Configuring a RADIUS server for WPA2-Enterprise authentication over a VPN tunnel requires the following:
A remote location with a Wi-Fi-enabled Ericsson Cradlepoint router (AER or IBR series) and/or wireless access points.
A main office where the RADIUS server is located.
A RADIUS server (for example: FreeRADIUS).
A VPN tunnel from the remote location to the main office. See IPsec Tunnel Configuration.