How-To: Connect Your Ruckus Unleashed Network to Keytos Shield

Learn how to securely connect your Ruckus Unleashed network to Keytos Shield using Cloud RADIUS.

Ruckus APs can operate in Unleashed mode or in controller-based mode. This guide focuses on Ruckus Unleashed, which is Ruckus’s controller-less WiFi solution for small to medium-sized businesses. For more information on setting up RADIUS with Ruckus in controller-based mode, refer to Ruckus’s official documentation such as the SmartZone docs or Ruckus cloud docs.

Overview - How to Protect Your Ruckus Unleashed Network with Cloud RADIUS

Having a single Wi-Fi password for your network is a security nightmare. It’s impossible to know who has access to your network, and it’s nearly impossible to change the password regularly without causing major outages. The best way to secure your Ruckus Unleashed network is to use WPA-Enterprise with either certificates or individual user accounts for authentication.

To protect your Ruckus Unleashed network using certificates or Entra ID accounts, you will need a RADIUS server to handle authentication requests. Keytos Shield includes a cloud-based RADIUS-as-a-Service that integrates directly with Entra ID to provide secure authentication for your Ruckus Unleashed network without needing to manage any RADIUS servers or infrastructure. Simply add Keytos Shield as a RADIUS server in your Ruckus Unleashed Controller, and your users can log in using either passwordless certificates or their Entra ID username and password.

Prerequisites for Setting Up Cloud RADIUS for Ruckus Unleashed

The first step to getting started with Keytos Shield is to create a subscription. This will allow you to access the Keytos Shield portal and begin onboarding your users and devices.

How to Install Keytos Shield and Create a Subscription

It's free to get started and there's no sales call or credit card required

Keytos Shield uses native Entra ID authentication to provide a seamless passwordless experience for your users. Begin by registering the Keytos Shield Entra ID application using the link below. Make sure to use your Global Administrator account (or forward the link to your Global Administrator) to complete the consent process.

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.com/organizations/adminconsent?client_id=2963e596-88f5-43a1-ab17-68b8026c6468&redirect_uri=https://portal.keytos.io/Welcome

You will see a consent screen similar to the one below. Click Accept to register the applications in your tenant.

Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

Single Click

The easiest way to register the applications is to click the button below while logged in with your Global Administrator account:

Register Keytos Applications

Manual URL

Alternately, you can copy & paste the following URL into your browser. Make sure you are logged in with your Global Administrator account before accessing the link.

https://login.microsoftonline.us/organizations/adminconsent?client_id=2cf07322-0273-4052-bd9b-e38c1c433803&redirect_uri=https://portal.keytos.us/Welcome
Keytos Shield uses native Entra ID authentication as shown in the admin consent screen

For more information on these specific permissions and why they are needed, please refer to the Keytos Shield FAQs.

Collapses this section and completes the checkmark.

How to Create Your Keytos Shield Subscription

A Keytos Shield subscription handles permissions, billing, and central configuration for your organization. You can create a subscription directly with us, or through the Azure Marketplace. Both options provide a 1-month free trial, and you can cancel at any time.

To create a Keytos Shield subscription directly through the Shield portal, follow these steps:

  1. Open the Keytos Shield portal in your browser. (US Government Portal).

  2. Under Subscription Name, enter a friendly name for your subscription. (you can always change this later)

  3. Select a Deployment Location for your subscription. This will be your primary region where your Keytos Shield resources will be hosted.

  4. Optionally enter your credit card information. You can click Skip for now if you just want to try out Keytos Shield for free for 1 month and add a payment method later.

    • If you are managed by a MSP or reseller, the credit card form will not be shown, and you can proceed with creating your subscription without entering any payment information.
  5. Check the Terms & Conditions box to agree to the terms of service.

  6. Click Register to create your subscription. It should complete in just a few seconds.

    Get started with a Keytos Shield free trial subscription
  7. You should now see your newly created Keytos Shield subscription endpoint listed under Existing subscriptions:

    Keytos Global Get Endpoint in Existing Subscriptions

We are finishing up our Azure Marketplace review with Microsoft and will have our documentation available soon. In the meantime, please deploy your Keytos Shield subscription directly through the Shield portal.

