40 makes and models, from a £60 router in a café to a controller running a resort. No box to buy from us, no approved shopping list, no rip-and-replace. Find yours below and read exactly what it does before you commit to anything.
Holding a guest at a sign-in page, and asking somebody else whether to let them in, is something Wi-Fi equipment has been able to do for twenty years. Airports, airlines and hotel chains have all been using it that whole time. We are the "somebody else" — which is why this works on equipment that was fitted long before we existed.
A phone joining your Wi-Fi is kept in a waiting room until somebody says otherwise. Instead of showing a page of its own, your equipment is told to show ours — carrying your logo, your colours and your welcome message.
The guest signs in, and your equipment checks the answer with us before letting anybody onto the internet. The reply carries their speed, their time limit and how many devices they may bring, so those are enforced by the equipment rather than promised on a page.
This is the one that separates the list below into two halves. Some equipment can be told to end a session already in progress — which is what makes a checkout at eleven actually mean something. Some cannot, and on those, access ends at the guest's time limit instead.
Every make in the list does the first two. Each page says plainly whether it does the third, because that is a decision worth making before you buy rather than discovering afterwards.
Supported does not mean somebody once got it working. It means there is a page for that make, and your console fills it in with your property's own details.
When you add a router or controller in your console, it produces the instructions for that exact device — your sign-in page address, your credentials, your settings. Nobody copies a value out of a manual, and nobody types a password twice.
Short, ordered, in the words that appear on that make's screens — and a troubleshooting table of what a symptom usually means, because captive portals mostly fail in ways that do not name their cause.
Where a make cannot do something, the page says so in the place your installer will look, rather than leaving your front desk to find out from a complaint.
Setting the equipment up is a service we offer, on any make in this list. For a site with nobody technical, that is usually the right answer.
We do not sell hardware and we take nothing from anybody who does. The advice you get on equipment is the advice we would give a friend.
Almost all Wi-Fi equipment speaks the same sign-in pattern, so adding a make is usually straightforward rather than a rebuild. Tell us what you have.
Two groups, split by the one thing that actually differs: whether a checkout can take a guest offline immediately. Everything in both groups gets your branded sign-in page, every way in you have switched on, and speed, time and device limits that are enforced.
23 makes. A departure at the front desk takes that guest offline there and then.
| Equipment | How it reaches us | Worth knowing |
|---|---|---|
| Alcatel-Lucent OmniAccess Stellar | Private link | Full feature set over a private link. UPAM has to be pointed at us rather than at its own guest list. |
| Arista Cognitive WiFi (formerly Mojo) | Private link | Full feature set over a private link, for both management generations — newer cloud-hosted sites may qualify for a more direct connection. |
| Aruba Central (AOS-10) | Direct, encrypted | Full feature set, configured entirely in Central — and the strongest checkout story on this list, with no private link needed. |
| Aruba controller (ArubaOS 8) | Direct, encrypted | Full feature set, over the controller's own encrypted connection, which is present across the whole 8.x line. |
| Aruba Instant (IAP) | Direct, encrypted | Full feature set. Configure the cluster, not an individual access point. |
| Cambium cnPilot | Private link | Full feature set over a private link — for a property that already has this hardware; it is not current for a new purchase. |
| Cisco Catalyst 9800 | Private link | Full feature set. The checks travel through a private link rather than the controller's own encryption. |
| Cisco Meraki MR access points | Your vendor's cloud reaches us | Set up in the Meraki dashboard. Full feature set, including checkout cut-off — with no private link needed at all. |
| Cisco WLC (AireOS) | Private link | Full feature set over a private link — but the software line is frozen, so treat this as what an existing site already has, not what to buy. |
| ExtremeCloud IQ Controller | Direct, encrypted | Full feature set, for the on-premises controller line specifically — see the note below if the property's equipment is older Aerohive gear. |
| Fortinet FortiGate | Direct, encrypted | Full feature set. Needs FortiOS 7.4 for the secure direct connection. |
| Juniper Mist | We authorise each guest | Full feature set, configured entirely in the Mist cloud — with no private link needed, because the Mist cloud is always reachable. |
