New Features and Enhancements:
- Change of Authorization (CoA) support for RADIUS-based external captive portal authentication.
- Option to separately enable or disable 802.11k/v protocols when the AP is managed through NETGEAR Insight. Now these protocols can be enabled irrespective of the 802.11r and band steering configuration.
- Support for additional special characters in the device login password.
- Enhanced logic to prevent client connectivity issues while the AP scans for neighbouring APs.
- Blocking of IPv6 traffic for a client that is connected to a guest SSID until the client is authenticated.
- After a captive portal session expires for a client, the client is now disconnected from the SSID so that the client can be automatically redirected to the captive portal login page.
- Option to configure the DTIM interval, beacon interval, broadcast/multicast rate limiting, ARP proxy, and DHCP offer for broadcast traffic from NETGEAR Insight.
- Alarms are now generated if a RADIUS server failover occurs.
An alarm is generated if the primary RADIUS server becomes unreachable and a switchover occurs to the secondary RADIUS server or the other way around. An alarm is also raised if only a single RADIUS server is configured and the RADIUS server stops responding to the requests from the AP. - Load balancing alarms now include the reason a client is denied a connection to the AP.
Bug Fixes:
- Fixes the issue where an access point (AP) that is running firmware version 9.9.4.7 and has an uptime of more than 10 days might lose connectivity to Insight or a new AP configuration on Insight might not be applied to the AP.
- Fixes the issue where the data path is blocked for clients that are connected to a guest SSID if the session length value is not present in the RADIUS access-accept message from the external captive portal server.
- Fixes the issue where the error message “ERR_TOO_MANY_REDIRECTS" is shown on the splash page while authenticating through an external captive portal server.
- Fixes the issue where a client that is connected to a guest SSID might get Internet access without authentication.
- Fixes the issue where a client that is connected to a guest SSID might access HTTPS websites without authentication.
- Fixes the issue where the OWE Transition SSID is not broadcast for the 5 GHz radio even though the 5 GHz radio is enabled.
- Fixes the issue where re-association alarms are not sent by the AP after roaming.
- Fixes the issue where invalid RSSI values are shown for neighboring APs.
- Fixes the issue where clients connected to the same SSID, and the same radio can ping each other even though client isolation is enabled.
- Fixes the issue where the AP sends duplicate alarms on client association and re-association.
- Fixes the issue where clients are not redirected to the splash page during captive portal authentication if the AP is configured with a non-default management VLAN.
- Fixes various stability issues that are related to the Captive Portal feature.
- Fixes issues that are related to system stability.
Known Issues:
- The AP stops responding after you first change or enable an Instant Captive Portal and then change or enable a dynamic VLAN (DVLAN) configuration, or the other way around.
Workaround: After enabling the Instant Captive Portal, wait a few minutes before you enable the DVLAN configuration. Or, after enabling the DVLAN configuration, wait a few minutes before you enable the Instant Captive Portal. - A MAC ACL might not work as expected when MAC randomization is enabled on a WiFi client.
Workaround: Disable MAC randomization on the WiFi client. - An Instant Captive Portal does not work for clients that are connected to an SSID with OWE security. This situation might occur on an AP that is newly set up.
Workaround: Re-apply the captive portal configuration from Insight. - Issues might occur with Insight Instant Mesh WiFi, causing the AP to operate on a non-optimum channel.
Workaround: Configure the AP to use a static channel. - Client connectivity and throughput-related interoperability issues might occur on a WiFi device that is running a Windows, Android, or iOS version when WPA3/WPA2 Personal security is enabled on the SSID.
Workaround: Update the WiFi device to the latest available Windows, Android, or iOS version, and update the device’s WiFi client to the latest driver. - Interoperability issues might occur with certain clients when band steering is enabled.
Workaround: Disable band steering. - The pop-up login screen might not display for clients that are connected to an Instant Captive Portal SSID.
Workaround: Launch a web browser and enter the URL for the captive portal authentication page in the browser’s address field. You can also open http://NeverSSL.com, but using this URL to connect to the SSID doesn’t provide encryption or good authentication. - After updating to a newer firmware version, the local browser user interface (UI) might not show the latest changes.
Workaround: Clear the web browser cache.
Download Link: https://www.downloads.netgear.com/files/GDC/WAC505/WAC505_510_firmware_V9.9.5.1.zip
Firmware Update Instructions:
To update the firmware of your product, follow the instructions mentioned in the product manual. To refer the user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.