Hotel network estates have quietly become the most complicated small networks in British business. A 164-bedroom property runs more addressable devices than a professional services firm three times its size, and it runs them for six different customers at once: the guest in room 312 streaming a film, the waiter taking a card at table nine, the receptionist rebuilding a folio, the security officer scrubbing back through last night’s footage, the housekeeper closing a room on a handheld, and the plant room quietly reporting a chiller fault to a maintenance contractor in another county.
Network design in a hotel is therefore not one network at all. It is six overlapping systems that share cable, power, switches and an internet circuit, but share almost nothing else — different owners, different risk appetites, different uptime expectations and, critically, different consequences when they fail. Get the hotel network separation right at the drawing stage and most of the hospitality security advice published in the last three years becomes something you already did. Get it wrong and you spend the next decade paying for it in penetration test findings, PCI DSS scope, and outages that reach the guest.
That is why the NCSC puts architecture near the top of its network security fundamentals: “If security and resilience are not incorporated in the design stage, it can lead to greater difficulties (and costs) later on.” In hospitality that sentence has teeth, because the design stage happens once every ten or fifteen years — during a refurbishment — and everything in between is a workaround.
This guide is the design document. It walks the whole hotel network estate: the six logical networks and what belongs on each, a full VLAN and address plan, the inter-segment rule matrix, cabling and comms room design, switching and PoE arithmetic, and wireless sizing from occupancy.
It then treats CCTV as a bandwidth and storage problem rather than a security product, covers the January 2027 PSTN switch-off that is about to strand lift lines and alarm circuits, and closes with a costed 164-bedroom model that lands the whole hotel network at £2.73 per occupied room night. If you have already read hotel WiFi security and VLAN segmentation for guest WiFi, this is the layer above both: the whole estate on one page.
Table of contents
- Why Hotel Network Design Is Not Office Network Design
- The Six Networks Hiding Inside One Hotel Network
- Hotel Network Design Principles Worth Writing Down
- Guest WiFi: The Part of the Hotel Network Everyone Judges
- POS and Payments on the Hotel Network
- The PMS at the Centre of the Hotel Network
- CCTV Is the Heaviest Load on the Hotel Network
- Staff and Back-Office Segments of the Hotel Network
- Building Services, Lifts and Door Locks on the Hotel Network
- The Hotel Network Address Plan and VLAN Map
- Inter-VLAN Rules: What Talks to What on a Hotel Network
- Cabling and Comms Rooms: The Hotel Network You Cannot Upgrade Later
- Switching, PoE and Uplinks in a Hotel Network
- Wireless Design Across the Hotel Network
- Circuits and Resilience: How the Hotel Network Reaches the Internet
- Security Controls a Good Hotel Network Gives You Free
- Compliance Your Hotel Network Design Has to Satisfy
- Monitoring and Running the Hotel Network
- What a Hotel Network Design Costs: A 164-Bedroom Model
- Building a New Hotel Network Without Closing the Property
- Hotel Network Design Mistakes We See Most Often
- Hotel Network Design FAQ
- References and Further Reading
Why Hotel Network Design Is Not Office Network Design
Most network engineers arrive in hospitality with an office model in their heads: a trusted internal network, a guest SSID bolted on the side, a firewall at the edge. That hotel network model survives about two hours of walking the building. A hotel network breaks nearly every assumption an office design rests on, and the differences are structural rather than cosmetic.
The whole building is the hotel network estate
An office network serves people who work for you. A hotel network serves several hundred people a night who do not, plus a payment estate, plus a life-safety estate, plus a surveillance estate, plus a building management estate that predates the IT department. The hotel network footprint is bedrooms, corridors, plant rooms, lift shafts, roof spaces and a basement, not an open-plan floor with a comms cupboard.
Every hotel network user is anonymous and temporary
You cannot enrol a guest device, you cannot patch it, you cannot audit it, and you will never see it again. The design has to assume the hostile-user case as the normal case on at least one segment, which is precisely the assumption an office network never makes about its own staff.
The hotel network has no maintenance window
A hotel trades 24 hours a day, 365 days a year. There is no Sunday evening at which the front desk can be down. Anything a hotel network design cannot do in service — a switch firmware upgrade, a core failover, a cable pull through a corridor — has to be engineered around at the design stage with redundancy, not scheduled away afterwards.
Half the hotel network has no IT owner
The lift company owns the lift comms. The fire contractor owns the panel. The BMS integrator owns the plant controllers. The lock vendor owns the door gateways. The brand owns the loyalty kiosks. Each will happily plug into any port you give them, and each will tell you their system “needs to be on the same network as everything else”. A hotel network design that does not settle ownership on paper settles it badly in practice.
Hotel network devices outlive their vendors
An access point has a seven-year life. A door lock has fifteen. A lift controller has twenty-five. A BMS field device may still be working in 2045. The design has to survive vendors going out of support and out of business, which means segmentation and default-deny are not paranoia, they are asset protection.
What a good hotel network looks like
A well designed hotel network is legible on one A3 sheet, has a documented rule between every pair of segments, degrades gracefully when a circuit or a switch dies, and can absorb a new system class — a kiosk fleet, an EV charger array, a robot — without anyone having to argue about which VLAN it goes in. Everything below is in service of that.
The Six Networks Hiding Inside One Hotel Network
Before any addressing or hardware decisions, agree the logical hotel network segments. Almost every hospitality property resolves to the same six, and naming them early stops the “can we just put it on the office network” conversation from ever starting.
Network one — guest internet access
The largest hotel network segment by device count, the smallest by business criticality, and the only one the guest ever notices. It carries laptops, phones, tablets, games consoles, streaming sticks and the occasional work VPN. It should reach the internet and nothing else. Sizing comes from occupancy, not from bedroom count, and is worked through later in this guide.
Network two — payments and point of sale
Tills, kitchen displays, card terminals, the interface service that posts charges to the folio. Small, extremely sensitive, and the hotel network segment whose boundary decides how much of the estate falls into PCI DSS scope. The design goal here is not “secure the tills” but “make the rest of the hotel network irrelevant to the assessor”.
Network three — the property management system and front of house
Reception workstations, key encoders, the reservation interface, back-office reporting. Low device count, very high business criticality: when this segment stops, the hotel stops selling rooms. See hotel PMS cyber security for what the system itself holds.
Network four — CCTV and physical security
Cameras, recorders, storage, access control panels, intercoms. Almost no interactive users, enormous sustained bandwidth, long data retention, and a legal footprint of its own. This is the hotel network segment most often bolted on by a security contractor with no reference to the IT design at all.
