Skip to main content

External Access Point Integration

WAVER Gateways can be integrated with most third-party Access Point (AP) platforms, including Ubiquiti UniFi, HPE Networking Instant On, TP-Link Omada and Cambium Networks etc. 

In this deployment, the WAVER Gateway controls the guest network, while the Access Points provide wireless coverage and bridge guest traffic to WAVER.

WAVER provides:

  • Guest DHCP and IP address assignment

  • NAT and Internet access control

  • Captive Portal redirection and authentication

  • Login methods, vouchers and paid access

  • Guest policies, speed limits and session management

The Access Points must not provide a second DHCP server, NAT service or captive portal for the same guest network.

“Bridge Mode” may be named AP Mode, Bridged, Same as Local Network, Third-party Gateway or External Gateway, depending on the platform. The required result is the same: guest traffic must reach the WAVER Guest Port without being routed or translated by the AP platform.

Deployment Method

WAVER supports two common AP integration methods.

Deployment Recommended when Guest traffic Network requirements
Without VLAN The guest network uses dedicated APs, switch ports or cabling Untagged No managed VLAN configuration is required
With VLAN Guest and staff networks share switches and Access Points Tagged Managed switches and VLAN-capable APs are required

Option 1: Dedicated Guest Network Without VLAN

Use this method when the equipment or physical network path is dedicated to guest access. Guest traffic leaves the WAVER Guest Port untagged and passes through an optional dedicated switch to the Access Points.

image.png

Configuration
  1. Configure the WAVER Guest Port for untagged traffic.

  2. Leave VLAN Traffic Only disabled.

  3. Connect the WAVER Guest Port directly to an AP, or to a dedicated switch serving multiple APs.

  4. Configure the guest SSID to use the AP’s native or untagged network.

  5. Disable any AP-platform DHCP server, NAT mode or built-in captive portal for this SSID.

Network safety: Do not connect an untagged WAVER Guest Port to an existing untagged LAN that already has another DHCP server. Doing so can introduce competing DHCP services and disrupt the existing network. Use a dedicated physical path or the VLAN method below.

Option 2: Shared Network Infrastructure With VLAN

Use this method when guest and staff services share the same managed switches and Access Points. The Guest Port sends tagged traffic, and the guest SSID is mapped to the same VLAN throughout the network. The following example uses VLAN 10. You may use another available VLAN ID, but it must match at every point in the path.

image.png

Configuration
  1. Assign a VLAN ID to the WAVER Guest Port—for example, VLAN 10.

  2. Enable VLAN Traffic Only.

  3. Configure the managed-switch port connected to the WAVER Guest Port to allow VLAN 10 as tagged traffic.

  4. Allow VLAN 10 as tagged traffic on every switch uplink between WAVER and the Access Points.

  5. Allow VLAN 10 on the AP uplink ports.

  6. Map the guest SSID to VLAN 10.

  7. Disable the AP platform’s DHCP server, NAT mode and captive portal for the guest SSID.

The AP management network can remain on the existing native network or on a separate management VLAN. Do not move AP management to the guest VLAN unless this is part of your network design.

Preparing the WAVER Gateway

Complete these steps before configuring the AP platform.

1. Connect the Gateway
Connect the WAVER Gateway’s WAN port to the existing Internet router, firewall or upstream network.

2. Open the Administration Interface
Connect a computer to a WAVER LAN/MGMT port, then open the Administration interface - https://192.168.10.1

3. Configure the Guest Network
Open Guest Network and configure the guest IP range, DHCP settings and any required access policies. WAVER must remain the DHCP server and default gateway for guest devices.

4. Test the Guest Port
Before connecting the switch or APs, connect a computer directly to the WAVER Guest Port and verify that:

  • The computer receives an IP address from the WAVER guest range
  • The WAVER Captive Portal appears
  • Authentication completes successfully
  • Internet access works after authentication

5. Configure the Guest Ethernet Output
Choose the configuration that matches your deployment:

  • Without VLAN: use untagged output and leave VLAN Traffic Only disabled.  (default settings)
  • With VLAN: enter the selected VLAN ID and enable VLAN Traffic Only.

6. Connect the AP Network
Connect the WAVER Guest Ethernet Port to the dedicated switch or to the managed switch carrying the guest VLAN.


Ubiquiti UniFi

With VLAN

  1. In the UniFi Network application, go to Settings > Networks and create a new virtual network.

  2. Enter a descriptive name such as WAVER Guest.

  3. Under Router, select Third-party Gateway.

  4. Enter the VLAN ID configured on the WAVER Guest Port - for example, 10.

  5. Apply the changes.

  6. Go to Settings > WiFi and create or edit the guest WiFi network.

  7. Select WAVER Guest in the Network field.

  8. Ensure VLAN 10 is allowed on the switch port connected to WAVER and on all AP uplink ports.

  9. Do not enable the UniFi Hotspot Portal for this SSID; authentication is provided by WAVER.

Without VLAN

  1. Connect the AP or its dedicated switch to the WAVER Guest Port and assign the guest SSID to the native/untagged network. This physical segment must not be shared with the existing LAN. 
  2. If the Access Points need to reach the Internet (eg. Cloud Management purposes), bypass MAC Addresses for each Access Point by adding them in the Guest Devices > Allowed Devices list.

