Atlas Wireless
Enterprise Wi-Fi Infrastructure
WPA3-Enterprise Wi-Fi with certificate auth and a VLAN per SSID — no shared password on the wall, running on hardware you own.
Why this exists
Without Atlas Wireless
The office Wi-Fi uses WPA2-PSK with a shared password written on the wall. Guest and corporate devices share the same SSID. The BYOD laptop with adware is on the same network as the finance server. A rogue AP installed by an employee has been bridging traffic to a mobile hotspot for 6 months — nobody noticed.
With Atlas Wireless
WPA3-Enterprise with EAP-TLS means every user authenticates with a certificate — the shared PSK is gone. Corporate, IoT, and Guest SSIDs are separate VLANs with firewall rules. The MikroTik CAPsMAN controller manages every AP from one plane — switches and APs stay on a single vendor with no cloud-account dependency. RouterOS native WIDS watches for rogue APs and triggers an alert to Atlas Observe within minutes. Every connected device is visible centrally, and firmware is pushed from the controller.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(d) | VLAN-per-SSID prevents guest and IoT from accessing corporate resources | CAPsMAN SSID to VLAN mapping export · inter-VLAN firewall log |
| BSI WLAN.1 | WPA3-Enterprise with EAP-TLS, WIDS rogue AP detection, centralised management | RouterOS WIDS log · WPA3 policy config export · SSID audit |
| BSI INF.1.2 | All APs managed, authorised, and monitored — no rogue devices | CAPsMAN AP inventory · provisioning log · firmware version report |
| GDPR Art. 32(1)(d) | WIDS provides ongoing wireless security assessment | RouterOS WIDS alert history · rogue AP detection log |
| NIS2 Art. 21(2)(i) | WPA3-Enterprise with 802.1X ensures only authenticated users access Wi-Fi | FreeRADIUS accounting log · EAP-TLS certificate audit |
| DORA Art. 9(4)(b) | Multiple APs provide wireless HA with no single point of failure | CAPsMAN uptime report · AP failover test log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
CAPsMAN controller — standalone deploy
MikroTik CAPsMAN controller on RouterOS / CHR. Provision up to 10 MikroTik cAP ax / hAP ax³ APs. Corporate SSID (WPA3) + guest SSID. VLAN-per-SSID. RouterOS native WIDS enabled. Centralised firmware updates.
€ 890
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGuest Wi-Fi + captive portal
Isolated guest SSID on VLAN 30. MikroTik hotspot portal with custom branding. GDPR-compliant usage notice with consent. Bandwidth limits per device. Internet only — no internal resources.
€ 590
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteWi-Fi site survey
On-site RF survey up to 500m² (single floor). Signal heatmap. Dead zone identification. AP placement recommendation. Channel plan. Expected throughput estimates.
€ 790
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteFull integration
Full integration starts with a 2–3 week audit. XpertOne maps your existing environment, identifies gaps, and produces a fixed-price statement of work. On-site engineer included for the full integration period.
5–50 users · 1 site · 1 month on-site
from € 9,600
Net, excl. VAT · fixed price scoped by audit
50–500 users · multi-site · 3 months on-site
from € 24,000
Net, excl. VAT · fixed price scoped by audit
500+ users · multi-site · 6 months on-site
from € 54,000
Net, excl. VAT · fixed price scoped by audit
All integration engagements begin with a 2–3 week technical audit. The audit is a paid engagement producing a gap analysis, architecture recommendation, and fixed-price statement of work.
Request audit engagementCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz