How To Manage Wi-Fi Access in Captive Portal Hotspots & Shared Working Spaces
We are talking to more and more wireless service providers with customers in retail, hospitality, and shared working spaces. They recognize that providing Wi-Fi access is more than a simple customer amenity.
It’s a way to use the Wi-Fi network to build services that increase customer and brand loyalty, improve engagement, gain customer insight and upsell new services:
A retail store can offer in-store promotions and influence shoppers based on known preferences
Restaurants and coffee shops can deliver ″good-today-only″ coupons to on-site customers
Hotel chains can offer perks such as free Wi-Fi to loyalty program members
Shared working hubs can control access, meter and charge tenants for its Wi-Fi service
Building compelling Wi-Fi services that work both for the end user and for the site, have a number of requirements. The service provider or business owner must architect a solution that delivers:
Simple user interface – Customers must be able to easily access the portal and get internet access via a browser based login.
Ability to gather information – Network owners must be able to derive value from the service offering by capturing customer names or other desired information, or measure and record usage.
Content delivery mechanism - To deliver targeted ads, discount offers, and other information to influence customer behavior.
Seamless integration with a back-end data store - Whether a simple SQL database or a self registration or third-party guest management system.
Ability to deliver service level according to customer – Portal owners must be able to configure network connections to enforce service access policies, including session time limits or bandwidth throttling.
A robust, easy-to-implement captive portal based hotspot system comprises the following elements:
Access points with screen redirect / captive portal support. GlobalReach works with Meraki and Ruckus, for example.
Captive portal web server - Either built-in or external, which provides the portal interface, user sign-on, and content delivery mechanisms.
Back-end data store - Where the portal will authenticate users,. This might be a VIP or customer loyalty program database, a self-registration system or a guest management system like those used by large hotel chains.
Cloud-hosted RADIUS server - GlobalReach RADIUS can handles customer authentication, service level configuration, and usage tracking.
The RADIUS server is a key component of the Wi-Fi captive portal infrastructure. It provides a multi-layer authentication service to let portal merchants and owners control who gets onto the network and what they are able to do. It also provides comprehensive user and usage insight and data.
GlobalReach RADIUS offers the following benefits to businesses and venues offering captive portal-based Wi-Fi network access:
Cost-effective – As a hosted cloud-based service, GlobalReach RADIUS requires no physical footprint. It can reduce capital and operating expenses by eliminating server hardware and software costs, and administrative complexity. GlobalReach RADIUS’s usage-based pricing allows network owners to pay only for the services they need. (GlobalReach RADIUS can be run in a private cloud on a virtual machine. Refer to example 2 below.)
Capable of configuring customer service levels – GlobalReach RADIUS can authorize specific user network privileges such as session time limits or bandwidth restrictions, allowing network owners to offer the services that make sense for their business.
Compatible with a wide variety of back-end data stores – GlobalReach RADIUS can validate credentials against a wide array of user stores, including a native MySQL database, or external stores such as LDAP or SQL databases, Active Directory, or cloud-based user stores such as Google Apps. A powerful API is also available to automate the interaction with third party self-registration programs, VIP & Customer Loyalty Program databases, and user / guest management systems.
Support for Wi-Fi APs and captive portal functionality from leading vendors. GlobalReach RADIUS works with any RADIUS-compatible Wi-Fi AP, controller, or gateway supporting Universal Access Method (UAM) base screen redirect, including Cisco, Meraki, Ruckus, Aruba, Motorola and other leading Wi-Fi vendors.
Usable in public or private cloud – You can use GlobalReach RADIUS in the public cloud, where you can take advantage of a shared multi-tenant infrastructure. You get the cost savings and management simplicity of RADIUS-as-a-service, while critical user data stays under your control. Or, you can choose to deploy GlobalReach RADIUS on a virtual machine running in a private cloud, data center, or individual or regional locations.
Example 1: Cloud-based Wi-Fi Implementation
When a hotspot implementation is based entirely in the public cloud, a user — located, for example, in a retail store, hotel, or shared working space — gains Wi-Fi access via a browser-based login to a captive portal from a Wi-Fi network managed by a cloud controller platform.
When using a browser-based login to authenticate a user to a captive portal, the cloud controller platform sends the authentication request to GlobalReach RADIUS. This then authenticates the user against an existing user data store, or new credentials issued by a guest management or payments platform, stored in an LDAP or SQL database.
Once the user is authenticated, GlobalReach RADIUS returns authorization attributes to the Wi-Fi AP or controller to configure user specific network privileges such as session time limits, time of day or bandwidth restrictions, VLAN assignment, and other configurable gateway parameters.
GlobalReach RADIUS then records all authentication and accounting activity to log files, which can be aggregated with other network and user store information to create a comprehensive view of user and session data for customer analytic and billing purposes.
Example 2. Private Cloud: Captive Portal Browser Based Login via GlobalReach RADIUS Virtual Appliance
When the GlobalReach RADIUS and the Wi-Fi controller are located in a private cloud (for example at a private enterprise or carrier data center), the user might be a hotel, conference center, or shared working hub. They gain Wi-Fi access via a browser-based login to a captive portal on a Wi-Fi network managed by a Wi-Fi network controller on the local network.
When using a browser-based login to authenticate a user to a captive portal, the AP or the Wi-Fi network controller sends the authentication request to the GlobalReach RADIUS virtual appliance, which then authenticates the user against a supplementary user store, or new credentials issued by a guest management or payments platform, stored in an LDAP or SQL database.
Once authenticated, GlobalReach RADIUS authorizes specific user network privileges such as session time limits, time of day restrictions, VLAN assignment, and other configurable gateway parameters.