Some smaller deployments might use SoHo suppliers like UniFi. If getgovroam is used as the user database (IdP), no RADIUS server is necessary within the deployment at the organisation. So the UniFi access points can be configured through the UniFi management server to send their RADIUS requests directly to govroam. The RADIUS traffic does not traverse the management server so the placement of the management server is not critical.

The steps below are to be followed in chronological order, since the earlier steps provide the prerequisites for the later steps.

Prerequisites

Settings > Profiles > RADIUS

image-20240927-123443.png

You will receive the IP-addresses of the govroam national roaming servers in the onboarding process. Do not enable accounting!

Settings > Networks:

image-20240927-123614.png

…where your VLAN ID is the VLAN that access is allowed to after authentication via govroam, which is usually an internet-bound guest network without web authentication portal. You could use a previously defined network that you want to use for guest access.

The VLAN ID is dependent on your choice, just like the other options on this page).

Settings > wifi:

image-20240927-123947.png

…where:

You might experiment with settings like BSS Transition, Fast Roaming and PMF but the settings above are most safe to support most clients.

For wired govroam, add: Settings > Profiles > Ethernet ports:

image-20240927-123228.png

and assign this profile to switchports that you want to protect with govroam (where the advanced settings and VLAN settings are dependent on your local situation).