NetGuard is the control point of an Immunity network. It is the box that decides who gets on the network, what they are allowed to reach, how much bandwidth they get, whether they pay for it, and what is written into the log. Designed in India, built at our Sanand GIDC facility in Gujarat, and supported by engineers you can reach on the phone.
Most network diagrams place a firewall at the internet edge and access points at the far end, and leave a vague cloud in between. In practice, a large share of the operational work in a venue network happens in that gap: onboarding a guest who has never seen your SSID before, deciding whether a device belongs to the finance VLAN or the visitor VLAN, throttling the one user pulling a 40 GB game update on a shared link, keeping a lawful record of who used which IP address at what time, and — increasingly in Indian public Wi-Fi — collecting money for the session. The NetGuard Controller family exists to do that work in one managed appliance instead of four scripts and a spreadsheet.
NetGuard sits between your access layer and your uplink. Below it are the NetWave Wi-Fi access points serving clients, and the NetForce switches providing PoE and wired distribution. Above it are your ISP links, whether that is a leased line, a broadband service, or fibre delivered over NetBeam optical transport between buildings on a campus. Alongside it is NetCloud Central, our AIOps cloud platform, which pulls telemetry from the controller and the APs so that a network manager in Mumbai can see what is happening in a property in Coimbatore without opening a VPN tunnel.
The practical consequence of this position in the stack is that NetGuard is the natural home for policy. Policy that lives on individual access points drifts. Policy that lives only in a firewall rule set has no idea which human being is behind an IP address. A controller that terminates the authentication session and shapes the traffic knows both, and can act on both at the same moment.
A simplified view of the Immunity stack, from the client device to the cloud.
The dashed link to NetCloud Central matters more than it looks. A controller that can only be configured from a serial console or a local web page is a controller that will be misconfigured within eighteen months, because the person who set it up will have moved on. Sending state and telemetry to a cloud plane means configuration is versioned, changes are attributable, and a site that starts behaving oddly can be compared against a site that is behaving normally.
The current flagship of the family.
The NetGuard X5 Controller is our security and performance gateway for venue and campus networks. It brings captive portal, subscriber authentication, bandwidth and policy control, gateway security and session accounting into a single appliance, managed locally or through NetCloud Central. It is the model most of our venue, campus and public Wi-Fi deployments are built around.
We deliberately do not publish throughput figures, session counts or port configurations on this page. Those numbers depend on firmware version, licence tier and the exact hardware revision shipping at the time you order, and a number scraped from a web page a year later helps nobody during a tender evaluation. Tell us your concurrent user target, your uplink capacity and the features you intend to run, and we will size the platform and confirm current specifications in writing. If your procurement process needs those figures in a formal document, our team will provide them on letterhead — ask us to confirm current specifications in writing and we will turn it around against your tender timeline.
Branded splash pages, OTP and voucher journeys, terms acceptance, and language options appropriate to the venue. Portal design is a commercial decision as much as a technical one, and the controller should not fight you on it.
Local subscriber databases, RADIUS integration and directory-backed logins for staff, so that a single controller can host guest and corporate identities without collapsing them into one policy.
Per-user and per-group rate limits, fair-use quotas, time-of-day rules and application-aware shaping, so one heavy user cannot degrade a shared uplink for everyone else in the building.
Content and category filtering, client isolation, protection against common abuse patterns on open networks, and controls that keep a guest VLAN genuinely separated from operational systems.
Paid plans, vouchers, prepaid packs and, in PM-WANI deployments, the accounting records that feed PDO settlement. Money and logs come from the same session record, which is how they should be reconciled.
Session records, login attribution and exportable logs, retained to your policy so that a compliance request or an internal investigation does not turn into a week of guesswork.
The path a guest device takes from association to authorised traffic.