Collapses this section and completes the checkmark.

Now that you have created a Keytos Shield subscription, you can proceed to onboard your environment to Shield using the onboarding guide.

How to Configure Shield via the Onboarding Guide

The Shield onboarding guide will walk you through the steps to onboard your environment to Shield

It’s easy to get started with the interactive onboarding guide within Keytos Shield. Follow these steps to onboard your environment and configure your network security settings.

  1. Open the Keytos Shield global portal in your browser. (US Government Portal). Make sure to sign in with the same account used to create your Keytos Shield subscription.

  2. Under Existing subscriptions you’ll see your region-specific Keytos Shield endpoint. Open it to access the onboarding guide and start configuring your network security settings.

    Keytos Global Get Endpoint
  3. You should automatically be redirected to the network security onboarding guide on first login. If not, you can manually navigate to it from the left-hand nav bar under Onboarding:

    Onboarding Section

Collapses this section and completes the checkmark.

How To Register the Keytos Entra ID Application (already completed)

Since you have already completed this earlier, the step should be marked as completed. If there was an issue with the consent, refer to Step 1 above to re-consent the application using your global administrator account.

Register the Keytos Entra ID Application

Collapses this section and completes the checkmark.

How To Configure Your Infrastructure and PKI Environment

In step 2, you’ll answer a few questions about your environment and how you want to configure your PKI and MDM settings.

How to Set Up Your PKI in Keytos Shield

Keytos Shield includes a Cloud PKI which will issue your SCEP certificates. If you only have cloud resources and no on-premises PKI, you can rely solely on the Cloud PKI for certificate issuance. If you have an existing on-premises PKI, you can integrate it with Keytos Shield to chain your Shield SCEP CA up to your existing Root CA.

  1. What type of environment do you have?

    • Select Hybrid infrastructure if you have an on-premises Active Directory environment and/or an existing PKI environment that you want to integrate with Keytos Shield.

    • Select Cloud only if you have a cloud-only environment and do not have an on-premises Active Directory or PKI infrastructure. You won’t be asked any further questions about on-premises PKI integration.

      Select Environment Type
  2. Will you use Windows Hello for Business for on-premises resources?

    • Select Yes if you have a hybrid environment and want to use Windows Hello for Business and certificates issued by Keytos Shield to authenticate to your on-premises resources.

    • Select No if you do not plan to use Windows Hello for Business for your on-premises resources.

      Windows Hello for Business
  3. Do you have an existing on-premises PKI?

    • Select Yes if you have an existing on-premises PKI environment and want to integrate it with Keytos Shield.

    • Select No if you do not have an existing on-premises PKI environment or do not want to integrate it with Keytos Shield.

      Existing PKI
  4. Will you use your existing Root CA as your Root CA?

    • Select Yes if you have an existing Root CA and want the certificates issued by Keytos Shield to chain up to it.

    • Select No if you want to use Shield’s Root CA instead of chaining up to your existing Root CA.

      Chain to Root CA
  5. Bring your own Root CA - If you selected Yes to the previous question, follow these steps to bring your own Root CA:

    1. Download the CSR from Keytos Shield.
    2. Submit the CSR to your existing Root CA to generate a certificate.
    3. Once you have the certificate, upload it to Keytos Shield, along with the Root CA certificate.
    Chain to On-Prem Root CA
  6. Which MDMs do you use to manage your devices?

    • Select any Mobile Device Management (MDM) solutions that you use to manage your devices. This will help Keytos Shield configure your SCEP CA correctly to be able to issue certificates via your MDM. You can always add more MDMs later if needed from the Network profiles page.

      Select Your MDMs
  7. Mark as Complete

    • Click Mark as Complete to save your settings and continue to the next step.

Collapses this section and completes the checkmark.

