Services
Partners
Use cases
Clients
Company
Contact
FRENDE
Wi-Fi & coverage

Designing and securing a Wi-Fi network

Wi-Fi has become the default access network: workstations, mobiles, industrial equipment and connected objects all travel over it. Badly sized, it hampers daily work; badly separated, it offers access to the heart of the information system from the car park.

The challenge

An access network in its own right, not an accessory

Two distinct problems are often confused. The first is physical: insufficient coverage, badly placed access points, interference or capacity unsuited to the real density of users. It is not solved by adding access points at random — that usually makes things worse.

The second is a security problem: a shared key everybody knows, a guest network that reaches the internal network, connected objects on the same segment as the servers, or no certificate-based authentication. Wi-Fi then becomes the easiest way in.

We address both together: a predictive study on floor plans, validated by on-site measurements, determines placement and sizing; the authentication and segmentation architecture guarantees that each population reaches only what concerns it. The result is verified by a wireless penetration test.

What is at stake
  • Dead zones and drop-outs when moving around
  • Capacity saturated at peak times
  • A shared key everybody knows, never renewed
  • Guest network able to reach the internal network
  • Connected objects not separated from the information system
Diagram

Cover without gaps, separate without exception

Wi-Fi coverage and network segmentation COVERAGE & CAPACITY AP 1AP 2AP 3AP 4 SEGMENTATION Employees802.1X · certificateGuestsportal · isolatedIoT / OTdedicated VLAN
Cells overlap to allow roaming; each population has its own logical network and its own level of access.
Our approach

How we proceed

A study on floor plans first, measurements on site next: the model gives direction, the field decides.

01

Needs and constraints

Gathering the real uses — density, mobility, latency-sensitive applications, specific hardware — and the building constraints: materials, ceiling heights, areas to cover or deliberately to exclude.

02

Predictive survey

Modelling propagation on the floor plans, with a first placement of access points, a choice of transmit power and channels, and an estimate of capacity per area.

03

On-site survey

Measurements on site to test the model against reality: received levels, signal-to-noise ratio, interference and actual overlap between cells. The plan is adjusted on that basis.

04

Architecture and segmentation

Certificate-based authentication (802.1X) for employees, an isolated portal for guests, a dedicated segment for connected objects and industrial equipment, with explicit filtering rules between segments.

05

Validation and documentation

A wireless penetration test to verify the separation and the robustness of the authentication, then delivery of the coverage plan, the configurations and the operating rules.

Services involved

Several disciplines, a single point of contact

Radio study, integration and offensive validation: the design and its verification are carried out by the same team.

Deliverables
  • Predictive survey report (modelling on floor plans)
  • On-site survey report and field measurements
  • Coverage plan: placement, channels and transmit power
  • Authentication and segmentation architecture
  • Wireless penetration test report and recommendations
Frequently asked questions

Frequently asked questions

They complement each other. The predictive study lets you design before the works and avoid costly mistakes; the on-site one validates in the field, where materials and interference often hold surprises. For an existing building we recommend both.

Not necessarily — it is often counterproductive. Too many badly tuned access points interfere with each other and degrade throughput. Correct tuning is as much about transmit power and channels as about the number of devices.

For a properly isolated guest network, possibly. For employees, no: a shared key cannot be invalidated when someone leaves and provides no traceability. Certificate-based authentication (802.1X) answers both problems.

On a dedicated segment, with explicit filtering rules towards the rest of the network. Many of these devices do not support strong authentication: separation and flow control compensate for that limitation.

Wi-Fi that covers and separates?

A coverage study and a segmentation review give both answers quickly. Let's talk.