Cloud or on-premises RADIUS, set up and configured by our network engineers.
Authenticate users against the directories you already use, including SQL, Google Workspace, LDAP, Active Directory and Microsoft Entra ID.
From 802.1X, EAP and certificate-based authentication with MFA, to quotas, billing and dynamic policies with CoA.

Run RADIUS wherever it suits your network best.
RADIUS in the cloud, with no server hardware at your sites. A good fit for networks spread across many locations.
RADIUS on your own servers, so authentication and user data stay inside your network.
One place to authenticate users and devices across all your sites, access points and network equipment.
Control what each user or device can access after they connect, from one central server.
Track sessions and usage to bill subscribers, from ISP plans to paid Wi-Fi access.
Define access policies for users, groups and devices, and apply them consistently across your network.
Change a live session's policy or disconnect a user instantly with Change of Authorization (CoA), with no reconnect needed.
Set upload and download speed limits, and assign IP addresses or address pools, per user, group or plan.
Limit access by time online or data used, for example to enforce subscriber plans or fair use.
Keep detailed authentication and session logs, and report on users, sessions and usage.
Authenticate devices with digital certificates instead of passwords, for stronger, phishing-resistant security.
Require a second verification factor on top of the password for stronger protection of network access.
Give every user their own credentials on your network, instead of one shared password.
Let devices join your Wi-Fi automatically and securely, with no captive portal or manual sign-in.
The most common 802.1X methods, and others when you need them. Choose what fits your users, devices and security requirements.
Certificate-based authentication on both the client and the server. The strongest option, with no passwords to steal.
Username and password sent inside an encrypted TLS tunnel. Widely supported and easy to roll out.
Username and password inside a TLS tunnel, with flexible inner authentication methods for different directories.
Need something else? We can work with other EAP methods your devices or network require.
Authenticate users against your existing identity source, so there's no separate user database to maintain.
Integrations with SQL databases, Google Workspace, LDAP, Active Directory, Microsoft Entra ID and other identity providers.
Let users sign in to WPA-Enterprise Wi-Fi with their Google Workspace accounts. See how with FreeRADIUS and Secure LDAP
Assign VLANs and policies based on directory groups. See how with Google Workspace Secure LDAP
Don't see your directory? We can integrate with other identity sources too. Talk to us
We build and integrate RADIUS for service providers and enterprises alike.
Subscriber authentication, accounting and billing for internet service providers.
Authenticate and manage subscribers across your wireless towers and hotspots.
Secure, centralized network access for staff, guests and devices, connected to your corporate directory.
Companies all over the world are using our products and services
Common questions about our RADIUS and AAA services.
RADIUS is the standard protocol networks use for Authentication (who is connecting), Authorization (what they can access) and Accounting (what they used). Access points, switches and other network equipment send login requests to a RADIUS server, which checks them against your user directory.
Cloud RADIUS suits networks spread across many locations and avoids running server hardware. On-premises RADIUS keeps authentication and user data inside your own network. We'll help you choose based on your requirements.
SQL databases, Google Workspace, LDAP, Active Directory and Microsoft Entra ID, among others. If your directory isn't listed, get in touch: we can integrate with other identity sources too.
Yes. We support 802.1X (WPA-Enterprise), including certificate-based authentication, so users and devices connect with their own credentials instead of a shared password.
CoA lets the RADIUS server update an active session, for example to change a user's policy or disconnect them, without the user having to reconnect. It's what makes dynamic policies possible.
ISPs, WISPs and enterprises, with use cases ranging from subscriber billing to centralized authentication, policy management and Passpoint.
We support EAP-TLS for certificate-based authentication, plus PEAP and EAP-TTLS for username and password logins inside an encrypted tunnel. We can also work with other EAP methods your devices or network require, and we'll help you pick the right one.
Yes. RADIUS can enforce time and volume quotas, set bandwidth limits and assign IP addresses per user, group or plan, and CoA lets you change these on live sessions.