How to Configure Your Shield Network Profile

A Shield network profile defines how your network connects to Shield via RADIUS and/or RadSec. In this step you’ll configure how you plan to connect your network to Keytos Shield.

How to Configure Your Network Profile Basics
  1. Under Network profile name, enter a friendly name for your network profile, such as “Office Network” or “Headquarters”.

    Network Profile Name
  2. Select if you want to use RADIUS or RadSec for network authentication.

How to Configure RADIUS or RadSec

Based on your choice of RADIUS or RadSec, you will need to follow the specific configuration steps for that authentication method. Use the tabs below to view the instructions for each option.

Classic RADIUS is a great option if you want a straightforward and widely supported method for network authentication and you plan to do certificate-based authentication or Entra ID username & password authentication.

  1. Under Add IP addresses, click My IP or manually enter the public IP address for your network that will be sending RADIUS requests to Keytos Shield.

  2. Click Add to save the IP address to your network profile.

  3. Repeat for all your public IP addresses, including any backup IP addresses you may have for redundancy.

    Enter Classic RADIUS IPs

While RadSec is more complex to configure than Classic RADIUS, it is compatible with dynamic IP addresses and offers better security for legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 if you plan to use them on your network.

Note: Make sure your network equipment supports RadSec. If it does not, you will need to use Classic RADIUS instead, or run a local proxy within your network that protects your RADIUS traffic inside an encrypted tunnel (useful if you’re using unencrypted protocols like PAP or MS-CHAPv2).

  1. Under Authorized certificate authorities > Certificate source, select where the certificate authority for your RadSec connection is located. Some APs, such as Meraki, come pre-configured with their own certificate authorities, while others like Unifi require you to provide your own certificate authority.

    • Shield: Select this option if you want to use the certificate authority provided by Keytos Shield to issue RadSec certificates for your network.

    • EZCA: Select this option if you want to use an existing EZCA certificate authority for your RadSec certificates.

    • Local CA: Select this option if you want to use a 3rd party certificate authority for your RadSec certificates.

      Select RadSec Trusted Certificate Authority
  2. (optional) Authorized certificate thumbprints: If you want to trust individual RadSec certificates based on their thumbprints, expand this section and upload your self-signed or third-party certificates.

    Network Profile RadSec Trusted Certificate

Want to protect your legacy authentication protocols like PAP, PEAP, and MS-CHAPv2 but can’t use RadSec? Or want to increase availability + reduce latency for your authentication requests? Running a local server within your network can help achieve these goals.

Keytos Shield comes with a free local RADIUS/RadSec server that you can optionally run within your network to handle authentication requests locally, providing an additional layer of security and control over your network authentication.

To set up a local RADIUS server, first set up RADIUS or RadSec as your primary authentication here in the onboarding flow, and then visit our guide on adding a local Shield RADIUS server to complete the setup.

How to Configure Network Profile Assignment and Optional Settings

Now that you have configured RADIUS or RadSec, the final steps are to choose what users and/or devices will be assigned to this network profile and configure any optional settings.

  1. For Authentication type, select the appropriate option for your network.

    • Device: Select this option if you want to authenticate individual devices on your network.

    • User: Select this option if you want to authenticate users on your network.

      Authentication Certificate Type

    Note: Want to use both? Select your primary authentication type here and complete the onboarding guide, and you can add additional authentication types in the Network profiles page later.

  2. For Profile assignment, either keep Assign to all licenses users selected, or uncheck it and choose the Entra ID user(s) and/or group(s) that you want to assign this network profile to.

    Network Profile Assign Profile
  3. Optionally enable Enable MAC authentication bypass if you want devices to bypass authentication based on their MAC address.

    • If you have a small set of MAC addresses, manually enter them and click Add.

    • If you have a large set of MAC addresses, check the box for Bulk upload addresses and upload a CSV file containing the MAC addresses.

      Network Profile MAC Authentication Bypass
  4. Click Save RADIUS Server to save your network profile and proceed with the configuration.

Collapses this section and completes the checkmark.

