One Decision, Three Doors
Every TP-Link Omada deployment needs a controller: the management brain that configures your access points, runs the SSIDs, and, for our purposes, operates the external captive portal handshake that makes WiFi marketing work. TP-Link gives you three ways to run that brain, and the choice shapes your costs, your failure modes, and how a cloud portal platform reaches you.
The three doors:
- A hardware controller, the OC200 or the larger OC300: a small appliance on your network
- The software controller: the same controller as free software you host yourself, on an on-site machine or a VPS
- The cloud-based controller: TP-Link hosts the controller for you, licensed per managed device
Get more WiFi marketing insights
Practical guides, case studies, and growth strategies, delivered weekly.
All three run captive portals and all three integrate with VoqadoWiFi. The differences live in operations, reachability, and money.
Door One: The OC200, the Venue Default
The OC200 is a palm-sized appliance, powered over Ethernet, managing up to 100 Omada devices, which is more than any single venue will own. You plug it in, adopt your APs, and the controller runs silently for years. The OC300 is the same idea with more capacity and headroom for larger estates.
What it gets right for a venue. It is a one-time cost at roughly the price of a mid-range access point. It keeps working through internet outages, so your staff SSID, VLANs, and network config never depend on the cloud. It has no monthly fee and no server to patch beyond occasional firmware. For a single site that wants to set and forget, this is the sane default.
The integration consideration. The OC200 lives inside your network, which means the same NAT reachability question every local controller faces: VoqadoWiFi must be able to reach its API to authorize guests. The answers are the usual ones, a source-restricted port forward or, better, an outbound tunnel; the reasoning in our Cloudflare Tunnel guide is written against UniFi but the architecture applies to any local controller, the OC200 included.
The honest caveat on outages. A local controller keeps the network alive without internet, but an external captive portal cannot authorize guests without internet, because the portal and the platform live on the cloud side. During an outage your guest WiFi is down for new guests regardless of controller choice; the OC200's resilience protects operations, not the marketing layer. Worth knowing before you buy resilience you cannot use.
Door Two: The Software Controller, Free and Yours
The Omada software controller is functionally the OC200 as an installable application, at no cost. Where you run it changes its character completely.
On-site on a spare machine: the cheapest possible start, and the most fragile. The controller inherits the reliability of whatever it runs on, and venue back offices are hard places for computers to live long, dignified lives. Acceptable for a pilot; upgrade to an appliance or a server before you depend on it.
On a VPS: this is the configuration that changes the game for multi-venue operators. One controller on a small cloud server, publicly reachable by design, one Omada site per venue, hardware at each location adopted over the internet. The reachability problem disappears entirely, VoqadoWiFi integrates against one URL with per-site scoping, and adding venue number six is an afternoon, not a shipment. We wrote the full operational playbook for this pattern on the UniFi side, one central controller on a VPS, and the architecture translates to Omada nearly line for line: sizing, port discipline, backups, staged updates.
The cost of door two is that you are now responsible for a server: updates, backups, monitoring. Small, but real, and it should be someone's actual job rather than nobody's.
Door Three: Omada Cloud, Rented Simplicity
TP-Link's cloud-based controller hosts the brain for you, with licensing per managed device per year. No appliance, no server, reachable from anywhere by design, which neatly dissolves the NAT question for portal integrations too.
Where it shines. Zero infrastructure to own, sensible for an operator with no technical appetite at all, and the reachability story is clean.
Where it costs you. The subscription scales with device count forever, so the lifetime cost crosses the OC200's one-time price surprisingly quickly for a stable single venue. You also adopt TP-Link's maintenance windows and platform pace as your own, and your controller access rides on their account system. None of these are disqualifying; they are simply rent versus buy, and venues tend to be long-lived enough that buying wins.
The Decision, Compressed
- One venue, wants to think about this never again: OC200. Solve reachability once with a tunnel, and it will outlive your lease
- Two to four venues, some technical comfort: OC200 per site is fine, but this is the point where the VPS software controller starts paying for its keep. If growth is the plan, jump early; migrations are easier with fewer sites
- Five venues and up, or an operator with an IT function: VPS software controller, one site per venue, no contest. The operational leverage compounds with every site
- No technical resource at all, and paying rent is acceptable: the cloud-based controller, eyes open about lifetime cost
Whichever door you choose, the marketing integration is the same shape: guest SSID, external portal pointed at your VoqadoWiFi portal, walled garden entries, and the authorize flow, exactly as covered in the Omada integration reference and the original Omada setup guide.
The Pattern That Tends to Emerge
Talk to enough operators and the same pattern keeps appearing: single sites default to the OC200 and stay happy on it for years; growing groups that started with per-site appliances eventually consolidate onto a VPS controller and describe the consolidation as the best operational decision of the rollout; and the cloud controller serves a real but narrow slice of operators who value zero ownership above everything else.
The controller is a means. The end is the guest data layer it enables: the portal, the consent, the visit history, the return-visit automation that turns a utility into a channel. Pick the door that matches your operational reality, and then spend your energy where the return actually lives. The portal side costs nothing to start, Starter is free forever for one location, so the controller really is the only infrastructure decision in the whole stack. Connect yours once it is running.
Share this article