Network and Telecom

Enterprise Wi-Fi Installation in Istanbul

Video calls dropping in the meeting room, handheld scanners losing signal in the warehouse, one Wi-Fi password that everybody knows. We design wireless networks from real measurements and install them secure and centrally managed.

CybUP TeamLast updated: 7 min read

In short

Enterprise Wi-Fi installation is building a wireless network for an office, warehouse or production floor that gives enough coverage and capacity, is managed centrally, authenticates each user individually and keeps guests off the internal network. It is for companies of any size that have outgrown a consumer router. CybUp carries out the site survey, plans access point placement, installs with UniFi, Aruba, Ruckus or MikroTik and documents the result.

How is enterprise Wi-Fi different from home Wi-Fi?

Enterprise Wi-Fi is a wireless network in which several access points behave as one network, are managed centrally and authenticate users individually. It does three things that a home router, or a handful of range extenders unaware of one another, cannot: it hands users over to the nearest access point as they walk from room to room, coordinates channel and power settings across devices, and separates different user groups onto different networks (VLANs).

A business wireless network is only as healthy as the wired network behind it. Access points are powered from PoE switches and each needs its own cable run, so we usually take the project on together with structured cabling and Cisco switch configuration.

What is a wireless site survey, and why do it before installation?

A wireless site survey measures how the signal spreads through the building and how much interference neighbouring networks cause; the number and position of access points are decided from those measurements. Software can predict coverage from a floor plan, but concrete shear walls, glass partitions, lift shafts and metal shelving affect the signal very differently from the prediction.

Picture a three-storey office building with 400 square metres per floor: open-plan areas, glass-walled meeting rooms and an archive in the basement. We start with a predictive design on the floor plan, then measure on site to check signal strength, channel utilisation and neighbouring networks. In Istanbul business centres, where dozens of neighbouring networks share the same building, the channel plan can turn out to be the most decisive part of the design. After installation we run a validation survey and hand over the results in a report.

How many access points do you need, and where should they go?

The number of access points depends not only on the area to cover but on how many devices connect at once and what they are doing. One access point can cover a 40-seat meeting room, but once everyone joins a video call at the same time, it runs out of capacity. That is why more access points at lower power in busy areas usually beat a single powerful unit.

We follow a few placement rules: mount access points on the ceiling, close to the middle of where people work; do not hide them above metal ceiling tiles or on top of cupboards; use only the non-overlapping channels 1, 6 and 11 on 2.4 GHz; and keep channel widths narrow on 5 GHz in dense environments. Turning transmit power up to maximum is a common mistake: the access points hear each other, and clients stay stuck to a distant one.

UniFi, Aruba, Ruckus or MikroTik: which management model should you choose?

The management model comes before the brand: an on-premises controller (a physical appliance or a virtual machine) or the vendor’s cloud management portal? An on-premises controller keeps management running when the internet is down and keeps the data in-house; cloud management lets you watch several sites from one screen and takes effort out of installation.

UniFi is common in SMEs and easy to manage. Aruba and Ruckus are strong in high-density environments and in advanced radio management. MikroTik offers central management through CAPsMAN and makes sense where MikroTik routers are already in place; the details are on our MikroTik configuration page. We are not a reseller for any particular brand, and we base our recommendation on your space, your user numbers and how your team likes to manage things.

How do you secure Wi-Fi with WPA3 Enterprise and 802.1X?

The foundation of enterprise Wi-Fi security is that every user authenticates with their own account instead of one shared password, and we do that with 802.1X and a RADIUS server. In a Windows environment, Network Policy Server (NPS) can do the job: with PEAP-MS-CHAP v2, users connect with their Active Directory password, and only the NPS server needs a certificate (Microsoft: 802.1X wireless access). Where a tighter setup is wanted, we deploy EAP-TLS with device certificates. When a leaver’s account is disabled, their Wi-Fi access ends with it; see Active Directory setup for the infrastructure behind this.

For encryption the target is WPA3. According to the Wi-Fi Alliance, WPA3 is now mandatory for Wi-Fi CERTIFIED devices, and WPA3 networks require Protected Management Frames (PMF) (Wi-Fi Alliance: Security). If the office has older printers, handheld terminals or barcode scanners that do not support WPA3, we give them their own SSID and VLAN and restrict their access to the servers they actually need.

“WPA3 is mandatory for Wi-Fi CERTIFIED devices and includes additional capabilities specifically for personal and enterprise networks.”

