Case studyPublic sector · Education — Romania

WiFi Campus

Secure, managed WiFi delivered to thousands of Romanian schools at once — a nationwide access network provisioned end to end by automation, with engineers watching a Slack channel instead of driving a console.

ClientPublic education, Romania
RoleNetwork automation, integration & delivery
Footprint4,500+ sites · 2 core · 4 distribution
StatusDelivered
WiFi Campus — a secure access network for 4,500+ Romanian schools, provisioned end to end by automation with Cisco PnP and Ansible over encrypted DMVPN to a dual active-active MPLS core. A classroom access point, a school building and network cabling, with figures: 4,500+ schools, 20,000+ access points, 5,000+ switches.

01The challenge

Connect a nation’s schools —
faster than hands can configure.

Thousands of schools, spread across every county, each needing the same secure, segregated, centrally managed WiFi — and each with only a broadband line and no on-site network engineer. Delivering that estate by hand, device by device, was never going to finish.

So it wasn’t delivered by hand. This was Metaminds’ first deployment built entirely on automation: routers, switches and access points that provision themselves the moment they are powered on and reach the Internet.

P1 Zero-touch A device ships to a school, is plugged in, and configures itself — no engineer on site, no console session.
P2 Always-on connectivity A wired broadband primary and a 4G secondary in every school, so a single line failure never takes a school offline.
P3 Segregated & encrypted User traffic and management kept apart by VRF, every school-to-core link encrypted over the public Internet.
P4 Managed centrally One addressing plan, one policy, one place to see every site — for an estate no team could touch box by box.

02Scale of the project

A national access network,
provisioned without hands.

4,500+
Cisco ISR routers, one per school
5,000+
Cisco Catalyst switches
20,000+
Cisco access points
1.5M
devices under IP management

In partnership with BlackBerry, WiFi Campus became the largest BlackBerry deployment in Europe — the network behind a smart-education programme reaching Romanian schools nationwide.

03Zero-touch automation

Every device provisions itself. Engineers just watch Slack.

The whole estate was built with Cisco Plug and Play and Ansible: configuration generated per school from one source of truth, delivered to devices that call home on first boot. No golden image copied by hand, no per-site console work.

Plug in A router, switch and access points arrive at a school and are powered on against the school’s broadband line. Nothing is pre-staged.
Call home Cisco PnP discovers the controller, which hands each device the exact configuration Ansible generated for that site — routing, VRFs, DMVPN, wireless and addressing.
Register online Each device reports in as it comes up. A Slack channel streams the progress of every location, live, with no dashboard to log into.
Auto-close When every device at a location is online, the location closes itself automatically — the engineers only step in for the exceptions.

The result: routers, switches and access points across thousands of sites brought online in fully automated mode, without human intervention — a scale of hands-off rollout Metaminds had not attempted before, and the template for everything since.

04Network architecture

Three tiers: access, distribution, core

The model below is the reference architecture, not the actual implementation. Schools reach four regional distribution centres over encrypted DMVPN tunnels; the distribution tier hands off to a dual active-active MPLS core that fronts the Internet and the national research-and-education network.

01
Access — the school router, PoE switching, wireless
Cisco ISR 4321

Edge router with an on-board compute module; dual WAN.

Dual uplinks

Wired broadband primary + 4G LTE secondary.

Catalyst 2960-CX

8-port PoE switching, one or more per school.

Cisco access points

Wireless coverage sized to the building.

02
Transport — DMVPN encrypted, over the public Internet
DMVPNAES-256

Every school-to-distribution tunnel encrypted end to end.

Four regions, dual-homed

Each region terminates on two distribution routers in different centres.

Primary & secondary

Wired path to the primary hub, 4G path to the secondary.

VRF-separated

Management and user planes carried in their own VRFs.

03
Distribution — 4 sites regional aggregation & security
Cisco ASR 1001-X

DMVPN hubs, primary/secondary per region.

Palo Alto NGFW

Next-gen firewall cluster at every distribution site.

Nexus switching

Layer-2 aggregation to the core.

BlueCat IPAM

DHCP / DNS / IPAM cluster serving the region.

04
Core — 2 sites MPLS backbone & Internet edge
Cisco ASR 9010

Active-active core routers, 40G aggregated links.

MPLS · OSPF · BGP

MPLS-VPN backbone with route-reflected MP-BGP.

Carrier-Grade NAT

CGNAT for Internet access across the estate.

Palo Alto NGFW

Firewall clusters guarding the core.

05Security & IP management

Guarded at every tier, addressed from one system

PerimeterPalo Alto next-generation firewalls protect every site — all four distribution centres and both core sites — so policy is enforced consistently across the estate.
Encryption in transitAll traffic between schools and the distribution tier rides AES-256 DMVPN tunnels over the public Internet; spoke-to-spoke traffic is forced through the hubs, never direct.
Traffic segregationManagement and user traffic are separated into distinct VRFs end to end, so infrastructure is never reachable from the user plane.
IP address managementA BlueCat cluster runs DHCP, DNS and IPAM for 1.5 million devices — one of the largest BlueCat deployments in Eastern Europe.

06The rollout

Two core sites, four regions,
one Slack channel.

The backbone was built as two active-active core sites — both fronting the Internet with Carrier-Grade NAT — and four regional distribution centres, each carrying the DMVPN hubs, firewalls and addressing for its region.

Against that backbone, sites were turned up continuously and automatically. Progress lived in Slack: a location lit up as its devices registered, and closed itself once they were all online — leaving the team free to chase only what didn’t.

— 2 core sites Active-active MPLS core, each with CGNAT and its own Internet edge.
— 4 distribution sites Regional DMVPN hubs, Palo Alto firewalls and BlueCat IPAM.
— RoEduNet interconnect Peered with the national research-and-education network.
— Slack-driven ops Live per-location status; automatic close on full registration.

07Confidentiality note

We do not disclose specific locations, addressing, or the actual internal configuration of the project.

The figures and the architecture on this page describe the reference model and the publicly communicable scale of the engagement.

08Next step

Rolling out a network at national scale?

We designed, automated and delivered a secure access network for thousands of sites — provisioned with zero touch and run from a chat channel. If you are planning a rollout that hands can’t finish, we can help.

Connect with us →