Firewall policy, application and content filtering, intrusion prevention, VPN and multi-ISP failover on one managed device - installed and supported by iberry from Mohali, across North India.
A hotel, a college or an office with public WiFi is running a small public ISP, and it carries the same three obligations: keep the guests apart from your own systems, control what the network may be used for, and be able to say afterwards who did what. A router handed over by the broadband provider addresses none of them. It hands out addresses and gets out of the way.
Unified threat management means putting the parts that do address them into one managed device: a stateful firewall that separates the guest network from the PMS server and the cameras, application and category filtering that decides what the connection may be used for, intrusion prevention on anything you expose, and records that survive the guest’s departure. On an iberry site that device is the same one running the hotspot and captive portal, which is what makes the isolation real rather than nominal.
None of this is exotic, and it is not expensive relative to what it protects. It is simply not what arrives in the box from the ISP.
Deployed on standard MikroTik RouterOS hardware and managed centrally, with the higher tiers adding gateway antivirus and word and URL filtering.
Rules that decide what may cross between the internet, your office LAN, the guest network and the management network. The guest side is isolated, so a device on the public WiFi cannot reach your PMS server, your cameras or the back-office machines.
Application-aware rules that can stop traffic the port number alone will not reveal - BitTorrent and similar clients being the usual reason a property's bandwidth disappears overnight.
Real-time inspection for known attack patterns against anything you expose, with the option to drop the source rather than only log it.
Category-based blocking - adult, gambling, malware hosts - plus word and URL filters on the higher tiers. On a guest network this is usually a licensing and liability requirement rather than a preference.
Scanning at the gateway on the Standard tier, so a compromised guest laptop is dealt with before it reaches the rest of the property.
Encrypted WireGuard tunnels between properties and for staff working away from the building, so a group's sites and its people share one private network instead of exposing services to the internet.
Two or more internet links, with traffic moved to the surviving one automatically when a link dies and moved back when it returns. Recursive routing with gateway checks does the switching; PCC spreads load when both are healthy.
Who connected, when, from which device, and how much they used, retained and available to you. A public-facing network in India is expected to be able to answer that question long after the guest has left.
A proprietary UTM appliance sets two prices: the one you pay now, and the one you pay when it reaches end of life, when the throughput licence needs raising, or when the subscription that keeps the filtering current lapses. The hardware and the software are the same purchase, so you cannot change one without the other.
iberry deploys the same capabilities on standard MikroTik RouterOS equipment. The hardware is commodity and replaceable, the configuration is ours and portable, and the management, policy and reporting run in the iberry cloud rather than on a box in your server room that somebody has to patch. If you later move the site, or grow out of the device, the platform moves with you.
The trade-off is honest and worth stating: this is a managed service, not a product you administer yourself. If your requirement is an in-house team holding the console, say so and we will tell you whether we are the right fit.
UTM stands for unified threat management: one device doing firewalling, application and content filtering, intrusion prevention, antivirus and VPN together, rather than a separate box for each. An ISP-supplied router does none of those - it gives you an address and a NAT table. The practical difference on a property is that a UTM can separate the guest network from your own, decide what traffic is allowed, and tell you afterwards what happened.
Standard MikroTik RouterOS equipment, sized to the property - the same range the published Lite, Medium and Standard plans are built around. It is deliberately not a proprietary appliance: the hardware is widely available, and replacing or upgrading it does not mean renegotiating a licence.
Yes, and on most of our sites they are. The same RouterOS device runs the hotspot and captive portal, the per-guest speed and data limits and the firewall policy, and all of it is managed centrally from the iberry cloud. That is why guest isolation actually holds - the rules and the login system are not two vendors' products bolted together.
Both, and we prefer to do the installation. Our engineers are based at TDI Business Centre, Sector 118, Mohali, and cover Chandigarh, Mohali, Panchkula, Zirakpur and Kharar on site, with the rest of North India by arrangement. Day to day the device is managed remotely over an encrypted tunnel.
The published plans are ₹30,000 one-time for a small site, ₹50,000 for a medium one and ₹99,000 for large and five-star properties, each with ₹12,000 yearly maintenance. What changes the figure is the hardware the site needs, not a per-seat licence. Full detail is on the pricing page.
If it is RouterOS, usually yes - we can adopt an existing router rather than replace it, which is how several of our sites started. If it is another vendor's appliance we will tell you plainly whether it is worth keeping in place alongside the WiFi platform or replacing.
Tell us what is installed today and what the property has to protect, and we will come and look at it. See also the supported hardware and plans, hotspot billing and our tricity service area.
Talk to an Engineer