UniFi Cloud Gateway captive portal setup
Cloud Gateways are the small UniFi OS consoles many single venues now start with. They behave like the UDM family for the integration. The thing that catches groups is the site name: every one of them calls its site default.
www.voqadowifi.com, and allow www.voqadowifi.com and voqadowifi.com in Pre-Authorization Access. Give the gateway a reachable HTTPS address, save it in the dashboard with a local admin and site default, and register each access point MAC if another venue also uses default.At a glance
- Runs
- UniFi OS
- Login and API prefix
/api/auth/login, then/proxy/network- Usual site id
default- Shared site name risk
- Yes, solved by registering access point MACs
- Reachability
- Port forward 443 or an outbound tunnel
Checked against the VoqadoWiFi integration code on 7 October 2026. Controller menu labels move between firmware releases; the setting names above are the ones the setup wizard prints.
Step by step
- Create or open the guest SSID and turn on the hotspot portalIn Settings, WiFi, use a dedicated open guest SSID and switch on the hotspot or guest portal for it.
- Point the external portal server at VoqadoWiFiIn the hotspot settings choose External Portal Server and enter the host
www.voqadowifi.com. UniFi always sends guests to the fixed path/guest/s/<site>/on that host, which is how VoqadoWiFi knows which venue they are at. If your Network version asks for an IP address, switch on Redirect using hostname and enter the host there instead. - Add the pre-authorization entries and leave HTTPS redirection offAdd
www.voqadowifi.comandvoqadowifi.comto Pre-Authorization Access. If your version shows an HTTPS Redirection toggle, leave it off: intercepting HTTPS is what produces certificate warnings on guest phones. - Create a local admin for the integrationUnder Admins and Users add an account restricted to local access, with access to the Network application and no two factor prompt. A ui.com cloud account cannot log in to the controller API, and a two factor challenge fails every automated login.
- Give the gateway a reachable addressThe gateway is usually also your edge router, so a DDNS hostname with TCP 443 forwarded to it works when your provider gives you a public address. Behind carrier grade NAT, use an outbound tunnel instead.
- Save it in the dashboard and register the access pointsEnter the address with no port, the local admin, Console Type Auto-detect, and site
default. Then add the MAC of every access point at the venue to the location’s AP MAC field, separated by commas.
What breaks on this controller
Two venues both on default
When more than one active venue uses the same UniFi site name, VoqadoWiFi matches the ap MAC in the redirect against each venue’s registered access points. If none match, it falls back to the oldest venue, and your guests see someone else’s portal. Register the MACs.
A new access point added later
An access point added after setup is not in the AP MAC list. If the site name is shared, guests on that access point can land on the wrong venue’s portal until you add it.
Carrier grade NAT
Many small venues sit behind carrier grade NAT, where forwarding a port does nothing. Test Connection reports a timeout. An outbound tunnel is the fix.
Questions
Is a Cloud Gateway handled differently from a UDM Pro?
What if I only have one venue?
Can I run the portal without exposing the gateway?
Deeper reading
Longer articles from the blog that cover this controller. Where an article and this page disagree, this page is the one checked against the current integration.
- UDM Pro guest WiFi portal guide. Covers the Cloud Gateway line too; same UniFi OS rules.
- Exposing a UniFi controller with Cloudflare Tunnel
- Access point placement for venues
Keep reading
Sources: lib/unifi/api.ts and app/guest/s/[site]/route.ts (ambiguity guard), read on the date above. Ubiquiti and UniFi are trademarks of Ubiquiti Inc. VoqadoWiFi is not affiliated with or endorsed by either vendor.
Run your UniFi portal free
One location and 25 guest logins a month on the Starter plan, no card. The dashboard prints the finished portal URL for this controller.