Caravan and holiday parks: holidaymakers on the portal, staff on EAP-TLS, a personal WiFi key per owner
Owners keep a private network all season on a key that is theirs. Holidaymakers sign in on the portal, staff authenticate with EAP-TLS, and the park's tills, barriers and cameras get MAC-bound keys apart from everyone else.
- 80,000+ venues in 90 countries
- 500 million logins a year
- 99.9% RADIUS uptime SLA
- 99.999% uptime
Who is on the caravan and holiday parks network
Who is on the park network, and the lane each one gets
Owners' holiday homes each get a private network for the season, holidaymakers use the portal, and point-of-sale devices, barriers and cameras sit on locked-down keys.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Holidaymakers | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Park management, reception and maintenance staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| caravan and lodge owners | xPSK | Individual key, MAC-bound (a private network for the season) | An owner VLAN per key set, apart from holidaymakers and from each other | Runs for the season, revoked alone if the plot is sold |
| On-site shop, bar, restaurant and leisure operators | xPSK | Individual key, MAC-bound | A network per business: its own VLAN and key set | Revoked when the lease ends, one business at a time |
| Park tills and card terminals | xPSK | Individual key, MAC-bound | A payments VLAN, apart from guests and owners | One key per device, rotated or revoked alone |
| Barriers, gates, CCTV and metering | xPSK | Individual key, MAC-bound | A site-systems VLAN, unreachable from owners and guests | Keyed at install, revoked at decommissioning |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Caravan and holiday parks: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Holidaymakers and seasonal staff: portal and onboarding lane
The public lane for people who stay a week, and the BYOD lane for seasonal staff on their own phones.
- Holidaymakers on the portal. SSO, Google, Apple, Facebook or SMS with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller.
- Seasonal staff with no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android.
Park management and reception: EAP-TLS
One WPA-Enterprise SSID for the park's own managed devices. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Reception and maintenance by group. Entra ID, Okta or Google Workspace over SAML and SCIM. A leaver is disabled once and every site of a multi-park group stops authenticating them.
Owners, businesses and park systems: a key each
An owner's smart TV and a barrier controller will never hold a certificate. A key per owner or device on one SSID gives each its own VLAN and its own end date.
- A private network per owner, all season. Each caravan or lodge owner gets a key set that works for the season, so their TV, speaker and laptop find each other and the next plot's never appear.
- On-site businesses in their own networks. A key set and VLAN per shop, bar or leisure operator, apart from owners, guests and the park's own systems.
- tills, barriers and cameras on locked-down keys. Each device on a MAC-bound key and a device VLAN, so an owner's phone never reaches the barrier controller or the payments VLAN.
Lifecycle
Key lifecycle: season start, place, operate, season end
The owners' register and season dates are the system of record, and a key lasts as long as its agreement.
Issue from the owners' register
At season start import the register and each owner gets a key set with the season's end date. Park devices are keyed at install.
Place each owner on its own VLAN
RADIUS returns the VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Owners, businesses and park systems land on separate lanes.
Operate one log across the park
Every accept and reject carries the plot, the business or the device and the reason, so "my TV will not connect" is a lookup on the log and not a drive round the loop road.
End one owner at plot sale or season end
A plot that is sold has its key revoked alone and nobody else is touched, with RADIUS CoA ending the live session on access points that support it. Season keys stop on the end date.
One authentication log
One authentication log across the whole park
Owners, guests, businesses and park systems share one log, so a site manager sees what is online and where without walking the pitches.
- Which plots' owners are connected, and on which access point.
- Which park systems are online, and on which VLAN.
- Which tills authenticated today, and which were rejected and why.
Audit
Park tills apart from owners and guests: what the assessor tests
The shop, bar and reception take cards on the park's access points. Purple never touches card data, and segmentation gives the assessor a VLAN map and log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, and not every till on the park.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
A platform proven at 80,000+ venues
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points on the park?
No. Purple Access is a cloud overlay on the access points your park already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
How does an owner's smart TV or speaker, with no portal, get on?
To the device its key is an ordinary WPA2-Personal passphrase, so there is no portal and no supplicant. The key is MAC-bound where the device has a fixed MAC and held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Are owners kept apart from each other and from holidaymakers?
Yes. Each key set returns its own VLAN or role from RADIUS and client isolation is on, so owners, holidaymakers and the park's tills are separate lanes.
What happens to access when a plot is sold?
Revoke that owner's keys and only that owner is affected, because each key is its own entry in RADIUS. The new owner is issued fresh keys.
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Book a demo: we issue and revoke a key on a live network
Bring one loop road's worth of lanes: an owner's TV, a bar till, a barrier controller and a holidaymaker's phone. We issue each a key, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.