Public Wi-Fi Hotspot Platform Development

Job ID: 40192151

Budget: $750 – $1,500 USD

PROJECT OVERVIEW

We are building a zone-based public Wi-Fi hotspot platform with paid and free access, advertising support, and roaming capabilities similar in concept to eduroam.

Each Wi-Fi network is treated as an independent zone, but users should be able to authenticate once and roam across participating zones.

The system must be modular, upgrade-safe, and built without modifying the core code of third-party platforms.

This is a multi-stage project with clearly defined milestones.
The minimum viable product (MVP) must be fully functional by the end of Stage 2.

CORE TECHNOLOGY STACK

OpenWISP (network and device management)

OpenWrt (access point firmware)

FreeRADIUS (authentication, authorization, accounting)

Perfex CRM (business backend and customer login area)

Revive Adserver (advertising engine, integrated via Perfex module)

Captive portal using Coova-Chilli or OpenNDS

WPA2/WPA3 Enterprise (EAP-TTLS / PEAP) for roaming

Perfex CRM and OpenWISP core code must not be modified.
All customisation must be done via modules, hooks, APIs, and external services.

PROJECT SCOPE (DIVIDED INTO 5 STAGES)

STAGE 1 – NETWORK AND AAA FOUNDATION

Deploy OpenWISP and provision OpenWrt access points

Deploy FreeRADIUS with SQL backend

Configure RADIUS authentication and accounting

Implement zone-based access policies

Configure RADIUS realms and proxy logic (roaming-ready)

Establish secure VPN tunnels

Basic captive portal redirection

Outcome:
Working Wi-Fi authentication and accounting with zone awareness.

STAGE 2 – MVP: PERFEX INTEGRATION, PAYMENTS, AND BASIC ROAMING

Install and configure Perfex CRM

Build Perfex modules for:

Zone management

User accounts and subscriptions

RADIUS integration

Integrate payment gateways:

Paystack

Flutterwave

PayPal

Connect captive portal to Perfex for login and payment

Automatic internet access activation after payment

Enable captive-portal roaming:

One user account usable across multiple zones

Outcome (MVP):
A user can sign up once, pay, and access Wi-Fi across zones without manual intervention.

STAGE 3 – ADVERTISING AND WPA-ENTERPRISE ROAMING

Deploy Revive Adserver

Build Perfex CRM module to manage Revive campaigns

Integrate captive portal with Revive for ad-gated free access

Enable WPA2/WPA3 Enterprise SSID for seamless roaming

Issue roaming credentials via Perfex

Outcome:
Ad-supported free access and eduroam-style roaming without captive portal.

STAGE 4 – REPORTING, HARDENING, AND FEDERATION READINESS

Improve reporting dashboards in Perfex

Zone-level usage, revenue, and roaming reports

Security hardening and performance optimisation

Prepare RADIUS configuration for external federation (future use)

Outcome:
Operationally stable, secure, and federation-ready system.

STAGE 5 – DOCUMENTATION AND HANDOVER

Full technical documentation

Deployment and rollback guides

Final QA and bug fixes

Developer handover

Outcome:
Production-ready system with clear documentation.

REQUIRED EXPERIENCE

You must have strong, demonstrable experience with:

Linux server administration

OpenWrt

FreeRADIUS (including realms and proxying)

VPNs (OpenVPN or WireGuard)

REST APIs

PHP backend development

Perfex CRM module development

Experience with hotspot systems, ISPs, or campus Wi-Fi networks is a strong advantage.

IMPORTANT CONSTRAINTS

No modification of Perfex CRM core code

No modification of OpenWISP core code

All extensions must be upgrade-safe

Clean separation between network layer and business logic

DELIVERABLES

Working system per stage

Custom Perfex CRM modules

FreeRADIUS production configuration

Captive portal integration

Revive Adserver integration

Technical documentation

ENGAGEMENT TYPE

Milestone-based contract

Long-term collaboration possible

Payment released per completed stage

HOW TO APPLY

Please include:

Relevant projects using OpenWrt, FreeRADIUS, or hotspot systems

Experience with Perfex CRM (if any)

Your proposed technical approach

Estimated timeline per stage

Generic applications will be ignored.