All capabilities
Guest network access

Captive Portal with RADIUS

Built-in captive portal with RADIUS authentication for secure, isolated guest Wi-Fi-without a separate AAA appliance.

Captive Portal with RADIUS

Overview

Nebero’s captive portal with built-in RADIUS lets visitors authenticate on a dedicated guest network before accessing the internet. Guests stay isolated from the corporate LAN while administrators control who connects, how long sessions last, and how much bandwidth they consume-all from the same NGFW control plane.

Capabilities in this category

Guest captive portal UI

Redirect unauthenticated guests to a branded splash page before granting internet access.

When a device joins the guest SSID or VLAN, the firewall intercepts HTTP(S) traffic and presents a captive portal for credentials or vouchers. After successful authentication, access is granted per policy-ideal for offices, hotels, clinics, and shared workspaces that need controlled visitor Wi-Fi.

Built-in RADIUS AAA

Authenticate guests with an integrated RADIUS server-no separate AAA appliance required.

Use the on-appliance RADIUS service for authentication, authorization, and accounting, or federate with an existing RADIUS backend. Built-in AAA simplifies guest deployments where standing up a dedicated authentication server would add cost and operational overhead.

Guest VLAN isolation

Keep guest traffic segregated from corporate LAN and sensitive internal resources.

Map captive-portal clients to a dedicated guest VLAN or security zone with strict inter-zone policies. Guests reach the internet (and only allowed services) while east-west paths into corporate segments remain blocked-reducing blast radius if a visitor device is compromised.

Session and bandwidth controls

Limit session duration, concurrent devices, and guest bandwidth so visitors do not starve business traffic.

Apply session timeouts, idle disconnects, and QoS/bandwidth caps for portal-authenticated users. Time-limited vouchers and fair-use policies keep guest Wi-Fi reliable during peak hours without degrading critical applications on the corporate network.