Shield bolts onto every Purple Access network
Purple Access runs three kinds of network on one platform: open, secure and xPSK. Shield adds protective DNS after the connection. Nothing in Access changes except the DNS resolver, and from that moment every network carries its own policy.
- OpenGuest WiFi through a captive portalStrict, family-safe
- SecurePasspoint and OpenRoaming, staff on EAP-TLS with MDMThreat defence first
- xPSKThings, communities and concessionsSafeguarding per group
The three-SSID tie-in
Three networks, three policies, one layer
Access gets people and things online. Shield decides what each network can reach once they are on.
Network 1
Open
Guest WiFi through a captive portal.- Strict, family-safe categories
- Safe Search on Google, Bing and YouTube
- Ad blocking for faster pages
Network 2
Secure
Passpoint and OpenRoaming for provisioning and secure guest access, plus staff on EAP-TLS with MDM.- Threat defence first
- Command-and-control callbacks blocked
- Staff allow and block lists
Network 3
xPSK
PPSK, iPSK and EasyPSK for IoT, communities such as MDU, student accommodation and elderly care, and concessions in a mall.- Safeguarding per group
- A policy per VLAN
- Schedules by time of day
How the bolt-on works
Nothing changes in Access except the DNS resolver
Access runs the WiFi
Your SSIDs, captive portal, sign-in and identity stay exactly as they are in Purple Access.
Shield becomes the DNS resolver
Each network you want protected points its DNS at Shield, as a per-network setting or a DHCP change on your controller. No appliance, no firewall change.
Network settings
- SSID
- Guest WiFi
- DNS resolver
- Purple Shield
- Protective DNS
A per-network setting, or a DHCP change on your controller
Each network and VLAN gets its policy
Guests, staff, students, residents and paid tiers each carry their own categories, lists and schedules.
- OpenStrict, family-safeGuest WiFi through a captive portalOpen network tiersFree WiFiAd blocking on, streaming limited at busy timesPaid WiFiIts own rules, separate from the free tier
- SecureThreat defence firstPasspoint and OpenRoaming, staff on EAP-TLS with MDM
- xPSKSafeguarding per groupThings, communities and concessions
Schedule, per venue
Every device is covered
Everyone who joins through Access is protected by Shield, on any device, with nothing to install, from their first lookup.
Why add Shield to Access
The network you already run, made safer and faster
Duty of care
Harmful content stays off guest, student and resident networks.
A layer behind your firewall
Guest and BYOD devices a firewall agent never touches are covered too.
Faster, lighter networks
Pages load up to 500% faster and use up to 44% less data, which matters on shared or metered backhaul.
One platform, one supplier
It comes from the platform that already runs sign-in and analytics for your venues.
Questions about Shield and Access
Does adding Shield change my Access setup?
No. Your SSIDs, captive portal and sign-in stay in Purple Access. The one change is the DNS resolver on each network you want protected, set per network or as a DHCP change on your controller.
Can different SSIDs and VLANs have different policies?
Yes. Policies are set per SSID, VLAN and venue, and can change by time of day and day of week, so guest, staff, resident and paid networks each have their own rules.
Do I need new hardware to add Shield?
No. Shield works at the DNS layer, so there is no appliance to rack, no firewall change and nothing to install on devices.
Can I run Shield without Purple Access?
Yes. Shield runs standalone on any WiFi network. With Access it bolts onto every open, secure and xPSK network, with a policy per SSID, VLAN, venue and time of day.
Give every Access network the policy it needs, free for 30 days
Tell us which networks you run and who is on them. We map a policy to each one: guests, staff, students, residents and paid tiers. Then point one network at Shield and see what it stops for 30 days, before you pay anything. Running change control? We plan a pilot on one SSID with your team instead. No hardware, no agents on devices.
- We map your networksA Purple expert maps your networks, your venues and the people on each, and answers your questions on bypass, outages, data handling and integrations.
- You get a policy for each oneGuests, staff, students, residents and paid tiers, each with the policy it needs.
- You prove it, then get your tailored quote30 days free on one network, or a pilot on one SSID planned with your team, then Shield priced standalone or as an add-on to your Access plan.
Your policy map
Tell us your networks. We map a policy to each one.
A Purple expert comes back with a policy for every SSID you run, from the team that has run content filtering on WiFi since 2012 and runs WiFi for 80,000+ venues in 90 countries.