Ports: visitors on the portal, port staff on EAP-TLS, hauliers and vessel crews on a personal WiFi key
Port authority staff sit on EAP-TLS, each terminal operator and agent on its own VLAN, and gate, crane and camera systems on locked-down MAC-bound keys. Visiting hauliers and crews get short-lived keys, and the public use the portal.
- Vancouver International Airport
- Kinetic Melbourne Airport
- 99.9% RADIUS uptime SLA
Who is on the ports network
Who and what connects across a port, and where each one lands
A port is many legal entities on one authority's infrastructure, the airport model: each terminal operator and agent gets its own VLAN and key set, gate and crane systems sit on locked-down device keys, and visiting hauliers get keys that end with the visit.
| Who or what connects | Network | Authentication | Placement | What starts and ends access |
|---|---|---|---|---|
| Visitors and inspectors at port offices | Open | Captive portal sign-in, consent recorded | Guest VLAN, client isolation on | Consent recorded at sign-in, session ends on timeout |
| Port staff on personal phones | Open | Purple app onboarding, certificate installed, no MDM | Onboarding lane, then the group VLAN | Ends with the directory account |
| Port authority staff | Secure | EAP-TLS, certificate from your MDM over SCEP | VLAN by directory group, apart from every operator | Account disabled in the directory ends access |
| Terminal operator and shipping agent staff | Secure | EAP-TLS, certificate from your MDM over SCEP (the operator's own directory and MDM) | The operator's own VLAN or role | Ends when the operator disables the account or the concession ends |
| Visiting haulage firms and truck drivers | xPSK | Individual key, MAC-bound (short-lived, no MDM) | A visitor-operations VLAN and a bandwidth limit per key | Ends when the visit does |
| Visiting vessel crews | xPSK | Individual key, MAC-bound (short-lived, no MDM) | A crew VLAN and a bandwidth limit per key | Ends on the vessel's departure date |
| Gate, camera and access control systems | xPSK | Individual key, MAC-bound | A locked-down gate-systems VLAN, apart from every operator | One key per device, revoked alone |
| Crane and yard-equipment terminals | xPSK | Individual key, MAC-bound | An equipment VLAN, crossings set at your gateway | One key per terminal, revoked when it is retired |
Placement is what RADIUS returns at authentication: a VLAN, or a role or group policy, depending on your vendor. Your access points and gateway enforce it. VLAN numbers on the illustrations are examples.
Ports: open, secure and xPSK
Three networks, each doing its own job
Identity decides the VLAN inside each network, so one SSID carries many groups.
Visitors and staff phones: portal and onboarding lane
The public lane and the BYOD onboarding lane, on VLANs that share nothing with an operator's network or the gate systems.
- Visitors and inspectors on a portal. A captive portal records consent and puts the session on a guest VLAN with client isolation on, so a visitor's phone never shares a segment with a gate controller.
- Port staff phones with no MDM. Sign in once in the Purple app and a WiFi pass installs, then the phone moves to its group's VLAN.
- A terminal in minutes. Add the splash URL and RADIUS to a terminal's controller in under 15 minutes, on the access points already installed.
Authority and operator staff: EAP-TLS and each operator's own directory
One WPA-Enterprise SSID across the port. Each organization brings its own identity and cloud RADIUS returns that organization's VLAN.
- EAP-TLS from your MDM. Microsoft Intune, Jamf Pro, JumpCloud, Kandji, Hexnode, Iru and Addigy deliver the certificate over SCEP. Setup is five to ten minutes, once, for each organization.
- Directory groups decide the VLAN. Authority operations, security and finance land on separate VLANs from Entra ID, Okta or Google Workspace groups.
- Each operator signs in with its own directory. A terminal operator or shipping agent federates its own Entra ID, Okta or Google Workspace, and its group lands on that operator's VLAN.
Gates, cranes, cameras and visiting crews: a key each, a VLAN each
Everything with no 802.1X supplicant, and everyone who is on the port for a day, on one xPSK SSID with a key and a policy per device or person.
- Each operator and agent on its own network. A VLAN or role per organization returned by RADIUS, on any access point whose switching carries it, so an operator's devices land in its lane across every terminal.
- Short-lived keys for visiting hauliers and crews. A time-limited key from the self-service portal or the Purple API, ending when the visit does, with nothing to install and nothing to collect.
- Gate, crane and camera systems on locked-down keys. A MAC-bound key and a VLAN per class, so a leaked key opens one device and a camera swap revokes one key.
