Add mobile service to Wi-Fi Traverse.

Aditum Carrier Connect gives resellers and system integrators a recurring service opportunity within their Aditum Connect® Wi-Fi Traverse™ deployments. Built-in carrier integration and centrally distributed carrier profiles limit the additional operational work.

Build on the compatible Zero Touch AX network you already deploy. Your team prepares the site network and validates the experience; the platform distributes carrier profiles and applies approved carrier activations.

Built with Wi-DAS carrier integration.

Aditum Carrier Connect is the Aditum service delivered to properties and partners. Behind it, Wi-DAS supplies the carrier-integration layer that allows participating mobile networks to recognize and authenticate through the building Wi-Fi infrastructure.

Wi-DAS carrier integration logoAditum is an authorized Wi-DAS reseller.
Passpoint / Hotspot 2.0WPA3-EnterpriseCarrier authenticationCarrier profiles

Technical Architecture

Turn Wi-Fi into carrier connectivity.

Carrier Connect is more than just guest Wi-Fi. It adds carrier-integrated mobile connectivity to Wi-Fi Traverse using Carrier Wi-Fi Offload and Passpoint / Hotspot 2.0. Phones with service from enabled carriers can discover and authenticate automatically, while the dedicated Conduit and VLAN keep the service separate from tenant networks.

Carrier recognition

The phone recognizes that its mobile carrier is available through the property Wi-Fi footprint and treats the connection as part of the carrier experience, not as a manually selected restaurant-style guest hotspot.

Carrier authentication

The phone authenticates through the mobile carrier relationship. Tenants do not receive shared credentials, portal instructions, or a guest-style password for Carrier Connect.

Network separation

Carrier Connect traffic follows its own network service path, like all Wi-Fi Traverse networks, separate from tenant LANs, property operations, and unrelated guest networks.

Aditum Implementation

One Conduit. A dedicated service path.

The Conduit is what makes the implementation clean: Carrier Connect uses Wi-Fi Traverse on Zero Touch AX series routers, places the service on a dedicated building VLAN, and gives the reseller a clean path to route through the site firewall.

Conduit-based delivery

Carrier Connect is delivered through a Wi-Fi Traverse Conduit with carrier integration added. The service runs on 5 GHz only and carries the path from the Zero Touch routers into the building switch as a carrier-enabled conduit, not as a generic guest SSID with a shared password or captive portal.

Built-in carrier management

Your team prepares the Conduit, VLAN, firewall, and internet path, selects carriers with the property, and validates coverage and phone behavior. The platform distributes carrier profiles and applies approved carrier activations, while preserving partner visibility for service health and support.

Carrier Profiles

Choose carriers for each property.

Carrier Connect lets the reseller and property choose the carrier set that matters for that building. Some carriers are available for straightforward activation after the conduit path is ready; others require carrier approval before they activate at the property.

No approval required carriers

AT&TAT&T FirstNetGoogle FiHeliumExtended Carrier Network

AT&T, AT&T FirstNet, Google Fi, and Helium can be activated immediately after the Carrier Connect conduit path is ready. The Extended Carrier Network represents additional Wi-DAS-backed carrier relationships that also do not require property-specific approval.

Carrier approval required

VerizonT-Mobile / MetroT-Mobile / SprintMint Mobile

These carriers require approval before activation. Once approved, the selected carrier is automatically deployed at the property.

Deployment Flow

Configure the path. Activate carriers.

For resellers, the flow is straightforward: configure the Carrier Connect Conduit path, confirm the required firewall destinations are reachable, select the carrier set with the property, and test the tenant-facing experience.

1

Use Zero Touch AX series routers

Carrier Connect is deployed on Zero Touch AX series routers and supported 5 GHz networks. Legacy Zero Touch AC hardware does not support Wi-Fi Traverse or Carrier Connect.

2

Build the conduit path

Configure the switch VLAN, firewall, routing, and upstream internet path. Test and ensure that the IPs, ports, and FQDNs listed in the Firewall Requirements section are reachable before carrier activation.

3

Select carrier support

After the VLAN and service path are ready, select the carriers the property wants to enable. Changes roll out to all devices over roughly the next 20 minutes; carriers requiring approval are automatically deployed once approval is granted.

4

Test the tenant-facing experience

Use real phones with service from enabled carriers in representative property areas. Carriers requiring approval should be tested once approval activates at the property.

Network Design

A dedicated VLAN for carrier traffic.

The reseller configures the Carrier Connect VLAN on the switch, supplies and installs the firewall, and routes that VLAN to the internet. In most deployments, that firewall is connected as a tenant behind the core router.

Conduit mapping

Carrier Connect is mapped to a VLAN the same way any other Wi-Fi Traverse Conduit VLAN is mapped through the building network.

Carrier authentication flow

Phones with service from enabled carriers authenticate through the carrier integration. The property does not issue a shared password or tenant credential for Carrier Connect.

Traffic separation

The Conduit keeps Carrier Connect traffic separate from tenant LANs, property operations, and unrelated guest networks while providing the internet reachability required by each carrier.

5 GHz Deployment

Built for 5 GHz indoor coverage.

Carrier Connect uses the 5 GHz Wi-Fi footprint created by Wi-Fi Traverse and Zero Touch routers to provide carrier-integrated mobile connectivity inside the property.

Performance profile

Carrier Connect does not run on 2.4 GHz. The service uses 5 GHz because carrier offload needs lower latency, higher throughput, and cleaner airtime than 2.4 GHz can reliably provide.

Indoor focus

The shorter practical reach of 5 GHz helps focus Carrier Connect on residents, staff, visitors, and service personnel inside the property instead of turning the network into a public amenity for nearby neighbors or passersby.

