Translated using DeepL

Machine-translated page for increased accessibility for English questioners.

Wireless network at FI

The wireless network operates on the Wi-Fi 5 standard for the 5 GHz band and Wi-Fi 4 for the 2.4 GHz band. It also complies with several other standards designed to improve network quality. Since autumn 2019, the faculty’s Wi-Fi infrastructure has been based on UniFi AP HD access points.

Eduroam network

Usernames in the format učo@eduroam.muni.cz are no longer supported; please use učo@muni.cz.

How to connect to the eduroam network.

Eduroam (EDUcation ROAMing) is an international project supporting user mobility across academic networks. It allows users to connect to the networks of all participating organisations (primarily via Wi-Fi). See the map of covered locations.

Communication between your device and the wireless access point is secured using WPA/WPA2. The internal segment 172.27.48.0/20 is reserved for the eduroam wireless network, which is NATed to the public range 147.251.47.0/24. For IPv6, addresses are allocated from the range 2001:718:801:21b::/64. Connected devices obtain their IP address via DHCP or SLAAC. Unlike wlan_fi, there is no need to activate your device after connecting to the network.

The wlan_fi network

Once connected to the network, authentication is required for full internet access at https://wifi.fi.muni.cz or via the captive portal.

Once an IP address has been assigned, the device is only permitted access to DNS servers and tohttps://fadmin.fi.muni.cz. For full internet access, you must activate your device by accessing the URL https://wifi.fi.muni.cz using your faculty login details. Access is limited to a maximum of a few hours.

Activation is also possible via the captive portal, which redirects you to the login page for faculty authentication. If the captive portal does not appear automatically, you must open an HTTP-only page in your browser, e.g. http://neverssl.com, and you will then be redirected to the captive portal.

If it is difficult or impossible to authenticate from the device (e.g. an embedded device), you can use the script wlan_fi-auth.sh – see the comments in the introduction for instructions on how to use it.

Short-term accounts: Staff and PhD students can create short-term accounts for guests or small events (but see also the temporary network for events).

The 147.251.43.0/24 segment, or 2001:718:801:22b::/64. Connected devices obtain their IP address dynamically via DHCP or SLAAC.

In addition to being available via the Wi-Fi network with the ESSID wlan_fi, this network is also accessible in certain locations via freely accessible Ethernet cables. Once again, authentication via https://wifi.fi.muni.cz is required.

Once activated, the assigned IP address allows access to any part of the Internet outside the FI network. From the FI network’s perspective, the connected device is treated in much the same way as any other computer outside the FI network. Therefore, all FI services that you would normally use, for example, when connected via another internet service provider, should work. However, some services will not work – for example, file sharing via NFS and SMB (Windows).

The faculty firewall checks whether an activated device is still active. If it fails to respond to a ping (ICMP echo request) or an ARP query for more than 5 minutes, the activation of that IP address is revoked and the user must re-activate their address using the URL provided above.

ICMP can be enabled in Windows via the Start menu → Windows Firewall → Advanced settings → Inbound rules → File and Printer Sharing (Echo Request – ICMPv4-In). Right-click and select Enable rule. This applies to the network type you selected when connecting towlan_fi (typically Private, Public).

Firewall exception for ICMP

Users must be aware that all communication between their device and the wireless access point is vulnerable to eavesdropping; indeed, under certain circumstances, a potential attacker may be able to take over their address and thus ‘hijack’ the existing connection. It is therefore recommended to use secure, encrypted protocols for both logging in and data transfer (such as HTTPS, IMAPS, POP3S and SSH).

Temporary network for events

For small events where a representative SSID is not required, please use short-term accounts on wlan_fi, which you can set up yourself immediately.

For events expected to have more than 100 connected devices simultaneously (the number of devices may exceed the number of people), we also recommend contacting to request the setup of a separate Wi-Fi network. Please specify:

  • the network name (SSID),
  • shared password (at least 8 characters),
  • where the Wi-Fi should be available (please specify only the areas required, particularly if the event is taking place in a small part of FI; also, is access required in building S?)

Please note – if access is also required in the S building, neither the network name nor the password may contain any characters other than alphanumeric characters, an underscore and a hyphen. The assigned IP addresses are from the range172.24.0.0/20, or2001:718:801:218::/64.

Reporting issues

Providing as detailed a description of the problem as possible will greatly help to resolve it successfully. Please send your report to or, and it should include:

  • a precise description of the problem (slow speed, high packet loss, inability to connect to the network, frequent disconnections from the network, etc.),
  • the time (always specify to the nearest minute), the location within the building (if relevant) and the network name (ESSID),
  • the device’s MAC address and operating system, and, if possible, attach system logs,
  • whether the problem has been ongoing or has only recently started,
  • is the problem widespread, or does it only occur under certain circumstances?

or any other useful information.