HPE Networking Instant On

Instant On guest networks may use NAT mode by default. This must be changed so clients receive their addresses from WAVER.

With VLAN

  1. Create or select a wired network using the VLAN ID configured on WAVER - for example, VLAN 10.

  2. Create or edit the wireless guest network.

  3. Under IP Assignment, select Same as a Local Network. This is Instant On’s bridged mode.

  4. Select the wired network associated with VLAN 10.

  5. Disable the Instant On captive portal for this network.

  6. Apply the configuration.

Do not select Specific to This Network, because that enables Instant On NAT and local IP assignment instead of using WAVER.

Without VLAN

  1. Set IP Assignment to Same as a Local Network and select the untagged local network connected exclusively to the WAVER Guest Port.
  2. If the Access Points need to reach the Internet (eg. Cloud Management purposes), bypass MAC Addresses for each Access Point by adding them in the Guest Devices > Allowed Devices list.

With VLAN

  1. In the Omada Controller, go to Network Config > Network Settings > LAN > VLAN.

  2. Add a new network and enter a descriptive name such as WAVER Guest.

  3. Select External Device as the DHCP Server Device, because DHCP is provided by WAVER.

  4. Enter the VLAN ID configured on the WAVER Guest Port—for example, 10.

  5. Apply the VLAN to the relevant switch path. The WAVER-facing port and AP uplinks must carry VLAN 10 as tagged traffic.

  6. Go to Network Config > Network Settings > WLAN > SSID and create or edit the guest SSID.

  7. Open Advanced Settings, set VLAN to Custom, and assign the network created above or enter VLAN ID 10 directly.

  8. Do not configure an Omada Portal for this SSID.

Without VLAN

  1. Leave SSID VLAN assignment at the native/default network and connect the APs through a physical network dedicated to the WAVER Guest Port.
  2. If the Access Points need to reach the Internet (eg. Cloud Management purposes), bypass MAC Addresses for each Access Point by adding them in the Guest Devices > Allowed Devices list.

Cambium Networks

The exact menu names vary between cnPilot, XV/XE-series APs and cnMaestro versions, but the required network behavior is the same.

With VLAN

  1. Create or edit the guest WLAN in cnMaestro or the AP management interface.

  2. Enter the required SSID name.

  3. Assign the VLAN ID configured on the WAVER Guest Port - for example, 10.

  4. In the AP Group or Ethernet/VLAN configuration, ensure traffic from this WLAN is bridged and sent to the Ethernet uplink as tagged VLAN 10.

  5. Allow VLAN 10 across the connected switch ports and uplinks.

  6. Disable Cambium NAT, local DHCP and built-in captive portal services for this WLAN.

Without VLAN

  1. Assign the WLAN to the native/untagged network and connect the AP or dedicated switch directly to the WAVER Guest Port.
  2. If the Access Points need to reach the Internet (eg. Cloud Management purposes), bypass MAC Addresses for each Access Point by adding them in the Guest Devices > Allowed Devices list.

Vendor menu names may vary between controller releases and device families. If the exact labels differ, apply the same network principles: WAVER remains the guest gateway and DHCP server, the SSID is bridged to the correct untagged network or VLAN, and the selected VLAN is carried consistently across every switch and AP uplink.


WiFi Security and Client Isolation

The guest SSID may be configured as either:

  • Open: Guests join WiFi without a wireless password and authenticate through the WAVER Captive Portal.

  • WPA2/WPA3 Personal: Guests enter a WiFi password before reaching the WAVER Captive Portal.

An open SSID is common for public guest networks, but it is not required for WAVER integration.

Wireless client isolation may be enabled if required. However, it must not block client access to essential network services such as DHCP, DNS, the default gateway or the WAVER Captive Portal.

Verification Checklist

After completing the integration, connect a new device to the guest SSID and verify that:

  • The device receives an IP address from the WAVER guest DHCP range

  • The default gateway belongs to the WAVER guest network

  • The Captive Portal opens automatically

  • The selected login method works

  • Internet access is blocked before authentication and available afterward

  • Staff and management networks continue to operate normally

  • No other DHCP server is responding on the guest network

Troubleshooting

Problem Likely cause What to check
Guest device does not receive an IP address VLAN mismatch or guest path interruption Confirm the VLAN ID and tagged/untagged status on every port between WAVER and the AP
AP goes offline after configuration AP management network was changed unintentionally Restore the AP’s native or management VLAN and keep the guest VLAN assigned only to the guest SSID
Captive Portal does not appear Client is not reaching WAVER or another portal is enabled Confirm the client’s IP and gateway, disable the AP platform’s portal and retry with a new/incognito browser session
Internet works before WAVER authentication Traffic is being routed or NATed elsewhere Disable AP NAT/gateway mode and confirm the guest SSID is mapped to WAVER’s network
Existing LAN clients receive WAVER addresses Untagged guest traffic has leaked into the existing LAN Disconnect the Guest Port immediately and correct the physical separation or VLAN configuration