Skip to content
Education and public: Local government

City networks: portal for the public, OpenRoaming for returners, a personal WiFi key per household or device

Free public WiFi on the captive portal, returning residents and students on a Passpoint profile, staff on EAP-TLS, and scheme households, high-street businesses, CCTV and sensors each on a MAC-bound key and VLAN.

  • World's first city-wide OpenRoaming network
  • £0 cost to Newcastle City Council
  • 1,000 SMEs on the city network
  • 53,000+ students

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40
Book my design session

Who is on the local government network

Who connects across a city, and where each one lands

A city network serves three audiences that share nothing: the public, who must connect in one tap, residents in a digital inclusion scheme, who need a key of their own, and civic devices, which share a lane with neither. OpenRoaming carries returning users, so the portal is for first contact.

Who connects across a city, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Residents and visitors connecting for the first timeOpenCaptive portal sign-in, consent recorded (SSO, social or SMS)Public VLAN, client isolation onConsent recorded at sign-in, then the session times out
Staff and volunteers on personal phonesOpenPurple app onboarding, certificate installed, no MDM (directory account)Onboarding lane, then the group VLANEnds with the directory account
Returning residents and studentsSecurePasspoint or OpenRoaming profilePublic VLAN, no portal on returnProfile installed once, valid across the city's hotspots
Staff on managed laptopsSecureEAP-TLS, certificate from your MDM over SCEP (from your MDM)VLAN or role by directory groupAccount disabled once, and RADIUS CoA ends the session
Households in a digital inclusion schemexPSKIndividual key, MAC-bound (issued by the scheme)A household VLAN, a bandwidth limit per keyEnds when the household leaves the scheme
High-street businesses, one network eachxPSKIndividual key, MAC-bound (a key set per business)A VLAN per business, with its own limitKeys added and withdrawn per device
CCTV, signage and environmental sensorsxPSKIndividual key, MAC-boundA device VLAN, unreachable from the publicOne key per device, revoked when replaced

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Local government: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

The public: one portal across every site

The open network is the front door of a municipal network, for everyone who has never connected.

  • Free public WiFi on the captive portal. SSO, social or SMS sign-in, consent recorded for GDPR and CCPA, under 15 minutes to add to a controller.
  • One portal across a mixed access point estate. Buildings, libraries and street cabinets rarely share a vendor. The portal and RADIUS sit above all of them.
  • Staff and volunteers on their own phones. One sign-in in the Purple app with a work account installs a pass on Windows, macOS, Linux, iOS and Android, with no MDM.
Illustration

Lifecycle

Key lifecycle: enroll, place, operate, withdraw

The same four moves serve a scheme household and a street camera, tied to the scheme's household list and your asset register.

Issue from the scheme list or the asset register

A household's key is created when the scheme enrolls it. Cameras and sensors are keyed on installation, from the console, a bulk list or the Purple API, each bound to a MAC.

Illustration

Place on a VLAN by audience

RADIUS returns the VLAN, role or group policy, depending on your vendor. Your access points and gateway enforce it, so the public lane never reaches the camera lane.

Illustration

Operate from one log across every site

Every accept and reject carries its reason, by resident, member of staff and device, streamed to Sentinel, Splunk, Elastic or Datadog.

Illustration

End one device, one household or one business

Withdraw a key and that device drops alone, with RADIUS CoA ending the live session. A household that leaves the scheme takes only its own keys.

Illustration

One authentication log

One authentication log across every site

Public sign-ins, staff certificates, scheme keys and street devices land in one log, so an elected member's question and an auditor's request get the same answer.

  • How many first-time, returning and scheme connections landed on each network this week.
  • Which cameras and sensors are on the network, and on which VLAN.
  • Which staff accounts were rejected, by which method, and why.
  • Which scheme keys are live, and which households have left the scheme.
Illustration

Audit

Assurance across sites: what the log evidences

Public bodies answer to auditors and elected members. Purple holds ISO 27001 and Cyber Essentials Plus, and the log is evidence for your own controls.

  • ISO 27001

    Every accept and reject is logged with its reason and streamed to your SIEM, as evidence for access control and logging controls.
  • CIPA

    Libraries that take E-rate discounts must filter internet access for minors. A separate VLAN for public terminals lets one policy cover them.

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Newcastle, the world's first city-wide OpenRoaming network

Newcastle City Council runs it on Purple, used by 1,000 SMEs and by students roaming between campus, city and trams.

1st
city-wide OpenRoaming network in the world, in Newcastle
£0
cost to Newcastle City Council
1,000
SMEs on the Newcastle city network
53,000+
students roaming between campus, city and trams in Newcastle

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Does OpenRoaming replace the captive portal?

No. The portal is first contact for anyone who has never connected. A Passpoint profile installed at that first sign-in lets the same person rejoin across the city with no portal, on the secure network.

How does a household in a digital inclusion scheme get its key?

Scheme staff issue it from the console, a branded self-service portal or the Purple API. The key is bound to the household's device by MAC, carries its own VLAN and bandwidth limit, and ends when the household leaves the scheme. Every other household stays connected.

How do high-street businesses each get their own network on one set of access points?

One SSID carries a VLAN and a key set per business. Each business's registers and printers see each other and nobody else's, and your gateway enforces any rule that lets them reach a shared service. There is no per-SSID key ceiling.

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites and street cabinets already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

What evidence do we get for assurance?

Every accept and reject is logged with its reason and streamed to your SIEM, as evidence for ISO 27001 access control and logging controls. Purple holds ISO 27001 and Cyber Essentials Plus.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring one site's worth of everything: a public sign-in, a staff laptop, a scheme household and a street camera. We issue each a key or a certificate, place it on its VLAN and revoke one live, on the access points you already run.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.