SafeNet Setup guides
Guides / SafeNet gateway box

SafeNet gateway box with any access point

A small Linux computer between the internet and any access point. Every SafeNet feature, with any brand of Wi-Fi.

Guest's phone
→
Any access pointAP mode, DHCP off
→
SafeNet gatewaymini PC
→
Internet router
→
Internet

The gateway is a small Linux computer that sits between your access point and the internet. It gives guests their addresses, shows your login page, sells packages, and opens the internet only for guests who paid. It works with any access point (TP-Link, Comfast, Tenda, Ubiquiti…) because the access point only has to broadcast Wi-Fi.

What you need

Set the mini PC's BIOS to power on after power loss ("Restore on AC power loss: Power On"), so it starts by itself after a power cut. A small UPS keeps it running through short cuts.

1. Create a gateway key in SafeNet

  1. Pick the siteIn SafeNet, choose the site in the top bar (or on Sites, click View on it).
  2. Create the keyOpen Gateways, type a name (for example "Mwenge gateway") and click Create gateway key.
  3. Copy it nowSafeNet shows two lines starting with SAFENET_API_URL and SAFENET_API_KEY. Copy them somewhere safe: the key is shown only once.

2. Connect the cables

  1. Internet portCable from the internet router to the mini PC's first network port.
  2. Access point portCable from the mini PC's second network port to the access point (or its PoE adapter's LAN port).

3. Install the gateway

On the mini PC, log in and run these commands.

  1. Find the port names
    ip -br link
    You see names like enp1s0 and enp2s0. The one connected to the internet router shows an address in ip -br addr; the other one is the access point port. Below we use enp1s0 = internet and enp2s0 = access point: change them to yours.
  2. Give the access point port its addressCreate a network file:
    sudo nano /etc/netplan/60-safenet.yaml
    paste this (with your access point port name) and save:
    network:
      version: 2
      ethernets:
        enp2s0:
          dhcp4: false
          addresses: [10.10.0.1/24]
    then apply it:
    sudo chmod 600 /etc/netplan/60-safenet.yaml
    sudo netplan apply
  3. Install the software
    sudo apt update
    sudo apt install -y git nftables dnsmasq-base python3
    git clone https://github.com/Kelvin-Charles/safenet.git ~/safenet
    sudo ~/safenet/gateway/install.sh
  4. Enter your settings
    sudo nano /etc/safenet-gateway/gateway.env
    Change these lines (use your port names and the key from step 1):
    LAN_IFS="enp2s0"
    WAN_IF="enp1s0"
    DHCP_ENABLED="yes"
    SAFENET_API_URL="https://radius.safezonetz.com"
    SAFENET_API_KEY="sgw_…your key…"
  5. Start it, and make it start on boot
    sudo systemctl enable --now safenet-gw-firewall safenet-gw-dns safenet-gw-portal
    systemctl is-active safenet-gw-firewall safenet-gw-dns safenet-gw-portal
    All three lines should say active. In SafeNet, the Gateways page now shows the gateway as seen "just now".

4. Set up the access point

Open the access point's own setup page and set:

Repeaters: extra repeaters are fine, but set them to repeater / range extender mode. In router or WISP mode every guest behind them looks like they are sharing a hotspot and is blocked.

5. Test it

  1. Join the Wi-FiYour phone gets an address like 10.10.0.x and the login page opens. If it does not, open http://neverssl.com.
  2. Log inUse a voucher from Vouchers → Generate, or buy a package. You see "You're online" and can browse.

What the gateway adds

Updating the gateway

cd ~/safenet && git pull && sudo gateway/install.sh

Your settings in /etc/safenet-gateway/gateway.env are kept. Guests who are online stay online.