Senior IT Leader
Wi-Fi Across NICNET
Design, Deploy & Operate
Rolling out wireless in a government setting is not the same as deploying it in a corporate office. The buildings are older, the user population is enormous and varied, the security requirements go well beyond what most enterprise policies cover, and the expectation is that it just works — for ministers, for clerks, for visiting delegates, and for the devices they bring through the door.
I've been responsible for end-to-end wireless services across NICNET for over a decade — which means I've seen what breaks, when it breaks, and why. The architecture we settled on is centralised controller-based, which makes large-scale management possible. Authentication runs on 802.1X with a RADIUS backend. For IoT and legacy devices that can't do 802.1X, we use Identity PSK (iPSK) — each device gets its own unique key without the management overhead of full 802.1X. Rogue AP containment runs continuously because in a shared government building, unauthorised APs get plugged in — and detecting them quickly matters.
I documented the methodology we developed in the TUNE INTO WLC handbook (ISBN 978-93-5419-656-0, Copyright L-97828/2020) so that teams across NIC could build on it rather than rediscovering the same lessons at every new site.
Project Information
- Operational
End-to-end wireless services across Government of India sites on NICNET — RF planning, centralized WLC architecture, 802.1X security, rogue AP containment, and the operational model that keeps it all running.
Scale & Reach
The deployment spans government offices, ministries, and NIC facilities across multiple states and union territories — ranging from small district-level offices to large multi-building campuses with hundreds of simultaneous users. The same architecture and operational playbook is designed to scale from a single building to a pan-India footprint without a redesign.
- Pan-India coverage
- Multi-site, multi-state
- Single building to large campus
- High-density user environments
- Centralised management
Architectural Overview
Authentication runs on 802.1X with a RADIUS backend. For IoT and legacy devices that can't do 802.1X, we use Identity PSK (iPSK) — each device gets its own unique key without the management overhead of full 802.1X. Rogue AP containment runs continuously because in a shared government building, unauthorised APs get plugged in — and detecting them quickly matters.
I documented the methodology we developed in the TUNE INTO WLC handbook (ISBN 978-93-5419-656-0, Copyright L-97828/2020) so that teams across NIC could build on it rather than rediscovering the same lessons at every new site.
What the architecture handles
Capabilities and design considerations built into the deployment — independent of any single site's size.
Centralised Control
A controller-based architecture gives a single point of configuration, monitoring, and policy enforcement across every site — regardless of how many access points are connected.
802.1X / RADIUS Authentication
Staff devices authenticate via 802.1X against a RADIUS backend — no shared passphrases, no static credentials to leak or rotate manually.
Identity PSK (iPSK)
IoT and legacy devices that can't do 802.1X get their own unique pre-shared key per device — segmentation without the 802.1X overhead.
Rogue AP Containment
Continuous detection and containment of unauthorised access points — essential in buildings shared across multiple departments.
RF Planning & Channel Design
Predictive modelling and physical site surveys drive AP placement, channel assignment, and power levels — tuned for India's regulatory spectrum constraints.
Seamless Roaming
Users move between APs and buildings without re-authenticating — validated through dedicated roaming tests during deployment.
Segmented SSIDs & VLANs
Staff, guest, and IoT traffic are kept on separate logical networks by design — minimising blast radius if any one segment is compromised.
IPv6-Ready
The wireless architecture is built to carry IPv6 alongside IPv4, in line with the broader IPv6 rollout across NICNET.
Proactive Monitoring
Ongoing health monitoring, firmware lifecycle management, and capacity planning — so growth in user numbers doesn't surprise the network.
How a deployment happens
Five phases, every time — no exceptions.
01 Survey
Site survey & RF planning
Predictive modelling first, then a physical walkthrough. We map coverage, identify interference sources, and decide AP placement before a single cable is pulled.
02 Design
Architecture & security design
SSID structure, VLAN mapping, roaming domains, QoS policy, and authentication method — all decided before installation begins. Changes after the fact are expensive.
03 Deploy
Installation & configuration
AP mounting, cabling, WLC onboarding, RADIUS integration, and initial channel / power calibration. We follow the design — any deviations get documented.
04 Test
Validation & acceptance
Coverage walkthrough, roaming tests, 802.1X authentication tests, rogue AP containment test, and load simulation before handover.
05 Operate
Ongoing operations
Proactive monitoring, firmware management, capacity planning as user counts grow, rogue detection, and periodic re-surveys when the physical environment changes.
Certifications behind the work
A public example of this thinking
While NICNET deployment details aren't public, the same design principles — RF planning, channel reuse, density management, and authentication trade-offs — apply to any high-traffic public venue. I wrote up a teardown of one such environment based purely on publicly observable network behaviour.
Read: Analysis of IGI Airport T3 Wi-Fi Setup →Related Technical Research Logs
Posts that grew directly out of this work.
-
Analysis of IGI Airport T3 Wi-Fi Setup[cite: 5] Real-world teardown of enterprise Wi-Fi in a high-density venue — Oct 2016[cite: 5]
-
Identity PSK (iPSK)[cite: 5] Per-device PSK without the overhead of full 802.1X — Jul 2021[cite: 5]
-
WLAN Channel Availability in India[cite: 5] Which 5 GHz channels are usable in India and why — Dec 2021[cite: 5]
-
MIMO — Multiple Input Multiple Output[cite: 5] How spatial multiplexing changed Wi-Fi throughput — Sep 2020[cite: 5]
-
Common Terms Used in Wireless[cite: 5] The glossary that comes up constantly in enterprise wireless — Aug 2020[cite: 5]