The Portal Light LED blinks orange after installation, after a Wi-Fi network reconfiguration, or after a reboot. Orange means the Portal Light could not complete its network connection, and the number of blinks identifies which part failed.
Before you troubleshoot
A solid red LED is normal — it means the Portal Light is powering on. Allow up to 3 minutes after Wi-Fi credentials are applied before concluding anything: the Portal Light reboots and reconnects during this time, and the LED settles to green when it succeeds.
Count the orange blinks between pauses, then use the table to jump to the right check.
| Orange blinks | What failed | Go to |
|---|---|---|
| 2 | No Wi-Fi network — offline, out of range, or not broadcasting | Check 2 |
| 3 | Wrong network name (SSID) or password, or enterprise authentication | Check 1, then Check 3 |
| 4 | Connected to Wi-Fi, but no IP address from DHCP | Check 6 |
| 5 | Cannot reach the NTP time source | Check 6 |
| 6 or 7 | Cannot reach Kio Cloud — usually a firewall, or a certificate mismatch | Check 4, then Check 5 |
Important: If the LED is blinking red rather than orange, this article does not apply — a blinking red LED indicates an internal hardware issue. Submit a support request. For every LED state, see Portal Light LED status indicator guide.
Check 1: Wi-Fi credentials are incorrect (3 blinks)
Wi-Fi credentials are case-sensitive. A single incorrect character — including a capital letter, space, or special character — causes the connection to fail.
Open the Portal Light's action menu in Kio Setup Manager and tap Configure network.
-
Review the current SSID and re-enter the Wi-Fi Network SSID and Password exactly as they appear on the network.
Note: If available networks are shown, tap the target network name to populate the SSID without typing it, then enter the password carefully.
Tap Connect and wait up to 3 minutes for the LED to turn green.
If the LED turns green, the credentials were the issue.
Check 2: Wi-Fi network is not in range or not broadcasting (2 blinks)
The Portal Light may be installed too far from the access point, or the target SSID may not be broadcasting at this location.
- Open the Portal Light's action menu and tap Fetch diagnostic report.
- Review the Main network visible and Main network RSSI results.
- If Main network visible shows as not visible: the access point is out of range or the SSID is incorrect. Verify the SSID and access point placement.
- If Main network RSSI shows a weak signal (weaker than approximately −70 dBm): the signal is insufficient. Relocate the Portal Light closer to the access point or add a closer access point.
- Review Nearby networks to see all networks the Portal Light can detect. Confirm the target network appears in the list.
Check 3: Enterprise Wi-Fi requires additional setup (3 blinks)
If the network uses WPA2-Enterprise, TLS, TTLS, or PEAP authentication, standard credential entry in Kio Setup Manager is not sufficient. Enterprise networks require certificate-based or EAP authentication that must be configured with Kontakt.io support assistance.
- Confirm with your IT team whether the Wi-Fi network uses enterprise authentication.
- If it does, submit a support request before continuing. Include the network authentication type and the Portal Light's Unique ID.
Check 4: Portal Light joined Wi-Fi but cannot reach Kio Cloud (6 or 7 blinks)
The Portal Light is on the network but its outbound traffic to Kio Cloud is being blocked, most often by a firewall or network policy.
- Tap Fetch diagnostic report from the Portal Light's action menu.
- Review the API connection and Event collect connection checks.
- If these fail while Connected to Wi-Fi passes: a firewall or network policy is blocking outbound traffic to Kio Cloud.
- Contact your IT team and confirm that the Portal Light's network allows outbound HTTPS traffic to Kontakt.io cloud endpoints. Verify the Portal Light network requirements are met.
Check 5: Certificate is expired or mismatched (6 or 7 blinks)
If the device's API certificate does not match the current Kio Cloud certificate, the Portal Light cannot authenticate even with a working network connection.
- Open the Portal Light's action menu in Kio Setup Manager.
- If Update certificate appears at the top of the list, tap it and follow the prompts.
- Wait up to 3 minutes for the Portal Light to reboot and reconnect.
Check 6: No DHCP address or no NTP time source (4 or 5 blinks)
These two states are resolved by whoever administers the network, not from Kio Setup Manager.
- 4 blinks — the Portal Light joined the Wi-Fi network but received no IP address from the DHCP server.
-
5 blinks — the Portal Light cannot reach an NTP time source, so it cannot synchronize its UTC time. Port UDP 123 must be open to reach the factory-default sources (
pool.ntp.org,time.google.com).
Give your IT team or network administrator the blink count and the Portal Light's Unique ID.
If the issue persists
If the LED still blinks orange after working through the checks above, contact Kontakt.io support. Include:
- Portal Light Unique ID (from the device label or Device Management)
- Portal Light model (Portal Light, Portal Light 2, or Portal Light 2 IR)
- Wi-Fi network type (WPA2, WPA3, Enterprise, etc.)
- Results from the Fetch diagnostic report — note which checks failed
- The LED colour and, for orange, the number of blinks between pauses
If a fleet of Portal Lights is affected rather than one device, start with Troubleshooting: Portal Light network connection issues.