Network five — staff and back office
Reception is on network three; everyone else is here. Managers’ PCs, the accounts machine, HR, the duty manager’s laptop, staff handhelds, printers, DECT or WiFi handsets. It behaves most like a conventional office network and should be designed like one, with identity doing the heavy lifting.
Network six — building services and IoT
BMS controllers, lifts, fire panel interfaces, energy meters, door lock gateways, meeting-room AV, EV chargers, laundry, kitchen refrigeration monitoring. Individually trivial devices, collectively the largest unmanaged population in the building, and the segment that most benefits from being unable to speak to anything.
| Logical network | What lives on it | Who owns it day to day | Internet access | PCI DSS position |
|---|---|---|---|---|
| Guest internet | Guest laptops, phones, consoles, streaming sticks | IT or a managed WiFi provider | Full outbound, filtered | Out of scope if genuinely isolated |
| Payments and POS | Tills, KDS, POI terminals, interface service | IT plus the F&B systems vendor | Outbound to named acquirer hosts only | In scope — this is the CDE |
| PMS and front of house | Reception PCs, key encoders, folio printers | IT plus the PMS vendor | Outbound to PMS cloud and OTA endpoints | Connected-to; in scope by connectivity |
| CCTV and physical security | IP cameras, NVR, storage, access panels | Security contractor, rarely IT | None inbound; outbound for updates only | Out of scope if isolated from the CDE |
| Staff and back office | Manager PCs, printers, handhelds, handsets | IT | Full outbound, filtered and logged | Out of scope only if payments are separated |
| Building services and IoT | BMS, lifts, fire interfaces, locks, AV, meters | Facilities plus multiple contractors | None by default; brokered exceptions | Out of scope; must be proven so |
Six hotel network segments is the floor, not the ceiling
Larger properties split further — conference and events onto its own segment, spa and leisure onto another, a separate segment for a franchised restaurant operator that is a different legal entity. The rule is one purpose per hotel network segment, and the test is whether you can write a one-sentence description of what belongs there. If the sentence needs an “and also”, split it.
Hotel Network Design Principles Worth Writing Down
Principles sound like filler until the third contractor asks for an exception. Write six of them into the design document, get the general manager to sign it, and every later argument becomes a five-minute conversation instead of a negotiation.
Segment the hotel network by trust, not by convenience
Hotel network devices belong together when they share a trust level and a purpose, not when they happen to be in the same room. The bedroom TV and the bedroom data port are physically adjacent and belong on different segments, because one is a managed hotel asset and the other is a socket for a stranger’s laptop.
Default deny between every hotel network segment
Every pair of hotel network segments starts with no traffic allowed, and each permitted flow is added explicitly with a source, a destination, a port and a business reason. This is the single decision that does more for a hotel network than any security product, and it costs nothing at design time and a fortune to retrofit.
One purpose per VLAN, one VLAN per purpose
Resist the temptation to save VLAN IDs. They are free. A shared “miscellaneous” segment always becomes the place where the unbudgeted system goes, and within two years it holds the card terminal, the digital signage and a contractor’s laptop.
Design the hotel network for the failure case
The interesting question is never “does it work” but “what happens when the primary circuit drops, or a core switch reboots, or the cloud PMS is unreachable”. Every segment needs a documented degraded mode, which is the point where this overlaps with the hotel disaster recovery plan.
Make the hotel network design legible
Anyone competent should be able to pick up the hotel network drawing pack and understand the hotel network in twenty minutes. That means a one-page logical diagram, a VLAN table, an address plan, a rule matrix, a labelled patching schedule and a photograph of every comms room. Undocumented networks are not secure; they are merely obscure.
Assume the device is never patched
For guest devices, BMS controllers, older cameras and anything a contractor installed, assume the firmware will never change. Design so that assumption is survivable: restrictive segments, no inbound access, no internet egress unless justified, and monitoring that notices when the assumption breaks.
Write down who owns each hotel network segment
Ownership is a hotel network design artefact. Name a person — not a department — accountable for each of the six segments, and record which vendor supports it, what the change process is and who is called at 3am. A hotel network with six segments and one nominal owner has, in practice, no owner at all.
Guest WiFi: The Part of the Hotel Network Everyone Judges
Guest wireless is the only hotel network segment with a Tripadvisor score. It is also the segment where hotels most often overbuild the radio and underbuild everything behind it, which produces the classic complaint: full signal bars, unusable internet.
Size the guest hotel network segment from occupancy, not bedrooms
Bedroom count tells you how many rooms you can sell, not how big the hotel network must be. Concurrency tells you how much bandwidth you need. For the 164-bedroom property modelled later in this guide, 75% occupancy gives 123 occupied rooms; at 1.6 guests per occupied room that is 197 people; at 2.6 connected devices each that is 512 devices associated at peak. Assume 40% actively transferring at any instant and you are engineering for 205 concurrent sessions.
Translate sessions into megabits
At 3.5 Mbps per active session — enough for high-definition streaming with headroom — 205 sessions need 717.5 Mbps. That is the number that should drive the circuit order, and it is why so many hotels with excellent access points still deliver a poor guest experience: they bought radios, not bandwidth.
Access point density and placement
One access point per two bedrooms is the current UK planning norm for a four-star property with solid walls, giving 82 bedroom-area radios for 164 rooms, plus roughly 22 more across lobby, restaurant, bar, meeting rooms, leisure and back of house — 104 in total. Corridor-mounted radios are cheaper to install and worse at everything; in-room or wall-plate units win on capacity, cost more, and are covered in detail in the hotel WiFi upgrade cost guide.
Client isolation on the hotel network is not optional
Every guest device must be prevented from seeing every other guest device at layer 2. Without it, a hotel network becomes a shared LAN for several hundred strangers, and the file-sharing service somebody left enabled on a laptop becomes a public resource. Client isolation, ARP suppression and multicast control are the three settings that separate a guest SSID from a hazard.
Captive portals and onboarding
Portals exist for terms acceptance, marketing capture and occasionally for tiered bandwidth. They also have a poor security history — see what UK hotels can learn from CaptiveCrunch — and they are the single most common source of “the WiFi is broken” tickets. Keep the portal simple, keep it patched, and never let it hold anything that matters.
Enhanced Open, Passpoint and roaming
The Wi-Fi Alliance’s Enhanced Open (OWE) gives each client its own encryption on a password-free SSID, which removes passive eavesdropping from the risk register. It does not authenticate anybody and provides no access control, so it complements segmentation rather than replacing it. Passpoint-based roaming is worth considering for group properties and conference venues where repeat guests should join without touching a portal.
