New: AI-powered Google Review automation is liveLearn more →
VoqadoWiFi
TP-Link Omada

Omada captive portal setup, start to finish

One controller setting, one URL and two walled garden entries turn an Omada guest SSID into a branded login page that keeps the guest email. Here is each screen, and the two mistakes that account for most failed first attempts.

Generate my Omada settingsIs my EAP model supported?
How do I set up a captive portal on TP-Link Omada?
In the Omada controller open Settings, Authentication, Portal, edit the portal bound to your guest SSID, and set the authentication type to External Portal Server. Paste your portal URL with no query string of your own, then add www.voqadowifi.com to the pre-authentication walled garden so unauthorised devices can load the page.

The six steps

  1. Open the portal settings for your guest SSID
    In the Omada controller, go to Settings, then Authentication, then Portal. Edit the portal attached to your guest SSID, or create one and bind it to that SSID.
  2. Set the authentication type to External Portal Server
    Change the authentication type from whatever it is now, usually No Authentication or Simple Password, to External Portal Server. This is what stops Omada serving its own login page.
  3. Paste the portal URL exactly as the dashboard prints it
    Enter https://www.voqadowifi.com/portal/your-venue-slug with no trailing slash and no query string of your own. Omada appends its own parameters, and a second question mark breaks the redirect.
  4. Add the walled garden entries
    Add www.voqadowifi.com and voqadowifi.com to the pre-authentication access list. Without them an unauthorised device cannot reach the portal domain, so the page never loads.
  5. Connect the controller from the VoqadoWiFi dashboard
    In the dashboard, open your location and enter the controller address and a controller login. This is the authenticated call that puts each guest device online after the form is submitted.
  6. Test on a phone that has never joined the network
    Join the guest SSID on a device with no remembered connection. The branded portal should load, and submitting the form should grant internet access within a second or two.

The two mistakes that cause almost every failure

1. A query string in the portal URL

Omada appends the client MAC, the access point MAC and the SSID to your portal URL as query parameters. If the URL you pasted already ends in a question mark and a parameter of your own, the two collide. The visible symptom is cruel: the portal loads perfectly, the guest fills in the form, and nothing happens, because the portal was never told which device to authorise. Paste the URL exactly as the dashboard prints it.

2. An empty walled garden

Before a device is authorised, Omada blocks everything. If the portal domain is not on the pre-authentication access list, the phone cannot fetch the page it is being redirected to, and the guest sees a timeout or a blank screen rather than your brand. Add both www.voqadowifi.com and voqadowifi.com.

Where the setting lives on each controller

The same option, three navigation paths
ControllerHow you reach itPath to the portal settings
Omada Cloud Controlleromada.tplinkcloud.comSettings, Authentication, Portal
OC200 or OC300The controller’s address on your LANSettings, Authentication, Portal
Software ControllerThe host machine, in a browserSettings, Authentication, Portal

The option is identically named on all three, which is unusual and helpful. What differs is only how you reach the controller in the first place.

What Omada gives you on its own, and what it does not

Built in Omada portal versus an external Social WiFi portal
CapabilityOmada on its ownWith an external portal
Show a login pageYesYes
Voucher and simple password accessYesYes, plus email sign in
Your branding beyond a logo and backgroundLimitedFull control
Keep the guest email addressNoYes, with consent recorded
Send a review request after the visitNoYes
Guest CRM with repeat visit historyNoYes
Export the list and take it elsewhereNoYes, CSV at any time

If all you need is a terms page and a password, Omada already does that and you should not add a second system. The external portal earns its place only if you intend to use the list afterwards.

Before you start

  • The guest SSID should be open, with no WPA password. A portal behind a password is a door behind a door.
  • Guest network isolation should stay on. Guests should not see each other or your point of sale.
  • Create a dedicated controller login for the integration rather than sharing your main administrator account.
  • Changing the portal setting will drop devices currently on that SSID while they reconnect. Do it outside your busiest hour.

Omada questions

Does Omada have a built in captive portal already?
Yes. Omada can show a local portal with a simple password, a voucher or a terms page. What it does not do is keep the guest email address anywhere you can use it, or send anything afterwards. That is the difference between a captive portal and Social WiFi.
Which Omada controllers work with an external portal?
All three: the cloud controller at omada.tplinkcloud.com, the OC200 and OC300 hardware controllers, and the software controller you host yourself. The External Portal Server option is in the same place on each.
Do I need to buy anything from TP-Link?
No, provided you already run Omada EAP access points and one of the three controllers. No extra licence, no additional hardware and no firmware purchase is involved.
Why does my portal load but never let anyone online?
Almost always one of two things. Either the portal URL was pasted with its own query string, which collides with the parameters Omada appends, or the controller credentials in the dashboard are wrong or lack permission to authorise clients.
Can I keep my existing SSID name and password?
Keep the SSID name. A guest SSID running a portal should be open, with no WPA password, because the portal is the access control. Guests cannot reach a login page they need a password to get to.
Is this free on Omada specifically?
Yes. The Starter plan covers one location and 500 guest logins a month at no cost and takes no card, and it does not treat Omada differently from UniFi.

Keep reading

Generate the exact settings for your controllerThree questions, then a copyable pack.Omada integration details and supported modelsWhat the integration does, rather than how to switch it on.The same walkthrough for Ubiquiti UniFiOmada or UniFi, which to buyWhat Social WiFi isWhy the email address is the point, not the login.

TP-Link and Omada are trademarks of TP-Link Technologies. VoqadoWiFi is not affiliated with, endorsed by, or sponsored by TP-Link. Controller menus change between firmware releases; if a label has moved, the setting is still under Authentication.