RADIUS Authentication
RADIUS (Remote Authentication Dial-In User Service) is a network protocol providing centralised authentication, authorisation, and accounting (AAA), defined in RFC 2865, and used by enterprise WiFi, VPNs, and captive portals to control network access.
RADIUS (Remote Authentication Dial-In User Service) is a network protocol that provides centralised authentication, authorisation and accounting - the "AAA" functions - for users connecting to a network. Designed in the dial-up era and standardised in RFC 2865 (authentication and authorisation) and RFC 2866 (accounting), it remains the backbone of enterprise WiFi, VPN and hotspot access control today.
How a RADIUS exchange works
- The network access server - in WiFi, the access point or controller - sends an Access-Request to the RADIUS server (UDP port 1812) containing the user's credentials or identifiers.
- The server checks them against its user store and replies with Access-Accept, Access-Reject, or Access-Challenge (for multi-step methods).
- An Access-Accept can carry attributes that shape the session: time limits, bandwidth caps, data quotas, or a dynamic VLAN assignment.
- Accounting packets (UDP port 1813) record session start, stop and usage - the trail behind billing and fair-use policies.
RADIUS in guest WiFi
Many captive portal platforms use RADIUS behind the scenes: the guest signs in on the splash page, the portal authorises the device via RADIUS, and session length, speed tiers for paid WiFi, and voucher limits are enforced through RADIUS attributes and accounting. FreeRADIUS, the most widely deployed implementation, powers a large share of these systems.
Related standards
For staff and corporate networks, RADIUS pairs with IEEE 802.1X and EAP as WPA2/WPA3-Enterprise: each user gets individual credentials instead of one shared password, and access is revoked per person. Passpoint roaming also authenticates against RADIUS infrastructure. In short: if network access is being decided per user rather than per shared password, RADIUS is usually doing the deciding.
Related terms
Captive Portal
A captive portal is a web page that public WiFi users see before being granted internet access - typically used to authenticate users, accept terms, and capture data such as email or social-login identity.
Passpoint / Hotspot 2.0
Passpoint, also known as Hotspot 2.0, is a Wi-Fi Alliance certification based on IEEE 802.11u that lets devices discover, securely authenticate to, and roam between participating WiFi networks automatically, with no captive portal or manual sign-in.
VLAN
A VLAN (Virtual Local Area Network) is a logical segmentation of a physical network, defined by IEEE 802.1Q, that isolates groups of devices - such as guest WiFi users and staff systems - from each other while sharing the same switches and cables.
Paid WiFi
Paid WiFi is a guest WiFi model in which users buy internet access - by time block, data allowance, or speed tier - through a checkout on the captive portal, common in hotels, holiday parks, marinas, and events.
Try CaptiFi free for 30 days
Capture guest emails, run automated email/SMS campaigns, and grow Google reviews - all from your existing WiFi.