How To Add Your Wi-Fi Networks

Now that you have configured your RADIUS server, the next step is to add your Wi-Fi networks to Keytos Shield.

  1. Enter your Wi-Fi network basics:

    • Wi-Fi network name (SSID) - Add your SSID name here. This is case sensitive, so make sure to enter it exactly as it is configured on your network.

    • Wi-Fi encryption - Select the encryption type that matches your Wi-Fi network configuration.

    • Hidden SSID - If your SSID is hidden, enable this option.

    • Connect automatically when in range - Choose if you want your device to connect automatically when in range or not.

      Wi-Fi Network Basics
  2. Select if you want to Enable Keytos Connect for BYOD devices. This allows BYOD devices to connect via the Keytos Connect app without the need for an MDM solution. If you centrally managing your devices via an MDM solution, you can leave this option disabled.

    • If enabled, you can select if all licensed users can connect to this network, or only specific users/groups.

      Enable Keytos Connect
  3. Click Save Wi-Fi network to save your Wi-Fi network configuration and continue to the next step.

Collapses this section and completes the checkmark.

Here is where you will connect your Ruckus Unleashed to Keytos Shield. Follow the instructions below to complete the network connection process.

Collapses this section and completes the checkmark.

Step-by-Step Guide to Setting Up Cloud RADIUS for Ruckus Unleashed

The following steps will guide you through the process of setting up Cloud RADIUS for your Ruckus Unleashed network using Keytos Shield.

How to Add Keytos Shield as a RADIUS Server in Ruckus Unleashed

Now that you have your Keytos Shield subscription and access policy set up, you can add Keytos Shield as a RADIUS server in your Ruckus Unleashed Controller.

How to Add a Cloud RADIUS Server to Ruckus Unleashed

  1. Begin by logging into your Ruckus Unleashed admin interface. You can do this by entering the IP address of your Ruckus Unleashed device into a web browser and logging in with your admin credentials.

  2. Under Services, navigate to Authentication Servers.

    Ruckus Unleashed Authentication Settings
  3. Click on Add to create a new RADIUS server entry.

    Add RADIUS Server in Ruckus Unleashed
  4. Fill in the RADIUS server basics:

    • Name: Enter a name for your RADIUS server (e.g., “Keytos Shield”).
    • Type: Select RADIUS.
    • Encryption: Leave TLS unchecked for classic RADIUS.
    • Auth Method: Select PAP.
    • Backup RADIUS: Check the box for Enable Backup RADIUS support, as Keytos Shield provides multiple servers for redundancy.

How to Get Your RADIUS Server IP Addresses in Keytos Shield for Ruckus Unleashed RADIUS

The Keytos Shield RADIUS IP addresses are needed for your network controller to communicate with Keytos Shield. You can get them from the onboarding guide or from the network policies page.

If you’re currently going through the onboarding guide, you can find the Keytos Shield RADIUS IP addresses in step 5, Connect your network. Copy one IP from each region, starting with the closest to you.

Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

If you’ve already gone through the onboarding guide previously, you can find the Keytos Shield RADIUS IP addresses directly from the network profiles page.

  1. Navigate to the Keytos Shield Network Policies page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. Copy one of the IP address from the region closest to your network controller (you’ll add the others later).

    Keytos Shield Network Policies with the RADIUS Server IP Addresses highlighted

How to Add Keytos Shield RADIUS Servers IP Addresses in Ruckus Unleashed

  1. Back in your Ruckus Unleashed admin interface, fill in the details for the First Server:
    • IP Address: Paste the RADIUS server IP address you copied from the Keytos Shield portal.
    • Port: Leave as default (1812).

How to Get Your Keytos Shield Shared Secret for Ruckus Unleashed RADIUS

When you added your public IP address to your Keytos Shield policy, a shared secret was automatically generated for you. This shared secret is used to authenticate your network controller (RADIUS client) to the Keytos Shield server.

In step 5, Connect your network, of the Keytos Shield network security onboarding guide the Keytos Shield shared secrets are listed for each IP. Reveal and copy the value from your IP address.

Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted
  1. In the Keytos Shield portal, navigate to the Keytos Shield Network Profiles page from the left-hand menu.

  2. At the top of the page, select the Settings tab.

    Keytos Shield Network Policies with the Settings tab highlighted
  3. Scroll down to the bottom of the page and expand the Network Equipment section.

  4. For your public IP addresses, click the Copy button under the Shared secret column.

    Keytos Shield Network Policies with the Classic RADIUS Shared secret highlighted

How to Complete Adding Keytos Shield RADIUS Servers in Ruckus Unleashed

  1. Under Shared Secret, paste the shared secret you copied from the Keytos Shield portal.
  2. Set Confirm Secret to the same shared secret.

How to Configure Additional RADIUS Server Settings in Ruckus Unleashed

  1. For the Second Server, repeat the previous step using another geography from the Keytos Shield portal for redundancy.

    Ruckus Unleashed RADIUS Server Details Form
  2. Under Retry Policy, set the following:

    • Retry Timeout: Set to the highest value of 20 seconds to account for the round-trip time to the Keytos Shield servers.

    • Max Number of Retries: Set to 5 to ensure multiple attempts before failing over to the backup server.

    • Max Number of Consecutive Drop Packets: Set to 5 to allow for some packet loss without immediately failing the authentication.

    • Reconnect Primary: Set to 5 minutes to allow the system to attempt to reconnect to the primary server periodically.

      Ruckus Unleashed RADIUS Retry Policy Settings
  3. Click Add to save the RADIUS server configuration.

    Ruckus Unleashed RADIUS Servers List

How to Add RADIUS Accounting Servers in Ruckus Unleashed

  1. To set up RADIUS Accounting, click Add again.

    Add RADIUS Accounting Server in Ruckus Unleashed
  2. Repeat the previous steps to add the same RADIUS servers for accounting.

    • Name: Enter a name for your RADIUS accounting server (e.g., “Keytos Shield Accounting”).
    • Type: Select RADIUS Accounting.
    • Encryption: Leave TLS unchecked.
    • Backup RADIUS: Check the box for Enable Backup RADIUS Accounting support.
    • Fill in the First Server and Second Server details as before, but use port 1813 for accounting.
    • Set the Request Timeout to 20 seconds.
    • Set the Max Number of Retries to 5.
    • Set the Max Number of Consecutive Drop Packets to 5.
    • Set the Reconnect Primary to 5 minutes.
  3. Click Add to save the RADIUS accounting server configuration.

  4. You should now see both your RADIUS Servers and Accounting Servers listed.

    Ruckus Unleashed dashboard with RADIUS Servers and Accounting Servers configured

How to Add a RADIUS Server to a Ruckus Unleashed Network

Now that you have added Keytos Shield as a RADIUS server within Ruckus Unleashed, you can add it to your network so that when users connect to that network, they will be authenticated via Keytos Shield.

How to Add RADIUS to a Ruckus Unleashed Wi-Fi Network

  1. Under the Wi-Fi menu, navigate to Wi-Fi Networks List.

    Ruckus Unleashed Wi-Fi Networks
  2. Select your SSID and click Edit.

    Ruckus Unleashed Wi-Fi Networks List with Edit button highlighted
  3. Fill in the following Network Details:

    • Authentication Method: Select 802.1X EAP from the dropdown menu.

    • Encryption Method: Select your desired encryption method (WPA2, WPA3, or WPA2/WPA3 Mixed).

    • Authentication Server: Select the RADIUS server you created earlier from the dropdown menu.

    • Accounting Server: Select the RADIUS accounting server you created earlier from the dropdown menu.

    • Send Interim-Update: Keep this as the default value of 10 minutes.

      Ruckus Unleashed Wi-Fi Network Authentication Settings
  4. Click Apply to save the SSID configuration.

  5. Done! You’ve successfully configured RADIUS authentication in your Ruckus Unleashed network using Entra ID via Keytos Shield.

    Ruckus Unleashed Wi-Fi Networks List showing updated SSID