Wi-Fi Management · Panel › Wi-Fi › Office Wi-Fi

Manage your staff network, separate from your guest network, with RADIUS.

The Office Wi-Fi page is a completely separate flow from the guest portal: staff authenticate with RADIUS PAP against a local username/password defined in izgate. The page has two tabs, Users and Networks.

Office Wi-Fi page in the izgate panel, Users tab
What's on screen?

Users and Networks tabs

  1. 1

    Users (default tab)

    Table columns: Username, Full Name, Source, Networks, MAC Count, Validity, Active, and Last Login; a search box sits above, with a "New User" button in the top right.

  2. 2

    Networks

    A second tab listing the networks attached to Office Wi-Fi (separate from the Networks tab under Guest Wi-Fi, for office-type networks).

  3. 3

    Empty state

    If no user has been defined yet, the table shows a "No users yet" message.

Users

Local users, MAC lists, expiration dates

A local user is defined in izgate for each staff member: username/password, an optional MAC list (restricting which devices the user may connect from), and an expiration date (for example, a last-use day for a contractor whose contract is ending). The "Active" column lets you temporarily disable a user, "Last Login" shows when they last connected, and "Source" indicates where the user was defined from.

Authentication runs over RADIUS PAP; the NAS (firewall) shared secret is read from the device record matched in RADIUS Sessions.

izgate panel Office Wi-Fi Users table: username, full name, source, networks, MAC count, validity, active, last login
Users: username, networks, MAC count, validity, and active status.
What can you do?

Keep your staff network under control

Add new staff

Use "New User" to set a username/password and attach the user to the relevant Office Wi-Fi network.

Restrict by MAC

If you want a user to connect only from specific devices, define a MAC list for them.

Limit validity

For temporary staff or contractors, set an expiration date so that access automatically ends.

RADIUS Sessions tab in the izgate panel, where Office Wi-Fi connections appear
Office Wi-Fi connections are tracked on the "RADIUS Sessions" tab of the Sessions page.
RADIUS infrastructure

Auth + Accounting, signed packet verification

RADIUS Auth (1812/UDP) and Accounting (1813/UDP) are used; each packet's Message-Authenticator field is verified with HMAC-MD5, and packets that fail verification are silently dropped. An Accounting-On/Off signal only closes that NAS's (that firewall's) own sessions and does not affect other devices.

Session-to-user matching uses the RADIUS Class attribute; a session that goes quiet (accounting has stopped) is automatically closed within 30 minutes. You can monitor every open session from the "RADIUS Sessions" tab on the Sessions page.

How does it work?

Opening access for a new staff member

1

Add a user

On the Users tab, use "New User" to set a name, username, and password.

2

Choose a network

Attach the user to the relevant Office Wi-Fi network (defined on the Networks tab).

3

Add MAC and validity if needed

Fill in these fields if device restriction or an expiration date is required.

4

Set up NAS/RADIUS on the firewall

On the firewall side, define izgate as the RADIUS server (with a shared secret); the connection then appears on the Sessions page.

Good to know

Limits

Office Wi-Fi today supports only local user authentication over the RADIUS PAP protocol. Certificate-based 802.1X/EAP-PEAP authentication (sourced from local/AD/LDAP directories) is not yet available; it is on the roadmap. The NAS shared secret is read from the device record — if it is not set, or is incorrect, RADIUS requests cannot be verified.

Frequently asked questions

About Office Wi-Fi

Are Office Wi-Fi and Guest Wi-Fi managed from the same panel?

Yes, both are managed from the izgate panel, but they are separate flows: Office Wi-Fi uses a local-user model over RADIUS, while Guest Wi-Fi works through a captive portal and multiple authentication methods.

Is 802.1X/EAP supported?

Not yet. Today, Office Wi-Fi supports only local-user authentication over RADIUS PAP; certificate-based 802.1X/EAP is on the roadmap.

Can I restrict a user to specific devices?

Yes, by defining a MAC list for the user so they can connect only from those devices.

How do I make access end automatically for temporary staff?

Set an expiration date on the user record; after that date, the user can no longer authenticate over RADIUS.

Where do I monitor Office Wi-Fi connections?

From the "RADIUS Sessions" tab on the Sessions page, with user, IP, MAC, device, and traffic information.

See all questions

Making your network Law No. 5651 compliant is a one-day job.

Configure izgate Cloud based on your number of firewall devices and storage needs; no setup, get started in minutes. Call us with any questions.