Skip to content
Industries

Travel and venues WiFi: every employer, tenant and device on its own personal WiFi key

The public sign in on the open network, returning visitors roam on Passpoint, staff from many employers sit on a role and VLAN each, and scanners, TVs and gate readers get MAC-bound keys. One authentication log across every site.

  • Vancouver International Airport
  • Kinetic Melbourne Airport
  • SoFi Stadium runs on Purple
  • Whitbread runs segmented staff WiFi on Purple

Phones, laptops, tills, CCTV and TVs join through your access point. Cloud RADIUS checks each one and sends it to the open, secure or xPSK network by identity, each on its own VLAN; a leaver whose account is disabled is rejected.

Every deviceYour access pointsCloud RADIUSRejected: account disabled
Open
  • Captive portal sign-in
  • Consent recorded
  • BYOD onboarding lane
Secure
  • EAP-TLS from your MDM
  • Identity decides the VLAN
  • Passpoint and OpenRoaming
xPSK
  • A key per device
  • Own VLAN and bandwidth limit
  • Revoke one key alone
VLAN 10VLAN 20VLAN 40
Book my design session

Travel and venues

Travel and venues: pick your estate

Mixed crowds on one estate: staff from many employers, short-term workers and the public, each held in their own lane on shared access points.

  • Airports

    Airlines, handlers, concessions and agencies share one terminal's access points and nothing else: a role and VLAN per organization, keys for scanners and kiosks, passengers on the portal.
  • Hotels

    Three networks per property: guests on the portal with a PMS room check, staff on EAP-TLS or Passpoint, and room TVs, thermostats and registers on key-bound VLANs guests never see.
  • Serviced apartments and long stay

    Unit devices keep their keys through every changeover, each guest's access ends on its own date, and a corporate client's staff share one company network across apartments.
  • Stadiums and arenas

    Accreditation tiers are roles that expire after one event, and scanners and point-of-sale devices sit on MAC-bound keys, so a dozen employers share the bowl's access points and nothing else.
  • Conference centers and events

    An exhibitor network per stand, created in bulk from the exhibitor list and ended at close, with AV and production crews on their own VLAN, off delegate WiFi.
  • Marinas

    RF over pontoons is the hard part; the identity model is a campus's: a year-round key per berth holder, a network per tenant, visiting crews on the portal.
  • Caravan and holiday parks

    Owners' holiday homes each get a private network for the season, vacationers use the portal, and point-of-sale devices, barriers and cameras sit on locked-down keys.

Use cases

The problems that thread these estates

FAQ

Questions IT leads ask

Do we need new access points?

No. Purple Access is a cloud overlay on the access points your sites already run: Cisco Meraki, HPE Aruba, Ruckus, Juniper Mist, Ubiquiti UniFi, Cambium, Extreme and Fortinet. Mixed estates are supported.

How do we keep contractors, concessions and the public apart on shared access points?

Each organization gets its own role and VLAN, devices that cannot do 802.1X get a MAC-bound key, and the public use the captive portal. Your access points enforce the lanes. Purple decides which lane each connection lands in, and logs why.

Is xPSK one SSID or one per household, tenant or device?

One SSID. Every key on it has its own VLAN, policy and bandwidth limit, returned by RADIUS at authentication, and there is no per-SSID key ceiling. Adding a key never adds a beacon.

What does revoking one key do to everyone else?

Nothing. Each key is its own entry in RADIUS, bound to its device by MAC, so withdrawing one ends that device's access and leaves every other key connected. A live session is ended with RADIUS CoA on access points that support it.

Book a demo: we issue and revoke a key on a live network

Bring the list of what connects to your network. We issue a key, bind it to a device, place it on its VLAN and revoke it on a live network, on the access points you already own.

  1. Tell us what connectsYour SSIDs, your access points and the devices nobody wants to talk about.
  2. We issue a key and revoke it liveOne device, one key, its own VLAN, then switched off while you watch the log.
  3. You leave with the three-network planWhich of your groups sit on open, secure and xPSK, and what to pilot first.

Your design session

Your live key demo

A Purple network engineer runs the demo with you, on your kind of estate.