Skip to content
Operations and IoT: Ports

Ports: visitors on the portal, port staff on EAP-TLS, hauliers and vessel crews on a personal WiFi key

Port authority staff sit on EAP-TLS, each terminal operator and agent on its own VLAN, and gate, crane and camera systems on locked-down MAC-bound keys. Visiting hauliers and crews get short-lived keys, and the public use the portal.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the ports network

Who and what connects across a port, and where each one lands

A port is many legal entities on one authority's infrastructure, the airport model: each terminal operator and agent gets its own VLAN and key set, gate and crane systems sit on locked-down device keys, and visiting hauliers get keys that end with the visit.

Who and what connects across a port, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Visitors and inspectors at port officesOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, session ends on timeout
Port staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Port authority staffSecureEAP-TLS, certificate from your MDM over SCEPVLAN by directory group, apart from every operatorAccount disabled in the directory ends access
Terminal operator and shipping agent staffSecureEAP-TLS, certificate from your MDM over SCEP (the operator's own directory and MDM)The operator's own VLAN or roleEnds when the operator disables the account or the concession ends
Visiting haulage firms and truck driversxPSKIndividual key, MAC-bound (short-lived, no MDM)A visitor-operations VLAN and a bandwidth limit per keyEnds when the visit does
Visiting vessel crewsxPSKIndividual key, MAC-bound (short-lived, no MDM)A crew VLAN and a bandwidth limit per keyEnds on the vessel's departure date
Gate, camera and access control systemsxPSKIndividual key, MAC-boundA locked-down gate-systems VLAN, apart from every operatorOne key per device, revoked alone
Crane and yard-equipment terminalsxPSKIndividual key, MAC-boundAn equipment VLAN, crossings set at your gatewayOne key per terminal, revoked when it is retired

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Ports: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and staff phones: portal and onboarding lane

The public lane and the BYOD onboarding lane, on VLANs that share nothing with an operator's network or the gate systems.

  • Visitors and inspectors on a portal. A captive portal records consent and puts the session on a guest VLAN with client isolation on, so a visitor's phone never shares a segment with a gate controller.
  • Port staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
  • A terminal in minutes. Add the splash URL and RADIUS to a terminal's controller in under 15 minutes, on the access points already installed.
Illustration

Lifecycle

Key lifecycle: issue, place, operate, end

The same four moves cover a gate controller and a haulier, tied to the records a port already keeps: the equipment register, the visit booking and each operator's directory.

Issue from the equipment register and the visit list

Import the equipment register, or issue visit keys from the self-service portal or the Purple API. Every device key is bound to the device's MAC address, and every visit key carries its end date.

Illustration

Place on the operator's VLAN or the device VLAN

RADIUS returns the VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and which operator systems the port authority may reach is policy at your gateway.

Illustration

Operate from one log across every terminal

Every accept and reject carries the organisation, the key, the VLAN and the reason, so the authority answers which operator, which device and why from one place, and streams it to the SIEM.

Illustration

Revoke one device, one visit or one operator

Withdraw a key and only that device drops. A visit key ends on its date, and a departing operator has its keys revoked without touching anyone else. RADIUS CoA ends a live session on access points that support it.

Illustration

One authentication log

One authentication log across the port

Operator staff certificates, gate controllers and visiting haulier keys land in the same log, tagged by organisation, so "who is on the port and on whose network" is a query.

  • Which operators and agents authenticated today, and on which VLAN.
  • Which gate, crane and camera keys were rejected, and why.
  • Which visit keys are live, and which ended on their date.
  • Whether a retired device's key, or a departed operator's, still authenticates.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

The shared-estate model, proven at airport scale

Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys, which is how a port keeps its operators apart.

Vancouver
International Airport runs on Purple, concessions on their own keys
Melbourne
Kinetic Melbourne Airport runs on Purple, concessions on their own keys
80,000+
venues run on Purple, in 90 countries

FAQ

Questions IT leads ask

Do we need new access points across the port?

No. Purple Access is a cloud overlay on the access points your terminals already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Does this fix coverage across container stacks?

No. Coverage is a site survey and access point placement question, and stacks that move change it daily. Purple decides what each connection lands on, whichever access point carries it, so the same policy follows a device across the estate.

How do we keep one operator off another's network?

Each operator is its own VLAN or role, returned by RADIUS and enforced by your access points, with client isolation by default. What may cross between operators, if anything, is policy at your gateway.

How do short-lived keys reach hauliers and crews?

From the self-service portal or the Purple API, with an end date set when the key is issued. After it RADIUS rejects the key, and a CoA ends a live session on access points that support it.

Does each operator need its own SSID?

No. One xPSK SSID carries every operator and every device, and RADIUS returns the VLAN, so a new operator adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring a terminal's worth of kit: a gate reader, a crane terminal, an operator's laptop and a haulier's phone. We issue each a key or a certificate, place it on its VLAN and end one live.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.