In-room entertainment and casting
Guests expect to cast to the bedroom television. Casting protocols rely on multicast DNS discovery, which by default does not cross a routed boundary — and you absolutely do not want a flat network where room 312’s phone can discover room 415’s television. The correct design keeps televisions on their own segment and uses a controlled discovery proxy that pairs a device to a single room, usually keyed off the PMS room assignment.
What guest traffic on the hotel network must never reach
Write the deny list into the hotel network design: no access to the payment segment, the PMS segment, the CCTV segment, the management segment, the building services segment or any RFC1918 destination inside the property. The only permitted destination is the internet, through the firewall, with DNS and content filtering applied.
POS and Payments on the Hotel Network
Payments occupy a tiny slice of the hotel network device count and an enormous slice of the compliance burden. The design objective is containment: build the boundary so tightly that the assessor’s questions stop at the edge of one small segment.
Card data lives in fewer places than people think
If the terminals are part of a validated point-to-point encryption solution, account data is encrypted inside the reader and the till only ever sees a token. If they are not, every device in the transaction path is storing, processing or transmitting account data, and the segment boundary is doing all the work. That distinction is worked through in hotel POS security.
Standalone versus integrated terminals
A standalone PTS-approved terminal on its own IP connection is the cheapest scope position available to a hotel. The moment the terminal is integrated into the till so the amount populates automatically, the till joins the cardholder data environment. Both designs are legitimate; only one of them is cheap to assess, and the decision belongs in the network design rather than the F&B tender.
The POS to PMS interface is a hotel network object
Room charging works because the point of sale posts to the folio over an interface service. That single flow is the reason the payment segment and the PMS segment cannot be fully isolated from one another. Design it as an explicit, single-direction, single-port rule between two named hosts — not as “allow the POS VLAN to the PMS VLAN”.
Offline mode is a hotel network design requirement, not a feature
Oracle’s Simphony documents workstation online, yellow and red modes, with a Check and Posting Service holding transactions locally when the enterprise is unreachable. A hotel network design that assumes the tills need the core to be up has failed before it is built: the outlets must keep trading through a core switch reboot or a circuit failure and reconcile afterwards.
Keep kitchen and ordering devices on the right hotel network segment
Kitchen display screens, order printers and handheld ordering devices are not card devices, but they are on the same vendor’s platform and usually the same VLAN. That is acceptable if the whole segment is treated as in scope. It is not acceptable to have them on the staff segment “because they only print tickets” — that is how the office network joins the CDE.
Hotel network segmentation has to be tested, not asserted
PCI DSS Requirement 11.4.5 requires a penetration test of the segmentation controls at least every twelve months and after any change, and states plainly that a configuration review alone does not satisfy it. Service providers do it every six months under 11.4.6. Budget for the test as a recurring line, because the design is only as good as the last time somebody tried to get through it.
The PMS at the Centre of the Hotel Network
The property management system is the smallest critical segment in the building and the one with the most inbound relationships. It is worth drawing on its own sheet.
Count the hotel network interfaces before you draw the boundary
A typical PMS talks to the channel manager, the booking engine, the payment gateway, the point of sale, the door lock system, the telephone system, the in-room entertainment platform, the energy management system, the revenue management tool, the CRM and at least one reporting extract. Each is a rule; each is a supplier; each is a dependency.
IFC8 and FIAS are the part nobody documents
Oracle’s interface platform connects on-premise vendor systems to the PMS “over synchronous TCP/IP or serial connection exchanging messages”, using the FIAS, XML-POS or vendor-specific specifications, carrying check-in and check-out notifications, charge postings, door key requests and credit card payment requests. Those are plaintext-capable, long-lived TCP sessions between named hosts — precisely the kind of flow that should be pinned to a rule, not left to a permissive VLAN.
Cloud PMS changes the hotel network topology, not the dependency
Moving to a cloud property management system removes the on-premise server and adds a hard dependency on the internet circuit. The front desk workstation is now a browser, the interfaces run through a local connector appliance, and the failure mode moves from “the server is down” to “the circuit is down”. Design the circuit resilience accordingly — the section on circuits below assumes exactly this.
Front desk workstations are the sensitive hotel network endpoints
Reception PCs display guest records, take payments, run key encoders and sit in a public area where the screen is visible over the counter and the machine is reachable from the guest side of the desk. Treat them as a distinct device class with their own hardening, their own screen-lock timing and their own segment, not as ordinary office PCs that happen to live in the lobby.
Key encoders deserve their own thought
Encoders write credentials to door cards. On many estates they sit on a USB cable behind reception with an application that has been in place since the last refurbishment. They belong on the front-of-house segment with tightly controlled access, and their software should be on the patching register alongside everything else — the Unsaflok research showed how long a lock ecosystem can carry an unfixed flaw.
CCTV Is the Heaviest Load on the Hotel Network
Surveillance is usually procured as a security product and installed as an afterthought on the hotel network. In bandwidth and storage terms it is normally the largest single consumer in the building, and it needs designing like infrastructure.
Camera bandwidth is a sustained load, not a peak
Unlike guest traffic, cameras transmit continuously. For the modelled property, 72 four-megapixel cameras at 4 Mbps and 24 eight-megapixel cameras at 8 Mbps produce 288 Mbps plus 192 Mbps — a constant 480 Mbps flowing from the edge toward the recorder, every second of every day. On a flat hotel network that traffic crosses the same uplinks as everything else.
Storage is where the arithmetic bites
480 Mbps is 60 MB per second, which is 216 GB per hour and 5.184 TB per day. A fortnight of continuous recording is 72.6 TB; a calendar month is 160.7 TB; ninety days is 466.6 TB. Those numbers are why retention policy is a network design decision and not merely a privacy one, and why smart codecs and motion-based recording are worth real money.
Power over Ethernet is a second budget
Cameras draw power from the same switches that carry their traffic. Under IEEE 802.3, a PoE port sources 15.4 W and delivers 12.95 W to the device; PoE+ sources 30 W and delivers 25.5 W; 802.3bt Type 3 delivers 51 W and Type 4 delivers 71.3 W. Seventy-two standard cameras at 12.95 W plus twenty-four infrared or PTZ units at 25.5 W is 932.4 W plus 612 W — 1,544.4 W of camera load before a single access point is powered.
ONVIF is your exit from vendor lock-in
The ONVIF profiles define interoperability between cameras, recorders and management software: Profile S for video streaming, Profile G for recording and storage, Profile T for advanced streaming, Profile A and C for access control, Profile D for peripherals and Profile M for metadata and analytics. Specifying conformance in the tender is what lets you replace one vendor’s cameras without replacing the whole system.
