On this page

Data-Only Mobile configuration requires the Passpoint protocol. Please ensure your Ubiquiti network is using [UniFi Network Controller version 8.4.54](https://community.ui.com/releases/UniFi-Network-Application-8-4-59/d3ba4443-ad36-4566-b1e6-2d21d8b4f225) or higher and [AP firmware version 6.6.77](https://community.ui.com/releases/UniFi-Access-Point-6-6-77/1368d5eb-f4d7-4861-9eae-a317e2bebce9) or [AP firmware version 7.0.66](https://community.ui.com/releases/UniFi-Access-Point-7-0-66/edfb7cb4-c629-4e3b-a362-549eec2e0e1b) or higher, depending on hardware release track.

## Obtain RadSec Certificates

Each onboarded network requires a unique NAS-ID. For Ubiquiti networks, it is recommended to use the MAC address of the network controller as the NAS-ID.

Run the UniFi network controller locally or log into the cloud [UniFi Site Manager](https://unifi.ui.com/).

Navigate to **UniFi Devices**, choose your **Network Controller** and copy the **MAC Address**.

Use this NAS-ID in the [WiFi Conversion Onboarding](https://docs.helium.com/mobile/wifi-conversion-onboarding) flow and return to this guide after the network is onboarded and certificates have been delivered.

If updating from older RadSec certificates:

If early access certificates were previously deployed on the network, a Ubiquiti bug may prevent new certificates from propagating.

Restart all APs on the network after updating the certificates, and the new certificates should be applied.

## Configure UniFi Network Controller

After retrieving certificates, configuration is a two-part process: create the RADIUS profile, then apply it to a new WiFi SSID named **Helium**.

### Create a RADIUS Profile

Configure a TLS connection to Helium Cloud AAA server (aka Radiator), which performs Authentication, Authorization, and Accounting for the end customers. Enabling RADIUS communication over TLS (RadSec) increases the level of security for authentication that is carried out across the cloud network.

In the sidebar, choose **Settings**, then **Networks**, then scroll to the bottom to **Radius Servers**.

Click **Create New**.

Specify a profile name, for example " **Helium RadSec**".

Configure RADIUS properties:

1. Under **Radius Settings**, check the **TLS** box.
2. Click **Upload** next to **Client Certificate**, choose the path to `cert.pem`.
3. Click **Upload** next to **Private Key**, choose the path to `key.pem`. Leave the Private Key password empty.
4. Click **Upload** next to **CA Certificate**, choose the path to `ca.pem`.

5. Specify **Authentication Servers**:
   1. Enter IP Address: `52.37.147.195` Port: `2083` Shared Secret: `radsec`. Click **Add**.
   2. Enter IP Address: `44.229.62.214` Port: `2083` Shared Secret: `radsec`. Click **Add**.
   3. Enter IP Address: `44.241.107.197` Port: `2083` Shared Secret: `radsec`. Click **Add**.
6. Check the **Accounting** checkbox. RADIUS Accounting Server settings will appear.

### Workaround for greyed out Accounting checkbox

If the Accounting Servers checkbox is greyed out, create the RADIUS profile with only the Authentication Servers, save, then reopen and edit the profile to add Accounting Servers.

7. Specify the following Accounting Servers:
   1. Enter IP Address: `52.37.147.195` Port: `2083` Shared Secret: `radsec`. Click **Add**.
   2. Enter IP Address: `44.229.62.214` Port: `2083` Shared Secret: `radsec`. Click **Add**.
   3. Enter IP Address: `44.241.107.197` Port: `2083` Shared Secret: `radsec`. Click **Add**.
8. Check **Interim Update Interval** box.
9. Set **Interim Update Interval** to **300** seconds (standard for the Helium Network).

Click **Apply Changes** to create the new RADIUS profile.

### Create the Helium SSID

Navigate to **Settings** in the sidebar, choose **WiFi**, then click **Create New**.

Configure settings for the new network.

1. Set the **Name** of the SSID to `Helium`. Leave the password blank.
2. Under **Application** select **Hotspot**.
3. Under **Hotspot Type** select `Passpoint`. Passpoint settings will appear below.
4. Specify **Venue Name** to a name for your site.
5. Specify **Venue Type** with the option that best matches your site.
6. Set **Network Type** to `Chargeable Public Network`
7. Set **IP Address Type Availability**:
   - IPv4 to `Double NATed private IPv4`.
   - IPv6 to `Unavailable`
8. Add **NAI Realms** with the following two entries:
   - Name: `freedomfi.com` EAP Method: `EAP-TLS` Sub-Methods: `Certificate`.
   - Name: `hellohelium.com` EAP Method: `EAP-TLS` Sub-Methods: `Certificate`.
9. In **Domain List**, add `freedomfi.com`. Click **Add**.

10. Set **Security Protocol** to: `WPA3 Enterprise`
11. Choose **External RADIUS Profile**: **Helium RadSec**.

12. Under **_NAS ID_** Enter the NAS-ID used during Helium onboarding in the **Custom** field of **NAS-ID**.

13. Ensure **Client Device Isolation** is checked for secure networking. Click **Add WiFi Network**.

Your Helium SSID is now configured. To verify, forget the existing network on your device and connect to the new network with a device that has a supported carrier, such as [Helium Mobile](https://hellohelium.com/).

## Video Walkthrough
Unlock rewarded Cellular Traffic on your Ubiquiti Network with Helium - YouTube
