SafeNet Setup guides
Guides / TP-Link Omada (EAP)

TP-Link Omada access points

EAP225 and other Omada access points: plug in, point them to SafeNet, and sell internet. No extra box needed.

Guest's phone
→
Omada access pointEAP225…
→
Your internet router
→
Internet
Omada access point
⇄
SafeNetradius.safezonetz.com

Your access points connect to SafeNet over the internet. SafeNet runs the Omada Controller for you, so you set everything up inside SafeNet: no Omada account needed. When a guest pays or enters a voucher, SafeNet lets that phone online for the time they bought. Browsing goes straight from your access point to the internet; it does not pass through SafeNet.

What you need

1. Create your Wi-Fi in SafeNet

  1. Open your siteLog in to SafeNet, open Sites, click Omada next to the site, then Set up Wi-Fi access points.
  2. Name your Wi-FiType the name guests will see (for example "Zulu Connect WiFi") and click Create my Wi-Fi. SafeNet prepares everything: an open Wi-Fi with your login page.
  3. Add packagesOn the Packages page, make sure at least one package is on sale at this site (or at "All sites").

2. Prepare the access point

  1. Plug it inOn the PoE adapter: the PoE port goes to the access point, the LAN port goes to your internet router. Plug the adapter into power and wait about 2 minutes.
  2. Reset it if it was used beforeIf the access point was set up before (or added to a TP-Link cloud account), hold its Reset button for about 10 seconds with the power on, until the light flashes. Wait 3 minutes.
  3. Open its setup pageConnect your laptop or phone to the same router. Find the access point in your router's list of connected devices (usually called "EAP225" or similar) and open its address in a browser, for example https://192.168.1.33. Accept the browser's security warning.
  4. Finish its quick setupLog in with admin / admin. When asked:
    • Operation mode: AP Mode.
    • Create a username and password for the device, and write them down.
    • Leave the Wi-Fi names as they are. SafeNet replaces them.
    • If it offers to sign in with a TP-Link ID or cloud account, skip it. That would tie it to TP-Link's cloud instead of SafeNet.
  5. Point it to SafeNetOpen Controller Settings (under System or Management). Turn on Cloud-Based Controller Management (also called Controller Inform URL or Controller Hostname/IP) and enter:
    radius.safezonetz.com
    Click Save.

Setting up many access points? On a Windows laptop, TP-Link's free Omada Discovery Utility finds every access point on the network. Tick them, click Batch Setting, and enter radius.safezonetz.com as the Controller Hostname/IP.

No "Controller Settings" on the page? The firmware is too old. Download the newest firmware for your model and hardware version (printed on the label, for example "Ver: 5.0") from tp-link.com, install it under System → Firmware Update, then try again.

3. Add it in SafeNet

  1. Enter its MAC addressBack on SafeNet's Wi-Fi access points page, type the MAC address from the label (for example B8-FB-B3-79-C7-E6). If you created a username and password on the access point, enter them too. Click Add.
  2. Wait for "Online"The access point restarts once while it takes your Wi-Fi settings. After 1–3 minutes it shows Online in the list (click Refresh).

"SafeNet can't see it yet"? The access point hasn't reached SafeNet: check it has internet and that the controller address in step 2.5 is exactly radius.safezonetz.com, wait 2 minutes, and try again.

4. Test it

  1. Make a test voucherIn SafeNet open Vouchers → Generate and make one voucher for 1 hour.
  2. Join your Wi-FiOn your phone, join your new Wi-Fi name. Your SafeNet login page opens by itself. If it does not, open http://neverssl.com.
  3. Log inEnter the voucher code. You see "You're online" and can browse. The login appears on your SafeNet dashboard.
  4. Try a real paymentOpen the Buy package tab, pick a package and pay with mobile money to check payments end to end.

Adding more access points

Repeat sections 2 and 3 for each new access point. It joins the same site, broadcasts the same Wi-Fi and uses the same login page. Guests move between access points without logging in again.

Already have your own Omada Controller?

If you run your own controller (software, OC200 or OC300), you can keep it:

  1. Create a hotspot operatorIn your controller: Hotspot Manager → Operators → Create, with access to the site.
  2. Connect it in SafeNetIn SafeNet: Sites → Omada → Or use your own Omada Controller. Enter the controller address (for example https://203.0.113.5:8043), the operator name and password, then Save and test.
  3. Make it reachableSafeNet must reach your controller over the internet. If it runs on a PC or OC200 at the location, forward port 8043 on your router to it.
  4. Create the portalFollow the portal steps below in your own controller, using the portal URL SafeNet shows.

For SafeNet support: doing it by hand

SafeNet does all of this automatically. Only if the automatic setup is unavailable, support can do it in the Omada Controller (https://omada.safezonetz.com):

  1. Create the customer's siteSite menu (top left) → Add Site. Use the customer's name, country Tanzania, time zone Nairobi (UTC+3). SafeNet gets access to new sites automatically within 5 minutes.
  2. Adopt the access pointIn that site: Devices → the access point shows as Pending → Adopt. Enter the device username and password the customer set. Wait until it is Connected.
  3. Create the guest Wi-FiSettings → Wireless Networks → Create: the customer's Wi-Fi name, security None, Guest Network on.
  4. Create the portalSettings → Authentication → Portal → Create: the guest Wi-Fi, authentication type External Portal Server, and the portal URL from the customer's SafeNet Sites page (it starts with https://radius.safezonetz.com/omada/).
  5. Allow the login page before paymentIn the same area, Access Control → Pre-Authentication Access: add radius.safezonetz.com.
  6. TestJoin the Wi-Fi with a phone and log in with a voucher from the customer's account.