Connectivity IPSec Guest Filtering Public Access Cradlepoint

Home  ›  Connectivity Beyond the Campus

Extending Secure Access into Public Locations

During COVID, the limitations of home connectivity became impossible to ignore. Some students simply did not have reliable internet access outside of school, regardless of device availability.

By this point, secure cellular connectivity was already proven on school buses. The architecture did not need to change. It only needed to be extended.

Solar-powered access units were deployed in public locations across the district. These units provided guest wireless access to students using district-issued devices. As with buses, cellular served only as transport. All traffic was tunneled back to centralized guest firewalls, where filtering and policy enforcement occurred.

Solar-powered community site providing filtered student access Wi-Fi tunneled via IPSec to centralized district enforcement over LTE
Figure 2 — Solar-powered community connectivity sites provide filtered student internet access over LTE, terminating IPSec tunnels at centralized PAN-OS enforcement to maintain consistent policy and logging.
Click the diagram to open the full-size PDF.

No permanent construction was required. No new security model was introduced. Students experienced the same access they would receive on campus, and operations teams managed these deployments using the same tooling already in place.

This phase reinforced an important lesson: once policy enforcement is centralized, where users connect becomes far less important than how traffic is handled.

Previous: Secure Internet Access on School Buses
Next: Cellular as Infrastructure for Site Resiliency