Marinas: visitors on the portal, staff on EAP-TLS, a personal WiFi key per berth holder and tenant
Annual berth holders get a private network that lasts the year. Chandlery, fuel dock and restaurant tenants each land on their own VLAN, visiting skippers sign in on the portal, and the marina's own staff sit on EAP-TLS.
- 80,000+ venues in 90 countries
- 500 million logins a year
- 99.9% RADIUS uptime SLA
- 99.999% uptime
Who is on the marinas network
Who is on the quay network, and the lane each one gets
RF over pontoons is the hard part; the identity model is a campus's: a year-round key per berth holder, a network per tenant, visiting crews on the portal.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visiting skippers and crew | Open | Captive portal sign-in, consent recorded (or SSO, social, SMS) | Guest VLAN, client isolation on | Consent recorded at sign-in |
| Marina office, harbour master and operations staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group | Account disabled, and RADIUS CoA ends the session |
| Annual berth holders | xPSK | Individual key, MAC-bound (a year-round private network) | A berth-holder VLAN, apart from visitors and from each other | Runs for the year, revoked alone if the berth is surrendered |
| Chandlery, restaurant and boatyard tenants | xPSK | Individual key, MAC-bound | A network per tenant: its own VLAN and key set | Revoked when the lease ends, one tenant at a time |
| Fuel dock and shop tills | xPSK | Individual key, MAC-bound | A payments VLAN, apart from berths and visitors | One key per device, rotated or revoked alone |
| Gates, CCTV, shore power meters and pontoon cameras | xPSK | Individual key, MAC-bound | A shoreside-systems VLAN, unreachable from berths | Keyed at install, revoked at decommissioning |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Marinas: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visiting crews and dock staff: portal and onboarding lane
The transient lane for boats that stay a night, and the BYOD lane for dock staff on their own phones.
- Visiting skippers on the portal. SSO, Google, Apple, Facebook or SMS with consent recorded for GDPR and CCPA, and under 15 minutes to add the splash URL and RADIUS to a controller.
- Dock and seasonal staff with no MDM. Sign in once in the Purple app and a WiFi pass installs on Windows, macOS, Linux, iOS and Android.
Marina operations: EAP-TLS and Passpoint
One WPA-Enterprise SSID for the marina's managed devices. Cloud RADIUS checks the directory and returns the VLAN for the group.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once.
- Office and operations by directory group. Entra ID, Okta or Google Workspace over SAML and SCIM. Disable a leaver once and every pontoon stops authenticating them.
Berth holders, tenants and shoreside systems: a key each
A boat has no 802.1X supplicant to configure and a skipper will not install a certificate. A key per berth or device on one SSID gives each its own VLAN and its own end date.
- A year-round private network per berth holder. The key runs for the berth contract, MAC-bound to the boat's router where it has a fixed MAC, with no portal to hit every time they step aboard.
- Shops and restaurants in their own networks. A key set and VLAN per tenant, apart from berths, visitors and the marina's own systems.
- Shoreside systems on locked-down keys. Gates, cameras and power meters each on a MAC-bound key and a systems VLAN, so a berth holder's phone never reaches the barrier controller.
Lifecycle
Key lifecycle: contract, place, operate, surrender
The berth register is the system of record, and a key lasts as long as the contract behind it.
Issue from the berth register
Key each berth holder and tenant when the contract starts, from the console, in bulk from the register or through the Purple API. Each key carries the contract's end date.
Place on a VLAN by class
RADIUS returns the VLAN, role or group policy, depending on your vendor, with a bandwidth limit per key. Berth holders, tenants and shoreside systems land on separate lanes.
Operate one log across every pontoon
Every accept and reject carries the berth, the tenant or the device and the reason, so a skipper who cannot connect is a lookup and not a walk down the pontoon.
End one berth or one lease
A surrendered berth ends one key and nobody else is touched, with RADIUS CoA ending the live session on access points that support it.
One authentication log
One authentication log from the harbour office to the last pontoon
Berth holders, tenants, staff and shoreside systems share one log, so a failing pontoon shows in the data first.
- Which berths are connected, and which access point each one is on.
- Which shoreside devices are online, and on which VLAN.
- Which tenant tills authenticated today, and which were rejected.
Audit
Fuel dock and shop payments apart from berths: what the assessor tests
The fuel dock and shops take cards on the marina's access points. Purple never touches card data, and segmentation gives the assessor a VLAN map and log.
PCI DSS v4.0.1 Req 2.3.2
Wireless keys must change when anyone who knows them leaves. A key per device makes that one rotation, and not every till on the quay.PCI DSS Req 8 and 10
Every authentication is logged with the identity and the reason, and streamed to your SIEM as evidence.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
A platform proven at 80,000+ venues
- 80,000+
- venues run on Purple, in 90 countries
- 500M
- logins a year
- 99.9%
- cloud RADIUS uptime SLA, in your contract
- 99.999%
- uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
Add-on: Purple Shield
Add protective DNS with Purple Shield
Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.
FAQ
Questions IT leads ask
Do we need new access points on the pontoons?
No. Purple Access is a cloud overlay on the access points your marina already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Does Purple fix RF coverage over water and steel hulls?
No. Coverage and radio design are an RF job for your installer. Purple Access decides who each connection is and which VLAN it lands on, on whatever access points you already run.
How does a boat's own router or smart-home kit get on?
To the device its key is an ordinary WPA2-Personal passphrase, so there is no supplicant, certificate or portal. The key is MAC-bound where the device has a fixed MAC and held on the access point side under each vendor's name for it (Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK).
Do visiting crews sign in every night?
On the portal, per session. A visitor who installs a Passpoint or OpenRoaming profile rejoins automatically on every return and at every marina that runs it.
Does xPSK take our WiFi out of PCI scope?
Purple never touches payment card data. Each till and card machine sits on its own key and its own VLAN, apart from guests and staff, and every authentication is logged as evidence for PCI DSS Req 8 and 10. We hand your QSA the VLAN map and the authentication log to test against.
Book a demo: we issue and revoke a key on a live network
Bring one pontoon's worth of lanes: a berth holder's router, a chandlery till, a barrier controller and a visitor's phone. We issue each a key, place it on its VLAN and revoke one live, on the access points you already run.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.