Immunity Networks designs, manufactures and supports the complete enterprise wireless stack — NetWave Wi-Fi 6 access points, NetForce PoE switching, the NetGuard X5 controller and NetCloud Central management. One Indian OEM, one support line, no integration gaps between layers.
Request a network design consultation See a deployment case study
Most enterprise wireless problems are not radio problems. They are design and ownership problems that surface only once the network is carrying real users.
Access points placed to a grid rather than to an RF survey leave dead zones exactly where people work — stairwells, lift lobbies, shielded rooms and long corridors. Dense construction and metal racking change propagation far more than a floor plan suggests.
A site can show full signal everywhere and still collapse when three hundred people arrive at once. Coverage is about reach; capacity is about how many clients each radio can serve at usable throughput. Conference halls, lecture theatres and boarding gates are capacity problems wearing a coverage costume.
Users walking between floors or buildings should not lose a call or a session. Roaming behaviour depends on controller configuration and consistent policy across every access point — which is difficult when APs and controller come from different vendors on different firmware cycles.
A typical deployment ends up with access points from one vendor, switches from another, a firewall from a third and a captive portal from a fourth. Each has its own licence renewal, support contract and finger to point when something breaks. Accountability disappears precisely when you need it.
| Layer | Product | What it does |
|---|---|---|
| Wireless | NetWave Lotus Alpha | Wi-Fi 6 access points — indoor AX820 and ruggedised outdoor AX821 |
| Access & power | NetForce Switches | Managed L2/L3 PoE switching with VLAN segmentation enforced in hardware |
| Control & security | NetGuard X5 Controller | Gateway security, wireless control, captive portal and billing in one appliance |
| Management | NetCloud Central | AIOps cloud console, zero-touch provisioning and remote operations |
Because all four layers come from the same OEM, policy is consistent, firmware is tested together, and there is a single accountable party for the whole network.
Most networks run a separate firewall, wireless controller, captive portal and billing server. The NetGuard X5 converges those functions into a single appliance — fewer boxes to licence, fewer support contracts and fewer failure points.
There are situations where separate appliances remain the better answer, and we say so. Read the honest comparison →
Every vertical stresses the network differently. These pages cover the specific requirements, constraints and design decisions in each.
Immunity Networks has designed and manufactured networking equipment since 2009 at our facility in Sanand GIDC, Gujarat. For buyers, Indian manufacturing changes three practical things: lead times are not hostage to import cycles, hardware and firmware can be adapted for specific deployments, and engineering support sits in the same time zone as your network.
Our equipment is MTCTE certified (and CE, FCC & RoHS compliant), with products listed on the Trusted Telecom Portal. Immunity also holds WPC approval, an IEEE OUI and an IANA PEN. Certification status varies by model and changes over time — ask us for current certification status on the specific models in your design and we will confirm in writing.
Immunity networks run in airports, hospitals, hotels, campuses, public Wi-Fi and rural connectivity. Client names, logos and specific performance figures are shared under NDA on request.
It depends on client density and construction far more than on floor area. A useful starting point is to size for the busiest hour rather than the average, then validate with a survey. We size this as part of the design consultation.
Yes. NetWave access points are standards-based and will run on third-party PoE switching. Using NetForce switches alongside them simplifies VLAN policy and gives you one vendor for support, but it is not a requirement.
Our equipment is MTCTE certified (and CE, FCC & RoHS compliant), with products listed on the Trusted Telecom Portal. Ask us for current certification status on specific models.
No. The network can be managed on-premises through the NetGuard X5 controller, or from the cloud through NetCloud Central. Many customers run both — local control with central visibility across sites.
Support comes directly from the OEM, with India-based engineers. Because Immunity manufactures the hardware, escalations do not have to travel through an overseas vendor.
Tell us about your buildings, user numbers and any segregation or compliance requirements. Our engineers will recommend a design and send datasheets, usually within one business day.
Most disappointing deployments were sized by area. A quote that says "one access point per 2,000 square feet" is a guess dressed as a method. We size against the three variables that actually determine performance.
A 200-person office does not have 200 devices. It has laptops, phones, tablets, printers, IP handsets, cameras, door controllers and sensors — frequently three or four connected endpoints per person. Peak concurrency is what the radios have to carry, and it is usually far higher than the staff list suggests.
Fifty people reading email is not the same load as fifty people on video calls. Applications drive throughput requirements per client, and video conferencing has changed the baseline permanently. We ask what runs on the network before deciding how many access points it needs.
