Universal
Access Platform.

One access point that attaches to any control plane and runs either software stack — and one console over all of it.

One solution does not fit all

Wireless complexity does not grow with the number of access points. It grows with what has to move between them.

A single-site office needs a controller in the same box as its firewall. A multi-site retailer needs policy that follows the branch. A campus or a carrier network needs client mobility across thousands of APs and VLANs, with authentication and forwarding that never centralize into a bottleneck. These are not three sizes of the same requirement — they are three different architectures.

The industry's usual answer is three different product lines, three firmware trees and three operations teams. Ours is one access point that speaks to all of them.

IntegratedController, firewall, routing and PoE in one box, sitting at the edge of a single site. Nothing to install, nothing to size.
Cloud-managedAPs report directly to the cloud with no on-premise control plane at all. The lightest possible footprint per site.
Dedicated controllerA purpose-built WLAN controller for density, mobility and carrier-grade authentication. Appliance, VM or cloud.

Universal AP

Every access point connects to every control plane — automatically or by choice

An IDL access point discovers and attaches to whichever control plane it finds, and an administrator can redeploy it to a different one at any time. No separate firmware image, no re-flash to a different product line, no change to the code running on the box. The AP you bought for a branch office can be redeployed into a campus fabric on Monday and into a carrier network on Friday.

What that buys an operator

  • Inventory that does not fragment — one part number covers every architecture you sell into, so stock, spares and RMA pools stay pooled instead of splitting per segment
  • Architecture decided after the sale — quote the hardware before the customer has settled on centralized or cloud management, and let the site's requirements pick the control plane later
  • One qualification, one certification cycle — regulatory approval, interop testing and internal acceptance are done once per model, not once per deployment model
  • Growth without replacement — a site that outgrows its integrated gateway moves to a dedicated controller by re-pointing the APs, not by replacing them

Under the hood

A chipset abstraction layer is why a single build can span three silicon vendors

Wi-Fi features are usually written against a silicon vendor's driver, which is why most vendors end up with a separate firmware tree per chipset and features that land on one platform months before another.

IDL splits the wireless stack in two. An upper MAC layer holds the feature set — roaming, policy, security, radio resource management — and knows nothing about silicon. Beneath it, a thin abstraction layer maps that feature set onto each vendor's driver.

A feature is written once, above the line, and appears on every platform at the same time. Adding a new chipset means writing one adapter, not re-implementing a product.

This is also what makes the second software line cheap to carry: the same separation that lets one firmware span three silicon vendors is what lets an IDL access point ship a TIP OpenWiFi image as an alternative to our own — see OpenWiFi · Dual-Image AP.

NMP

The other half of the story — one cloud console across every product and every scenario

A universal access point solves the device side. It does not, on its own, stop an operator from running four consoles: one for the carrier network, one for the campus estate, one for the branches and one for whatever the home team deployed. NMP is the single management plane over all of it — the access points, the switches, the gateways, the controllers and the home routers, in every scenario they are deployed into.

Four things it does

Platform managementInventory, configuration, service definition, users, roles and permissions — the administrative layer under everything else.
OperationsWireless monitoring, alarms, network diagnostics and reporting, with AIOps turning raw telemetry into a root cause rather than another dashboard.
InsightUsage, user behaviour and application analytics, segmented by time and by zone — the data an operator needs to price and package a service.
Security auditVenue management, status monitoring, audit trails and third-party or regulatory data exchange, for deployments that have to answer to someone.

What makes it different from a vendor cloud

  • You choose where it runs — public cloud, your private cloud, or plain x86 servers in your own data centre. A managed network should not require handing your operational data to a vendor's SaaS as a condition of managing your own equipment
  • Multi-tenant and domain-scoped by design — multi-user, multi-role, hierarchical administration, so a service provider can run many customers, and a customer can delegate a site without handing over the estate
  • Open API rather than an export button — statistics, service configuration and raw data APIs, with application registration, API scoping and data-range control, so your own BSS/OSS drives the network instead of your staff re-typing into it
  • Built to hold the volume — Docker on Linux, distributed storage across NoSQL, SQL and Redis, and a Spark processing engine, because carrier-scale telemetry is a data problem before it is a networking one

The full NMP feature list is in the software capabilities section below, and the product entry is on the products page.

Which control plane, at which scale

The same access point, positioned differently

SegmentUsersAccess pointsTypical control plane
Home1–91–8miniAC + AP, or a standalone router
Micro business10–1001–8Cloud + smart AP, no on-premise controller
Small business100–2001–16Cloud + miniAC + AP
Mid and large enterprise200–1,00016–1,000Cloud + dedicated AC + AP
Carrier>1,000>1,000Cloud + dedicated AC + AP
Smart city>1,000>1,000MSG + AP + switching

Indicative sizing. Density, roaming behaviour and authentication method move these boundaries more than raw client count does — talk to us with a floor plan rather than a headcount.

Software capabilities

Four layers, one architecture — from the radio to the cloud API

What follows is the shipping feature set at each layer. Items marked roadmap are in development and are called out rather than blended in — if a capability decides your tender, ask us for its current status in writing.

Universal AP · enterprise Wi-Fi

Runs on the access point itself, in every deployment model.

