisms that behave differently. Test both before go-live. The second most common pitfall is forgetting to synchronise the portal configuration to the EG product in JaCS - there is an explicit Synchronise button you must click after creating or editing a portal, otherwise the gateway does not pick up the changes. RAPID-FIRE Q AND A - 1 minute Let me run through the questions I get asked most often. Can Ruijie APs run a captive portal without a gateway? Yes, on ReyeeOS 1.219 or later, but functionality is limited compared to gateway-based deployments. Does Ruijie support 802.1X for guest networks? Yes, the RG-WS series controllers support full 802.1X with dynamic VLAN assignment via RADIUS. Can I integrate Ruijie with Purple? Yes. Configure the external captive portal mode, point the portal URL at Purple's endpoint, set up the RADIUS server group with Purple's credentials, and add Purple's domains to the allowlist. Purple's hardware-agnostic architecture handles the rest. Does WPA3 work with captive portals? Yes. You run an open SSID for the captive portal flow. WPA3 applies to authenticated SSIDs. For guest networks, the portal itself is the authentication layer. SUMMARY AND NEXT STEPS - 1 minute To summarise: Ruijie Networks gives you a capable, flexible platform for guest WiFi and captive portal deployment. The three deployment models - native cloud portal, external RADIUS-based portal, and standalone AP - cover everything from a single-site boutique hotel to a multi-site retail chain. The key decisions are VLAN isolation over NAT, external platform for any multi-site or data-capture use case, and proper walled garden configuration to avoid iOS authentication failures. Your next steps: audit your current Ruijie firmware versions to confirm ReyeeOS compatibility, decide whether you need native or external portal management, and if you are running more than five sites or need analytics, speak to Purple about integrating their platform with your Ruijie infrastructure. You can find Purple's integration documentation and request a demo at purple.ai. Thanks for listening. We will see you in the next briefing.

📚 Part of our core series: Captive Portal Guide

header_image.png

Executive Summary

Die Konfiguration von Gäste-WiFi und Captive Portals auf Hardware von Ruijie Networks erfordert ein klares Verständnis der Plattformarchitektur, insbesondere der Wahl zwischen nativen Cloud-Portalen und externen RADIUS-Integrationen. Dieser technische Leitfaden bietet IT-Managern, Netzwerkarchitekten und Betriebsleitern von Veranstaltungsorten die entscheidenden Schritte zur Bereitstellung sicherer, isolierter und skalierbarer Gästenetzwerke mit Ruijie RG-WS-Controllern und Reyee EG-Gateways. Wir behandeln den Übergang von der einfachen NAT-Weiterleitung zur robusten VLAN-Isolierung, die Konfiguration externer Captive Portals über WISPr und die Integration von Drittanbieter-Plattformen wie Purple, um First-Party-Daten zu erfassen und den Umsatz zu steigern. Unabhängig davon, ob Sie ein einzelnes Hotel oder ein standortübergreifendes Einzelhandelsportfolio verwalten, bietet dieser Leitfaden die praktischen, herstellerneutralen Konfigurationsschritte, die für den Aufbau eines konformen und leistungsstarken drahtlosen Netzwerks erforderlich sind.

Technischer Deep-Dive

Ruijie Networks bietet eine robuste, professionelle Wireless-Architektur, die mehrere Bereitstellungsmodelle für den Gästezugang unterstützt. Die Kernentscheidung für jeden Netzwerkarchitekten ist die Auswahl des geeigneten Authentifizierungsflusses und der Isolationsstrategie.

Captive Portal Bereitstellungsmodelle

Ruijie unterstützt drei verschiedene Bereitstellungsmodelle für Captive Portals, die jeweils für unterschiedliche betriebliche Anforderungen geeignet sind:

  1. Natives Cloud-Portal (Ruijie JaCS): Die integrierte Ruijie Cloud-Plattform, insbesondere die JaCS-Schnittstelle für das Gastgewerbe, bietet einen Drag-and-Drop-Portal-Builder. Dieses Modell wird unter „Device Config“ konfiguriert, wo die SSID-Authentifizierung auf Captive Portal eingestellt ist. Es unterstützt grundlegende Anmeldeoptionen wie One-Click-Zugang und Gutscheincodes. Dies eignet sich für Einzelstandorte, die keine tiefgehenden Analysen oder externen CRM-Integrationen erfordern.
  2. Externes Captive Portal (WISPr/RADIUS): Für Unternehmensbereitstellungen, standortübergreifenden Einzelhandel und große öffentliche Veranstaltungsorte ist das externe Portalmodell zwingend erforderlich. Dieser Ansatz verwendet das WISPr-Protokoll, um den Gästeverkehr auf eine Drittanbieter-Plattform wie Purple umzuleiten. Die Authentifizierung erfolgt über eine externe RADIUS-Servergruppe mit PAP-Verschlüsselung. Dieses Modell ermöglicht eine fortschrittliche Datenerfassung, ein GDPR-Konformitätsmanagement und eine nahtlose Integration in bestehende Marketing-Systeme.
  3. Standalone AP Portal: Ruijie Reyee Access Points mit ReyeeOS 1.219 oder höher unterstützen ein lokalisiertes Captive Portal, ohne dass ein EG-Gateway erforderlich ist. Dies ist eine Fallback-Option für temporäre Bereitstellungen, bietet jedoch nicht die robusten QoS- und Isolationsfunktionen einer Controller-basierten Architektur.

architecture_overview.png

Netzwerkisolation: NAT versus VLAN

Die wichtigste architektonische Entscheidung ist die Frage, wie der Gast-Traffic vom Unternehmensnetzwerk isoliert werden soll. Ruijie bietet zwei Weiterleitungsmodi für Gast-SSIDs:

  • NAT-Modus: Das Gateway weist IP-Adressen aus einem dedizierten Pool zu (standardmäßig 192.168.23.0/24) und führt eine Network Address Translation durch, bevor der Traffic ins Internet geleitet wird. Diese Methode ist zwar einfach zu implementieren, bietet jedoch nur eingeschränkte Sichtbarkeit und Kontrolle über den Gast-Traffic auf Layer 3.
  • VLAN-Modus: Der empfohlene Unternehmensstandard. Die Gast-SSID wird einem dedizierten VLAN (z. B. VLAN 100) zugewiesen. Das Reyee EG-Gateway oder der RG-WS-Controller verwendet Access Control Lists (ACLs), um eine strikte Isolation durchzusetzen. Es muss eine erweiterte ACL konfiguriert werden, um IP-Traffic vom Gast-Subnetz zum Unternehmensnetzwerk zu blockieren, während der ausgehende Internetzugriff erlaubt wird. Dieser Ansatz entspricht den Prinzipien von Enterprise WiFi Security: A Complete Guide for 2026 .

Walled Garden Konfiguration

Bevor ein Gast die Authentifizierung über das Captive Portal abschließt, befindet sich sein Gerät in einem eingeschränkten Zustand. Ein Walled Garden (eine Whitelist) muss konfiguriert werden, um den Zugriff auf wichtige Dienste zu ermöglichen. Wenn Sie eine externe Plattform nutzen, müssen Sie die Domain der Plattform, die IP-Adressen und die Authentifizierungs-Endpunkte aller Social-Login-Anbieter (wie Facebook oder Google) hinzufügen. Besonders wichtig ist die Aufnahme von captive.apple.com, um sicherzustellen, dass iOS-Geräte den Mini-Browser des Captive Portals korrekt aktivieren.

captive_portal_flow.png

Implementierungsleitfaden

Die Bereitstellung eines externen Captive Portals auf Ruijie-Hardware erfordert eine präzise Konfiguration der SSID, der Authentifizierungsrichtlinien und der Netzwerkisolationsschichten. Befolgen Sie diese Schritte, um Ruijie mit einer externen Plattform wie Purple zu integrieren.

Schritt 1: Konfigurieren der Gast-SSID und des VLANs

  1. Melden Sie sich in der Ruijie Cloud oder auf der lokalen eWeb-Benutzeroberfläche Ihres Controllers an.
  2. Navigieren Sie zu den Wireless-Einstellungen und erstellen Sie eine neue SSID mit einem für Ihren Standort passenden Namen.
  3. Stellen Sie den Sicherheitsmodus auf "Open". Das Captive Portal dient als Authentifizierungsmechanismus.
  4. Weisen Sie die SSID Ihrem dafür vorgesehenen Gast-VLAN zu. Stellen Sie sicher, dass die entsprechende VLAN-Schnittstelle auf Ihrem EG-Gateway mit einem DHCP-Bereich konfiguriert ist.

