Skip to main content

What is RADIUS?

Definition

RADIUS, the Remote Authentication Dial-In User Service, is the protocol that brokers authentication between an access point and an identity store. It provides authentication, authorisation and accounting (AAA) for network access. It is the hub of every 802.1X and WPA-Enterprise deployment, and guest captive portals use it too.

RADIUS explained

RADIUS is defined in RFC 2865. In a WiFi network, the access point or wireless controller acts as the RADIUS client, also called the network access server. It forwards each connection attempt to the RADIUS server, which checks the credential against an identity store such as Active Directory, LDAP or a cloud identity provider, then returns Access-Accept or Access-Reject.

The reply can carry instructions as well as a decision. RADIUS attributes tell the network which VLAN to place a user on, what bandwidth to allow and how long a session may last. That is how one SSID can put staff, contractors and devices on different segments through dynamic VLAN assignment. Accounting records then log who was connected, where and for how long.

Common servers include Microsoft NPS, FreeRADIUS and Cisco ISE on premises, and cloud RADIUS services that remove the hardware. Classic RADIUS traffic is only partly encrypted, so traffic that crosses the internet should use RadSec, which carries RADIUS inside TLS. RADIUS federation over RadSec is also what makes OpenRoaming work between organisations.

Need more than a definition?

Talk to our team about how Purple combines guest WiFi, captive portals, RADIUS, and analytics into a single platform that runs on the access points you already own.