- A bandwidth limit per key. A cap on what any one key can take, so a crew's streaming cannot crowd the gate readers sharing the same radios.
Lifecycle
Key lifecycle: issue, place, operate, end
The same four moves cover a gate controller and a haulier, tied to the records a port already keeps: the equipment register, the visit booking and each operator's directory.
Issue from the equipment register and the visit list
Import the equipment register, or issue visit keys from the self-service portal or the Purple API. Every device key is bound to the device's MAC address, and every visit key carries its end date.
Place on the operator's VLAN or the device VLAN
RADIUS returns the VLAN, role or group policy, depending on your vendor, plus the bandwidth limit. Your access points enforce it, and which operator systems the port authority may reach is policy at your gateway.
Operate from one log across every terminal
Every accept and reject carries the organization, the key, the VLAN and the reason, so the authority answers which operator, which device and why from one place, and streams it to the SIEM.
Revoke one device, one visit or one operator
Withdraw a key and only that device drops. A visit key ends on its date, and a departing operator has its keys revoked without touching anyone else. RADIUS CoA ends a live session on access points that support it.
One authentication log
One authentication log across the port
Operator staff certificates, gate controllers and visiting haulier keys land in the same log, tagged by organization, so "who is on the port and on whose network" is a query.
- Which operators and agents authenticated today, and on which VLAN.
- Which gate, crane and camera keys were rejected, and why.
- Which visit keys are live, and which ended on their date.
- Whether a retired device's key, or a departed operator's, still authenticates.
Works with
Your directory, your MDM, your SIEM, your access points
Nothing is replaced. Purple Access sits on the systems your team already runs.
Identity providers
Over SAML and SCIM. Group membership decides the VLAN.- Microsoft Entra ID
- Okta
- Google Workspace
Device management
EAP-TLS certificates delivered over SCEP, with a compliance-gated join.- Microsoft Intune
- Jamf Pro
- JumpCloud
- Kandji
- Hexnode
- Iru
- Addigy
SIEM
The authentication log, over webhook or syslog.- Microsoft Sentinel
- Splunk
- Elastic
- Datadog
Access points
Mixed estates are supported.- Cisco Meraki
- HPE Aruba
- Ruckus
- Juniper Mist
- Ubiquiti UniFi
- Cambium
- Extreme
- Fortinet
Identity providers: setup and mappingDevice management: setup and mappingSIEM: setup and mappingHardware setup by vendor
Proof
The shared-estate model, proven at airport scale
Vancouver International Airport and Kinetic Melbourne Airport put their concessions on their own keys, which is how a port keeps its operators apart.
- Vancouver
- International Airport runs on Purple, concessions on their own keys
- Melbourne
- Kinetic Melbourne Airport runs on Purple, concessions on their own keys
- 80,000+
- venues run on Purple, in 90 countries
FAQ
Questions IT leads ask
Do we need new access points across the port?
No. Purple Access is a cloud overlay on the access points your terminals already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.
Does this fix coverage across container stacks?
No. Coverage is a site survey and access point placement question, and stacks that move change it daily. Purple decides what each connection lands on, whichever access point carries it, so the same policy follows a device across the estate.
How do we keep one operator off another's network?
Each operator is its own VLAN or role, returned by RADIUS and enforced by your access points, with client isolation by default. What may cross between operators, if anything, is policy at your gateway.
How do short-lived keys reach hauliers and crews?
From the self-service portal or the Purple API, with an end date set when the key is issued. After it RADIUS rejects the key, and a CoA ends a live session on access points that support it.
Does each operator need its own SSID?
No. One xPSK SSID carries every operator and every device, and RADIUS returns the VLAN, so a new operator adds keys and never beacons. 8 to 10 SSIDs use 15 to 25% of channel airtime.
Is xPSK the same as iPSK, PPSK, DPSK, MPSK or EasyPSK?
Yes. xPSK is our name for the capability each vendor ships under its own: Cisco iPSK and EasyPSK, Ruckus DPSK, Extreme PPSK, HPE Aruba MPSK, Ubiquiti UniFi PPSK and Juniper Mist MPSK. Purple runs all of them from one platform, on a mixed estate.
Book a demo: we issue and revoke a key on a live network
Bring a terminal's worth of kit: a gate reader, a crane terminal, an operator's laptop and a haulier's phone. We issue each a key or a certificate, place it on its VLAN and end one live.
- Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
- We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
- You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.
Your design session
Your live key demo
A Purple network engineer runs the demo with you, on your kind of estate.