Safety

How to set up guest WiFi in a hotel: Security and performance

Hotel guest WiFi must meet two seemingly contradictory requirements: being as fast and convenient as possible for guests while simultaneously being as secure as possible from the hotel's perspective. With the correct configuration, both can be achieved at the same time.

VLAN segmentation: the cornerstone of a secure hotel network

The biggest security flaw in hotel networks is sharing a single network for guests, staff and internal systems (PMS, POS, IP cameras). If malware from a guest's laptop enters such a network, it can compromise the entire hotel infrastructure.

VLAN (Virtual Local Area Network) segmentation addresses this issue by logically separating traffic at the level of network switches and routers. Each segment communicates only with what it needs to communicate with, and nothing more.

Recommended VLAN architecture for hotels

GUEST - VLAN 10

Internet for guests. Full isolation from other VLANs. Client isolation enabled (guests cannot see each other). Bandwidth limit 20-50 Mbps per client. Captive portal authentication upon connection.

STAFF - VLAN 20

Staff network. Access to PMS, printers and POS systems. WPA3-Enterprise or certificates. No access to the guest VLAN and vice versa.

IOT - VLAN 30

Smart TVs, thermostats, door locks, IP phones. Minimum privileges, communication allowed only with the PMS server and the internet (firmware updates). No access to guest or staff VLANs.

SECURITY - VLAN 40

IP cameras, CCTV system. Fully isolated network. Access only from the security workstation and NVR server. No Wi-Fi devices.

MGMT - VLAN 99

Management of network devices (switches, access points, routers, firewalls). Accessible only from specific administrator IP addresses. SSH only, no Telnet.

Captive portal: guest verification and compliance with legal obligations

A captive portal is a web page that appears for guests after connecting to the WiFi but before they gain internet access. In hotels, it serves several functions simultaneously:

  • Guest identification: WiFi access linked to reservation (room number + surname). Compliance with logging obligations under the Electronic Communications Act.
  • Agreement to terms and conditions: The guest approves the acceptable use policy: legal protection for the hotel against network misuse.
  • Marketing and branding: The captive portal can display a welcome message, hotel offers or request consent to subscribe to the newsletter.
  • Access control: Automatic disconnection after checkout, limit on the number of devices per room, time-based access restrictions.

Bandwidth throttling: fairness for all guests

Without bandwidth throttling (speed limitation), a single guest with an active torrent client can consume 80 % of the hotel's total internet connection capacity. Throttling ensures that every guest receives a fair share.

Hotel type Recommended limit per client Uplink capacity (100 rooms)
Budget/hostel 5-10 Mbps 500 Mbps-1 Gbps
3* hotel 10-20 Mbps 1-2 Gbps
4* hotel 20-50 Mbps 2-5 Gbps
5* hotel / luxury 50-100 Mbps 5-10 Gbps

QoS (Quality of Service) rules additionally enable prioritisation of sensitive services: video calls and streaming take precedence over downloads, even within the 20 Mbps limit, a guest will experience a smooth Zoom call.

GDPR and logging of access to WiFi

The Act on Electronic Communications (transposing an EU directive) obliges WiFi network operators to retain access records for the potential needs of criminal justice authorities. At the same time, GDPR regulates how this data is processed.

What to log and how long to retain records

  • Log in: Device MAC address, connection/disconnection time, assigned IP address, guest identifier (room number)
  • Logging in is PROHIBITED: Monitoring communication content (websites visited, emails) without legal grounds constitutes wiretapping.
  • Retention time: Typically 6–12 months (consult a lawyer depending on jurisdiction)
  • Log security: Encrypted storage, access restricted to authorised personnel only, regular backups
  • Informational obligation: Guests must be informed about logging as part of the captive portal terms.

WPA3: why the new standard is key for hotels

WPA2 (standard since 2004) has several critical vulnerabilities, notably the KRACK attack and offline dictionary attacks. WPA3 (since 2018) addresses these issues:

SAE (Simultaneous Authentication of Equals)

Replaces PSK handshake, eliminates brute-force offline attacks on the WiFi password. Critical for guest WiFi with a publicly available password.

Forward Secrecy

Compromise of a single session key does not expose historical data. Each guest connection has a unique encryption key.

Enhanced Open (OWE)

Encryption even on open networks without a password, ideal for lobby hotspots where you do not want to ask guests for a password.

WPA3-Enterprise 192-bit

Military-grade encryption for the staff network. Certificates instead of passwords: the most secure option for accessing PMS and financial data.

Recommended hardware solutions for hotel WiFi

The choice of hardware depends on the size of the hotel, the budget and management requirements. The best options for the hotel sector:

Ubiquiti UniFi

Best price-to-performance ratio

Cloud management (UniFi Network Controller), excellent monitoring, easy configuration of VLANs and captive portals. We recommend the U6 Pro AP for hotel corridors and rooms.

AP Price: 4 000-8 000 Kč/unit | Suitable for: 10-200 rooms

Cisco Meraki

Enterprise choice

Cloud management with advanced visitor analytics, SLA reporting and an integrated firewall. Higher price, but a compromise TCO for larger hotels.

AP price: 15 000–30 000 Kč/unit + licence | Suitable for: 50+ rooms, chains

Aruba (HPE) Instant On

Mid-range segment

Simple cloud management with no licensing fees and good performance in dense environments. Ideal for small and medium-sized hotels with limited IT staff.

Price per unit: 5,000–12,000 Kč | Suitable for: 10–80 rooms

Conclusion: Checklist for safe guest WiFi

  • VLAN segmentation: guest, staff, IoT, security, management: each in an isolated segment
  • Client isolation enabled on the guest VLAN: guests cannot see each other.
  • Captive portal with guest authentication, acceptable use policy and GDPR consent
  • Bandwidth throttling and QoS for fair access and prioritisation of sensitive traffic
  • Logging of access in accordance with legal requirements, encrypted storage, defined retention policy
  • WPA3 on guest and staff networks: minimum WPA2 with AES encryption
  • Regular firmware updates for access points and network devices (minimum once per month)
  • Real-time network monitoring: alerts for anomalies and outages

A correctly configured guest WiFi is an unobtrusive foundation of the hotel experience. It works seamlessly, guests take it for granted, but they remember it if it fails. Investing in proper configuration and quality hardware is one of the best investments a hotel can make towards customer satisfaction.

Do you need to set up guest WiFi in a hotel?

We will design the architecture, configure VLAN segmentation, set up the captive portal and implement monitoring. Completed within 1-3 days.

Free consultation