Where the recorder sits on the hotel network matters
Recorders should sit in a secure comms room on the CCTV hotel network segment, not in the back office under a desk, and their storage should be sized for retention plus a rebuild margin. The design question everybody skips is what happens to the footage if the recorder is stolen or encrypted — which is an argument for replicating a low-resolution stream or the last 24 hours off-site.
Camera supply chain is now a hotel network design constraint
In November 2022 the UK government instructed departments “to cease deployment of such equipment onto sensitive sites, where it is produced by companies subject to the National Intelligence Law of the People’s Republic of China”, and advised “that no such equipment should be connected to departmental core networks”. Hotels are not government departments, but corporate clients, insurers and public-sector booking frameworks increasingly ask the question, and the second half of that instruction is a network design statement whoever made it.
CCTV and UK data protection law
Recorded footage of identifiable people is personal data, so a hotel needs a lawful basis, signage, a retention period, a subject access process and appropriate security for the recordings. Note that the statutory Surveillance Camera Code of Practice binds a “relevant authority” as defined in section 33 of the Protection of Freedoms Act 2012 — local authorities, police forces and police and crime commissioners — and a hotel is not one. Your obligations come from UK GDPR and the Data Protection Act 2018, with ICO guidance as the practical reference.
Martyn’s Law adds a reason to get this right
The Terrorism (Protection of Premises) Act 2025 puts premises expecting 200 to 799 people into a standard tier and 800 or more into an enhanced tier, with a stated implementation period of at least 24 months from Royal Assent in April 2025. Enhanced-tier public protection measures cover monitoring, movement, physical safety and security, and security of information — four categories that all touch how the surveillance and communications estate is designed.
| Design parameter | Modelled choice | Why it is set there |
|---|---|---|
| Camera count | 96 (72 × 4 MP, 24 × 8 MP) | Entrances, corridors, lifts, car park, cash points, back of house |
| Codec and bitrate | H.265 at 4 Mbps and 8 Mbps | Halves storage against H.264 at equivalent quality |
| Sustained network load | 480 Mbps toward the recorder | Drives the uplink sizing on every camera-bearing switch |
| Retention | 31 days continuous | Balances incident lookback against 160.7 TB of storage |
| PoE class | 802.3af standard, 802.3at for IR and PTZ | 1,544.4 W total; sets switch power budget per floor |
| Interoperability | ONVIF Profile S and Profile G minimum | Allows camera and recorder vendors to be replaced independently |
| Segment | Dedicated VLAN, no inbound, egress to update hosts only | Keeps 96 rarely-patched devices out of everything else |
| Remote viewing | Via a brokered VPN, never port-forwarded | Exposed recorders are a standing item in hospitality scan data |
Staff and Back-Office Segments of the Hotel Network
The staff segment is the most conventional part of the estate and therefore the part most likely to be designed by habit rather than by intent.
Wired desks and back-of-house wireless
Managers, accounts, HR, revenue and the duty office get wired ports where possible and a separate back-of-house SSID where not. That SSID uses 802.1X with certificates rather than a shared passphrase, because a shared passphrase in a building with seasonal staff turnover is a credential with no expiry date.
Handhelds, housekeeping and the room status loop
Housekeeping devices update room status straight into the PMS, which means a housekeeping handheld is a device with a write path into the most business-critical system in the building. They belong on the staff segment with an explicit rule to a single PMS endpoint, not on the guest SSID because it was easier to onboard.
Voice: DECT, WiFi handsets and the death of the analogue line
Most properties still run some form of on-site voice, and the migration from analogue handsets to SIP is happening at the same time as the PSTN switch-off. Voice needs its own VLAN and quality-of-service marking, and it needs to be tested against the failure mode where the internet circuit is down but the building still needs internal calling.
Printers, scan-to-email and the forgotten server
Every hotel has a multifunction device scanning to email and often a small file server holding decades of banqueting contracts. Both are network objects with credentials, both usually run firmware nobody tracks, and both belong behind identity controls covered in Microsoft 365 for hotels.
Identity does more work here than hotel network segmentation
On the staff segment, the meaningful boundary is who the user is, not which socket they plugged into. Multi-factor authentication, conditional access and privileged access management deliver more than any VLAN can, which is why the Microsoft 365 setup guide for hotels is the natural companion to this document.
Contractor and temporary hotel network access
Give contractors their own SSID and their own VLAN with a documented expiry, not the staff passphrase and a spare port. A hotel network that hands the AV company the same access as the finance manager has no segmentation worth discussing, whatever the diagram says.
Building Services, Lifts and Door Locks on the Hotel Network
This is the hotel network segment that grows without anybody noticing, because each addition is small and each is installed by someone whose job is not networking.
BMS and plant controllers
Heating, ventilation, chillers, boilers, energy meters and lighting controllers typically speak BACnet or Modbus, protocols designed with no authentication whatsoever. They should never be routable from anywhere except a named engineering workstation, and their remote support access should be brokered rather than permanent.
Lifts and their communications path
Lift emergency telephones, remote diagnostics and door-release interfaces are life-safety adjacent and contractually owned by the lift company. They must not be treated as ordinary IoT — put them on the building services segment, document them, and make sure their emergency communications path is independent of anything an IT change can break.
Fire alarm and life-safety interfaces
The fire panel itself is a certified system that must not be interfered with, but its network interfaces — remote monitoring, cause-and-effect links to lifts and door releases, alarm receiving centre signalling — are network objects. Design them so a hotel network failure never causes a life-safety failure, and never the other way round.
Door locks and gateways
Modern electronic locks are usually offline with a Bluetooth or proprietary radio link to floor gateways, which are network devices. The gateways carry credential updates and audit trails, and they belong on the building services segment with a single rule back to the lock management server.
Meeting-room AV, signage and the long tail
Projectors, room booking panels, digital signage, EV chargers, laundry monitoring, kitchen refrigeration telemetry and the vending machine’s telemetry SIM all end up here. NIST’s operational technology security guidance is the right reading for how to treat this population, and the practical rule is simple: they get power, they get an address, and they get nothing else without a written reason.
Prove the hotel network segment cannot reach anything
The building services segment is the easiest one to test, because the correct answer to every connectivity question is “no”. Include it in the annual segmentation test explicitly; it is also the segment where IoT device management pays for itself fastest.
The Hotel Network Address Plan and VLAN Map
Addressing is where the hotel network design becomes real. Do it once, do it with headroom, and write it down in a form that survives staff changes.
