User Manual
39
UniFi Controller User Guide
Ubiquiti Networks, Inc.
Chapter 3: Using the UniFi Controller Software
Access Control
Pre-Authorization Access  Enter any subnets that you 
want guests to be able to access, even if they have not 
been authenticated. Click the delete   icon to remove a 
subnet from this list.
•  Add Subnet  Click Add Subnet to add more allowed 
subnets.
Post-Authorization Restrictions  Enter any subnets that 
you don’t want guests to be able to access. Click the delete 
 icon to remove a subnet from this list.
•  Add Subnet  Click Add Subnet to add more restricted 
subnets.
Apply Changes  Click to save changes.
Reset  Click to cancel changes.
Settings > Profiles
You can use this option to create profiles for RADIUS 
authentication. RADIUS is a networking protocol providing 
centralized Authentication, Authorization, and Accounting 
(AAA) management for computer to connect to and use a 
network service.
Name  Displays the name of the RADIUS authentication 
profile.
# Servers  Displays the number of servers associated with 
this profile.
Accounting Enabled  Displays a check mark if RADIUS 
accounting is enabled or nothing if RADIUS accounting is 
not enabled..
Actions  Click a button to perform the desired action:
•  Edit  Click 
EDIT
to make changes.
•  Delete  Click 
to delete the profile. 
Add New RADIUS Profile  Click 
CREATE NEW RADIUS PROFILE
 to create a 
new RADIUS profile. The Create New Radius Profile screen 
appears.
Create New RADIUS Profile
Profile Name  Enter a name for the RADIUS profile.
VLAN Support  Use these options to configure VLAN 
support:
•  Enable RADIUS assigned VLAN for Wired 
Network  Disabled by default. 
•  Enable RADIUS assigned VLAN for Wireless 
Network  Disabled by default. 
RADIUS Auth Server  Enter information used to identify 
the RADIUS server(s):
•  IP Address  Enter the IP address of the RADIUS 
authentication server.
•  Port  Enter the port number of the RADIUS 
authentication server. The default is 1812.
•  Password/Shared Secret  Enter the password or 
shared secret (a case-sensitive text string) that will 
be used to validate communication with the RADIUS 
authentication server.
•  Add Auth Server  Click to add another RADIUS 
authentication server to the profile.
Accounting  This option is disabled by default. If you are 
using an accounting server, click Enable Accounting and 
then configure the RADIUS Accounting Server settings:
•  IP Address  Enter the IP address of the RADIUS 
accounting server.
•  Port  Enter the port number of the RADIUS accounting 
server. The default is 1813.
•  Password/Shared Secret  Enter the password or shared 
secret (a case-sensitive text string) that will be used to 
validate communication with the RADIUS accounting 
server.
•  Add Accounting Server  Click to add another RADIUS 
authentication server to the profile.
Cancel  Click to cancel your changes.
Save  Click to save the profile.










