Omada Cloud Controller – Guest Portal Authentication Issue

Omada Cloud Controller – Guest Portal Authentication Issue

Omada Cloud Controller – Guest Portal Authentication Issue
Omada Cloud Controller – Guest Portal Authentication Issue
2025-06-27 20:14:16 - last edited 2025-06-30 16:01:14
Model: EAP225  
Hardware Version: V5
Firmware Version: 1.3.1

Hello,

 

We operate a holiday cottage business and use the TP-LINK Omada Cloud Controller to manage our wireless network, which is powered by EAP225 access points running the latest firmware across our site.

 

Recently, we've encountered an issue where guests were unable to connect to the guest Wi-Fi network due to failed portal authentication. Although I can manually authorise connections through the controller, this shouldn’t be necessary on a regular basis.

 

The guest portal is configured with passwordless authentication and typically prompts the user with a connection page upon selecting the guest network. Once connected, it redirects them to our website before allowing full internet access.

 

There are no logs indicating portal failure, but the issue has been occurring intermittently since the recent firmware update. Reapplying the portal settings temporarily resolves the problem, but it tends to recur with new guest connections.

 

Could you confirm whether others have experienced a similar issue? I suspect this may be related to a recent firmware bug.

 

Many thanks,
Ben

Regards, Ben
  0      
  0      
#1
Options
5 Reply
Re:Omada Cloud Controller – Guest Portal Authentication Issue
2025-06-30 07:10:44 - last edited 2025-06-30 16:01:14

  @HBEN1603 

 

Portal authentication requires persistent communication with the controller. When enabling guest network functionality on an SSID, the system automatically blocks communication between that SSID and the portal server, resulting in the observed issue.

To resolve this, simply configure an EAP ACL rule to permit the SSID to access the controller's IP address.

 

Below is the guide:

How to allow guest network to access specific device on the main network by configuring EAP ACL?

 

In your specific scenario, you will need to substitute the controller's IP address with the printer's IP as referenced in the article.

  0  
  0  
#2
Options
Re:Omada Cloud Controller – Guest Portal Authentication Issue
2025-06-30 16:31:26

Hi @Vincent-TP 

 

My controller is a Cloud Based Controller and not a hardware/software controller, so therefore I am unable to add an ACL rule to permit a specific URL.

 

We do however have a ACL rule in place which prevents guests from accessing another VLAN network which you can see from the screenshot below

 

 

I think this rule probably isn't necessary because mostly guest networks do not usually allow access to other VLAN networks if the 'Guest Network' option is selected in the guest SSID, in this case it is.

 

I seem to think this is a bug because it was mentioned in the latest firmware update for one of our EAP225s, but the one we're talking in question is a slightly different model version to the other. The affected EAP is the EAP225 v5.0.

 

Below is the release note for EAP225 v3.0

 

EAP225(EU) v3.0 Release Note

5.1.11 Build 20250401 Rel. 50587

Recommended Controller Software version: Omada Controller v5.15 or above

 

New features/Enhancements:

1. Improved security protection capability.

 

Bug Fixed:

1. Fixed the issue of portal with external portal server taking effect abnormally.

2. Fixed the issue that the portal authentication page cannot be popped up in some clients.

3. Fixed the issue that Pre-Authentication Access with URL entry function works abnormally.

4. Fixed the issue that portal authentication page cannot be popped up automatically with HTTPS Redirection enabled under certain application scenarios.

5. Fixed the issue of inaccurate downstream traffic limit by portal.

6. Fixed the issue of random disconnection between VIGI IPC and VIGI App.

7. Fixed the issue of firmware assert occurring in some scenarios.

8. Fixed the issue that the AP reboots automatically under certain application scenarios.

 

Many thanks,

Ben

Regards, Ben
  0  
  0  
#3
Options
Re:Omada Cloud Controller – Guest Portal Authentication Issue
2025-07-04 08:35:53

Hi  @HBEN1603 

 

Thanks for the info.
 

If you're using a cloud controller, then it's probably not due to the reason I mentioned earlier.

 

Recently, we've encountered an issue where guests were unable to connect to the guest Wi-Fi network due to failed portal authentication. Although I can manually authorise connections through the controller,

>>>We want to check more details about this issue:

1. will the portal login page successfully pop up?

2. is there any error message on the clients when failed to pass the authentication?

3. How did you manually authenrize the connection? Via the Reconnect button on the client page? Or else?

4. When did this issue first occur? Since first installation? or began recently?

5. will all clients failed to pass the portal authentication?

 

 

Suggestions:

1. disable guest network;

2. make sure all the EAP are using the latest firmware.

 

 

  0  
  0  
#4
Options
Re:Omada Cloud Controller – Guest Portal Authentication Issue
2025-07-06 09:37:40

Hi @Vincent-TP 

 

These are the responses to your questions:

 

  1. Most of the time the portal login page successfully opens up but some Android devices (especially Pixel phones) trying to connect doesn't work.
  2. I could not recall seeing an error message when they fail the authentication.
  3. From your screenshot, yes that's correct.

 

Since there's been an update to the controller recently, I have a feeling that the issue will have been resolved as I haven't heard anything from our guests recently. So I do suspect this was caused when they were making changes to the HTTPS redirection behaviour. They stated this in their release notes in the enhancements section:

 

"Omada Controller v5.15.24.100

 

*Optimized portal HTTPS redirection behavior. When "HTTP Redirect to HTTPS" for Portal is enabled , clients connecting to the AP's SSID will be directly redirected by the AP to the HTTPS portal authentication page."

 

Source: Omada SDN Controller_V5.15.24 Pre-Release Firmware (Update on 3rd Jul, 2025) - Business Community

Regards, Ben
  0  
  0  
#5
Options
Re:Omada Cloud Controller – Guest Portal Authentication Issue
2025-07-07 01:49:27

Hi  @HBEN1603 

 

Thanks for your reply.  

Let's observe the behavior for a few more days and if anything comes up, don't hesitate to let us know.

  0  
  0  
#6
Options