— Wi-Fi Alliance — Wi-Fi security technologies

How do you isolate guest Wi-Fi from the internal network?

Guest Wi-Fi is kept completely apart from the internal network with its own SSID, its own VLAN and a firewall rule that allows internet access only. On top of that we enable client isolation on the access points, so guests cannot see each other’s devices. A per-user bandwidth limit stops one guest’s big download from slowing down the whole office.

Where you would rather not hand out a password at all, Wi-Fi Enhanced Open (OWE) encrypts traffic even on an open network; since older devices may not support it, we deploy it in transition mode when needed. The firewall rules for the guest network are written as part of firewall installation.

What matters for roaming, Wi-Fi 6 and Wi-Fi 7?

Roaming is a user moving from one access point to another without losing the connection, and it matters most for Wi-Fi phones, handheld terminals and video calls. The 802.11k, 802.11v and 802.11r standards shorten that handover by telling clients about nearby access points and speeding up authentication. Some older clients do have trouble with 802.11r, though, so we trial these features in a pilot area first.

Wi-Fi 6 brought capacity and efficiency gains in dense environments. Wi-Fi 7, introduced in 2024, adds features such as 320 MHz channels in the 6 GHz band and multi-link operation (MLO), which uses more than one band at the same time (Wi-Fi Alliance: Wi-Fi 7). Those gains only show up when laptops and phones support the same generation and the 6 GHz band is available under the device’s country setting. Choosing Wi-Fi 6 or Wi-Fi 7 access points for a new installation makes sense, but to get the benefit of multi-gigabit speeds, the switch ports and cabling have to keep up.

What you receive

  • Predictive design and on-site survey report
  • Access point placement plan and channel/power plan
  • Controller or cloud management setup
  • Separate SSIDs and VLANs for staff, guests and IoT
  • WPA3 and 802.1X (RADIUS/NPS) authentication
  • Post-installation validation survey and handover document

How we work

  1. 1

    Free initial review

    We review floor plans, user numbers and your existing cabling and switch infrastructure.

  2. 2

    Site survey and design

    We measure on site and decide the number and position of access points, the channel plan and the security design.

  3. 3

    Installation

    We mount the access points and configure the controller, SSIDs, VLANs and authentication.

  4. 4

    Validation

    We run a post-installation survey to test coverage and roaming, and adjust wherever needed.

  5. 5

    Handover

    We hand over the survey report, the placement plan and the management credentials.

Frequently asked questions

How long does an enterprise Wi-Fi installation take?

For a single-floor office, the site survey and installation are done within a few working days. Multi-storey buildings, warehouses and projects that need new cabling take longer, depending on scope; we give you the schedule in writing after the review.

How much does business Wi-Fi installation cost?

We give a written quote after reviewing the scope, and the review is free. Floor area, user density, the number of access points and cabling needs determine the scope.

Can we keep our existing access points?

Yes, if they support central management, WPA3 and current firmware. If they are out of support or a mix of brands, we say so in writing and set out the options.

Will the installation disrupt work?

Hardly. Access points can be mounted and configured while the existing network keeps running, and the switch from the old network to the new one happens in a short window, out of hours if needed.

Can you install Wi-Fi in warehouses and production areas?

Yes. In warehouses with high racking the signal behaves differently from aisle to aisle, so an on-site survey is essential, and we test roaming separately for handheld terminals.

Does 802.1X need a separate server?

It needs a RADIUS server. In an Active Directory environment the NPS role can be added to an existing Windows Server, and some management platforms have their own RADIUS service.

Can IP phones run over Wi-Fi?

Yes, but voice traffic needs its own SSID or VLAN, priority (QoS) settings and roaming that works well. In that case we design for voice quality rather than data traffic, and run walking call tests.

Do you install outside Istanbul?

We install and survey on-site in Istanbul. In other cities we can take on the configuration remotely, and we plan any on-site survey and mounting work separately for each project.

Sources and official documentation

CybUP Team

Written and reviewed by the CybUP technical team in Istanbul. Last updated: 10 October 2026.

Request a free review for this service

Fill in the form and we will get back to you as soon as possible. For urgent matters, WhatsApp or phone is faster.

Message on WhatsApp

Cookie preferences

Strictly necessary

Required for the core functions of the site and to remember your choices. Cannot be turned off.

Analytics

Lets us measure which pages are visited, anonymously (Google Analytics via Google Tag Manager).

Marketing

Used for advertising measurement and personalisation.