Before you change anything
- Confirm the correct venue
- Keep current settings handy
- Test with one device first
Connect Ubiquiti UniFi to WeefyBox
Prerequisites
- UniFi Network application or UniFi OS console
- A separate guest WiFi network
- A local, least-privilege controller account
- A controller address reachable from WeefyBox
Setup
- In WeefyBox, select the venue, open Setup, and choose UniFi Network.
- Copy the Portal URL and walled-garden domains.
- In UniFi Network, open Settings > WiFi and edit the guest SSID.
- Enable Hotspot Portal and choose External Portal Server.
- Paste the WeefyBox Portal URL exactly.
- Open Settings > Hotspot > Pre-Authorization Access.
- Add each WeefyBox walled-garden domain on its own line.
- Disable UniFi's branded/default portal for this SSID.
- Keep Client Device Isolation enabled; it does not block WeefyBox.
- Create a local controller account for WeefyBox. Do not use a UI.com SSO-only account.
- Enter the controller URL, account, site ID, and console type in WeefyBox.
- Keep TLS verification enabled. Disable it only for a known self-signed local certificate.
- Select Save credentials, then Test my setup.
- Join the guest SSID with a phone and complete the portal.
- Confirm a successful result in Setup > Portal debugger.
Controller behind NAT? Publish it through a restricted VPN/reverse tunnel or use an installer-managed endpoint. Never expose the full controller UI with a weak password.
Troubleshooting
| Symptom | Check |
|---|---|
| Splash never appears | Guest SSID has Hotspot Portal enabled; Portal URL is exact; DNS works |
| Splash works but no internet | Local account permissions, controller reachability, site ID, controller clock |
| iPhone works but Android fails | Allow connectivitycheck.gstatic.com, clients3.google.com, and www.gstatic.com |
| Returning guests sign up again | Keep Private WiFi Address set to fixed/stable; do not clear captive-browser data |
| Controller unreachable | Check firewall/VPN, HTTPS port, TLS certificate, and NAT forwarding |