Atlas Wireless
Enterprise Wi-Fi Infrastructure
WPA3-Enterprise Wi-Fi with certificate auth and a VLAN per SSID — no shared password on the wall, running on hardware you own.
Why this exists
Without Atlas Wireless
The office Wi-Fi uses WPA2-PSK with a shared password written on the wall. Guest and corporate devices share the same SSID. The BYOD laptop with adware is on the same network as the finance server. A rogue AP installed by an employee has been bridging traffic to a mobile hotspot for 6 months — nobody noticed.
With Atlas Wireless
WPA3-Enterprise with EAP-TLS means every user authenticates with a certificate — the shared PSK is gone. Corporate, IoT, and Guest SSIDs are separate VLANs with firewall rules. The MikroTik CAPsMAN controller manages every AP from one plane — switches and APs stay on a single vendor with no cloud-account dependency. RouterOS native WIDS watches for rogue APs and triggers an alert to Atlas Observe within minutes. Every connected device is visible centrally, and firmware is pushed from the controller.
Architecture
Regulatory compliance
| Regulation / Control | Requirement | Audit evidence |
|---|---|---|
| NIS2 Art. 21(2)(d) | VLAN-per-SSID prevents guest and IoT from accessing corporate resources | CAPsMAN SSID to VLAN mapping export · inter-VLAN firewall log |
| BSI WLAN.1 | WPA3-Enterprise with EAP-TLS, WIDS rogue AP detection, centralised management | RouterOS WIDS log · WPA3 policy config export · SSID audit |
| BSI INF.1.2 | All APs managed, authorised, and monitored — no rogue devices | CAPsMAN AP inventory · provisioning log · firmware version report |
| GDPR Art. 32(1)(d) | WIDS provides ongoing wireless security assessment | RouterOS WIDS alert history · rogue AP detection log |
| NIS2 Art. 21(2)(i) | WPA3-Enterprise with 802.1X ensures only authenticated users access Wi-Fi | FreeRADIUS accounting log · EAP-TLS certificate audit |
| DORA Art. 9(4)(b) | Multiple APs provide wireless HA with no single point of failure | CAPsMAN uptime report · AP failover test log |
Standalone installation
Each component can be deployed independently. Download the Customer Request Form, describe your environment, and we quote within 2 business days.
CAPsMAN controller — standalone deploy
MikroTik CAPsMAN controller on RouterOS / CHR. Provision up to 10 MikroTik cAP ax / hAP ax³ APs. Corporate SSID (WPA3) + guest SSID. VLAN-per-SSID. RouterOS native WIDS enabled. Centralised firmware updates.
€ 490
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteGuest Wi-Fi + captive portal
Isolated guest SSID on VLAN 30. MikroTik hotspot portal with custom branding. GDPR-compliant usage notice with consent. Bandwidth limits per device. Internet only — no internal resources.
€ 330
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteWi-Fi site survey
On-site RF survey up to 500m² (single floor). Signal heatmap. Dead zone identification. AP placement recommendation. Channel plan. Expected throughput estimates.
€ 540
Net, excl. VAT · travel within 100km Hamburg · hardware not included
Download CRF & request quoteReady-made boxes
Three boxes, three fixed prices. Each one ships pre-configured and pre-hardened: you power it up, work through a short quick-start guide, and it runs. No audit, no project phase, no consulting engagement required. Need it fitted into an existing environment instead? See the consulting packages below.
5–50 users · 1 site · single server
€ 1,590
Net, excl. VAT · one-off fixed price · hardware not included
50–500 users · 1–5 sites · HA-ready
€ 2,120
Net, excl. VAT · one-off fixed price · hardware not included
500+ users · multi-site · cluster-ready
€ 2,760
Net, excl. VAT · one-off fixed price · hardware not included
Consulting services
The boxes are built to run on their own. When you want one fitted into what you already have, add a fixed-price package — no open-ended day rates.
Installation & handover
We install the box in your environment, connect it to your network and DNS, and hand it over configured and documented. Remote, or on-site within 100 km of Hamburg.
€ 890
Net, excl. VAT · fixed price
Request this packageIntegration into your environment
Connecting the box to what you already run — Active Directory, an existing DNS or firewall, your monitoring or SIEM — including migration of existing data.
€ 1,890
Net, excl. VAT · fixed price
Request this packageCompliance mapping & audit support
We map the delivered configuration to NIS2, BSI IT-Grundschutz or DORA controls and hand over the evidence package your auditor will ask for.
€ 1,490
Net, excl. VAT · fixed price
Request this packageCopyright © XpertOne Security Consulting GmbH. All Rights Reserved. | Impressum | Datenschutz