The challenge
A campus network is never static. Devices arrive and leave, requirements shift between semesters, and the same SSID has to serve laptops, lab equipment and a growing population of IoT devices. Run that manually and two problems compound: every change costs operator time, and network and security tools drift apart into separate silos that have to be reconciled by hand.
The University of Basel wanted operations to scale with automation rather than headcount, and wanted routine requests handled by the people making them, through self-service, rather than by a ticket queue.
The approach
The core move was integration: connecting Infoblox, Extreme Management Center and the Cisco Wireless Controller so that host information flows between them automatically, with a self-service portal and an API on top.
What we built
The integration turned three routine, manual workflows into automated ones:
-
Automated device onboarding
Integrating Infoblox with Extreme Management Center lets host-specific information (VLAN, MAC, certificates) synchronise between the surrounding systems and Extreme XMC for network access control. No manual comparison, and no silo between the network and security tools. A device is identified and automatically connected to the services it is allowed to reach, regardless of where or when it joins the network.
-
Self-service wireless for IoT devices
Door signs, panels, tablets and building-automation devices increasingly connect over wireless. On a shared SSID that usually means one general pre-shared key, which has to be rotated regularly and after every incident, at a cost. Integrating Infoblox with the Cisco Wireless Controller generates an individual PSK per client, tied to its MAC address and stored in Infoblox. From that key and MAC, the device is automatically given its own VLAN and security profile, so clients with different VLANs and profiles share one SSID, and the general key is no longer needed.
-
DNS and DHCP via self-service
A customer-specific portal lets users manage their own DNS and DHCP records and options. Several functions and systems are combined behind a single web interface, and the portal is multi-tenant, so different units manage their own entries without going through operations.
The result
Routine onboarding, wireless provisioning and DNS or DHCP changes no longer land on the operations team as individual tickets. A small team can run a large, dynamic campus network, and the people closest to a request are the ones who handle it, through a portal built around their needs.