Enterprise AV Home WiFi Mobile Wifi Support Shop Deals

New Features and Enhancements:

  • Change of Authorization (CoA) support for RADIUS-based external captive portal authentication.
  • Option to separately enable or disable 802.11k/v protocols when the AP is managed through NETGEAR Insight. Now these protocols can be enabled irrespective of the 802.11r and band steering configuration.
  • Support for additional special characters in the device login password.
  • Enhanced logic to prevent client connectivity issues while the AP scans for neighbouring APs.
  • Blocking of IPv6 traffic for a client that is connected to a guest SSID until the client is authenticated.
  • After a captive portal session expires for a client, the client is now disconnected from the SSID so that the client can be automatically redirected to the captive portal login page.
  • Option to configure the DTIM interval, beacon interval, broadcast/multicast rate limiting, ARP proxy, and DHCP offer for broadcast traffic from NETGEAR Insight.
  • Alarms are now generated if a RADIUS server failover occurs.
    An alarm is generated if the primary RADIUS server becomes unreachable and a switchover occurs to the secondary RADIUS server or the other way around. An alarm is also raised if only a single RADIUS server is configured and the RADIUS server stops responding to the requests from the AP.
  • Load balancing alarms now include the reason a client is denied a connection to the AP.

Bug Fixes:

  • Fixes the issue where an access point (AP) that is running firmware version 9.9.4.7 and has an uptime of more than 10 days might lose connectivity to Insight or a new AP configuration on Insight might not be applied to the AP.
  • Fixes the issue where the data path is blocked for clients that are connected to a guest SSID if the session length value is not present in the RADIUS access-accept message from the external captive portal server.
  • Fixes the issue where the error message “ERR_TOO_MANY_REDIRECTS" is shown on the splash page while authenticating through an external captive portal server.
  • Fixes the issue where a client that is connected to a guest SSID might get Internet access without authentication.
  • Fixes the issue where a client that is connected to a guest SSID might access HTTPS websites without authentication.
  • Fixes the issue where the OWE Transition SSID is not broadcast for the 5 GHz radio even though the 5 GHz radio is enabled.
  • Fixes the issue where re-association alarms are not sent by the AP after roaming.
  • Fixes the issue where invalid RSSI values are shown for neighboring APs.
  • Fixes the issue where clients connected to the same SSID, and the same radio can ping each other even though client isolation is enabled.
  • Fixes the issue where the AP sends duplicate alarms on client association and re-association.
  • Fixes the issue where clients are not redirected to the splash page during captive portal authentication if the AP is configured with a non-default management VLAN.
  • Fixes various stability issues that are related to the Captive Portal feature.
  • Fixes issues that are related to system stability.

Known Issues:

  • The AP stops responding after you first change or enable an Instant Captive Portal and then change or enable a dynamic VLAN (DVLAN) configuration, or the other way around.
    Workaround: After enabling the Instant Captive Portal, wait a few minutes before you enable the DVLAN configuration. Or, after enabling the DVLAN configuration, wait a few minutes before you enable the Instant Captive Portal.
  • A MAC ACL might not work as expected when MAC randomization is enabled on a WiFi client.
    Workaround: Disable MAC randomization on the WiFi client.
  • An Instant Captive Portal does not work for clients that are connected to an SSID with OWE security. This situation might occur on an AP that is newly set up.
    Workaround: Re-apply the captive portal configuration from Insight.
  • Issues might occur with Insight Instant Mesh WiFi, causing the AP to operate on a non-optimum channel.
    Workaround: Configure the AP to use a static channel.
  • Client connectivity and throughput-related interoperability issues might occur on a WiFi device that is running a Windows, Android, or iOS version when WPA3/WPA2 Personal security is enabled on the SSID.
    Workaround: Update the WiFi device to the latest available Windows, Android, or iOS version, and update the device’s WiFi client to the latest driver.
  • Interoperability issues might occur with certain clients when band steering is enabled.
    Workaround: Disable band steering.
  • The pop-up login screen might not display for clients that are connected to an Instant Captive Portal SSID.
    Workaround: Launch a web browser and enter the URL for the captive portal authentication page in the browser’s address field. You can also open http://NeverSSL.com, but using this URL to connect to the SSID doesn’t provide encryption or good authentication.
  • After updating to a newer firmware version, the local browser user interface (UI) might not show the latest changes.
    Workaround: Clear the web browser cache.

Download Link: https://www.downloads.netgear.com/files/GDC/WAC540/WAC540_564_firmware_V9.9.5.1.zip

Firmware Update Instructions:

To update the firmware of your product, follow the instructions mentioned in the product manual. To refer the user manual, visit https://www.netgear.com/support/, enter your model number in the search box, and click the Documentation button on the product page.

Last Updated:07/07/2025 | Article ID: 000066123

This article applies to:

Recently Viewed Articles

    Our team is here to help!

    Phone
    Chat
    Email