Disclosure: We may earn commissions from partner links on this site. This does not affect our independent editorial reviews. All opinions are our own. Full disclosure.
Foxpass WiFi Access Control: Cloud-Native RADIUS & LDAP for Modern Enterprises
Foxpass provides cloud-hosted RADIUS and LDAP by acting as a SaaS gateway that syncs identities from your cloud directory — Google Workspace, Okta, or Azure AD — and speaks standard RADIUS (RFC 2865/2866) and LDAPS protocols to WiFi controllers, VPN gateways, and servers. No on-premise RADIUS server, LDAP appliance, or Active Directory domain controller is required.
The Cloud-Native Directory Challenge
Organizations that have migrated to cloud directories (Google Workspace, Okta, Azure AD) face a persistent problem: legacy network infrastructure — WiFi access points, VPN gateways, and servers — still expects RADIUS or LDAP authentication. Maintaining an on-premise LDAP server or RADIUS appliance just for network authentication undermines the cloud-first posture. Foxpass solves this with a SaaS gateway that speaks RADIUS and LDAP to your network gear while syncing identities from your cloud directory.
Foxpass vs. Alternatives for Cloud-Native Directory & Network Access
| Feature | Foxpass | JumpCloud | FreeRADIUS + OpenLDAP | Cisco ISE | Action |
|---|---|---|---|---|---|
| Deployment Model | Cloud-native (SaaS gateway) | Cloud-native (SaaS) | Self-hosted | On-prem appliance | |
| RADIUS Support | Yes (RFC 2865/2866) | Yes (add-on) | Yes | Yes (advanced) | |
| LDAP Support | Yes (LDAPS) | Yes | Yes | Yes | |
| Cloud Directory Sync | Google Workspace, Okta, Azure AD | Google Workspace, Okta, Azure AD | Manual integration | AD integration | |
| MFA Enforcement | Yes (DUO, TOTP) | Yes (TOTP, push) | Custom scripting | Yes | |
| SSO Integration | SAML/OIDC | SAML/OIDC | Custom integration | SAML | |
| WiFi Vendor Support | Cisco Meraki, Ruckus, Aruba, Ubiquiti, Mist | Cisco Meraki, Ruckus, Aruba | All (community support) | Cisco-centric | |
| VPN Gateway Support | OpenVPN, WireGuard, Palo Alto | OpenVPN, WireGuard | All (community support) | Cisco VPN | |
| Server Auth (SSH) | Yes (SSH key + LDAP) | Yes | Yes | TACACS+ | |
| API-First Design | Yes (REST API, Terraform) | Yes | No | Limited | |
| Audit Logging | Full event log, SIEM export | Full | Self-managed | Full (Cisco ecosystem) | |
| Pricing Model | Per-user/month; free tier available | Per-user/month; higher price point | Free (infra + labor cost) | Very high (licensing + hardware) |
Key Capabilities
- Cloud RADIUS: RFC 2865/2866 compliant RADIUS server as a service. Point your WiFi controllers, VPN gateways, and switches at Foxpass — no appliance, no maintenance.
- Cloud LDAP: LDAPS directory service synced from your cloud identity provider. Use for server authentication (SSH), application authentication, or any LDAP-dependent tooling.
- Directory Sync: One-click sync from Google Workspace, Okta, or Azure AD. Groups, users, and attributes are automatically mirrored to Foxpass. No manual provisioning.
- MFA for Network Access: Enforce DUO Security or TOTP for WiFi and VPN authentication — extending modern authentication to legacy RADIUS protocols.
- API-First Architecture: Full REST API for user provisioning, group management, and event export. Terraform provider for infrastructure-as-code workflows.
- SSH Key Management: Centrally manage SSH public keys via the Foxpass dashboard or API. Revoke access instantly across all servers.
- Audit & Compliance: Every authentication request is logged with timestamp, source IP, device info, and result. Export to SIEM via syslog or REST API.
Supported Integrations
WiFi Vendors
- Cisco Meraki
- Ruckus (ARRIS/CommScope)
- Aruba (HPE)
- Ubiquiti UniFi
- Mist (Juniper)
- Aerohive / Extreme Networks
VPN Gateways
- OpenVPN (Access Server + community)
- WireGuard
- Palo Alto Networks
- Fortinet FortiGate
- pfSense / OPNsense
Identity Providers
- Google Workspace
- Okta
- Azure AD (Entra ID)
- SAML/OIDC providers
- SCIM provisioning
Use Cases
- Enterprise WiFi 802.1X: Replace PSK-based WiFi with per-user RADIUS authentication. Employees authenticate with their cloud directory credentials. Guests get time-limited, isolated access.
- VPN Authentication: Authenticate remote users against Google Workspace or Okta groups via RADIUS. Enforce MFA on VPN login. Revoke access by removing the user from the group.
- Server Access (SSH): Centrally manage SSH access to Linux servers using Foxpass LDAP + SSH key management. No more copying
authorized_keysfiles across fleets. - Cloud-First Migration: Replace on-premise FreeRADIUS + OpenLDAP with a managed cloud service. Eliminate directory server maintenance, patching, and disaster recovery.
- Compliance: Meet audit requirements for network access controls, authentication logging, and user access reviews. Full event export for SOC 2, HIPAA, and SOX audits.
How Foxpass Works
- Connect identity provider — Google Workspace, Okta, or Azure AD. Foxpass syncs users and groups automatically.
- Configure network equipment — point WiFi controllers, VPN gateways, or switches at the Foxpass RADIUS endpoint (FQDN). No inbound firewall changes needed — Foxpass initiates connections.
- Set access policies — map cloud directory groups to RADIUS VLANs, VPN routes, or SSH access levels. Guest, employee, admin tiers.
- Enforce MFA — enable DUO or TOTP for WiFi and VPN authentication. Users approve push notifications or enter TOTP codes at login.
- Monitor and audit — review authentication logs, failed attempts, and access patterns. Export to SIEM for compliance reporting.
Pricing
Foxpass offers a free tier (up to 5 users) and paid tiers starting at approximately $3/user/month for the RADIUS + LDAP plan. Per-user pricing with no minimum commitment. Volume discounts available for 100+ users. No per-device, per-access-point, or per-gateway fees.
For a comprehensive comparison of identity and access management solutions, see our full vendor comparison matrix.
Frequently Asked Questions
How does Foxpass provide cloud-hosted RADIUS and LDAP?
Foxpass acts as a SaaS gateway that speaks standard RADIUS (RFC 2865/2866) and LDAP (LDAPS) protocols to your network equipment — WiFi controllers, VPN gateways, and servers — while syncing identities from your cloud directory provider (Google Workspace, Okta, or Azure AD). No on-premise RADIUS server or LDAP appliance is required.
Does Foxpass support per-user network authentication?
Yes. Foxpass maps individual cloud directory users and groups to network access policies. Each user authenticates with their own credentials via 802.1X for WiFi, RADIUS for VPN, or SSH key + LDAP for servers.
Foxpass vs JumpCloud — which is better for cloud RADIUS and directory services?
Foxpass focuses specifically on network authentication (RADIUS, LDAP, SSH key management) with a simpler, lower-cost per-user model starting with a free tier. JumpCloud offers a broader cloud directory platform (MDM, device management, SSO) at a higher price point. For pure network access control, Foxpass is more cost-effective.
How does Foxpass help replace legacy Active Directory for WiFi and VPN?
Foxpass syncs identities from your cloud directory (Google Workspace, Okta, Azure AD) and provides RADIUS/LDAP endpoints for network gear. You can decommission on-premise AD domain controllers used solely for network authentication while retaining full 802.1X and VPN auth.