Count the hotel network devices before choosing subnet sizes
The modelled 164-bedroom property carries 742 addressable devices before a single guest checks in: 104 access points, 164 bedroom data ports, 164 in-room televisions, 96 cameras, 12 door lock gateways, 41 payment and POS endpoints, 15 front-of-house devices, 34 staff PCs, 46 staff handhelds, 45 building services devices and 21 pieces of network hardware.
Choose subnet sizes with deliberate headroom
A /24 gives 254 usable addresses, a /23 gives 510, a /22 gives 1,022 and a /21 gives 2,046. Guest wireless is the only segment that needs a /22, because it holds transient devices rather than installed ones. Everything else fits comfortably in a /24, and payments should be deliberately small so that growth is a conversation rather than a default.
The worked hotel network VLAN and address plan
| VLAN | Purpose | Subnet | Usable | Devices | Addressing |
|---|---|---|---|---|---|
| 10 | Guest wireless | 10.10.0.0/22 | 1,022 | 512 at peak | DHCP, 4-hour lease |
| 12 | Guest wired bedroom ports | 10.10.4.0/24 | 254 | 164 | DHCP, 8-hour lease |
| 20 | In-room entertainment | 10.10.20.0/24 | 254 | 164 | DHCP reservation per room |
| 30 | CCTV and recording | 10.10.30.0/24 | 254 | 96 | Static or reserved |
| 40 | Building services and lock gateways | 10.10.40.0/24 | 254 | 57 | Static |
| 50 | Staff and back office | 10.10.50.0/24 | 254 | 95 | DHCP, 12-hour lease |
| 60 | Payments and POS | 10.10.60.0/26 | 62 | 41 | Static, deliberately tight |
| 70 | Network management | 10.10.70.0/24 | 254 | 125 | Static, out-of-band where possible |
DHCP scopes, leases and exhaustion
Guest scopes need short leases so addresses return quickly after checkout; a four-hour guest lease on a /22 comfortably supports the modelled turnover. Static segments should not run DHCP at all. Keep an eye on scope utilisation as a monitored metric — running out of guest addresses on a Friday night is a very visible failure.
DNS, NTP and the quiet dependencies
Every segment needs name resolution and accurate time, and both should come from the hotel network’s own resolvers rather than whatever a device was shipped with. Accurate time in particular is what makes the CCTV footage, the door lock audit trail, the till journal and the firewall log tell the same story about the same incident.
Naming, labelling and the hotel network as-built pack
Name switches by building, floor and role. Label every patch panel port to the room. Keep a live address spreadsheet, a rule matrix and a diagram in the same folder, and update them as part of change control. The best-designed hotel network in the country is worthless at 2am if nobody can tell which switch feeds the third floor.
Inter-VLAN Rules: What Talks to What on a Hotel Network
Hotel network segments only mean something if the rules between them are explicit. Build the matrix as a grid, review it annually, and treat every addition as a change request.
| From ↓ / To → | Guest | Payments | PMS / front of house | CCTV | Staff | Building services | Internet |
|---|---|---|---|---|---|---|---|
| Guest | Client isolation on | Deny | Deny | Deny | Deny | Deny | Allow, filtered |
| Payments | Deny | Allow within segment | One host, one port (folio posting) | Deny | Deny | Deny | Named acquirer hosts only |
| PMS / front of house | Deny | Reply traffic only | Allow within segment | Deny | Named reporting host | Lock server to gateways only | PMS cloud, OTA, channel manager |
| CCTV | Deny | Deny | Deny | Allow within segment | Deny | Deny | Update hosts only |
| Staff | Deny | Deny | Named PMS endpoint | Viewing client to NVR only | Allow within segment | Engineering workstation only | Allow, filtered and logged |
| Building services | Deny | Deny | Deny | Deny | Deny | Allow within segment | Deny by default |
| Management | Manage APs | Manage switches | Manage switches | Manage switches | Manage switches | Manage switches | Vendor cloud only |
The hotel network rules that always exist
Four flows appear in every hotel network: point of sale to the PMS interface for folio posting, the lock management server to the door gateways, the staff viewing client to the video recorder, and the management segment to every device it administers. Everything else should have to justify itself.
The hotel network rules people forget
Backup traffic, monitoring polls, certificate renewal, NTP, vendor remote support and firmware update paths are all real flows that get discovered at go-live because nobody drew them. Add a row for each in the design phase and the commissioning week gets a lot quieter.
Directionality is half the control
“Allow POS to PMS” and “allow PMS to POS” are very different statements. Write every rule with a direction and let the firewall handle return traffic statefully. A bidirectional rule between two segments is usually two segments pretending to be one.
Review the matrix on a schedule
Rules accumulate. Once a year, print the matrix, walk it with the people who own each segment, and delete anything nobody can explain. This is also the artefact an assessor will ask for first, so keeping it current has a compliance dividend as well as a security one.
Cabling and Comms Rooms: The Hotel Network You Cannot Upgrade Later
Active hotel network kit gets replaced every five to seven years. Cable and containment last thirty. Spend the design effort where the decision is irreversible.
Cable choice sets the hotel network ceiling for a generation
Cat5e carries 1 Gb/s reliably and often 2.5 Gb/s. Cat6 supports 10GBASE-T only to around 55 metres but handles 2.5 and 5 Gb/s across a full 100 metre channel. Cat6a supports 10 Gb/s to 100 metres. Fibre — OM4 multimode or single mode — belongs in every riser and between every comms room, because the copper you install today will outlive at least two generations of switching.
Horizontal versus backbone
Horizontal cabling runs from the floor comms room to the outlet: bedroom ports, television points, access point locations, camera positions, till positions and desk outlets. Backbone cabling links the floor rooms to the core. The single most common hotel network mistake is generous horizontal provision on a starved backbone, which produces a building full of fast ports funnelling into a bottleneck.
One comms room per floor, plus a main frame room
Each floor gets a lockable, ventilated cabinet or room within 90 metres of every outlet it serves, and the building gets one main frame room housing the core, the firewalls, the recorders and the circuit terminations. Five rooms — four floors plus a basement main frame — is the pattern for the modelled property.
