Several solutions have been proposed to provide authentication and safe encryption for Wifi networks in order to overcome the limitation of WEP based security. This document describes a solution based on IPSec VPNs with client and server certificates. The key advantages of this solution is its ability to provide roaming between institutions without having to build a specific roaming infrastructure, and to have client certificates without having to maintain an online PKI infrastructure. Thus, besides the specific hot-spot gateways, there is not much more specific physical infrastructure to manage.