Cudy AP1300 Outdoor setup
This guide starts from the supplied screenshots: AP1300 Outdoor, firmware shown as 2.4.4-20250808-095945, External Portal Server, Manual profile, two enabled Camel Towers radio interfaces, Local Network 10.1.30.0/24, and empty UAM Server / Preferred DNS.
The AP Controller and Mesh Cudy guides describe different captive portal fields. Confirm the exact AP1300 Outdoor firmware behavior for Manual-profile UAM, RADIUS accounting, and CoA. The values below are the intended app integration, not a claim that every field has been verified on the device.
Before opening the AP page
Collect these deployment values:
- Public DNS name or fixed IP for the API/RADIUS server:
api-towers.camelcreatives.com. - Public guest portal URL:
https://wateja-towers.camelcreatives.com/uam. - A guest client network that does not overlap other LAN/VPN networks; the screenshot uses
10.1.30.0/24. - Router RADIUS source/egress IP (for API firewall allow-list).
- AP address reachable by the server for outbound CoA, if disconnect is needed.
- Random UAM and RADIUS shared secrets entered in both the server environment and the AP.
- Unique NAS ID used identically by the AP and admin Devices record.
- DNS resolver reachable by unauthenticated guest clients.
Configure General Settings → Captive Portal
The portal settings page in the admin app presents the current server values. Map the AP fields as follows, then confirm their interpretation on this firmware:
| AP field | Intended value | How to choose / verify |
|---|---|---|
| Enable | On | Enable captive portal for the guest network. |
| Interface | Guest SSID on 2.4 GHz and 5 GHz | Select only the guest interfaces that should be paid. |
| Authentication Type | External Portal Server | Sends unauthenticated browsers to the external service. |
| Local Network | 10.1.30.0/24 | Must be the actual unauthenticated client subnet and equal CUDY_LOCAL_NETWORK. Match any VLAN tagging and DHCP configuration upstream. |
| Captive Portal URL | wateja-towers.camelcreatives.com | This firmware validates a hostname here. Do not enter https:// or a path. Cudy marks this field optional; test whether the profile uses this or UAM Server for redirect. |
| Profile | Manual | Required for the intended custom portal path. |
| UAM Server | https://wateja-towers.camelcreatives.com/uam | Proposed external UAM endpoint. Cudy’s AP Controller guide reserves the field for some named profiles; verify Manual behavior on AP1300. |
| UAM Secret | Same secret as UAM_SHARED_SECRET | Only if this firmware uses it in the Manual flow. Never expose it in browser code. |
| RADIUS server 1 | api-towers.camelcreatives.com | Public API VPS hostname; UDP auth listener is port 1812. |
| RADIUS server 2 | Same host only if required | The implementation is a single server, not independent primary/backup instances. Confirm whether blank is allowed; duplicating a host gives no failover. |
| RADIUS Secret | Same value as RADIUS_SHARED_SECRET | Must match byte-for-byte, including case. |
| RADIUS NAS ID | camel-towers-ap1300-01 | Must exactly match the AP record registered in admin Devices and sent as NAS-Identifier. |
| Preferred DNS | A resolver reachable from the guest VLAN | Use the approved network resolver; ensure pre-auth DNS can resolve the portal domain. Do not assume a public resolver is reachable through this network. |
| Alternate DNS | Optional resolver | Only add if the guest network can reach it. |
| Lease time | No longer than supported access duration | AP field’s exact meaning must be confirmed. RADIUS Session-Timeout is also returned per grant. |
| CoA Port | 3799 | AP must listen for CoA at this port and accept the configured RADIUS secret. |
| UAM Allowed | wateja-towers.camelcreatives.com | Allow the portal hostname before authentication, if required by the firmware. |
| UAM Domain | wateja-towers.camelcreatives.com and api-towers.camelcreatives.com | Add the specific portal and API hostnames if this firmware uses this field for the pre-auth allow-list; verify accepted syntax. |
The example NAS ID is a placeholder. Do not copy it if you use a different ID.
Register the AP in the admin
Go to Devices → Add device and save:
- A clear name, e.g.
Towers Outdoor AP - Model
AP1300 Outdoor - AP MAC address, if helpful for inventory
- Guest local network CIDR
- UAM server URL
- Exact RADIUS NAS ID
- CoA reachable IP address and port 3799
The IP in RADIUS_CLIENT_CIDRS is the source address the AP uses when sending UDP RADIUS packets. The device’s radius_client_ip field is the destination address for server-to-AP CoA. They may differ. The admin setup requires a NAS ID and local network for the AP to count toward purchase readiness.
Guest VLAN, DNS, and firewall
- Put guest clients on the subnet configured in both Cudy and
CUDY_LOCAL_NETWORK. - Route the guest subnet to the internet through the AP/controller gateway.
- Before login, permit DHCP and DNS plus HTTPS to the guest portal hostname. If clients cannot resolve or reach the portal before auth, the purchase page cannot open.
- Allow UDP 1812 and 1813 from the AP’s observed egress IP to the VPS. Restrict with host firewall and
RADIUS_CLIENT_CIDRS. - Keep TCP 8000, PostgreSQL 5432, and internal Docker ports private.
- Ensure the VPS can send UDP 3799 to the AP address registered for CoA. If the AP cannot accept inbound traffic, establish routable VPN connectivity.
Acceptance test
Use a low-value test plan and test both bands. For each check, record AP firmware, settings, server logs, result, and timestamp:
- Join guest SSID and observe the AP redirect to the correct HTTPS guest host.
- Confirm
res,uamip,uamport,challenge, anduserurlparse as expected. - Create a test purchase and verify the phone receives the Abliner prompt.
- Approve payment and confirm one paid invoice and one unexpired access grant.
- Verify the browser returns to AP
/logonand the AP sends a RADIUS Access-Request. - Verify Access-Accept contains remaining Session-Timeout and the AP grants internet.
- Confirm Accounting-Start, one or more Interim-Updates, and Accounting-Stop appear as expected.
- Confirm expiry blocks a subsequent authentication.
- Use admin Sessions → Disconnect and verify AP sends a CoA ACK and immediately blocks the client.
- Repeat on 2.4 GHz and 5 GHz, with iOS and Android captive network behavior.
Do not mark the AP integration verified until all required checks pass. If Cudy’s firmware sends different field names, challenge formats, NAS attributes, or CoA packets, update the adapter based on captured evidence and retest.
Documentation basis
Cudy’s AP Controller captive portal guide describes External Portal Server and Manual profile fields. The Mesh guide is a different product family. Check the AP1300 Outdoor firmware downloads for the exact hardware version. The app’s UAM flow follows the CoovaChilli hotspotlogin example .