Power, cooling and physical security
Every comms room needs a dedicated protected circuit, a UPS sized for a graceful shutdown, adequate ventilation, and a lock with a controlled key. A cabinet in a corridor with a hasp and a padlock is not a comms room; it is a shared cupboard that will eventually contain a mop.
| Medium | Practical ceiling | Distance | Where it belongs in a hotel |
|---|---|---|---|
| Cat5e | 1 Gb/s, often 2.5 Gb/s | 100 m | Legacy only — acceptable for televisions and door gateways |
| Cat6 | 2.5–5 Gb/s to 100 m; 10 Gb/s to ~55 m | 100 m | Acceptable for bedroom outlets on a tight budget |
| Cat6a | 10 Gb/s | 100 m | Default for access points, cameras and all new work |
| OM4 multimode fibre | 10–100 Gb/s | Building scale | Floor comms room to core, every riser |
| Single-mode fibre | 10–400 Gb/s | Campus scale | Between buildings, annexes and outbuildings |
Label everything, twice
Every outlet, patch lead, panel port and riser gets a label that matches the as-built drawing and the patching schedule. Labelling is the cheapest line in the whole project and the one that saves the most money over the following decade.
Leave spare capacity in the containment
Fill trays and conduits to no more than 60% at handover. The refurbishment that adds a kiosk fleet, a second camera ring or an EV charger array is coming, and pulling new cable through a full riser costs several times what leaving room would have.
Switching, PoE and Uplinks in a Hotel Network
With the cabling fixed, the active design is mostly arithmetic: count ports, count watts, size uplinks, and decide what happens when something fails.
Count hotel network ports honestly
The modelled property needs 104 access point ports, 328 bedroom ports (data plus television), 96 camera ports, 12 lock gateway ports, 41 payment ports, 15 front-of-house ports, 34 staff ports and 45 building services ports — 675 wired ports. Sixteen 48-port switches provide 768, an 87.9% fill that leaves room for the inevitable additions without a second procurement.
Power over Ethernet is the real constraint
A 48-port switch with a 740 W power budget cannot power 48 devices at 25.5 W. Across the modelled estate, 104 access points at 25.5 W (2,652 W), 96 cameras (1,544.4 W) and 12 gateways at 12.95 W (155.4 W) total 4,351.8 W against 11,840 W of available budget — comfortable at 36.8%, provided the load is spread rather than concentrated on the two switches serving the camera ring.
Distribution, core and the collapsed-core option
Most single-building hotels do not need three tiers. A pair of resilient core switches with 10 Gb fibre to each floor switch is sufficient, simpler to run and cheaper to support. Reserve a proper three-tier design for campuses and resorts with multiple buildings.
Uplink sizing follows the heaviest segment
A floor carrying 26 access points and 24 cameras can present well over a gigabit of sustained traffic. Size floor uplinks at 10 Gb from the outset — the optics are cheap, the fibre is already there, and undersized uplinks are the single most common cause of “the WiFi is slow” complaints that have nothing to do with wireless.
Hotel network redundancy without complexity
Dual uplinks from each floor to two core switches, link aggregation where the platform supports it, and a spanning tree configuration that is deliberate rather than default. Root bridge placement, BPDU guard and loop protection on every access port are non-negotiable in a building where a guest can plug a cable into two sockets.
| PoE standard | Sourced at the port | Delivered to the device | Typical hotel use |
|---|---|---|---|
| 802.3af (PoE) | 15.4 W | 12.95 W | Fixed cameras, lock gateways, IP handsets |
| 802.3at (PoE+) | 30 W | 25.5 W | Wi-Fi 6E access points, IR and PTZ cameras |
| 802.3bt Type 3 | 60 W | 51 W | Wi-Fi 7 access points, room booking panels |
| 802.3bt Type 4 | 90 W | 71.3 W | Digital signage, high-power PTZ, kiosks |
Wireless Design Across the Hotel Network
Radio is the part of the hotel network guests experience and the part most often bought on datasheet numbers rather than survey evidence.
Predictive survey before procurement, validation after
A predictive survey using the building’s actual floor plans and wall constructions tells you how many radios you need and where. A validation survey after installation tells you whether reality agreed. Skipping the first produces the wrong quantity; skipping the second produces a design nobody can defend when coverage complaints arrive.
The channel plan is the hotel network design
Two access points sharing a channel interfere with each other regardless of how good they are. In bedroom corridors with concrete walls the 5 GHz channel plan is usually workable; in glass-and-plasterboard extensions it rarely is. This is where 6 GHz earns its money, because it brings a large block of clean spectrum to a band that older guest devices cannot even see.
6 GHz, Wi-Fi 6E and Wi-Fi 7 in the UK
Ofcom has made the lower 6 GHz band, 5925–6425 MHz, licence-exempt for indoor use — the spectrum Wi-Fi 6E uses — and has moved to authorise higher-power indoor and outdoor use under an automated frequency coordination system. In 2026 it confirmed sharing arrangements for the upper band 6425–7125 MHz split at 6585 MHz, with Wi-Fi priority on the lower 160 MHz and mobile priority above, making the UK the first country in Europe to settle the question. Wi-Fi CERTIFIED 7 adds 320 MHz channels at roughly twice the throughput of Wi-Fi 6, 4K-QAM around 20% above Wi-Fi 6’s 1024-QAM, and multi-link operation.
Keep the hotel network SSID count down
Every SSID consumes airtime with management traffic. Four is a sensible ceiling for a hotel network: guest, back of house, contractor and a device SSID for handhelds and IoT. Resist the meeting-room-specific and event-specific SSIDs that sales teams request; use a portal or a VLAN instead.
Controller architecture and the failure mode
Cloud-managed, on-premise controller and controller-less designs all work. What matters is what happens when the management plane is unreachable: access points should continue serving clients and forwarding traffic locally. Confirm that behaviour in the tender, and test it during commissioning by pulling the circuit.
Rogue access point detection
PCI DSS Requirement 11.2.1 expects quarterly detection of unauthorised wireless access points, and it applies even where wireless is prohibited in the cardholder data environment. A hotel is a building full of guests carrying mobile hotspots, so the process needs to distinguish a guest phone from a rogue radio plugged into a staff socket — which is exactly what 802.1X on wired ports makes easy.
Circuits and Resilience: How the Hotel Network Reaches the Internet
Everything above is inside the building. This is the part that fails most visibly.
Size the circuit from the bandwidth budget
Adding the segments together for the modelled property: 717.5 Mbps of guest traffic, 150 Mbps for conference and events, 120 Mbps of operational traffic across PMS, POS, back office and cloud services, and 60 Mbps of off-site CCTV replication gives 1,047.5 Mbps. A single gigabit circuit is therefore already marginal on a busy Saturday, which is the argument for 2 Gbps primary.
Diversity beats capacity
Two circuits from the same provider entering the building through the same duct are one circuit with extra billing. Ask for physically diverse entry, different carriers where possible, and a genuinely independent technology — a leased line plus FTTP plus a 5G router is three failure modes, not one.
