To set up RADIUS for Cambium Networks, create a Cloud RADIUS profile in IronWiFi with your authentication sources, then in cnMaestro create a WLAN profile with WPA2-Enterprise security pointing to the RADIUS server IP and port assigned in the IronWiFi Console with the shared secret. Assign the WLAN profile to your AP group and sync. The Cambium APs forward 802.1X authentication requests directly to IronWiFi, which validates credentials and returns accept or reject decisions.
Cambium Networks offers a range of enterprise Wi-Fi access points managed through the cnMaestro cloud controller. Whether you deploy cnPilot e-series or the newer XV and XE series APs, integrating an external RADIUS server enables enterprise-grade 802.1X authentication. This guide walks through connecting Cambium wireless to IronWiFi Cloud RADIUS for secure network access control.
Why Use RADIUS with Cambium Networks?
RADIUS authentication on Cambium APs provides:
- Individual user credentials - Every person authenticates with their own identity
- Certificate-based authentication - Deploy EAP-TLS for passwordless device authentication
- Dynamic VLAN assignment - Segment users into VLANs based on role or device type
- Centralized access control - Manage WiFi access from the IronWiFi console
- Audit trails - Full visibility into who connected, when, and from where
- Identity provider integration - Authenticate against Microsoft Entra ID, Google Workspace, Okta, or LDAP
Prerequisites
- cnMaestro access - Admin credentials for cnMaestro cloud or on-premises controller
- Cambium APs - cnPilot, XV, or XE series access points managed by cnMaestro
- IronWiFi account - Talk to Sales
Trusted by 1,000+ organizations across 108 countries
Frequently Asked Questions
Yes. Cambium cnMaestro supports external RADIUS servers for WPA2-Enterprise authentication. You configure the RADIUS server details within the WLAN profile settings under Configuration > WLAN. cnMaestro pushes the RADIUS configuration to all APs in the assigned AP group.
All current Cambium enterprise Wi-Fi access points support 802.1X with external RADIUS servers, including the XV series (XV2-2, XV3-8), cnPilot e-series (e410, e425H, e430H, e505), and the newer XE series. These APs can be managed through cnMaestro cloud or on-premises controller.
In cnMaestro cloud, navigate to Configuration > WLAN and create or edit a WLAN profile. Set the security mode to WPA2-Enterprise, then enter the IronWiFi RADIUS server IP address (primary and secondary), the assigned port, and shared secret from your IronWiFi Console. Enable RADIUS accounting on the assigned accounting port. Apply the WLAN profile to your AP group to push the configuration.
Yes. Enable dynamic VLAN in the WLAN profile settings on cnMaestro. In IronWiFi, configure Tunnel-Type (64) = VLAN, Tunnel-Medium-Type (65) = IEEE-802, and Tunnel-Private-Group-ID (81) with the desired VLAN ID for each user group. The Cambium AP assigns the VLAN from the RADIUS Access-Accept response. The VLANs must be trunked to the AP switch ports.
Common causes include: (1) Firewall blocking the assigned RADIUS UDP ports from the AP subnet to the RADIUS server IPs. (2) The AP's public IP is not registered as an authorized client in IronWiFi. (3) Shared secret mismatch between cnMaestro and IronWiFi. (4) The WLAN profile has not been pushed to the AP group yet - check cnMaestro sync status. (5) Wrong RADIUS server IP. Check IronWiFi authentication logs for rejected or missing requests.
