SafeNet gateway box with any access point
A small Linux computer between the internet and any access point. Every SafeNet feature, with any brand of Wi-Fi.
The gateway is a small Linux computer that sits between your access point and the internet. It gives guests their addresses, shows your login page, sells packages, and opens the internet only for guests who paid. It works with any access point (TP-Link, Comfast, Tenda, Ubiquiti…) because the access point only has to broadcast Wi-Fi.
What you need
- A mini PC with two network (Ethernet) ports, for example a fanless Intel N100 "dual LAN" model. A Raspberry Pi 4/5 with a USB network adapter works for small sites.
- Ubuntu Server 24.04 (or Debian 12) installed on it, with internet during setup.
- Any Wi-Fi access point, and two network cables.
Set the mini PC's BIOS to power on after power loss ("Restore on AC power loss: Power On"), so it starts by itself after a power cut. A small UPS keeps it running through short cuts.
1. Create a gateway key in SafeNet
- Pick the siteIn SafeNet, choose the site in the top bar (or on Sites, click View on it).
- Create the keyOpen Gateways, type a name (for example "Mwenge gateway") and click Create gateway key.
- Copy it nowSafeNet shows two lines starting with
SAFENET_API_URLandSAFENET_API_KEY. Copy them somewhere safe: the key is shown only once.
2. Connect the cables
- Internet portCable from the internet router to the mini PC's first network port.
- Access point portCable from the mini PC's second network port to the access point (or its PoE adapter's LAN port).
3. Install the gateway
On the mini PC, log in and run these commands.
- Find the port names
You see names likeip -br linkenp1s0andenp2s0. The one connected to the internet router shows an address inip -br addr; the other one is the access point port. Below we useenp1s0= internet andenp2s0= access point: change them to yours. - Give the access point port its addressCreate a network file:
paste this (with your access point port name) and save:sudo nano /etc/netplan/60-safenet.yaml
then apply it:network: version: 2 ethernets: enp2s0: dhcp4: false addresses: [10.10.0.1/24]sudo chmod 600 /etc/netplan/60-safenet.yaml sudo netplan apply - Install the software
sudo apt update sudo apt install -y git nftables dnsmasq-base python3 git clone https://github.com/Kelvin-Charles/safenet.git ~/safenet sudo ~/safenet/gateway/install.sh - Enter your settings
Change these lines (use your port names and the key from step 1):sudo nano /etc/safenet-gateway/gateway.envLAN_IFS="enp2s0" WAN_IF="enp1s0" DHCP_ENABLED="yes" SAFENET_API_URL="https://radius.safezonetz.com" SAFENET_API_KEY="sgw_…your key…" - Start it, and make it start on boot
All three lines should saysudo systemctl enable --now safenet-gw-firewall safenet-gw-dns safenet-gw-portal systemctl is-active safenet-gw-firewall safenet-gw-dns safenet-gw-portalactive. In SafeNet, the Gateways page now shows the gateway as seen "just now".
4. Set up the access point
Open the access point's own setup page and set:
- Mode: Access Point (also called AP mode or bridge). Not router, WISP or repeater-router mode.
- DHCP server: off. The gateway gives guests their addresses.
- Wi-Fi: open, no password, with your Wi-Fi name. Your login page controls access.
- If it has client isolation or guest network, turn it on.
Repeaters: extra repeaters are fine, but set them to repeater / range extender mode. In router or WISP mode every guest behind them looks like they are sharing a hotspot and is blocked.
5. Test it
- Join the Wi-FiYour phone gets an address like
10.10.0.xand the login page opens. If it does not, openhttp://neverssl.com. - Log inUse a voucher from Vouchers → Generate, or buy a package. You see "You're online" and can browse.
What the gateway adds
- Hotspot-sharing block: guests can't share their connection through their own phone or laptop hotspot. Turn it on or off in Settings → Block hotspot sharing.
- One device per code, speed limits from your plans, and data usage per customer on the Live page.
- Instant disconnect from the Live page, and when you disable a voucher.
Updating the gateway
cd ~/safenet && git pull && sudo gateway/install.sh
Your settings in /etc/safenet-gateway/gateway.env are kept. Guests who are online stay online.
SafeNet Setup guides