Designing and securing a Wi-Fi network
Wi-Fi has become the default access network: workstations, mobiles, industrial equipment and connected objects all travel over it. Badly sized, it hampers daily work; badly separated, it offers access to the heart of the information system from the car park.
An access network in its own right, not an accessory
Two distinct problems are often confused. The first is physical: insufficient coverage, badly placed access points, interference or capacity unsuited to the real density of users. It is not solved by adding access points at random — that usually makes things worse.
The second is a security problem: a shared key everybody knows, a guest network that reaches the internal network, connected objects on the same segment as the servers, or no certificate-based authentication. Wi-Fi then becomes the easiest way in.
We address both together: a predictive study on floor plans, validated by on-site measurements, determines placement and sizing; the authentication and segmentation architecture guarantees that each population reaches only what concerns it. The result is verified by a wireless penetration test.
- Dead zones and drop-outs when moving around
- Capacity saturated at peak times
- A shared key everybody knows, never renewed
- Guest network able to reach the internal network
- Connected objects not separated from the information system
Cover without gaps, separate without exception
How we proceed
A study on floor plans first, measurements on site next: the model gives direction, the field decides.
Needs and constraints
Gathering the real uses — density, mobility, latency-sensitive applications, specific hardware — and the building constraints: materials, ceiling heights, areas to cover or deliberately to exclude.
Predictive survey
Modelling propagation on the floor plans, with a first placement of access points, a choice of transmit power and channels, and an estimate of capacity per area.
On-site survey
Measurements on site to test the model against reality: received levels, signal-to-noise ratio, interference and actual overlap between cells. The plan is adjusted on that basis.
Architecture and segmentation
Certificate-based authentication (802.1X) for employees, an isolated portal for guests, a dedicated segment for connected objects and industrial equipment, with explicit filtering rules between segments.
Validation and documentation
A wireless penetration test to verify the separation and the robustness of the authentication, then delivery of the coverage plan, the configurations and the operating rules.
Several disciplines, a single point of contact
Radio study, integration and offensive validation: the design and its verification are carried out by the same team.
- Predictive survey report (modelling on floor plans)
- On-site survey report and field measurements
- Coverage plan: placement, channels and transmit power
- Authentication and segmentation architecture
- Wireless penetration test report and recommendations
Frequently asked questions
Wi-Fi that covers and separates?
A coverage study and a segmentation review give both answers quickly. Let's talk.