Cudy AP1300 Outdoor setup

This guide starts from the supplied screenshots: AP1300 Outdoor, firmware shown as 2.4.4-20250808-095945, External Portal Server, Manual profile, two enabled Camel Towers radio interfaces, Local Network 10.1.30.0/24, and empty UAM Server / Preferred DNS.

Cudy AP and server network pathsDNS sends public hostnames to the VPS. Caddy routes HTTPS to the matching web service. RADIUS travels over UDP from AP to server and CoA returns to the AP.AP1300 OutdoorGuest VLAN / subnetCudy CoovaChilliPublic DNSapi-towerswateja-towersCaddy on VPSTCP 80 / 443TLS terminationGo APIHTTPS API + webhookUDP RADIUS 1812 / 1813Guest portalwateja-towers/uamAdmin + docstowers · docs-towersDNS + HTTPSweb trafficapi hostguest hostadmin / docs hostsUDP 1812 / 1813outbound CoA UDP 3799
Do not take payments based on a copied field list

The AP Controller and Mesh Cudy guides describe different captive portal fields. Confirm the exact AP1300 Outdoor firmware behavior for Manual-profile UAM, RADIUS accounting, and CoA. The values below are the intended app integration, not a claim that every field has been verified on the device.

Before opening the AP page

Collect these deployment values:

  1. Public DNS name or fixed IP for the API/RADIUS server: api-towers.camelcreatives.com.
  2. Public guest portal URL: https://wateja-towers.camelcreatives.com/uam.
  3. A guest client network that does not overlap other LAN/VPN networks; the screenshot uses 10.1.30.0/24.
  4. Router RADIUS source/egress IP (for API firewall allow-list).
  5. AP address reachable by the server for outbound CoA, if disconnect is needed.
  6. Random UAM and RADIUS shared secrets entered in both the server environment and the AP.
  7. Unique NAS ID used identically by the AP and admin Devices record.
  8. DNS resolver reachable by unauthenticated guest clients.

Configure General Settings → Captive Portal

The portal settings page in the admin app presents the current server values. Map the AP fields as follows, then confirm their interpretation on this firmware:

AP fieldIntended valueHow to choose / verify
EnableOnEnable captive portal for the guest network.
InterfaceGuest SSID on 2.4 GHz and 5 GHzSelect only the guest interfaces that should be paid.
Authentication TypeExternal Portal ServerSends unauthenticated browsers to the external service.
Local Network10.1.30.0/24Must be the actual unauthenticated client subnet and equal CUDY_LOCAL_NETWORK. Match any VLAN tagging and DHCP configuration upstream.
Captive Portal URLwateja-towers.camelcreatives.comThis firmware validates a hostname here. Do not enter https:// or a path. Cudy marks this field optional; test whether the profile uses this or UAM Server for redirect.
ProfileManualRequired for the intended custom portal path.
UAM Serverhttps://wateja-towers.camelcreatives.com/uamProposed external UAM endpoint. Cudy’s AP Controller guide reserves the field for some named profiles; verify Manual behavior on AP1300.
UAM SecretSame secret as UAM_SHARED_SECRETOnly if this firmware uses it in the Manual flow. Never expose it in browser code.
RADIUS server 1api-towers.camelcreatives.comPublic API VPS hostname; UDP auth listener is port 1812.
RADIUS server 2Same host only if requiredThe implementation is a single server, not independent primary/backup instances. Confirm whether blank is allowed; duplicating a host gives no failover.
RADIUS SecretSame value as RADIUS_SHARED_SECRETMust match byte-for-byte, including case.
RADIUS NAS IDcamel-towers-ap1300-01Must exactly match the AP record registered in admin Devices and sent as NAS-Identifier.
Preferred DNSA resolver reachable from the guest VLANUse the approved network resolver; ensure pre-auth DNS can resolve the portal domain. Do not assume a public resolver is reachable through this network.
Alternate DNSOptional resolverOnly add if the guest network can reach it.
Lease timeNo longer than supported access durationAP field’s exact meaning must be confirmed. RADIUS Session-Timeout is also returned per grant.
CoA Port3799AP must listen for CoA at this port and accept the configured RADIUS secret.
UAM Allowedwateja-towers.camelcreatives.comAllow the portal hostname before authentication, if required by the firmware.
UAM Domainwateja-towers.camelcreatives.com and api-towers.camelcreatives.comAdd the specific portal and API hostnames if this firmware uses this field for the pre-auth allow-list; verify accepted syntax.

The example NAS ID is a placeholder. Do not copy it if you use a different ID.

Register the AP in the admin

Go to Devices → Add device and save:

The IP in RADIUS_CLIENT_CIDRS is the source address the AP uses when sending UDP RADIUS packets. The device’s radius_client_ip field is the destination address for server-to-AP CoA. They may differ. The admin setup requires a NAS ID and local network for the AP to count toward purchase readiness.

Guest VLAN, DNS, and firewall

Acceptance test

Use a low-value test plan and test both bands. For each check, record AP firmware, settings, server logs, result, and timestamp:

  1. Join guest SSID and observe the AP redirect to the correct HTTPS guest host.
  2. Confirm res, uamip, uamport, challenge, and userurl parse as expected.
  3. Create a test purchase and verify the phone receives the Abliner prompt.
  4. Approve payment and confirm one paid invoice and one unexpired access grant.
  5. Verify the browser returns to AP /logon and the AP sends a RADIUS Access-Request.
  6. Verify Access-Accept contains remaining Session-Timeout and the AP grants internet.
  7. Confirm Accounting-Start, one or more Interim-Updates, and Accounting-Stop appear as expected.
  8. Confirm expiry blocks a subsequent authentication.
  9. Use admin Sessions → Disconnect and verify AP sends a CoA ACK and immediately blocks the client.
  10. Repeat on 2.4 GHz and 5 GHz, with iOS and Android captive network behavior.

Do not mark the AP integration verified until all required checks pass. If Cudy’s firmware sends different field names, challenge formats, NAS attributes, or CoA packets, update the adapter based on captured evidence and retest.

Documentation basis

Cudy’s AP Controller captive portal guide  describes External Portal Server and Manual profile fields. The Mesh guide  is a different product family. Check the AP1300 Outdoor firmware downloads  for the exact hardware version. The app’s UAM flow follows the CoovaChilli hotspotlogin example .