Schritt 2: Konfigurieren der externen Captive Portal Richtlinie

  1. Navigieren Sie zum Bereich „Auth & Account“.
  2. Wählen Sie Captive Portal unter dem Menü „Authentication“.
  3. Erstellen Sie eine neue Richtlinie und setzen Sie den „Policy Mode“ auf „External“.
  4. Wählen Sie die in Schritt 1 erstellte Guest SSID aus.
  5. Geben Sie die Portal-Server-URL ein, die von Ihrer externen Plattform bereitgestellt wird (z. B. der Portal-Endpunkt von Purple).
  6. Konfigurieren Sie die RADIUS-Servergruppe mit den IP-Adressen, Ports (normalerweise 1812 für die Authentifizierung und 1813 für das Accounting) und den von Ihrer Plattform bereitgestellten Shared Secrets.

Schritt 3: Walled Garden implementieren

  1. Suchen Sie im Bereich „Auth & Account“ die Konfiguration für die „Allowlist“.
  2. Fügen Sie die erforderlichen Domains und IP-Adressen für Ihre externe Plattform hinzu.
  3. Fügen Sie die Domains für alle Social-Identity-Anbieter hinzu, die Sie verwenden möchten.
  4. Stellen Sie sicher, dass Standard-Domains zur Erkennung von Captive Portals zugelassen sind.

Schritt 4: ACL-Isolierung erzwingen

Verbinden Sie sich mit der Befehlszeilenschnittstelle (CLI) Ihres Ruijie-Gateways oder -Controllers, um die Isolations-ACL zu konfigurieren. Dieser Schritt stellt sicher, dass Gäste keine internen Ressourcen erreichen können.

Ruijie(config)# access-list extended 107
Ruijie(config-ext-nacl)# deny ip 192.168.100.0 0.0.0.255 192.168.10.0 0.0.0.255
Ruijie(config-ext-nacl)# permit ip any any
Ruijie(config-ext-nacl)# exit
Ruijie(config)# interface BVI 100
Ruijie(config-if-BVI 100)# access-group 107 in

Best Practices

Um ein zuverlässiges und sicheres Gäste-WiFi-Erlebnis zu gewährleisten, halten Sie sich an diese branchenüblichen Best Practices:

  • Externe Authentifizierung für Skalierbarkeit nutzen: Wenn Sie mehrere Standorte verwalten oder detaillierte Guest WiFi -Analysen benötigen, umgehen Sie das native Portal und nutzen Sie eine externe RADIUS-Integration. Plattformen wie Purple bieten eine hardwareunabhängige Verwaltung, mit der Sie das Gästeerlebnis über Ruijie-, Cisco Meraki-, HPE Aruba- und Ruckus-Hardware hinweg standardisieren können.
  • Gestaffelte Bandbreite implementieren: Nutzen Sie die QoS-Funktionen des Ruijie EG-Gateways, um Bandbreitenbegrenzungen pro Benutzer durchzusetzen. Bieten Sie eine kostenlose Basisstufe an (z. B. 5 Mbps) und binden Sie über Ihr externes Portal ein Zahlungs-Gateway ein, um eine kostenpflichtige Premium-Stufe mit hoher Geschwindigkeit anzubieten. Dies schafft eine direkte Einnahmequelle aus Ihrer Infrastruktur.
  • Konfigurationen synchronisieren: Wenn Sie die Ruijie JaCS-Plattform verwenden, müssen Sie nach dem Ändern einer Captive Portal-Richtlinie explizit auf die Schaltfläche „Synchronise“ klicken. Andernfalls erhält das EG-Gateway die aktualisierte Konfiguration nicht, was zu einem inkonsistenten Verhalten des Portals führt.
  • Datenschutzbestimmungen einhalten: Stellen Sie sicher, dass Ihr Captive Portal explizite Opt-ins mit bewusster Zustimmung für Marketingkommunikation enthält. Bei der Verwendung von Purple übernimmt die Plattform automatisch die GDPR- und CCPA-Konformität und bietet eine sichere Datenschutzebene. Detaillierte Anforderungen finden Sie im Leitfaden The Network Administrator’s Guide to GDPR and Guest Data Privacy Compliance .

