Skip to content
Operations and IoT: Warehouses and logistics

Warehouses and logistics: drivers on the portal, staff on EAP-TLS, a personal WiFi key per scanner

Scanners, robots and vehicle terminals join with a MAC-bound key on an operations VLAN, apart from staff phones. Permanent staff sit on EAP-TLS, agency staff are onboarded in bulk and switched off when the season ends, and visitors use the portal.

  • 80,000+ venues in 90 countries
  • 99.999% uptime
  • 99.9% RADIUS uptime SLA
Illustration
Illustration: one xPSK SSID with a unique key per device, resident, tenant and contractor, each on its own VLAN and bandwidth limit, revocable on its own.
Book my design session

Who is on the warehouses and logistics network

Who and what connects to a depot, and where each one lands

A certificate has an expiry, and a scanner that sat in its cradle all off-season meets it on the first shift of peak, so scanners, robots and vehicle terminals get a MAC-bound key with no certificate to renew, and agency staff arrive in bulk and end on a date.

Who and what connects to a depot, and where each one lands
Who or what connectsNetworkAuthenticationPlacementWhat starts and ends access
Permanent staff on personal phonesOpenPurple app onboarding, certificate installed, no MDMOnboarding lane, then the group VLANEnds with the directory account
Visiting drivers, customers and auditors at receptionOpenCaptive portal sign-in, consent recordedGuest VLAN, client isolation onConsent recorded at sign-in, session ends on timeout
Permanent warehouse, transport and office staffSecureEAP-TLS, certificate from your MDM over SCEP (managed laptops and phones)VLAN by directory group, apart from the operations VLANAccount disabled in the directory ends access
Agency and peak-season staffxPSKIndividual key, MAC-bound (from a roster import, a personal phone, no MDM)A seasonal-staff VLAN and a bandwidth limit per keySwitched off on the season's end date
Handheld scannersxPSKIndividual key, MAC-boundAn operations VLAN, apart from staff phonesOne key per scanner, revoked when it is retired
Mobile robotsxPSKIndividual key, MAC-boundA robot VLAN with its own bandwidth limitOne key per robot, revoked alone
Vehicle terminals on forklifts and yard vehiclesxPSKIndividual key, MAC-boundThe operations VLANNo expiry to chase while it sits in its cradle
Equipment maintenance contractorsxPSKIndividual key, MAC-bound (time-limited, no MDM)A contractor VLAN, crossings set at your gatewayEnds on the visit's end date

Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.

Warehouses and logistics: open, secure and xPSK

Three networks, each doing its own job

Identity decides the VLAN inside each network, so one SSID carries many groups.

Visitors and staff phones: portal and onboarding lane

The guest lane and the BYOD onboarding lane, on VLANs that share nothing with the operations VLAN.

  • Drivers and auditors at reception. A captive portal records consent and puts the session on a guest VLAN with client isolation on. A visiting driver's phone never sits on the segment a scanner does.
  • Permanent staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
  • A new depot in minutes. Add the splash URL and RADIUS to the depot's controller in under 15 minutes, on the access points already installed.
Illustration

Lifecycle

Key lifecycle: deploy, place, operate, retire

The same four moves cover a scanner and a seasonal picker, tied to the records a depot already keeps: the device register, the agency's roster and the directory.

Issue in bulk, from the device register and the roster

Import the device list and the agency's roster, or issue from the console or the Purple API. Each key is bound to the device's MAC address, and each person's key carries the season's end date.

Illustration

Place on the operations VLAN or the seasonal VLAN

RADIUS returns the VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and what the warehouse management system may reach lives on your gateway.

Illustration

Operate from one log across every depot

Every accept and reject carries the device or person, the key, the VLAN and the reason, streamed to Microsoft Sentinel, Splunk, Elastic or Datadog.

Illustration

Retire one scanner, or end a whole season

Retire a scanner and you revoke one key. When the season's date passes, every agency key stops authenticating, and RADIUS CoA ends a live session on access points that support it.

Illustration

One authentication log

One authentication log for the fleet and the workforce

Scanners, robots, permanent staff and the seasonal intake land in the same log, so "which devices are on the floor and who is still switched on" is a query across every depot.

  • Which scanners, robots and terminals authenticated today, by depot and VLAN.
  • Which agency keys are live, and which ended on the season's date.
  • Which devices were rejected, with the reason: revoked, unknown or off its bound MAC.
  • Whether a retired scanner's key still authenticates anywhere.
Illustration

Works with

Your directory, your MDM, your SIEM, your access points

Nothing is replaced. Purple Access sits on the systems your team already runs.

  • Identity providers

    Over SAML and SCIM. Group membership decides the VLAN.
    • Microsoft Entra ID
    • Okta
    • Google Workspace
  • Device management

    EAP-TLS certificates delivered over SCEP, with a compliance-gated join.
    • Microsoft Intune
    • Jamf Pro
    • JumpCloud
    • Kandji
    • Hexnode
    • Iru
    • Addigy
  • SIEM

    The authentication log, over webhook or syslog.
    • Microsoft Sentinel
    • Splunk
    • Elastic
    • Datadog
  • Access points

    Mixed estates are supported.
    • Cisco Meraki
    • HPE Aruba
    • Ruckus
    • Juniper Mist
    • Ubiquiti UniFi
    • Cambium
    • Extreme
    • Fortinet

Proof

Built for estates that never close

80,000+ venues in 90 countries run on Purple, on a platform that holds 99.999% uptime.

80,000+
venues run on Purple, in 90 countries
99.999%
uptime, with a 99.9% cloud RADIUS SLA and multi-region failover
99.9%
cloud RADIUS uptime SLA, in your contract

Add-on: Purple Shield

Add protective DNS with Purple Shield

Purple Shield bolts onto Access or runs standalone, with a DNS policy per VLAN and by time of day, so each group on your three networks gets the filtering that fits it. Page loads up to 500% faster and 20 to 40% less web traffic. Try it free for 30 days.

Illustration

FAQ

Questions IT leads ask

Do we need new access points in our warehouses?

No. Purple Access is a cloud overlay on the access points your depots already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

Why not certificates on every scanner?

Certificates stay the default for what can hold one and be managed: office laptops and managed phones on EAP-TLS. Rugged handhelds, robots and vehicle terminals carry a certificate lifecycle you would run across thousands of units that sit unused for months. xPSK gives them a key instead.

Do scanners keep their key as they roam between access points?

Yes. The key authenticates against RADIUS on the SSID, not on one access point, so a device keeps its key and its VLAN as it moves across your estate. Fast-roaming behavior is a setting on your controller.

What happens when the season ends?

Each agency key carries the end date it was issued with. After it, RADIUS rejects the key, and a CoA ends a live session on access points that support it. Nobody chases handsets.

Does MAC binding work on rugged devices?

It is strongest on fixed-MAC devices, which scanners, robots and vehicle terminals are. The key is bound to the device's address, so a copied key does not work on another handset.

Can scanners still reach the warehouse management system?

Yes, by policy at your gateway or firewall. Purple returns the VLAN or role at authentication, and your gateway decides what the operations VLAN may reach, and what staff phones may not.

Does a VLAN per fleet mean an SSID per fleet?

No. One xPSK SSID carries every key and RADIUS returns the VLAN, so a new fleet adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime, which matters on a floor with hundreds of radios.

Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?

Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.

Book a demo: we issue and revoke a key on a live network

Bring a shift's worth of kit: a scanner, a robot, a vehicle terminal and an agency worker's phone. We issue each a key, place it on its VLAN and end one live.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.