Two details in that flow are worth dwelling on. First, the validation step is deliberately pluggable. Many venues start with a simple local database and an OTP journey, then a year later acquire a loyalty platform or an enterprise directory and want authentication to follow it. If validation is hard-wired into the portal, that becomes a rebuild. If it is a configurable step, it becomes an afternoon of work. Second, the accounting record is written once and used for several purposes — audit, billing, and in PM-WANI deployments the settlement data. Systems that generate separate records for each purpose eventually disagree with themselves, and reconciling them is somebody's unpleasant month.
Public Wi-Fi in India has a specific regulatory shape, and it is worth being precise about the roles, because the terminology is frequently muddled in the market. Under the PM-WANI framework, a Public Data Office (PDO) is the entity that physically operates the hotspot — a shopkeeper, a transport operator, a venue owner. A PDO Aggregator (PDOA) provides the authorisation and accounting infrastructure that the PDOs sit behind, and is the party registered with the central registry.
Immunity is a certified PDO Aggregator (PDOA) under PM-WANI. Separately and distinctly, Immunity is a Public Wi-Fi Partner with BSNL. These are two different relationships with two different counterparties, and we are careful not to conflate them: being a Public Wi-Fi Partner of BSNL does not make us a PDO, and our PDOA registration is a separate matter under the PM-WANI framework.
What this means for a NetGuard deployment is practical rather than abstract. In a PM-WANI-aligned rollout, the controller handles the hotspot-side session lifecycle and produces the accounting data that drives PDO settlement — how much each hotspot earned, over which sessions, in which period. If you are a venue operator considering monetised public Wi-Fi, or a partner planning to aggregate hotspots across a district, the conversation should start with the settlement model and work backwards to the hardware, not the other way round. Our partner team works through those commercial structures regularly, and it is usually a shorter conversation than people expect.
Different venues stress different parts of the same platform.
In hotel Wi-Fi deployments, the controller is where the guest experience is won or lost. Room-number-plus-surname login, tiered bandwidth by room category, conference-hall vouchers for a day event, and a portal that carries the property's brand rather than a vendor logo. Property management system integration matters here, and so does the ability to hand a duty manager a simple screen instead of a CLI.
In hospital networks, segregation is the whole job. Clinical devices, staff handhelds, attendant guest access and vendor engineers all share physical infrastructure and must not share reachability. A multi-speciality hospital group will typically run several policy profiles behind one controller, with strict isolation between the guest VLAN and anything touching clinical systems.
For campus wireless, the pressure is density and fairness. Thousands of student devices, examination periods where bandwidth must be reserved for academic systems, and hostel networks where per-user quotas prevent a handful of users from consuming a shared link. Time-of-day policy is heavily used here.
Regional airports, bus terminals and transit hubs have short dwell times and very high turnover of first-time users. Onboarding has to be fast and forgettable, logging has to be complete, and the network has to keep working when a delayed flight doubles the load in the lounge for two hours.
Shopping centres and high streets combine tenant networks, mall guest Wi-Fi, POS traffic and often a monetised public Wi-Fi layer. The controller is what keeps these logically separate on shared infrastructure while giving the operator one place to see usage.
For enterprise deployments, NetGuard typically handles the visitor and contractor edge while corporate devices authenticate against the directory. Combined with network security policy at the gateway, it gives an IT head a defensible answer to the question of who was on the network last Tuesday.
We are an OEM, so treat the following as interested advice — but it is advice we would give even if you bought from someone else.
Ask about certification in writing, for the specific model. Indian enterprise and government buyers increasingly require MTCTE registration, TEC compliance and, for radio products, WPC approvals. Certification status is model-specific and version-specific; a vendor's general claim on a website is not the same as a document naming the SKU you are purchasing. Ask any vendor — including us — to confirm the certification status of the exact model in writing before you finalise a purchase order. Our certifications page explains how we handle those requests and what documentation we can issue.
