
High-band 5G struggles to penetrate buildings, and new base stations are expensive and hard to site. IDL integrates Wi-Fi into the operator's core network as an alternate radio access technology, delivering unified mobility, unified policy and unified authentication across both networks.
Proven at scale: over 100,000 access points deployed and managed across a Tier-1 operator's national converged 4G + Wi-Fi network.
Service providers are asked to make the hardest call at the worst possible moment — before a single access point is on a wall. Commit to a vendor stack and inherit lock-in. Commit to OpenWiFi and inherit its gaps in carrier authentication, billing and offload. IDL removes the fork. The same access point ships with either image: IDL's own carrier-grade firmware, or TIP OpenWiFi. The platform decision becomes a software decision — reversible, site by site, at no hardware cost.
Carrying a second software line is only cheap because of how the first one is built: the wireless stack is already split from the silicon beneath it, so a second image is another consumer of that boundary rather than a second product. See the platform architecture.
| IDL image | OpenWiFi image | |
|---|---|---|
| Firmware | IDL WLAN firmware, hardened across national carrier deployments | TIP OpenWiFi, tracking the upstream release train |
| Management | IDL NMP cloud platform, IAC controllers or CloudOS | Any CloudSDK-compatible controller — a third-party platform or your own build |
| Carrier integration | EAP-SIM/AKA, Passpoint, SoftGRE/EtherIP WAG, VoWiFi, per-user policy and billing | OpenWiFi standard feature set, integrated through your own controller and AAA |
| Provisioning | Controller discovery or cloud zero-touch provisioning | Zero-touch provisioning against your OpenWiFi controller |
| Multi-vendor | IDL stack end to end | Interoperable with any TIP OpenWiFi device and controller |
| Source | IDL-maintained | Open source — auditable by your own engineering team |
| Best fit | Networks that need carrier authentication, billing and 3GPP offload today | Estates where openness, auditability and controller freedom decide the tender |
Available on selected IDL Wi-Fi 6 and Wi-Fi 7 access points. Evaluation units and images are shipping now — ask us which models are qualified for your band plan and regulatory domain.
Two images should never mean two operations teams. IDL is extending NMP into a single management plane that carries both: the installed base keeps running exactly as it does today, new sites go open, and both appear in one operational view. Existing estate untouched, new capacity open, one place to look — that is the shape of the migration, and it is on the roadmap rather than a condition of starting.
Until then the open path is already unblocked: the OpenWiFi image runs under any CloudSDK-compatible controller, so you can start on a third-party platform, or your own, and consolidate later on your schedule.
Broadband providers are squeezed: subscribers now buy connectivity alone, margins are thinning, and session management still runs on fixed hardware. IDL separates the control and data planes of the BNG and extends the home LAN into the edge cloud — so operators can move beyond selling a dumb pipe. SD-Edge ships in two product forms, sharing one platform.
The ONT drops back to bridge mode and the gateway itself moves to the cloud. No access network rebuild, no truck roll.
Where the customer needs the box on their own premises, the same software functions are modularized and virtualized onto white-box hardware. Every department gets its own security profile — because not every group carries the same risk, and performance shouldn't be spent on policies a group doesn't need.
VNF service chains are built by drag-and-drop from templates and matched by VLAN range or 5-tuple. A single VNF can be referenced by many chains; DPI, security gateway, TDF, CGNAT, WAG, BNG and ACF converge onto one virtualized platform at ultra-low latency.
Deployment is your choice: bare metal, virtual machine (KVM, VMware, OpenStack), or public and private cloud — including hybrid.
Six things operators tell us matter: one line serving many purposes · zero access network rebuild · short activation cycle · flexible point-to-point expansion · low operational complexity · full autonomy and control.
Policy-driven segmentation normally arrives with a bill for a whole new equipment stack: competing fabrics expect every switch to come from one vendor. IDL takes a different route. Traffic is steered to policy enforcement nodes over a tunnel overlay, so the campus keeps the switches it already owns.
In production: a university town campus network, and a national campus deployment in Central Asia.
Small and medium businesses are being asked to digitize with none of the budget, none of the certified staff and none of the tolerance for complexity that legacy enterprise networking assumes. IDL collapses routing, switching, security and Wi-Fi management into a single software-defined platform.
The router-per-apartment habit quietly destroys the airwaves: dozens of SSIDs, beacons eating over half the available airtime, and neighbours' signals bleeding through walls. Residents respond by installing their own gear, which makes it worse for everyone. Enterprise-style per-device onboarding is no answer either — no resident wants a RADIUS workflow for a new TV.
Built for: apartments · student housing · senior and assisted living · townhouses.
Why property owners care: Wi-Fi becomes a billable utility like water or power — bundled into the lease or tiered as an upsell. Occupancy rises, churn and trouble tickets fall, and the same network carries the building's own systems: access control, surveillance, climate, door locks.
Every new IoT service arrives with its own radio and,usually, its own network. Door locks speak one protocol, safety buttons another, asset tags a third,thermostats plain Wi-Fi. Each lands as a parallel overlay with its own hubs, its own cable run, its own PoE ports, its own controller and its own support contract. In a hospital or a hotel that means opening the ceiling a second, third and fourth time — and paying for every one of those installs. IDL access points carry a PCIe expansion slot. The IoT radio goes inside the AP, not on a hub bolted up beside it. One site survey, one cable, one PoE port,one management plane — and the IoT layer can be added long after the Wi-Fi went in, by fitting a module rather than re-wiring a building.
Why it pays: one truck roll instead of four, cabling and PoE ports that aren't duplicated, and capital deferred until the service is actually sold — fit the module then. When the next protocol wins, it is a module, not a forklift. For property owners, IoT becomes a service line sitting on top of the Wi-Fi they were building anyway.
Traditional monitoring is single-signal and after-the-fact: it tells you something broke, once users have already noticed. IDL's AIOps platform ingests logs, metrics and external signals together, and reasons across them.
Security stopped being a box you bolt on at the perimeter. In every solution above it is already there: in the campus enforcement node, in the edge service chain, in the carrier Wi-Fi gateway filtering content for a family. IDL builds it in rather than selling it back to you.
This is the same gateway that anchors SD-Branch. Deployed at a branch it is an SD-WAN edge; deployed at a perimeter it is a next-generation firewall. One product, one policy model, one console.
Visibility is the prerequisite for every other control. The IDL DPI Engine is available as an embedded SDK and as a standalone probe, built on industry-leading deep packet inspection technology.
Around the engine, IDL builds what turns detection into product: the policy enforcement layer, unified policy push from the cloud platform to every gateway, and the application control, content filtering and parental control your subscribers actually touch.
Architecture notes, deployment references and technical documentation are available on request. Tell us which solution you're evaluating and we'll get the right material to you.
Talk to our team