Netgraph · Sign In
Licensing model
Two deployment options: Cisco Service Gateway (per Mbps throughput) or Cisco Meraki (per activated MR access point).
Tier · Go
Tier · Enterprise
Optional capabilities that extend Sign In Enterprise.
Add-on · Enterprise
Turn the network into a filtering DNS resolver. Subscribe to blocklists or build your own, always allow the domains you trust, and apply rulesets to the whole network or selected sites, on a schedule. Delivered through your Service Gateway.
Licensing: add-on to Sign In Enterprise, independent of client count and DNS query volume.
Available for all modules. Pick the level that matches your operational needs.
Standard
Web & email tickets. Maintenance notices.
Premium
Priority handling. Quarterly reviews. Evenings & weekends.
Exclusive
P1/P2 SLA targets. Named contact. Phone support.
Pricing via partners
Talk to a Netgraph product specialist about features, sizing, support plans, and finding the right authorized partner.
Each module ships as a small stack: platform license, throughput or endpoint license, tier, and a service level. Pick a deployment and click your way through. License details live in the docs.
Sign In on any Cisco router acting as Service Gateway.
Choose where your data is stored.
Pick a throughput tier.
Go for limited features, Enterprise for the full set.
Optional. More instances of the tier you picked, plus add-ons.
Pick a service window.
Optional. Longer term, bigger discount.
Start with one module and add others as you grow. All modules share the same admin portal, self-service experience, and audit logging — they just light up new capabilities for different use cases.
Common combinations
Always included
One exception: on Sign In, the self-service portal comes with Enterprise, not Go.
FAQ
Go covers the essentials for guest Wi-Fi: the captive and administration portals, Click-to-Connect, self-provisioning by email (guest) and SMS, whitelisting, basic DHCP (10 scopes), audit log, and multi-language UI. Enterprise adds the self-service portal, Meeting Host, Conference ID, Event Access, BYOD email and SAML self-provisioning, username & password and its API, password subscription, blacklisting with verified-email bounce protection, multi-Service-Gateway support (up to 10), DNS service, walled garden, statistics & exports, data retention, and DHCP with full audit logging.
Two deployment options. With the Cisco Service Gateway you license per Mbps of throughput (plug-and-play on any network, with built-in DHCP). With Cisco Meraki you license per activated MR access point. Pick whichever matches how your network is built.
Cloud DNS is an add-on to Sign In Enterprise that turns a network into a managed filtering DNS resolver. You subscribe to published blocklists or build your own, keep an allowlist of domains that must always resolve, and combine them into rulesets that apply to the whole network or selected sites, on an optional weekly schedule. It is delivered through your Service Gateway. Licensing is an add-on to Sign In Enterprise, independent of the number of connected clients and of DNS query volume.
Per endpoint. Every device that authenticates through EntryPoint counts toward one shared endpoint license: 802.1X, iPSK, MAC Authentication Bypass, RADIUS Proxy, and EasyPSK via RADIUS all draw on the same pool, whether the device is a laptop, phone, printer, or IoT sensor.
Yes. Microsoft Entra ID (formerly Azure AD) is supported natively as the identity source for 802.1X EAP-TLS: user certificates matched to Entra group membership, with optional Intune device-compliance checks. EAP-PEAP (username & password) uses per-user accounts managed in the platform, with self-service for the user. EduRoam is available as an optional add-on for institutions that need to federate with the global EduRoam network.
EasyPSK turns a single SSID into thousands of private "personal" networks, one per resident, student, or guest, using per-user PSK. Devices on the same network are isolated from each other, giving each user a home-like experience. Onboarding is fully self-service via QR code or portal. It comes in two delivery variants under one umbrella: Meraki WPN (Cisco Meraki, via the Dashboard API) and EasyPSK via RADIUS (Cisco Meraki and Catalyst 9800, run inside EntryPoint).
It depends on the variant. Meraki WPN is licensed as the EasyPSK module plus AP licenses on Cisco Meraki; an AP license already bought with Sign In can be reused on a separate SSID. EasyPSK via RADIUS is the module plus Unit licenses, where a Unit covers a group of up to 30 devices and the per-Unit price drops as the count grows. If you run EasyPSK via RADIUS inside EntryPoint, it draws on your shared EntryPoint endpoint pool instead, alongside 802.1X, iPSK, and MAB. Your partner sizes whichever fits your deployment.
Per Cisco ISE installation, not per endpoint. The full feature set is included regardless of how many endpoints or services you manage through ISE.
Yes — modules share the same admin portal, self-service portal, audit logging, and multi-language UI. Common combinations: Sign In + EntryPoint (guest Wi-Fi + 802.1X for employees and IoT), Sign In + EasyPSK (public guest portal + private resident networks), Sign In + Endpoint Manager for ISE (offload guest Wi-Fi from ISE while delegating MAC management).
Standard (8/5 web & email tickets, maintenance notices) covers most deployments. Premium adds priority handling, quarterly reviews, and evening/weekend coverage. Exclusive is 24×7×365 with P1/P2 SLA targets, a named contact, and phone support — for critical or revenue-impacting operations.
Pricing is handled via authorized partners (Conscia, Telia, Tele2, Telenor, Atea, Advania, and others). They size your deployment, validate the technical fit, bundle services to match your contract preferences, and provide local first-line support.
Click "Get in touch" and tell us a bit about your environment and use case. We'll connect you with the right partner based on geography, infrastructure (Cisco Catalyst, Meraki, or mixed), and the modules you're interested in.
Cookies help us improve this site. With your consent we also measure how it is used, with our own analytics and Google Analytics, configured with no advertising or cross-site tracking. Read our Privacy Policy for more.
When you visit our website it may store or retrieve information in your browser, mostly as cookies. This information is used to make the site work as you expect and, with your consent, to understand how it is used. Because we respect your privacy, you can choose not to allow some cookies. Note that blocking some of them may affect your experience.
These cookies are needed for the website to function and cannot be switched off. They are usually set only
in response to actions you take, such as signing in to internal areas or filling in a form. They store no
information that identifies you personally (cookie: ng_learn_session).
With your consent, we measure how the site is used: unique and returning visitors, approximate city and
region, time on a page, and entry and exit pages. This runs on our own first-party cookies
(ng_consent, ng_vid, ng_sid) and on Google Analytics
(_ga), configured so Google gets no advertising or cross-site signals. We never store your IP
address. If you do not allow this, we use only privacy-friendly, cookieless measurement.