Wi-Fi Across NICNET

Design, Deploy & Operate

Rolling out wireless in a government setting is not the same as deploying it in a corporate office. The buildings are older, the user population is enormous and varied, the security requirements go well beyond what most enterprise policies cover, and the expectation is that it just works — for ministers, for clerks, for visiting delegates, and for the devices they bring through the door.

I've been responsible for end-to-end wireless services across NICNET for over a decade — which means I've seen what breaks, when it breaks, and why. The architecture we settled on is centralised controller-based, which makes large-scale management possible. Authentication runs on 802.1X with a RADIUS backend. For IoT and legacy devices that can't do 802.1X, we use Identity PSK (iPSK) — each device gets its own unique key without the management overhead of full 802.1X. Rogue AP containment runs continuously because in a shared government building, unauthorised APs get plugged in — and detecting them quickly matters.

I documented the methodology we developed in the TUNE INTO WLC handbook (ISBN 978-93-5419-656-0, Copyright L-97828/2020) so that teams across NIC could build on it rather than rediscovering the same lessons at every new site.

Project Information

  • Category: Enterprise Wi-Fi / WLAN
  • Network: NICNET
  • Org: National Informatics Centre
  • Auth: 802.1X / RADIUS + iPSK
  • Standards: 802.11 a/b/g/n/ac/ax
  • Handbook: TUNE INTO WLC
    ISBN 978-93-5419-656-0
  • Status: Operational

End-to-end wireless services across Government of India sites on NICNET — RF planning, centralized WLC architecture, 802.1X security, rogue AP containment, and the operational model that keeps it all running.

Scale & Reach

The deployment spans government offices, ministries, and NIC facilities across multiple states and union territories — ranging from small district-level offices to large multi-building campuses with hundreds of simultaneous users. The same architecture and operational playbook is designed to scale from a single building to a pan-India footprint without a redesign.

  • Pan-India coverage
  • Multi-site, multi-state
  • Single building to large campus
  • High-density user environments
  • Centralised management

Architectural Overview

Authentication runs on 802.1X with a RADIUS backend. For IoT and legacy devices that can't do 802.1X, we use Identity PSK (iPSK) — each device gets its own unique key without the management overhead of full 802.1X. Rogue AP containment runs continuously because in a shared government building, unauthorised APs get plugged in — and detecting them quickly matters.

I documented the methodology we developed in the TUNE INTO WLC handbook (ISBN 978-93-5419-656-0, Copyright L-97828/2020) so that teams across NIC could build on it rather than rediscovering the same lessons at every new site.

What the architecture handles

Capabilities and design considerations built into the deployment — independent of any single site's size.

Centralised Control

A controller-based architecture gives a single point of configuration, monitoring, and policy enforcement across every site — regardless of how many access points are connected.

802.1X / RADIUS Authentication

Staff devices authenticate via 802.1X against a RADIUS backend — no shared passphrases, no static credentials to leak or rotate manually.

Identity PSK (iPSK)

IoT and legacy devices that can't do 802.1X get their own unique pre-shared key per device — segmentation without the 802.1X overhead.

Rogue AP Containment

Continuous detection and containment of unauthorised access points — essential in buildings shared across multiple departments.

RF Planning & Channel Design

Predictive modelling and physical site surveys drive AP placement, channel assignment, and power levels — tuned for India's regulatory spectrum constraints.

Seamless Roaming

Users move between APs and buildings without re-authenticating — validated through dedicated roaming tests during deployment.

Segmented SSIDs & VLANs

Staff, guest, and IoT traffic are kept on separate logical networks by design — minimising blast radius if any one segment is compromised.

IPv6-Ready

The wireless architecture is built to carry IPv6 alongside IPv4, in line with the broader IPv6 rollout across NICNET.

Proactive Monitoring

Ongoing health monitoring, firmware lifecycle management, and capacity planning — so growth in user numbers doesn't surprise the network.

How a deployment happens

Five phases, every time — no exceptions.

01 Survey

Site survey & RF planning

Predictive modelling first, then a physical walkthrough. We map coverage, identify interference sources, and decide AP placement before a single cable is pulled.

02 Design

Architecture & security design

SSID structure, VLAN mapping, roaming domains, QoS policy, and authentication method — all decided before installation begins. Changes after the fact are expensive.

03 Deploy

Installation & configuration

AP mounting, cabling, WLC onboarding, RADIUS integration, and initial channel / power calibration. We follow the design — any deviations get documented.

04 Test

Validation & acceptance

Coverage walkthrough, roaming tests, 802.1X authentication tests, rogue AP containment test, and load simulation before handover.

05 Operate

Ongoing operations

Proactive monitoring, firmware management, capacity planning as user counts grow, rogue detection, and periodic re-surveys when the physical environment changes.

Certifications behind the work

Four CWNP certifications — earned because the knowledge mattered, not just for the badge.

A public example of this thinking

While NICNET deployment details aren't public, the same design principles — RF planning, channel reuse, density management, and authentication trade-offs — apply to any high-traffic public venue. I wrote up a teardown of one such environment based purely on publicly observable network behaviour.

Read: Analysis of IGI Airport T3 Wi-Fi Setup →

Related Technical Research Logs

Posts that grew directly out of this work.