  • Controller and controller-less operation
  • Multiple PSK for WPA2 / WPA3-Personal
  • Fast roaming — 802.11k/v and Client Match
  • Zero-wait DFS with fallback
  • Dual image with automatic rollback
  • Captive portal and rogue suppression
Full access point feature list
Access and identity
  • Controller and controller-less support
  • Multiple PSK for WPA2 / WPA3-Personal
  • Protected management frames
  • Opportunistic key caching (with WLC)
  • Captive portal
  • SSID scheduling
  • Hotspot 2.0 (with WLC) roadmap
Radio and mobility
  • Fast roaming — 802.11k/v and Client Match
  • Automatic channel selection
  • Frequency and AP load balancing
  • Channel utilization (duty-cycle measurement)
  • Spectrum analysis
  • DFS fallback (zero-wait DFS)
  • TX beamforming
  • Mesh networking (EasyMesh) roadmap
Traffic and quality
  • QoS profiles per SSID and per client
  • WMM access control
  • Broadcast and multicast management
  • Probe response suppression
  • 802.3az energy-efficient Ethernet
  • Remote APs (L2TP over BCP)
Security and resilience
  • Rogue detection and suppression
  • WIDS (with WLC)
  • DoS attack prevention
  • Dual image with automatic rollback
  • Location tracking (RTLS)
  • Onboard BT / BLE roadmap

Integrated edge · miniAC and ISG

Controller, security and routing converged into the gateway at a single site or branch. This is the software behind SD-Edge and SD-Branch.

  • WLAN control and policy in the same box as the firewall
  • Application control through the IDL DPI engine
  • SD-WAN with policy-based routing
  • Loadable services in Docker containers at the edge
  • Central provisioning from NMP
  • Integrated PoE switching
Full integrated edge feature list
Operation
  • Dashboard and configuration
  • Diagnostics
  • Log and report
  • Central management and provisioning
  • AIOps
  • Loadable services (Docker)
  • Closed-loop automation roadmap
Wireless and policy control
  • Wireless controller
  • Roaming (Client Match)
  • Access control
  • Spectrum analysis
  • AAA
  • Local portal
Security
  • Firewall
  • Device identification
  • Application control (DPI)
  • VPN
  • IPS
  • Anti-virus roadmap
  • URL and email filtering roadmap
  • DLP roadmap
  • Security as a service roadmap
Networking and switching
  • SD-WAN
  • IPv4 / IPv6
  • L2 switching
  • Routing and NAT
  • PoE
  • CPE and multi-WAN roadmap

WLAN controller · campus, carrier and smart city

The dedicated control plane, shipped as an x86 appliance, a virtual system or from the cloud — the same software in all three forms. This is the software behind SD-Access.

  • Portal authentication with PPSK, AD, LDAP and social identity
  • Centralized or local forwarding, chosen per policy
  • High availability and large-scale roaming
  • Hotspot 2.0
  • VPN — IPsec, GRE and SoftGRE tunnelling
  • Appliance, VM or cloud from one image
Full controller feature list
Operation and visibility
  • CLI and web UI
  • Configuration management
  • Monitoring
  • Diagnostics
  • Log and report
  • Systems integration (SNMP)
  • Central management and provisioning
  • Automation
Policy and control
  • Policy objects
  • Device identification
  • Portal authentication (PPSK, social, AD, LDAP)
  • AAA
  • Policy-based routing
  • Centralized and local forwarding
Security
  • VPN — IPsec, SoftGRE, GRE tunnel
  • Offline inspection
Essential network services
  • WLAN
  • IPv4 / IPv6
  • High availability
  • Broadcast suppression
  • Roaming
  • QoS
  • Routing, NAT and OSPF
  • L2 and L3 switching
  • Hotspot 2.0

NMP · the cloud management plane

One view over every control plane below it, and an open API surface so the network becomes something your own systems can drive.

  • Multi-tenant, multi-role management with delegated administration
  • Wireless monitoring, alarms and network diagnostics
  • User and traffic analytics with time and zone segmentation
  • Security audit and venue management
  • Open APIs for statistics, configuration and raw data
  • Deployable on x86, private cloud or public cloud
Full cloud platform feature list
Platform management
  • Resource inventory and statistics
  • Configuration management
  • Service management
  • User management
  • Role and permission control
  • System management
Operations
  • Operations overview
  • Wireless monitoring
  • Service management
  • Report management
  • Network diagnostics
  • Alarm management
Insight and audit
  • Usage overview and statistics
  • User behaviour analytics
  • Traffic and application analytics
  • Time and zone segmentation
  • Venue management
  • Status monitoring and security audit
  • Third-party security and regulatory data exchange
Open API and foundation
  • Statistics API
  • Service configuration API
  • Raw data API
  • Application registration and authorization
  • API creation, scoping and data-range control
  • Linux and Docker on x86, private or public cloud
  • Distributed storage — NoSQL, SQL and Redis
  • Spark data processing engine
  • SDN control and interaction interface

Two axes of choice, not one

The control plane is yours to pick. So is the software stack.

Which control plane?miniAC, ISG, MSG or a cloud AC — decided per site, changed by re-pointing the access point rather than replacing it.
Which software stack?IDL's own carrier-grade firmware, or a TIP OpenWiFi image on the same hardware — decided per estate, reversible as a firmware operation.OpenWiFi · Dual-Image AP →

Most vendors ask a customer to settle both questions at procurement, then charge them in hardware when the answer changes. We would rather sell the hardware once and let the answers keep moving.

Evaluating an architecture, not just a datasheet?

Deployment references, capability status in writing, and access to an evaluation unit are available on request. Tell us the scale and the control plane you have in mind.

Talk to our team

Let's talk about the network you're building.