Wireless network at FI
The wireless network operates on the Wi-Fi 5 standard for the 5 GHz band and Wi-Fi 4 for the 2.4 GHz band. It also complies with several other standards aimed at improving network quality . The Faculty’s Wi-Fi infrastructure is based on UniFi AP HD access points.
The eduroam network
How to connect to the eduroam network .
Eduroam (EDUcation ROAMing) is an international project supporting user mobility across academic networks. It allows users to connect to the networks of all participating organisations (primarily via Wi-Fi). See the map of covered locations.
Communication between your device and the wireless access point is secured using WPA/WPA2. The internal segment 172.27.48.0/20, which is NATed to the public range 147.251.47.0/24. For IPv6, addresses are allocated from the range 2001:718:801:21b::/64. Connected devices obtain their IP address via DHCP or SLAAC. Unlike wlan_fi, there is no need to activate your device after connecting to the network.
The wlan_fi network
Once connected to the network, authentication is required at https://wifi.fi.muni.cz or via the captive portal to gain full internet access.
Once an IP address has been assigned, the device is only permitted to access DNS servers
andhttps://fadmin.fi.muni.cz. For full internet access, you must
activate your device by accessing the URL https://wifi.fi.muni.cz using your
faculty login details.
Access is limited to a maximum of a few hours.
Activation is also possible via the captive portal, which redirects you to the login page for faculty authentication. If the captive portal does not appear automatically, you must open an HTTP-only page in your browser, e.g. http://neverssl.com, and you will then be redirected to the captive portal.
If it is difficult or impossible to authenticate from the device (e.g. an embedded device),
you can use this script wlan_fi-auth.sh
– see the comments in the introduction for instructions on how to use it.
Short-term accounts: Staff and PhD students can create short-term accounts for guests or smaller events (but see also the temporary network for events).
The segment 147.251.43.0/24, or 2001:718:801:22b::/64. Connected devices obtain their IP address dynamically via DHCP or SLAAC.
In addition to being available via the Wi-Fi network with the ESSID ‘wlan_fi’, this network is also accessible in some locations via freely accessible Ethernet cables. Once again, authentication via https://wifi.fi.muni.cz is required.
Once activated, the assigned IP address allows access to any part of the Internet outside the FI network. From the FI network’s perspective, the connected device is treated in much the same way as any other computer outside the FI network. Therefore, all FI services that you can use, for example, when connected via another internet service provider, should work. However, some services will not work – for example, file sharing via NFS and SMB (Windows).
The faculty firewall checks whether an activated device is still active. If it does not respond to a ping (ICMP echo request) or an ARP query for more than 5 minutes, the activation of that IP address is revoked and the user must re-activate their address using the URL provided above.
ICMP can be enabled in Windows via the Start menu → Windows Firewall
→ Advanced settings → Inbound rules → File and Printer Sharing (Echo
request – ICMPv4-In). Right-click and select ‘Enable rule’. This applies to
whichever network type you selected when connecting towlan_fi (typically Private,
Public).

Users must be aware that all communication between their device and the wireless access point can be intercepted; indeed, a potential attacker may, under certain circumstances, take over their address and thereby ‘hijack’ the existing connection. It is therefore recommended to use secure, encrypted protocols for both logging in and data transfer (such as HTTPS, IMAPS, POP3S and SSH).
Temporary network for events
For small events where a representative SSID is not required, please use short-term accounts on wlan_fi, which you can set up yourself immediately.
For events expected to have more than 100 connected devices simultaneously (the number of devices may exceed the number of people), we also recommend contacting to request the setup of a separate Wi-Fi network. Please specify:
- the network name (SSID),
- shared password (at least 8 characters),
- where the Wi-Fi should be available (please specify only the areas required, particularly if the event is taking place in a small section of FI; also, is access required in building S?)
Please note – if access is required in building S as well, neither the network name nor the password
may contain any characters other than alphanumeric characters, an exclamation mark, an at sign, an underscore and
a hyphen. The assigned IP addresses are from the range172.24.0.0/20 or
2001:718:801:218::/64.
Reporting issues
Providing as accurate a description of the problem as possible will greatly assist in resolving it successfully. Please send your report to or, and it should include:
- a precise description of the problem (slow speed, high packet loss, inability to connect to the network, frequent disconnections from the network, etc.),
- the time (always state to the nearest minute), the location within the building (if relevant) and the network name (ESSID),
- the device’s MAC address and operating system, and, if possible, attach system logs,
- whether the problem has been ongoing or has only recently started,
- is the problem widespread, or does it only occur under certain circumstances?
or any other useful information.