Fehlerbehebung & Risikominderung

Selbst bei sorgfältiger Konfiguration kann es bei der Bereitstellung von Captive Portals zu Problemen kommen. Hier sind die häufigsten Fehlerszenarien und deren Behebung:

  • iOS-Geräte zeigen das Portal nicht an: Dies ist fast immer ein Problem mit dem Walled Garden. Apple-Geräte prüfen captive.apple.com, um festzustellen, ob sie sich hinter einem Portal befinden. Wenn diese Domain blockiert ist, geht das Gerät davon aus, dass es vollen Internetzugang hat, und startet den Captive Network Assistant nicht. Überprüfen Sie Ihre Allowlist-Konfiguration.
  • Gäste können sich nicht über RADIUS authentifizieren: Überprüfen Sie das RADIUS Shared Secret und die Portkonfigurationen auf dem Ruijie-Gateway. Stellen Sie sicher, dass die öffentliche IP-Adresse des Gateways auf Ihrer externen Plattform korrekt registriert ist. Nutzen Sie die Ruijie-Diagnosetools, um die RADIUS-Erreichbarkeit zu überprüfen.
  • Bandbreitenbegrenzungen werden ignoriert: Wenn Sie eine externe Plattform zur Durchsetzung von Bandbreitenstufen nutzen, müssen Sie die Funktion "Client Escape" auf dem Ruijie-Gateway deaktivieren. Wenn Client Escape aktiv ist, umgeht das Gateway unter Umständen die QoS-Anweisungen der externen Plattform.
  • Gast-Traffic gelangt in das Unternehmensnetzwerk: Überprüfen Sie Ihre ACL-Konfiguration. Stellen Sie sicher, dass die erweiterte Access-Liste eingehend auf dem richtigen VLAN- oder BVI-Interface angewendet wird. Testen Sie die Isolierung, indem Sie ein Gerät mit der Gast-SSID verbinden und versuchen, eine bekannte interne IP-Adresse anzupingen.

ROI & geschäftlicher Nutzen

Die Bereitstellung eines robusten Captive Portals auf Ruijie-Hardware verwandelt das Gast-WiFi von einem Kostenfaktor in einen messbaren Geschäftswert. Durch die Integration einer externen WiFi Analytics -Plattform wie Purple können Veranstaltungsorte erhebliche Renditen erzielen.

  • Erfassung von First-Party-Daten: Das Captive Portal fungiert als primärer Datenerfassungspunkt. Indem sie kostenloses WiFi im Austausch gegen eine E-Mail-Adresse oder einen Social-Login anbieten, bauen Veranstaltungsorte eine reichhaltige Datenbank mit Kundenprofilen auf. Diese Daten speisen zielgerichtete Marketingkampagnen und steigern den Customer Lifetime Value.
  • Operative Effizienz: Das zentrale Cloud-Management über Ruijie Cloud und Purple reduziert den Zeitaufwand für IT-Teams bei der Behebung lokaler Netzwerkprobleme. Da das Overlay hardwareunabhängig ist, können Sie Access Points aktualisieren oder austauschen, ohne Ihren gesamten Analytics-Stack neu aufbauen zu müssen.
  • Direkte Umsatzgenerierung: Die Implementierung von gestuften Bandbreitenmodellen ermöglicht es Veranstaltungsorten, das Netzwerk direkt zu monetarisieren. So implementierte beispielsweise AGS Airports eine gestufte WiFi-Strategie und erzielte eine Investitionsrendite von 842 %.
  • Verbessertes Besuchererlebnis: Ein nahtloser, gebrandeter Login-Prozess steigert die Kundenzufriedenheit. In Branchen wie dem Gastgewerbe und dem Einzelhandel ist eine zuverlässige Konnektivität eine Grunderwartung; eine sichere Bereitstellung stärkt das Markenvertrauen.

Key Definitions

Captive Portal

A web page that a user of a public access network is obliged to view and interact with before access is granted.

The primary mechanism for authenticating guests and capturing first-party data on a Ruijie wireless network.

RADIUS

Remote Authentication Dial-In User Service. A networking protocol that provides centralized Authentication, Authorization, and Accounting management.

Used to securely connect Ruijie gateways to external platforms like Purple for guest authentication.