Decide what degrades and what does not
When the primary drops, the failover circuit will not carry 1,047.5 Mbps. Decide in advance that payments, PMS, voice and door systems get priority and guest streaming gets throttled, then configure the policy so it happens automatically at 3am without anyone making a judgement call.
The PSTN switch-off is now a hotel network project
Openreach is retiring the analogue telephone network on 31 January 2027. In February 2026 it reported roughly 2.8 million lines still to migrate, more than half a million of them serving business premises, including more than 12,000 lift lines and around 500 lines serving CCTV networks, alongside fire and burglar alarms and payment terminals. Rental prices for legacy lines rose 20% in April 2026 and a further 40% in July and again in October — effectively doubling the cost against 2025 rates.
Find the copper before it finds you
Walk the building and list every analogue line: lift emergency phones, fire panel dialler, intruder alarm signalling, disabled refuge phones, a fax nobody admits to, the standalone card terminal in the spa, the door entry panel and the gate intercom. Each needs a migration path, and lift and life-safety lines need one that has been tested rather than assumed.
| Path | Modelled service | Role | What it carries when primary fails |
|---|---|---|---|
| Primary | 2 Gbps leased line, 4-hour fix SLA | Everything | n/a |
| Secondary | 1 Gbps FTTP, different carrier | Automatic failover | Payments, PMS, voice, locks, staff; guest throttled |
| Tertiary | 5G router with external antenna | Last resort | Payments and PMS only |
| Out-of-band | Cellular management SIM | Remote access to the estate | Console access to core, firewall and switches |
Security Controls a Good Hotel Network Gives You Free
Segmentation is the expensive control, and the hotel network design has already paid for it. Several others become nearly free once the structure is right.
802.1X on wired hotel network ports
With segments defined, port-based authentication becomes straightforward: a device that cannot authenticate lands in a quarantine VLAN with no access. This single control eliminates the “guest plugged into the meeting room wall socket” class of problem, and it makes rogue-device detection a report rather than an investigation. It is one of the highest-value cybersecurity investments available to a hotel, and it costs a certificate authority and some patience.
MAC authentication bypass for the unauthenticated majority
Cameras, lock gateways and BMS controllers will never speak 802.1X. Profile them, allow them by MAC into a specific VLAN, and alert when a device profile changes. It is weaker than certificates and vastly stronger than an open port.
Egress filtering as a cybersecurity detection tool
Building services and CCTV segments should have no internet egress by default. The value is not only preventive: the first sign of a compromised camera is usually an outbound connection that the design says should be impossible, and that alert costs nothing once default-deny is in place.
Hotel network logging that tells one story
Send switch, firewall, wireless, PMS and POS logs to one place with synchronised time. The monitoring design should retain enough to reconstruct an incident and alert on the handful of events that matter: a new device on the payment segment, a rule change, an 802.1X failure burst, a link flap on a camera uplink.
Test the hotel network segmentation, do not trust it
An annual segmentation penetration test against the rule matrix is both a PCI DSS requirement and the only honest way to know the design still matches reality. Penetration testing that starts from the guest VLAN and tries to reach the payment segment is worth more than a hundred pages of policy.
Incident readiness follows the diagram
When something does go wrong, the network diagram is the first document the responder asks for, because it tells them what can be isolated and at what cost. Keep it with the incident response plan, not in a project folder on a laptop that left with a contractor.
Compliance Your Hotel Network Design Has to Satisfy
Hotel network decisions and compliance obligations meet in the same place: what is connected to what.
PCI DSS scope is a hotel network design outcome
Segmentation is not required by PCI DSS, but it is the recognised method of reducing scope, and the difference is dramatic. On a flat hotel network all 742 devices are in scope. Put payments on the staff segment and it drops to 136. Give payments a dedicated VLAN and it is 41. Move to validated point-to-point encryption with standalone terminals and only the 18 POI devices remain.
Read that chart before signing a POS contract
The gap between 742 and 41 is a network design decision made at drawing stage. The gap between 41 and 18 is a procurement decision made when the terminals are bought. Neither is recoverable cheaply afterwards, which is why PCI DSS for hotels belongs in the design conversation and not the finance one.
Cyber Essentials scoping
Cyber Essentials allows a defined sub-set whose network is segregated from the rest of the organisation by a firewall or VLAN, and it states that cloud services cannot be excluded from scope and that a scope excluding end-user devices is not acceptable. A clean segment design makes the certification exercise dramatically simpler, as Cyber Essentials for hotels sets out in detail.
UK GDPR and the security of processing
Article 32 requires the ability to ensure ongoing confidentiality, integrity, availability and resilience of processing systems, to restore availability after an incident, and to regularly test and evaluate the effectiveness of those measures. A documented, tested segmentation design is direct evidence for all three.
The retention obligation nobody expects
The Immigration (Hotel Records) Order 1972 requires keepers of premises providing lodging for reward to record the full name and nationality of every guest aged 16 or over, plus passport details and onward destination for non-UK and non-Irish nationals, and to keep those records for at least twelve months. That obligation lands on the PMS segment and shapes both its backup design and its data protection story.
Brand and franchise standards
Franchised and brand-managed properties inherit network standards from the brand: mandated SSID naming, minimum bandwidth per room, specified vendors, connectivity to a brand VPN and audit rights. Get the brand standard in writing before the design is drawn, because retrofitting it is expensive and the brand will not compromise.
Monitoring and Running the Hotel Network
A hotel network design is a snapshot. What keeps it true is operations.
Monitor the things guests notice
Circuit utilisation, access point client counts, DHCP scope exhaustion, portal availability and per-SSID throughput are the metrics that predict complaints. Alert on trends, not just outages — a guest segment that has been at 90% utilisation every Friday for a month is a problem you can fix before it becomes a review.
Monitor the things auditors notice
Configuration changes, rule additions, new devices on restricted segments, failed authentications and firmware versions. These are the evidence trail that shows the design is still the design, and they matter as much as availability data.
Hotel network change control a property can actually follow
Hotels do not have change advisory boards. What works is a simple rule: any change to the rule matrix, the VLAN plan or the address plan requires a written record and a named approver, and any change touching payments requires a second pair of eyes. Everything else is business as usual.
Back up the configurations, not just the data
Switch, firewall, controller and recorder configurations should be exported automatically and stored off the network they describe. Rebuilding a floor switch from a backup takes twenty minutes; rebuilding it from memory takes a day and produces a different configuration from the one you documented.
Decide the hotel network support model deliberately
In-house, managed IT services, the WiFi vendor or a mix — but written down, with response times and an escalation path per segment. A hotel network with four suppliers and no named owner produces a 45-minute conference call at every incident.