| MikroTik (RouterOS) | Direct, encrypted | Everything, on inexpensive hardware. The usual answer for a site being built from scratch. |
| MikroTik hAP or cAP — one box for a small site | Direct, encrypted | One box does the lot. The cheapest way to get every feature into a site with no equipment cupboard. |
| Netgear WAC (standalone) | Private link | The one standalone access point that keeps checkout cut-off. Needs firmware 9.9.5.1, and it is a discontinued line — see below. |
| Nomadix EG gateway | Private link | Full feature set over a private link, for the current EG line. The older AG series is discontinued — see below. |
| OpenWrt with CoovaChilli | Private link | Full feature set over a private link. Use the maker's own page where there is one. |
| OpenWrt with openNDS | The router checks in with us | Full feature set, and the lightest setup on this list: nothing has to reach the router for a guest to get online. Lighter usage records than CoovaChilli. |
| Peplink and Pepwave | Private link | Full feature set over a private link. Put the sign-in page on the Balance where there is one. |
| Ruckus SmartZone | Direct, encrypted | Full feature set. Needs SmartZone 5.1.2 for the secure direct connection. |
| Ruckus Unleashed and ZoneDirector | Private link | Full feature set over a private link. A property on SmartZone should use that instead. |
| Teltonika RUT and RUTX | Private link | Full feature set over a private link. Common on mobile connections and temporary networks. |
| Ubiquiti UniFi | We authorise each guest | Full feature set. We let each guest on by speaking to your controller directly, so we have to be able to reach it. |
17 makes. At checkout we stop the guest signing in again, and the session they already hold runs to its time limit. Set sessions in hours rather than days — on a café, a bar or a restaurant this rarely matters at all.
| Equipment | How it reaches us | Worth knowing |
|---|---|---|
| ANTlabs IG (formerly InnGate) | Private link | A hospitality appliance, usually already linked to the front desk. The vendor does not document checkout cut-off, so it is tested with a real phone during setup. |
| Aruba Instant On | Private link | Branded sign-in and enforced limits. Checkout does not cut a session short. |
| Cisco Business Wireless (CBW) | Private link | Branded sign-in and enforced limits. Checkout does not cut a session short. |
| Cisco Meraki MX | Your vendor's cloud reaches us | Good answer for wired guest access, including hotel room sockets. Checkout does not cut a session short, and usage is not recorded either. |
| D-Link Nuclias | Private link | Branded sign-in and enforced limits. Sold heavily into small hotels on price. |
| DrayTek Vigor | Private link | A reasonable one-box answer for a small site. Checkout does not cut a session short. |
| EnGenius Cloud | Private link | Branded sign-in and enforced limits. Checkout does not cut a session short. Does not cover the older EWS/ezMaster platform — see below. |
| Grandstream GWN | Private link | Branded sign-in and enforced limits. Checkout does not cut a session short. |
| LANCOM Public Spot | Private link | Branded sign-in and enforced limits. The Public Spot option has to be licensed, and checkout cut-off is tested with a real phone during setup. |
| pfSense and OPNsense | Private link | Branded sign-in and enforced limits. Checkout does not cut a session short on either. |
| Ruijie Reyee | Private link | Needs an EG gateway in the path — access points alone cannot do it. Checkout cut-off is tested with a real phone during setup. |
| Tanaza (TanazaOS) | Private link | Brings a cupboard of mixed access points onto one platform. Checkout does not cut a session short. |
| TP-Link EAP (standalone) | Private link | Fine for one or two access points. Above that, fit an Omada controller instead. |
| TP-Link Omada | Private link | Branded sign-in and enforced limits, configured once on the controller. Checkout cut-off is new on current controllers, so it is tested with a real phone during setup. |
| WatchGuard Cloud access points | Private link | Branded sign-in and enforced limits, on WatchGuard's current cloud-managed access points specifically. Checkout does not cut a session short. |
| Zyxel Nebula | Private link | Branded sign-in and enforced limits, on the Professional Pack licence tier. Checkout does not cut a session short. |
| Zyxel without Nebula (USG FLEX) | Private link | The firewall runs the sign-in page, not the access points. Checkout does not cut a session short. |
A short list, and worth reading before you assume. If your equipment is here, the honest answer is one small box in front of it rather than a setting we have not found yet.
Genuinely — that is usually all it takes. We will tell you which page above is yours, what it will and will not do at your property, and whether anything needs changing before you commit to anything.