Orion Setup Guide
Ubiquiti UniFi APs
Orion uses Passpoint to auto-connect users to your network. Passpoint requires UniFi Network version 8.4.54 or higher, and AP firmware 6.6.75 / 7.0.63 or higher. Ensure your UniFi system is updated before proceeding.
Download and extract your RadSec Certificate Bundle (radsec.zip) from the Orion Supply portal. See our Help Center for instructions.
The radsec.zip archive should contain 3 important files (among other unused files):
File Name | File Purpose |
cert.pem | Client Certificate |
key.pem | Private Key |
cacerts/bw.radsec.cacerts.pem | CA Certificate |
You'll need these files when creating your RADIUS profile in UniFi.
Log into the UniFi cloud at https://unifi.ui.com/
Select your Site under Site Manager and ensure you are in the Network application:
Orion provides two RADIUS over TLS (RadSec) servers for your use. These servers will handle all authentication, authorization and accounting (AAA) for users connecting to your Orion SSID.
As a first step, you'll create a RADIUS server profile for these endpoints. You can then use this profile when creating the Orion SSID.
In the sidebar, choose Settings > Profiles > RADIUS:
Click Create New. A form to create your new RADIUS profile will appear.
Give the profile a Name, such as Orion-AAA.
RADIUS Assigned VLAN Support should be unchecked by default (wired and wireless).
Under RADIUS Settings:
Click Apply Changes to create your new RADIUS Profile.
Next you'll create a dedicated WPA2-Enterprise SSID for Orion:
In the sidebar, click Settings > WiFi.
Add a new Wi-Fi network named Orion.
Set Hotspot 2.0 to Passpoint.
(If you do not see the Passpoint option, check your AP and Network versions)
In the Passpoint fields that appear:
Next we'll add the RADIUS parameters. This includes selecting the RADIUS profile we created earlier, and setting your NAS ID properly.
IMPORTANT: Orion automatically names your Networks based on their NAS ID. You should use one unique NAS ID for each unique Orion Network you operate. |
Scroll down to the Security and RADIUS section:
Click Add WiFi Network.
Your APs should now broadcast the Orion SSID. Proceed to Test your Orion Network and qualify for more traffic.