Setup a 802.1X SSID
Configure a Service Area
Overview
Service Areas are locations where you need Nile connectivity-as-a-service.
Configuring a new Service Area
- Log in to the Nile Portal. In the left navigation, select Network Setup > Service Areas.
- Click the '+' sign to start adding a site.
- Name: Define the site location where you need the Nile service.
- Find my address: Enter the exact shipping address where Nile will deliver its network elements.
- Click the newly created service area and start adding all buildings within that service area. Enter the information for each building where you need the Nile service and save.
- Note: If some buildings do not have unique addresses, you can drop a pin on the map for reference.
- Click the newly defined building and add all floors in that building. Attach the floor plan to each floor.
- Optional: After adding floor plans, you can define Wi‑Fi zones on the floors if applicable. Wi‑Fi zones are custom SSID zones used to serve a specific set of clients.
Configure DHCP
Overview
A DHCP server automatically assigns IP addresses, default gateways, and other network parameters to client devices. Nile offers cloud DHCP as a service you can use immediately, or you can use your own DHCP server (e.g., Windows Server, Infoblox).
If you are using your own DHCP server, configure the DHCP relay agent in the Nile Portal.
Option 1: Nile Cloud DHCP Server
- Log in to the Nile Portal. In the left navigation, select Network Setup > DHCP.
- Click on Nile DHCP.
- Click on the '+' icon and enter the following details:
- Pool Name: Enter a name for the DHCP user subnet.
- Network: Enter the subnet
- Default Gateway: This is auto-populated once you enter the network subnet. Please keep it as is.
- Lease Time: Select the lease time. Default is 1 day.
- DNS Server: Please input the IP addresses of your DNS server. For Example: 8.8.8.8,8.8.4.4
- IP Range: Click on the '+' icon to add an IP range. Specify the Start and End IP addresses. The fields are pre-populated; modify them as required.
- The basic setup is now complete; this covers the most common configuration.
- Advanced:
- DHCP Reservation: Enter the device Hostname, MAC address, and the IP address to reserve for each device.
- Options: This section is used to configure advanced settings such as NTP server, TFTP server, DNS Server, etc.
Option 2: Bring Your Own DHCP Server
Prerequisites
- Ensure you have the IP addresses of all the DHCP servers you plan to use in your enterprise.
- The Nile Service Block (NSB) acts as a DHCP relay and sends DHCP requests from the first IP address of each subnet (for example, for the employee subnet 192.168.1.0/24, it sends from 192.168.1.1).
- Ensure your DHCP server supports Layer‑3 DHCP. Standalone servers such as Windows Server and Infoblox support this; many routers and firewalls do not. Verify support before configuring the Nile Portal.
- Ensure bidirectional routing between the DHCP server and your core router/firewall that connects to the Nile Service Gateway.
Configuring DHCP
- Log in to the Nile Portal. In the left navigation, select Network Setup > DHCP.
- Click on the '+' icon and enter the following details:
- Name: Specify the name you would like to use for the DHCP server.
- Host: You can specify all the DHCP server IP addresses here. If you have multiple DHCP servers, please specify the other IP/FQDN in the subsequent hosts.
- Geo Scope: Select the sites where this DHCP server will be used to assign IP addresses.
- Subnet: Click on the '+' sign to add a subnet. Add all applicable subnets (for example, Employee, Corporate, and IoT).
- Router: Enter the default gateway IP address for the subnet. This address is used by the Nile Relay Agent when obtaining an IP lease from the DHCP server. Ensure this IP is configured on your DHCP server as the router/default gateway DHCP option (commonly Option 3). This is typically the first usable IP in the subnet.
- Click Save to complete configuration.
Configure Authentication
Overview
Nile supports RADIUS for authentication. RADIUS (Remote Authentication Dial-In User Service) is a client-server protocol that enables remote access servers to communicate with a central server to authenticate dial-in users and authorize their access to the requested systems or services.
Prerequisites
- Ensure that you have defined the Service Areas.
- Ensure that you have the IP addresses of all RADIUS servers you plan to use in your enterprise.
- Ensure that there is a route between the RADIUS server and your core router/firewall that connects to the Nile Service Gateway.
- Identify the shared secret to be configured in the Nile Portal.
Configuring Authentication
- Log in to the Nile Portal. In the left navigation, select Network Setup > Authentication.
- Click the '+' sign under Authentication to add a RADIUS server. Configure the fields:
- Name: Enter a name for the RADIUS server.
- Port: Specify the port used by the RADIUS server.
- Geo Scope: Select the locations that will use this RADIUS server to authenticate clients.
- Host: Enter the IP address of the primary RADIUS server in Host 1. Use Host 2 and later for secondary servers (failover).
- Shared Secret: Enter the shared secret.
- Wired MAC Auth (optional): Select if the RADIUS server will authenticate wired devices using MAC Authentication Bypass (MAB).
- Guest Portal URL (optional): Enter a static URL for the RADIUS server’s guest portal. If left blank, Nile uses the dynamic URL returned by the RADIUS server.
- Click Save to complete configuration.
Configure Segments
Overview
Segments function as user-defined profiles grouping specific sets of users within an enterprise (e.g., Corporate, Guest). Each segment operates similarly to a VLAN in traditional networking and encompasses both wired and wireless devices. A single segment can extend across multiple locations or be applied enterprise-wide.
Configuring Segments
- Log in to the Nile Portal. In the left navigation, select Network Setup > Segments.
- Click on the '+' sign to create a new segment.
- Configure the following:
- General Info: Enter a name for the segment.
- Service Areas: Select one or multiple sites, buildings, or zones. For example, a Corporate segment can span all corporate sites, with each site using its own authentication method and subnet.
- Authentication: For each site, select a custom RADIUS server or the default Nile RADIUS from the dropdown. Note: Custom RADIUS servers appear only after you configure them under Authentication.
- DHCP: Select the DHCP server to use for each site.
- Subnets: For each site, select the subnets configured on the selected DHCP server from the dropdown. Typically, one subnet per segment.
- Advanced:
- Wired Self Register: Allows wired users to self‑register their devices without administrator intervention.
- Walled Garden: Define the list of URLs accessible before authentication (e.g., help pages, login portals).
- Click Save to complete configuration.
Setup Wireless - 802.1X SSID
The Nile Access Service supports industry‑standard 802.1X authentication for both wired and wireless clients. By integrating with your existing RADIUS infrastructure (e.g., Active Directory), Nile ensures only authorized users and devices can access network resources. Learn more about 802.1x - Wired & Wireless authentication in the Nile Access Service.
Configuration Steps:
- Log in to the Nile Portal. In the left navigation, select Network Setup > Wireless, click the '+' sign, and choose the Type as Enterprise.
- Name: Enter the SSID name.
- Select the Hide SSID checkbox to hide the SSID.
- Security: Select WPA2 or WPA3 or WPA3 Enhanced.
- When WPA3 is selected, enable the Backward Compatibility checkbox to allow WPA2‑only legacy clients to connect. This sets the SSID to WPA3 Transition Mode. If Backward Compatibility is not enabled, only clients that support WPA3 (128‑bit) ciphers can connect to the SSID.
- When WPA3 Enhanced is selected, only clients that support WPA3 192‑bit (Suite‑B) ciphers can connect to the SSID.
- Segments: If you have configured RADIUS authentication for a segment, it will appear in the dropdown. Select the appropriate segment for this SSID and save your changes.