Walled Garden

An allowlist of domains and IP addresses that a guest device can access before completing the captive portal authentication.

Essential for allowing social login providers and captive portal detection mechanisms (like Apple's CNA) to function.

VLAN Isolation

The practice of assigning guest traffic to a separate Virtual Local Area Network and using Access Control Lists to prevent communication with internal corporate networks.

The standard security posture for enterprise guest WiFi deployments on Ruijie hardware.

WISPr

Wireless Internet Service Provider roaming. A protocol that allows users to roam between different wireless providers, often used to handle the redirect to external captive portals.

The underlying mechanism Ruijie uses when the captive portal policy is set to External mode.

Ruijie JaCS

Ruijie's cloud management platform specifically tailored for hospitality and hotel scenarios, offering native captive portal building tools.

Used for managing single-site deployments that do not require external data capture platforms.

Reyee EG Gateway

Ruijie's line of enterprise security routers that handle routing, firewall policies, and captive portal redirection for the wireless network.

The central hardware component where ACLs and RADIUS configurations are applied in a Ruijie deployment.

Client Escape

A feature on Ruijie gateways that, if enabled, can allow clients to bypass certain QoS or portal restrictions.

Must be disabled when using an external platform to enforce tiered bandwidth limits.

Worked Examples

A 200-room hotel deploying Ruijie RG-AP access points and an EG gateway needs to provide free guest WiFi while capturing email addresses for their marketing database. They also require strict isolation from their property management system (PMS) network.

The IT team configures a new Open SSID assigned to VLAN 100. On the EG gateway, they configure an extended ACL to deny traffic from VLAN 100 to the PMS VLAN, applying it inbound on the guest interface. They set the captive portal policy to External mode, pointing the Portal Server URL to Purple's platform. They configure the RADIUS server group with Purple's credentials and add Purple's domains to the allowlist. The Purple platform handles the branded splash page and email capture workflow.

Examiner's Commentary: This approach correctly uses VLAN isolation instead of basic NAT, ensuring security for the PMS. By leveraging an external portal via RADIUS, the hotel gains GDPR-compliant data capture capabilities that the native Ruijie portal cannot provide at an enterprise level.

A retail chain with 50 locations is rolling out Ruijie hardware. Customers report that when they connect to the guest WiFi on their iPhones, the login screen does not appear automatically, forcing them to open a browser manually.

The network administrator logs into Ruijie Cloud, navigates to Auth & Account, and opens the Allowlist configuration. They add 'captive.apple.com' to the walled garden list and synchronise the configuration to all EG gateways across the estate.

Examiner's Commentary: This resolves the classic Captive Network Assistant (CNA) failure. iOS devices require access to specific Apple endpoints to trigger the automatic portal pop-up. Adding this to the walled garden is a mandatory step for any captive portal deployment.

Practice Questions

Q1. You are deploying Ruijie WiFi across a stadium. You need to capture fan data for marketing and enforce a 5 Mbps bandwidth limit per user. Should you use the native Ruijie portal or an external platform, and how do you enforce the bandwidth?

Hint: Consider the scale of the deployment and the data capture requirements.

View model answer

You must use an external platform like Purple for the data capture and marketing integration. To enforce the bandwidth, configure the QoS settings on the Ruijie EG gateway for the guest SSID, and ensure the Client Escape feature is disabled so the external platform's policies are respected.

Q2. A client complains that their guest network is insecure because the SSID is set to 'Open'. They ask you to implement a pre-shared key (WPA2-Personal) alongside the captive portal. How do you advise them?

Hint: Consider the user experience and the purpose of the captive portal.

View model answer

Advise the client that for public guest networks, adding a pre-shared key introduces unnecessary friction without significantly improving security, as the key must be shared publicly anyway. The captive portal itself serves as the authentication and authorization layer. For true security, WPA3-Enterprise with 802.1X should be used, but this is rarely suitable for public guest access.

Q3. After configuring a new external captive portal policy on Ruijie Cloud and pointing it to Purple, guests are still seeing the default Ruijie login page. What is the most likely cause?

Hint: Think about the configuration deployment process in the Ruijie interface.

View model answer

The administrator likely saved the configuration in Ruijie Cloud but failed to click the Synchronise button. The configuration has not been pushed down to the local EG gateway, so it is still serving the default local portal.