Coverage follows the layout

Carrier Connect coverage follows the Wi-Fi Traverse and Zero Touch router layout across occupied spaces, common areas, garages, and operational areas.

Firewall Requirements

Keep carrier services reachable.

Carrier Connect gives the phone the data path, but calling, SMS, authentication, and voicemail still depend on carrier services being reachable through the site firewall.

Carrier Destination IP / Subnet / FQDN Port Protocol Description
AT&T epdg.epc.att.net 500 UDP Wi-Fi Calling / IKEv2
AT&T epdg.epc.att.net 4500 UDP Wi-Fi Calling / IKEv2
AT&T epdg.epc.att.net 143 TCP Internet Message Access Protocol (IMAP)
AT&T sentitlement2.mobile.att.net 500 UDP Wi-Fi Calling / IKEv2
AT&T sentitlement2.mobile.att.net 4500 UDP Wi-Fi Calling / IKEv2
AT&T sentitlement2.mobile.att.net 143 TCP Internet Message Access Protocol (IMAP)
AT&T vvm.mobile.att.net 500 UDP Wi-Fi Calling / IKEv2
AT&T vvm.mobile.att.net 4500 UDP Wi-Fi Calling / IKEv2
AT&T vvm.mobile.att.net 143 TCP Internet Message Access Protocol (IMAP)
T-Mobile 208.54.0.0/16 500 UDP IPsec – IKE authentication
T-Mobile 208.54.0.0/16 4500 UDP IPsec – NAT traversal encrypted voice traffic
T-Mobile 208.54.0.0/16 5061 TCP SIP/TLS encrypted SIP
T-Mobile 208.54.0.0/16 5061 UDP SIP/TLS encrypted SIP
T-Mobile 66.94.0.0/19 443 TCP HTTPS used for handset authentication
T-Mobile 66.94.0.0/19 993 TCP IMAP/SSL visual voicemail
T-Mobile 206.29.177.36 Not specified Not specified CRL server for DIGITS OTT and Wi-Fi Calling; crl.t-mobile.com
Testing

Test real phones. Confirm coverage.

Use real phones and real carrier service in representative areas of the property. The goal is to verify carrier discovery, authentication, visible network labels, and coverage where residents, staff, visitors, and first responders will rely on the service.

Device behavior

A phone may show the carrier name, Carrier Connect, or a combination of the two. The displayed label varies by device, carrier, and configuration. Verify actual authentication and connectivity; the label alone does not establish carrier activation.

Coverage behavior

Walk test representative units, corridors, common spaces, garages, and first-responder-relevant areas. Where coverage needs to expand, add compatible cAP ax access points behind Zero Touch routers as needed.

Carrier behavior

Record the exact network label, phone model, operating system, and carrier on each tested device. Use those verified examples to explain what residents may see on their own phones.

Security

Carrier authentication. Isolated traffic.

Carrier Connect uses WPA3-Enterprise authentication back to the mobile carrier. Carrier Connect traffic rides a dedicated VLAN, APs block device-to-device communication, and the switch should be configured to enforce the same isolation on the wired side.

Privacy

Mobile credentials stay with the carrier.

Carrier Connect authentication happens through the mobile carrier relationship. Aditum and partner visibility is operational: service health, carrier activation state, site configuration, and troubleshooting context, not routine inspection of tenant mobile traffic.

Troubleshooting

Check the path, phone, and carrier.

Carrier Connect troubleshooting works best when the reseller separates the site network path from the tenant device and the carrier activation state.

Conduit and VLAN

Verify the Carrier Connect VLAN is configured correctly, accepts tagged traffic from the Zero Touch router, routes through the firewall, and can reach the required carrier destinations.

Tenant device

Confirm Wi-Fi is enabled, Hotspot 2.0 / Passpoint is enabled where the device exposes that setting, the OS and carrier settings are current, and the phone is not being held on a different user-selected Wi-Fi network.

Carrier state

Confirm the tenant has active service with a carrier enabled at the property. For approval-gated carriers, verify the carrier has approved and activated the property before troubleshooting the device.

FAQ

Your Carrier Connect deployment questions.

These answers help resellers plan the conduit, firewall, and tenant-facing validation steps.

Is Carrier Connect a Wi-Fi Traverse Conduit?

Yes. Carrier Connect is a Wi-Fi Traverse Conduit with carrier integration added. The conduit maps to a dedicated VLAN and carries the service path from Zero Touch routers into the building switch.

What firewall access does Carrier Connect require?

Phones need carrier authentication, Wi-Fi Calling, messaging, and voicemail services reachable through the site firewall. The firewall table on this page lists the AT&T and T-Mobile ports, FQDNs, and destination networks that should be tested before carrier activation.

How should a reseller test Carrier Connect?

Test the VLAN path, tagged traffic from the Zero Touch router, firewall reachability, enabled carrier status, and real phone behavior. Also confirm Wi-Fi and Hotspot 2.0 or Passpoint settings on representative devices.

Is Carrier Connect just a guest SSID?

Carrier Connect is more than just guest Wi-Fi. It uses Carrier Wi-Fi Offload with Passpoint / Hotspot 2.0 so compatible phones on enabled mobile carriers can discover and authenticate automatically. A dedicated 5 GHz Wi-Fi Traverse Conduit, VLAN, and firewall path keep the service separate from tenant LANs and unrelated guest networks. Tenants do not need a shared password, captive portal, or separate Carrier Connect account.

What additional work does Carrier Connect require from our team?

Your team prepares the Conduit, VLAN, firewall, and internet path, selects carriers with the property, and validates coverage and phone behavior. Carrier integration and profile management are built into the Aditum platform, which distributes carrier profiles and applies approved carrier activations. Resellers retain responsibility for the site network and customer support.