Mode B uses RADIUS to validate each guest's unique passphrase in real time. When a guest connects, the Meraki AP sends an authentication request to the QuuPass RADIUS server, which checks the credential and either approves or denies the connection — instantly, without touching the Meraki API.
QuuPass provides the RADIUS server
You do not need to set up or manage a RADIUS server. QuuPass runs the RADIUS bridge as part of your Pro plan. Your onboarding email includes the server IP, port, and shared secret to enter into Meraki. This page tells you exactly how to configure the SSID to connect to it correctly.
Third-party RADIUS servers are not supported. QuuPass Mode B works exclusively with the QuuPass RADIUS bridge. The bridge is purpose-built to match credentials against the QuuPass credential pool — a standard RADIUS server has no access to that data and will reject all connections.
The SSID must be set to IPSK with RADIUS (Easy PSK) in the Meraki dashboard. This is different from WPA2-Enterprise — no 802.1X supplicant or certificate is required on the guest device. The guest simply types their passphrase and the AP validates it via RADIUS transparently.
WPA3 is not required and may cause compatibility issues with older guest devices. WPA2-only is the recommended setting.
| Field | Recommended value | Notes |
|---|---|---|
| RADIUS server (auth) | Your QuuPass server IP, port 1812 | UDP, standard RADIUS auth port |
| RADIUS server (acct) | Same host, port 1813 | Optional but recommended for session tracking |
| Server timeout | 1 s | Configured automatically by the wizard. The QuuPass bridge responds well within 1 s under normal load. |
| Retry count | 3 | Standard — retries before the AP gives up |
| RADIUS fallback | Disabled | Do not allow unauthenticated fallback; guests should be denied if RADIUS is unreachable |
| RADIUS testing | Disabled | Prevents periodic test auth requests from the Meraki dashboard |
| CoA support | Enabled | QuuPass sends a RFC 5176 Disconnect-Request to the AP when a credential is revoked, immediately terminating the active session |
Timeout is set automatically. The RADIUS wizard configures the server timeout to 1 second when deploying a portal. If you configured your SSID manually, set the timeout to 1 s — the QuuPass bridge is co-located with its database and responds well within 1 s under normal conditions.
| Attribute | Recommended format | Notes |
|---|---|---|
| Called-Station-ID | $NODE_MAC$:$VAP_NAME$ | AP MAC + SSID name; standard Meraki default |
| NAS-ID | $NODE_MAC$:$VAP_NAME$:$NODE_PUBLIC_IP$ | AP MAC + SSID name + AP public IP. All three components are required — the QuuPass RADIUS server uses the public IP to identify your network for tenant resolution and Connected Clients telemetry. |
| Group policy attribute | Filter-Id | RADIUS returns group policy name in Filter-Id (RADIUS attribute 11) |
NAS-ID is configured automatically. The RADIUS portal wizard sets the correct three-component NAS ID format (AP MAC : SSID name : AP public IP) automatically via the Meraki API when you deploy a portal. If you configured your SSID manually or before May 2026, go to Wireless → SSIDs → [SSID] → Edit → RADIUS → Advancedin the Meraki dashboard and set the NAS ID to include AP MAC address, SSID name, andAP public IP.
Enable RADIUS accounting on the SSID alongside authentication. Accounting tells the QuuPass bridge when a guest session starts and ends — this is how credential usage is tracked and how QuuPass knows when to retire a used credential from the pool.
These settings are configured on the SSID in the Meraki dashboard under Wireless → SSIDs → [your SSID] → Edit settings.
Bridge mode places clients on your site network so they can reach LAN resources (printers, NAS, cameras) and roam seamlessly. NAT mode (Meraki default for new SSIDs) isolates clients in a 10.0.0.0/8 network — suitable for internet-only guest access. If the QuuPass wizard created your SSID, it will have NAT mode set; switch to Bridge mode in Meraki Dashboard if LAN access or VLAN tagging is required.
Enable and set a VLAN ID only if you want to isolate guest traffic onto a separate network segment.
Allows the QuuPass RADIUS bridge to return a group policy for each guest — this is how per-portal policies are applied.
Improves compatibility with older guest devices.
Can cause connection issues with RADIUS-validated credentials on some devices.
true on the SSIDtrue