Reinforced concrete, metal partitions, lift shafts, shielded imaging rooms, cold-storage panels and full racking all attenuate signal in ways a floor plan does not show. This is why we survey rather than assume — the same layout in two different buildings can need materially different access point counts.
The output is a design document: access point count and placement, channel and power plan, PoE budget, switching requirements, VLAN and policy design, and the management model. You can put that out to tender if you wish. We would rather you bought on a design that works than on the lowest headline price.
On most enterprise networks, several classes of traffic share one physical infrastructure: corporate devices, guest access, operational technology, IP cameras and building systems. Keeping them apart is not optional, and it is not achieved by putting them on different SSIDs alone.
Traffic classes are placed on distinct VLANs enforced by NetForce switching, so they do not share a broadcast domain. Inter-VLAN policy is applied at the NetGuard X5 gateway. The practical effect is that a compromised guest device or camera cannot reach corporate systems, because there is no path rather than because a rule says no.
Guest networks are where most organisations are casually exposed. A captive portal with time-bound sessions, bandwidth limits and user identification gives you a record of who was on the network and when — useful for security, and increasingly expected in regulated environments.
Security is not a commissioning task. NetCloud Central provides ongoing visibility of what is connected across the estate, with alerting when behaviour changes, so problems surface before users report them.
| On-premises (NetGuard X5) | Cloud (NetCloud Central) | Both | |
|---|---|---|---|
| Suited to | Single site, or where control must stay on site | Multi-site estates, lean IT teams | Multi-site with local resilience |
| Configuration | Local appliance | Central console | Local, visible centrally |
| Remote operations | Via VPN to site | Native | Native |
| If the WAN drops | Wireless keeps running locally | Wireless keeps running; management pauses | Wireless keeps running locally |
| Typical adopters | Hospitals, government, single campuses | Retail chains, multi-branch | Hotel groups, multi-campus |
The choice is reversible. Sites commissioned with local control can be brought under central management later without replacing hardware.
Immunity has manufactured in India since 2009. Beyond the policy preference for domestic manufacturing in public procurement, three things change commercially when your OEM is in the same country.
Imported equipment is exposed to shipping, customs and global allocation cycles. Domestic manufacturing shortens that chain, which matters most when a project is phased or a site needs to expand at short notice.
When an escalation needs firmware attention, that request goes to an engineering team in India rather than into an overseas support queue. For an unusual deployment requirement, there is a team to discuss it with.
Our equipment is MTCTE certified (and CE, FCC & RoHS compliant), with products listed on the Trusted Telecom Portal. Immunity also holds WPC approval, an IEEE OUI and an IANA PEN. Certification status varies by model and changes over time — ask us for current certification status on the models in your design and we will confirm in writing.
Most projects are replacements rather than greenfield builds, and the constraint is that the current network has to keep working throughout.
Access points can run on your existing PoE switching during transition, so switching replacement need not happen at the same time.
Wireless proposals are difficult to compare because vendors quote different things. These questions expose the differences quickly, and we are happy to be asked all of them.
If a supplier has quoted an access point count without visiting the site or receiving detailed plans, the number is an estimate. That may be acceptable for budgeting, but it should be labelled as such rather than presented as a design.
Ask for the assumed concurrent device count and the per-client throughput the design targets. If the answer is only about coverage, capacity has not been considered.
Controller licensing, cloud management, support, firmware updates and configuration are sometimes bundled and sometimes not. Two quotes that look similar can differ substantially once three years of licensing is included.
Establish whether support comes from the manufacturer, a distributor or a reseller, and which country the engineering escalation path ends in. This determines resolution time when something is genuinely broken.
Networks are extended, not replaced, for most of their life. Ask what happens when you add a building, double the device count or need outdoor coverage later.
| Scenario | Principal challenge | Typical approach |
|---|---|---|
| Single-floor office | Device density, meeting rooms | Indoor access points on PoE, one controller, VLAN separation for guests |
| Multi-floor building | Vertical roaming, riser cabling | Per-floor access switching into an L3 core, unified policy |
| Multi-building site | Backbone and outdoor gaps | Indoor and outdoor mix, fibre between buildings, central management |
| Multi-site organisation | Consistency and remote operation | Cloud management, standard per-site template, zero-touch provisioning |
| Public-facing venue | Guest onboarding and isolation | Captive portal with identification, hardware segmentation from operations |
Each of these is covered in more depth on the relevant industry page above.