City networks: portal for the public, OpenRoaming for returners, a personal WiFi key per household or device
Free public WiFi on the captive portal, returning residents and students on a Passpoint profile, staff on EAP-TLS, and scheme households, high-street businesses, CCTV and sensors each on a MAC-bound key and VLAN.
- World's first city-wide OpenRoaming network
- £0 cost to Newcastle City Council
- 1,000 SMEs on the city network
- 53,000+ students
Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.
Who is on the local government network
Who connects across a city, and where each one lands
A city network serves three audiences that share nothing: the public, who must connect in one tap, residents in a digital inclusion scheme, who need a key of their own, and civic devices, which share a lane with neither. OpenRoaming carries returning users, so the portal is for first contact.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Residents and visitors connecting for the first time | Open | Captive portal sign-in, consent recorded (SSO, social or SMS) | Public VLAN, client isolation on | Consent recorded at sign-in, then the session times out |
| Staff and volunteers on personal phones | Open | Purple app onboarding, certificate installed, no MDM (directory account) | Onboarding lane, then the group VLAN | Ends with the directory account |
| Returning residents and students | Secure | Passpoint or OpenRoaming profile | Public VLAN, no portal on return | Profile installed once, valid across the city's hotspots |
| Staff on managed laptops | Secure | EAP-TLS, certificate from your MDM over SCEP (from your MDM) | VLAN or role by directory group | Account disabled once, and RADIUS CoA ends the session |
| Households in a digital inclusion scheme | xPSK | Individual key, MAC-bound (issued by the scheme) | A household VLAN, a bandwidth limit per key | Ends when the household leaves the scheme |
| High-street businesses, one network each | xPSK | Individual key, MAC-bound (a key set per business) | A VLAN per business, with its own limit | Keys added and withdrawn per device |
| CCTV, signage and environmental sensors | xPSK | Individual key, MAC-bound | A device VLAN, unreachable from the public | One key per device, revoked when replaced |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Local government: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
The public: one portal across every site
The open network is the front door of a municipal network, for everyone who has never connected.
- Free public WiFi on the captive portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
- One portal across a mixed access point estate. Buildings, libraries and street cabinets rarely share a vendor. The portal and RADIUS sit above all of them.
- Staff and volunteers on their own phones. One sign-in in the Purple app with a work account installs a pass on Windows, macOS, Linux, iOS and Android, with no MDM.
Returning users and staff: OpenRoaming and EAP-TLS
Passpoint turns the first sign-in into a profile, so the second visit needs no portal. Staff use certificates on the same secure SSID.
- OpenRoaming across the city. Newcastle runs the world's first city-wide OpenRoaming network, and its students roam between campus, city and trams. OpenRoaming is free through the Connect licence.
- EAP-TLS for staff from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Directory groups decide the VLAN. Entra ID, Okta or Google Workspace over SAML and SCIM. Department and role map to a VLAN, and a leaver is disabled once for every site.
Households, businesses and sensors: a key each
Everything that is not a person on a laptop gets an individual key on one SSID. To the device it is an ordinary WPA2-Personal passphrase.
- Digital inclusion scheme households. Issued from the console, a branded self-service portal or the Purple API, each key carries its own VLAN and bandwidth limit.
- High-street businesses, one network each. A VLAN and a key set per business on shared access points: its tills and printers see each other and nobody else's.
- CCTV, signage and smart city sensors. A key per device, bound to its MAC, in a device VLAN the public cannot reach. Replace a camera and you revoke one key.
Lifecycle
Key lifecycle: enrol, place, operate, withdraw
The same four moves serve a scheme household and a street camera, tied to the scheme's household list and your asset register.
Issue from the scheme list or the asset register
A household's key is created when the scheme enrols it. Cameras and sensors are keyed on installation, from the console, a bulk list or the Purple API, each bound to a MAC.
Place on a VLAN by audience
RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, so the public lane never reaches the camera lane.
Operate from one log across every site
Every accept and reject carries its reason, by resident, member of staff and device, streamed to Sentinel, Splunk, Elastic or Datadog.
End one device, one household or one business
Withdraw a key and that device drops alone, with RADIUS CoA ending the live session. A household that leaves the scheme takes only its own keys.
One authentication log
One authentication log across every site
Public sign-ins, staff certificates, scheme keys and street devices land in one log, so an elected member's question and an auditor's request get the same answer.
- How many first-time, returning and scheme connections landed on each network this week.
- Which cameras and sensors are on the network, and on which VLAN.
- Which staff accounts were rejected, by which method, and why.
- Which scheme keys are live, and which households have left the scheme.
Audit
Assurance across sites: what the log evidences
Public bodies answer to auditors and elected members. Purple holds ISO 27001 and Cyber Essentials Plus, and the log is evidence for your own controls.
ISO 27001
Every accept and reject is logged with its reason and streamed to your SIEM, as evidence for access control and logging controls.Cyber Essentials
User access control is one of the five controls. The directory decides who is on which VLAN, and the log shows who was and why.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
Newcastle, the world's first city-wide OpenRoaming network
Newcastle City Council runs it on Purple, used by 1,000 SMEs and by students roaming between campus, city and trams.
- 1st
- city-wide OpenRoaming network in the world, in Newcastle
- £0
- cost to Newcastle City Council
- 1,000
- SMEs on the Newcastle city network
- 53,000+
- students roaming between campus, city and trams in Newcastle
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Does OpenRoaming replace the captive portal?
No. The portal is first contact for anyone who has never connected. A Passpoint profile installed at that first sign-in lets the same person rejoin across the city with no portal, on the secure network.
How does a household in a digital inclusion scheme get its key?
Scheme staff issue it from the console, a branded self-service portal or the Purple API. The key is bound to the household's device by MAC, carries its own VLAN and bandwidth limit, and ends when the household leaves the scheme. Every other household stays connected.
How do high-street businesses each get their own network on one set of access points?
One SSID carries a VLAN and a key set per business. Each business's tills and printers see each other and nobody else's, and your gateway enforces any rule that lets them reach a shared service. There is no per-SSID key ceiling.
Do we need new access points?
No. Purple Access is a cloud overlay on the access points your sites and street cabinets already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
What evidence do we get for assurance?
Every accept and reject is logged with its reason and streamed to your SIEM, as evidence for ISO 27001 access control and logging controls. Purple holds ISO 27001 and Cyber Essentials Plus.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring one site's worth of everything: a public sign-in, a staff laptop, a scheme household and a street camera. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.