Case study · Wireless security

Hardening a busy clinical Wi-Fi network without breaking 100+ devices

Moving a live clinical wireless network to modern security settings, taming guest Wi-Fi, and fixing 2.4 GHz congestion, with a rollback ready at every step.

  • UniFi gateway
  • UniFi access points
  • WPA3 / PMF
  • Traffic rules
  • DPI
  • Intune Wi-Fi profiles

Role: Solo IT administrator

The challenge

What needed fixing

The main staff Wi-Fi was running older security settings, guest Wi-Fi was being used by staff for streaming, and the 2.4 GHz band was congested (high airtime use and retry rates).

My approach

What I did, in order

  1. Modern security without dropping legacy devices

    Moved the staff network to WPA2/WPA3 transition mode with Protected Management Frames (PMF) set to optional, so newer devices get WPA3 and older ones keep working.

  2. Tested Fast Roaming, then rolled it back

    Enabled 802.11r Fast Roaming. About 50 legacy clients dropped, so I rolled it back right away and ~105 clients recovered. I kept it off and documented why.

  3. Locked down guest Wi-Fi

    Applied a 10/10 Mbps speed limit, a business-hours-only schedule, and traffic rules blocking streaming.

  4. Fixed 2.4 GHz congestion

    Set a minimum data rate and lowered transmit power so the band stops carrying slow, far-away clients.

  5. Investigated with DPI, planned the next step

    Used deep packet inspection to see what traffic was really on the network, and planned a dedicated IoT network next.

Architecture

Sanitized diagram

Before: one flat wireless network. After: staff, guest and IoT wireless separated behind the gateway with their own rules.BeforeGatewayStafflegacyGueststreamingone flat setupAfterGateway · traffic rules · DPIStaff Wi-FiWPA2/WPA3 + PMFGuest Wi-Firate limit · hoursIoT (planned)dedicated networkClinical devicesVisitorsSensors, printers2.4 GHz: minimum data rate + lower transmit power
Before and after, simplified: one flat wireless setup becomes staff, guest, and (planned) IoT networks with their own rules behind the gateway. No real network names or IDs are shown.

Results

What changed

  • Stronger Wi-Fi security with no lasting user impact

  • Guest network limited to its real purpose

  • Less congestion on 2.4 GHz

  • Coming soon. More outcome details are being confirmed.

What I learned

Takeaway

Test changes on a live clinical network with a rollback ready. Security settings have to work with the oldest device on the network, not just the newest.

Tools used

Tools used

  • UniFi gateway
  • UniFi access points
  • WPA3 / PMF
  • Traffic rules
  • DPI
  • Intune Wi-Fi profiles

Contact

Want the full story?

Happy to walk through the details, the trade-offs, and what I would do differently.