Skip to main content

Technical WiFi guides

Deep, expert-led technical guides on guest WiFi, analytics, captive portals, and venue technology.

Ready to move from research to rollout? See how Purple's captive portal software handles branded guest sign-in, analytics, and compliance in one platform.

Aruba ClearPass vs. Purple WiFi: Comparing Features and Co-deployment
Authentication

Aruba ClearPass vs. Purple WiFi: Comparing Features and Co-deployment

A comprehensive technical guide detailing the co-deployment architecture of Aruba ClearPass and Purple WiFi. It covers RADIUS proxy configuration, dynamic VLAN assignment, and best practices for delivering secure, analytics-driven guest networks alongside enterprise NAC.

6 mins read1k words
Cisco ISE vs. Purple WiFi: How They Compare and Work Together
Authentication

Cisco ISE vs. Purple WiFi: How They Compare and Work Together

This guide explains how Cisco ISE and Purple WiFi serve distinct but complementary roles in enterprise networks. It details how to use Cisco ISE for secure 802.1X corporate access while leveraging Purple for GDPR-compliant guest WiFi, marketing analytics, and CRM integration.

6 mins read1k words
EAP-TLS vs EAP-TTLS: Which Certificate-Based WiFi Protocol Should You Choose?
Authentication

EAP-TLS vs EAP-TTLS: Which Certificate-Based WiFi Protocol Should You Choose?

This guide provides a definitive head-to-head comparison of EAP-TLS and EAP-TTLS for enterprise WiFi authentication under IEEE 802.1X. It explains the architectural difference between mutual certificate authentication and server-only certificate tunnelling, and gives IT managers, network architects, and CISOs a clear decision framework based on device management capabilities and compliance requirements. Purple supports both EAP-TLS and EAP-TTLS authentication paths for Staff WiFi, and this guide helps organisations understand the infrastructure trade-offs before committing to either approach.

9 mins read2k words
What is an 802.1X Supplicant? Client Types and Device Configuration
Authentication

What is an 802.1X Supplicant? Client Types and Device Configuration

This guide explains the role of the 802.1X supplicant in enterprise WiFi authentication. It covers the technical architecture, compares native OS supplicants with third-party clients, and provides practical configuration guidance for IT teams deploying EAP-TLS and PEAP.

5 mins read1k words
Managing Digital Certificates for EAP-TLS WiFi Authentication
Authentication

Managing Digital Certificates for EAP-TLS WiFi Authentication

This technical reference guide details the lifecycle management of digital certificates for EAP-TLS WiFi authentication. It provides actionable strategies for deploying, renewing, and revoking certificates at scale across enterprise networks using SCEP and MDM integrations.

4 mins read1k words
Troubleshooting Public WiFi: Fixing 'Connected, No Internet' and Splash Page Redirection Failures
Troubleshooting

Troubleshooting Public WiFi: Fixing 'Connected, No Internet' and Splash Page Redirection Failures

This authoritative technical reference guide explains the underlying mechanics of captive portal detection and details the six primary failure modes that prevent guest WiFi from connecting. It provides IT managers and network architects with a practical troubleshooting framework to resolve HTTP redirect issues, DNS conflicts, and MAC randomisation challenges.

6 mins read1k words
Captive Portal Architecture: Security, Redirection, and Best Practices
Captive Portals

Captive Portal Architecture: Security, Redirection, and Best Practices

A definitive technical reference on enterprise captive portal architecture. This guide unpacks network isolation, DNS redirection, RADIUS authentication, and security compliance for IT leaders deploying secure, data-rich guest WiFi networks.

5 mins read1k words
Optimising B2B Captive Portals: Capturing Company Names and Professional Data
Captive Portals

Optimising B2B Captive Portals: Capturing Company Names and Professional Data

This guide explains how IT managers, network architects, and venue operations directors can configure B2B captive portals to capture professional data - company names, job titles, and business email addresses - at the point of WiFi login. It covers the full technical architecture from VLAN isolation and RADIUS authentication through to CRM integration with Salesforce and HubSpot, with GDPR and CCPA compliance built in. Venues that deploy this correctly turn their guest WiFi network into a first-party data engine and automated lead generation system.

