Athentication free limited to 32 entries
Athentication free limited to 32 entries

Hello,
I was wondering if TPLINK could expand the entries for the Authentication-free List in the Portal Settings. Currently it only caters 32 entries both Mac or IP entries. This would be really helpful if entries would be expanded or maybe unlimited.
Does anyone knows any work-around on this limit. I am managing a Portal-Local User internet provider.
And does anyone knows how to do the settings where we can set an athentication timeout? I dont see the setting when in using LOCAL USER.
Thanks guys!
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Hi @Cebujohn
To better understand you request, why would you need to add so many auth-free clients?
Instead of adding them to the auth-free list, did you consider connecting those clients to a separe WLAN network?
Yes, we can configure Authentication Timeout on this page:
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
Hello @Vincent-TP, I concur with Cebujohn. I am on a similar situation and require the list to expend more than 32 entries. Initially, I have been using more than 70 wireless IoT devices at home which do not support portal log in feature. To reduce running cable all over the house, i am using a xiaomi BE5000 with 3 of Ax3000 mesh routers. We are planning to run a small cafe in front of the house. I am planning to provide internet access to customers with portal authentication while maintaining the IoT devices on the same network. To do that, recently, I have bought a set of omada devices, oc200, er605 and es206gp to act as a main server before the BE5000 which will now act as an access point. I have been adding my IoT devices by MAC address to Authentication Free Client list until I suddenly, I hit my 32 entries. Appreciate if you could advice a way to break the 32 entries limitation. Thanks in advance. Cheers!
- Copy Link
- Report Inappropriate Content
Hi @Cebujohn
I missed the screenshot of the timeout settings. Here is it:
Please check what's the config on your side.
As for the TVs, I would recommend create a new SSID in the same LAN, and don't configure portal authentication with the SSID for the TV. With this config, portal clients will also be able to access the TV, and the TV won't need to log in the portal. How do you think?
Cebujohn wrote
Hi Vincent, I manage a residential building where their TVs are on the same Portal and VLAN to the presently used Hotspot for Internet access. The TVs -- well some, randomizes mac address and doesnt have any option to use its own mac. Complaints were they keep on logging on to the Portal thru their TVs to authenticate. With authentication free list, it automatically connects the tv to the network. But really need more than 32 entries. Will there be any chances of extending the list into maybe unlimited? ... or i was really thinking some work-around on this problem. Any suggestion? I would really appreciate it. About the Authentication Timeout on the PORTAL section set to LOCAL USER, I am using OC300 using HOTSPOT - Local User. Clients will always complain they system keeps them logging-out and they keep on logging-in on a period of time. How am i going to go about this? Thank you very much, answers and very much appreciated. Thank you!
- Copy Link
- Report Inappropriate Content
SSID examples would be:
One for guests with portal authentication, the other is for TV without portal auth.
- Copy Link
- Report Inappropriate Content
Similair as your situation. You may create a separate SSID without portal auth for the IoT devices.
Vincent-TP wrote
SSID examples would be:
One for guests with portal authentication, the other is for TV without portal auth.
- Copy Link
- Report Inappropriate Content
@Vincent-TP I got this screenshot. But it is not what I meant. Currently using that feature too. What happens is -- Local users are forcefully logged-out if they go out of range for a day or 2. Take note that Authentication time-out is still valid. The system requests the user to re-login even if authentication is still valid.
as for TVs, if i create another SSID without security. Then they would easily shift and connect to that SSID to gain access. With mac address list -- no authentication is needed if it corresponds with the mac address list. So it would be great if 32-mac address limit is increased or be unlimited.
Thanks!
- Copy Link
- Report Inappropriate Content
Hi @Cebujohn
For SSIDs configured with a portal, when a client connects, it triggers the browser to redirect to the login page. Brief disconnections and reconnections don't require re-login because the browser cache is still valid. However, if the disconnection lasts several days, the cache will naturally be cleared when redirected to the login page again, so re-authentication is required. Currently, this scenario does not support login-free access.
Additionally, I personally believe it's completely reasonable to require re-login after being disconnected for several days.
As for the TVs, that screenshot shows two temporary SSIDs I created as examples – mainly to demonstrate the difference between having a portal and not having one. For simplicity, I chose "None" as the encryption method so I wouldn't need to enter passwords. In actual deployments, I recommend using WPA-Personal to encrypt your SSIDs.
- Copy Link
- Report Inappropriate Content
Hello @Vincent-TP. That is would be my approach if I were using the EAP from TpLink. However, since I am using router from Xiaomi BE5000 as an access point, the router is limited to single SSID in access point mode. It has guest SSID feature when I am using it in router mode however, it would bypass the portal authentication on all the other devices when one of the device connected to router has authenticated. Alternatively, I am thinking of using build in Radius Authentication but I don't have experience on it and I am not sure the IoT devices supports connecting to Radius Type Authentication. So far I know, if I could add more than 32 Authentication Free Client to the list, our issue could have been sorted. Please enlighten me if you have any way around. Cheers!
- Copy Link
- Report Inappropriate Content
Hi @ThawHZin
With oc200, er605 and es206gp Omada devices, unfortunately, there is no other workaround.
- Copy Link
- Report Inappropriate Content

Information
Helpful: 2
Views: 469
Replies: 18
Voters 2