Ask where the product is made and where it is supported from. Make-in-India status is not just a procurement checkbox. It affects lead times, whether a replacement unit can reach your site in two days or two months, and whether firmware changes can be made for your deployment at all. Immunity has been designing and building networking products since 2009, with manufacturing at Sanand GIDC in Gujarat and engineering out of our Powai, Mumbai headquarters. When a customer needs a portal behaviour changed for a regulator or a settlement report cut differently, that request goes to a team in the same country and usually the same time zone.
Ask what happens at renewal. Controllers are frequently sold with licence models that are cheap in year one and painful in year four. Get the multi-year cost of the features you actually intend to run — portal, AAA, filtering, analytics — before you compare sticker prices.
Ask how the controller behaves when the cloud is unreachable. Cloud management is useful; cloud dependency for basic forwarding and authentication is not. In our architecture, NetCloud Central is the management and analytics plane, and the controller continues to enforce policy locally when the link to it is interrupted. Ask any vendor to describe that failure mode precisely.
A controller is only as good as what it controls. A common failure pattern we see in tenders is a well-specified gateway paired with an access layer that cannot deliver the client experience the portal promises. If the access points are under-provisioned for the density, or the switching layer is running out of PoE budget, no amount of policy configuration at the gateway will fix the resulting complaints.
Our approach is to offer a specialist product in each layer and design them to work together: NetWave for wireless access, NetForce for wired switching and PoE, NetBeam for optical transport between buildings, NetGuard for gateway control and security, and NetCloud Central for management and analytics across all of them. You can buy any one of them on its own — plenty of customers do, and NetGuard will sit in front of a third-party access layer without complaint — but the operational value of shared telemetry and single-pane configuration accumulates when the layers come from one design team.
For a new build or a significant refresh, we would normally start with a site survey and a load model, not a bill of materials. That gives you a defensible design document that survives a procurement challenge, and it gives us the information to size the controller correctly rather than optimistically. If you have an existing network and want a second opinion before renewing with an incumbent, that is a conversation we are happy to have as well.
Tell us the number of concurrent users, the venue type, your uplink capacity and whether you need monetisation or PM-WANI settlement. We will come back with a sized configuration and confirm current specifications in writing.
In most of our deployments, no. NetGuard consolidates the functions that used to be split across a wireless controller and a gateway appliance — portal, authentication, policy, bandwidth control and gateway security — into one platform, with the NetWave access points managed through it and through NetCloud Central. Whether a separate controller adds anything in your specific case depends on scale and on what you already own, so it is worth walking through your topology with our team rather than assuming either way.
These figures depend on firmware version, licence tier and the hardware revision shipping at the time of order, so we do not publish them on a web page where they will go stale. Share your concurrent user target, uplink capacity and the feature set you intend to run, and we will size the platform and confirm current specifications in writing, in a form suitable for a tender file.
Immunity is a certified PDO Aggregator (PDOA) under the PM-WANI framework. Separately, Immunity is a Public Wi-Fi Partner with BSNL — a distinct relationship that does not make us a PDO. The two roles are often confused in the market. Our PM-WANI page sets out how the roles fit together and where NetGuard sits in a compliant deployment.
Certification status is model-specific and changes over time, so we do not make blanket claims on this page. Indian enterprise and government buyers increasingly require MTCTE registration, TEC compliance and, for radio products, WPC approvals — and our recommendation to every buyer is to ask any vendor, including us, to confirm certification status in writing for the exact model being purchased. See certifications or contact us and we will issue the documentation for your SKU.
Yes. NetGuard operates as a gateway controller in front of a mixed access layer, and many customers introduce it into an existing network before refreshing the edge. You will get deeper telemetry and simpler configuration when it is paired with NetWave and NetForce through NetCloud Central, but interoperation with third-party equipment is a normal deployment scenario, not an exception.
The controller continues to authenticate users, enforce policy and forward traffic locally. NetCloud Central is the management, configuration and analytics plane, not a dependency for basic operation. Configuration changes and telemetry upload resume once connectivity is restored. We would encourage you to ask the same question of every vendor you evaluate and to get the answer in writing — our engineers will walk you through the exact failure behaviour for your topology.