8 mins read2k words
Deploying SCEP for Secure Higher Education BYOD and WiFi Authentication
Authentication

Deploying SCEP for Secure Higher Education BYOD and WiFi Authentication

This technical guide provides network architects and IT managers with a vendor-neutral blueprint for deploying SCEP-based certificate enrolment to secure higher education WiFi. It details the transition from vulnerable password-based authentication to EAP-TLS, focusing on scalable BYOD onboarding and MDM integration.

5 mins read1k words
The Security Benefits of RADIUS as a Service for Hybrid Workforces
radius

The Security Benefits of RADIUS as a Service for Hybrid Workforces

This technical reference guide explains how RADIUS as a Service secures network access for hybrid workforces across distributed venues. It covers the architecture, security benefits, and deployment steps for replacing on-premise RADIUS infrastructure with a cloud-managed authentication service. For IT managers and network architects at hotels, retail chains, stadiums, and public-sector organisations, this guide provides the evidence needed to evaluate and act on a cloud RADIUS migration this quarter.

9 mins read2k words
Integrating RADIUS as a Service with Cloud Directories (Azure AD & Google Workspace)
radius

Integrating RADIUS as a Service with Cloud Directories (Azure AD & Google Workspace)

This technical reference guide details how to integrate RADIUS as a Service with cloud directories - Microsoft Entra ID and Google Workspace - for enterprise WiFi authentication. It covers the architectural shift from on-premises NPS to cloud-native RADIUS, the deployment of certificate-based EAP-TLS authentication, and the operational best practices for securing wireless access across hospitality, retail, and public-sector environments. For IT managers and network architects already invested in cloud identity, this guide bridges the gap between directory management and physical network security.

10 mins read2k words
Designing WiFi Networks for Multi-Tenant Office Buildings
Multi-Tenant WiFi

Designing WiFi Networks for Multi-Tenant Office Buildings

This guide provides IT managers, network architects, and CTOs with a vendor-neutral blueprint for designing scalable, secure, and isolated WiFi networks across multi-tenant office buildings. It covers VLAN segmentation under IEEE 802.1Q, Dynamic VLAN Assignment via 802.1X and RADIUS, RF planning for high-density environments, and compliance considerations under GDPR and PCI DSS. Venue operators and building managers will find actionable architecture guidance, real-world case studies, and configuration pitfalls to avoid before deployment.

9 mins read2k words
How to Set Up a Captive Portal on Starlink: A Guide for Remote & Maritime Venues
Captive Portals

How to Set Up a Captive Portal on Starlink: A Guide for Remote & Maritime Venues

This guide details how to bypass the native Starlink hardware and integrate a cloud-managed captive portal using enterprise routing equipment. You will learn how to overcome the CGNAT limitation, enforce VLAN segmentation, manage satellite bandwidth constraints, and ensure regulatory compliance.

5 mins read1k words
Hotel Guest WiFi Management: Integrating PMS, Portals, and Brand Standards
Network Design

Hotel Guest WiFi Management: Integrating PMS, Portals, and Brand Standards

This technical guide details how to architect enterprise-grade hotel WiFi networks, focusing on VLAN segmentation, PMS integration for automated session management, and captive portal optimisation for GDPR-compliant data capture.

5 mins read1k words
Captive Portal Best Practices: Designing for High Conversion and Compliance
Captive Portals

Captive Portal Best Practices: Designing for High Conversion and Compliance

This technical guide gives IT managers, network architects, and venue operations directors a complete blueprint for deploying captive portals that balance network security with high user conversion. It covers the full architecture from VLAN segmentation and RADIUS authentication to GDPR-compliant consent design and authentication method selection. Drawn from Purple's operational experience across 80,000+ venues and 440 million logins in 2024, every recommendation is grounded in real deployment data.

8 mins read2k words
How to Optimize Captive Portals for Maximum Network Security and User Conversion
Captive Portals

How to Optimize Captive Portals for Maximum Network Security and User Conversion

This guide provides a complete technical blueprint for optimising captive portals across enterprise venues, covering network segmentation architecture, authentication method selection, GDPR-compliant consent design, and conversion optimisation. It is written for IT managers, network architects, and CTOs at hotels, retail chains, stadiums, and public-sector organisations who need to balance network security with first-party data capture. Purple operates captive portal infrastructure across 80,000+ venues with 440 million logins in 2024, and the frameworks here reflect that operational experience.

10 mins read2k words
Hotel Guest WiFi Architecture: PMS Integration, Captive Portals, and Bandwidth Control
Captive Portals

Hotel Guest WiFi Architecture: PMS Integration, Captive Portals, and Bandwidth Control

This guide provides a comprehensive framework for architecting enterprise-grade hotel WiFi networks. It details the technical requirements for VLAN segmentation, PMS integration via FIAS, captive portal design, and per-client bandwidth control to ensure security, compliance, and optimal performance.

6 mins read1k words
How to Configure SCEP for Automated Enterprise WiFi Certificate Enrollment
Security

How to Configure SCEP for Automated Enterprise WiFi Certificate Enrollment

This guide explains how to configure SCEP (Simple Certificate Enrollment Protocol) for automated enterprise WiFi certificate enrolment, covering the full architecture from PKI and NDES through to MDM profile deployment and RADIUS validation. It is aimed at IT managers, network architects, and CTOs at hotels, retail chains, stadiums, conference centres, and public-sector organisations who need to move beyond pre-shared keys and implement scalable, identity-based 802.1X EAP-TLS authentication. Purple's hardware-agnostic, cloud overlay platform integrates directly with this architecture, providing the guest and BYOD WiFi layer that sits alongside your certificate-authenticated staff network.

10 mins read2k words
Mean time to innocence: how to prove it's not the WiFi
Multi-Tenant WiFi

Mean time to innocence: how to prove it's not the WiFi

Mean time to innocence (MTTI) is the critical metric defining how long IT teams spend proving a network issue is not their fault. This guide details a five-step observability methodology to eliminate the blame game in multi-tenant environments, replacing finger-pointing with shared evidence to drive down mean time to resolution (MTTR).

6 mins read1k words
The Enterprise Guide to SCEP: Deploying Simple Certificate Enrollment Protocol for Automated Campus WiFi Security
Security

The Enterprise Guide to SCEP: Deploying Simple Certificate Enrollment Protocol for Automated Campus WiFi Security

This technical reference guide provides a definitive architectural blueprint and step-by-step implementation strategy for enterprise WiFi certificate deployment using SCEP. It covers the critical differences between SCEP and PKCS, the exact deployment sequence required for success, and real-world risk mitigation strategies for IT leaders.

6 mins read1k words
Why is my guest WiFi not connecting? Troubleshooting captive portal issues
Captive Portals

Why is my guest WiFi not connecting? Troubleshooting captive portal issues

This authoritative technical reference guide explains the underlying mechanics of captive portal detection and details the six primary failure modes that prevent guest WiFi from connecting. It provides IT managers and network architects with a practical troubleshooting framework to resolve HTTP redirect issues, DNS conflicts, and MAC randomisation challenges.

6 mins read1k words
How to Implement SCEP for Automated WiFi Certificate Enrollment
Security

How to Implement SCEP for Automated WiFi Certificate Enrollment

This guide explains how to implement SCEP (Simple Certificate Enrollment Protocol) for automated WiFi certificate enrollment across enterprise venues. It covers the full architectural blueprint - from PKI design and MDM integration to the mandatory three-step deployment sequence - and shows IT managers and network architects how to eliminate shared credentials, automate certificate lifecycle management, and satisfy PCI DSS and GDPR requirements at scale.

10 mins read2k words
Integrating WeChat Authentication with Guest WiFi Captive Portals
Captive Portals

Integrating WeChat Authentication with Guest WiFi Captive Portals

This guide explains how to integrate WeChat OAuth 2.0 authentication into enterprise guest WiFi captive portals. It covers the dual-platform registration requirements, scope selection for first-party data capture, network enforcement via RADIUS Change of Authorization, and compliance with GDPR and China's PIPL. Venue operators in hospitality, retail, and events will find concrete implementation steps, real-world case studies, and security hardening guidance to deploy WeChat login guest wifi at scale.

8 mins read2k words
Understanding Cisco SUDI: Hardware-Based Device Identity in Network Access Control
Security

Understanding Cisco SUDI: Hardware-Based Device Identity in Network Access Control

This guide details the technical architecture of Cisco SUDI, explaining how hardware-anchored identity secures network access control. It provides actionable implementation steps for IT leaders to deploy 802.1X EAP-TLS authentication and automate Zero Touch Provisioning across enterprise venues.

6 mins read1k words