Keep an asset register that matches reality
IT asset management for a hotel means knowing which of the 742 devices exist, where they are, what firmware they run and who supports them. Reconcile it against what the network actually sees at least twice a year; the difference between the two lists is your real risk register.
What a Hotel Network Design Costs: A 164-Bedroom Model
The figures below are a complete design-and-build for one property, expressed so you can scale them. Every number is either a stated unit rate or arithmetic on the counts already given.
The modelled property
A 164-bedroom four-star hotel over four floors plus a basement, with two restaurants, a bar, a spa, six meeting rooms and a car park. Occupancy 75%. The build is a full network replacement during refurbishment: new structured cabling, new active kit, new wireless, new CCTV, new circuits.
The hotel network device inventory
742 addressable devices as set out in the address plan: 104 access points, 328 bedroom outlets across data and television, 96 cameras, 12 lock gateways, 41 payment and POS endpoints, 15 front-of-house devices, 80 staff PCs and handhelds, 45 building services devices and 21 pieces of network hardware.
| Capital line | Quantity | Unit | Cost |
|---|---|---|---|
| Predictive survey, IP plan and design pack | 1 | £8,400 | £8,400 |
| Cat6a outlets installed and tested | 675 | £145 | £97,875 |
| OM4 fibre risers and comms room fit-out | 5 | £2,150 | £10,750 |
| Wi-Fi 6E access points | 104 | £335 | £34,840 |
| 48-port PoE+ access switches (740 W) | 16 | £2,250 | £36,000 |
| Core switch pair, 10 Gb | 2 | £4,900 | £9,800 |
| Firewall pair, high availability | 2 | £3,750 | £7,500 |
| IP cameras (72 × £210, 24 × £395) | 96 | mixed | £24,600 |
| Recorder and 200 TB usable storage | 1 | £14,800 | £14,800 |
| UPS units for five comms rooms | 5 | £1,850 | £9,250 |
| Installation labour | 74 days | £520 | £38,480 |
| Project management and commissioning | 1 | £9,400 | £9,400 |
| Total capital | £301,695 | ||
| Per bedroom | 164 | £1,839.60 |
Where the capital actually goes
The annual running cost
| Running line | Basis | Annual cost |
|---|---|---|
| Circuits | £680 + £75 + £45 per month | £9,600.00 |
| Licences and subscriptions | 104 × £38 + 16 × £95 + £2,400 + 96 × £42 | £11,904.00 |
| Support contract | 24/7 cover across the estate | £14,400.00 |
| Electricity | 6.0318 kW × 8,760 h × 24p | £12,681.26 |
| Annual segmentation penetration test | PCI DSS 11.4.5 | £5,400.00 |
| Spares and refresh sinking fund | Access points, switches, cameras | £8,200.00 |
| Total annual | £62,185.26 | |
| Per bedroom per year | 164 | £379.18 |
The five-year total
Capital of £301,695 plus five years of running cost at £62,185.26 gives £612,621.30 over five years — £3,735.50 per bedroom, or £62.26 per bedroom per month. Capital is only 49.2% of the five-year figure, which is the single most useful number in this section: half the money is spent after the ribbon is cut, and a business case built on the build cost alone understates the commitment by a factor of two.
The number that closes the argument
At 75% occupancy, 164 bedrooms over five years is 224,475 occupied room nights. Divide £612,621.30 by that and the entire network — every camera, every access point, every switch, every circuit, five years of support and testing — costs £2.73 per occupied room night. That is the figure to put in front of a board, because it is smaller than the cost of the bathroom amenities.
Scaling the hotel network model
The cost per bedroom falls with size, because design, core kit, firewalls and project management are largely fixed. A 90-bedroom property will land nearer £2,300 per bedroom on capital; a 400-bedroom property nearer £1,300. The running cost per bedroom is far more stable, because it is dominated by per-device licensing and support.
Building a New Hotel Network Without Closing the Property
The hotel network design is the easy half. Delivering it in a trading building is where projects fail.
Phase 0 — survey, design and agree the rules
Predictive wireless survey, cabling survey, device inventory, VLAN plan, address plan and rule matrix, all signed off before anything is ordered. Include the brand standard, the PCI scope decision and the PSTN migration list. Two to four weeks, and the phase that saves the most money.
Phase 1 — passive infrastructure first
Comms rooms, containment, risers, fibre and horizontal cabling. Cable pulls in corridors and bedrooms are noisy and dusty, so they follow the refurbishment programme floor by floor. Nothing is cut over yet; the old network keeps running.
Phase 2 — build the new core alongside the old
Install the core, firewalls and main frame room kit in parallel with the existing estate. Bring the new circuits in and test them without traffic. This is the phase that lets everything after it be a move rather than a rebuild.
Phase 3 — migrate floor by floor, out of season
Move one floor at a time, at the quietest point in the week, with the previous floor’s configuration as a template. Keep a rollback: leave the old switch racked and powered for a fortnight after each floor is done.
Phase 4 — migrate the systems, one class at a time
Cameras, then building services, then staff, then PMS and front of house, then payments last. Payments go last because they are the most disruptive to get wrong and because by then every other segment has been proven.
Phase 5 — commission, test and hand over
Validation wireless survey, segmentation penetration test, failover test on every circuit, restore test on every configuration backup, as-built drawings, labelling audit and a documented handover to whoever runs it. A project that skips this phase has not finished; it has stopped.
| Phase | Duration | Guest impact | Exit criterion |
|---|---|---|---|
| 0 — Survey and design | 2–4 weeks | None | Signed design pack and rule matrix |
| 1 — Passive infrastructure | 6–10 weeks | Noise, rooms out of service | All links tested and certified |
| 2 — Core and circuits | 2–3 weeks | None | New core reachable, circuits proven |
| 3 — Floor migration | 1 floor per week | Brief, overnight | Floor live, old switch on standby |
| 4 — System migration | 3–5 weeks | Low, planned per system | Each system live on its own segment |
| 5 — Commission and hand over | 2 weeks | None | Tests passed, as-builts issued |
Hotel Network Design Mistakes We See Most Often
These hotel network faults recur across properties of every size and brand, and every one of them is cheaper to avoid than to fix.
One flat network because “it all needs to talk”
Almost nothing needs to talk to almost anything else. The four flows listed earlier cover it. A flat estate is a decision to put 742 devices into PCI scope and to let a compromised camera reach the front desk.
Buying radios instead of bandwidth
An excellent wireless hotel network behind a saturated 500 Mbps circuit produces exactly the guest experience of a poor deployment. Size the circuit from occupancy arithmetic first, then buy access points.
Letting the security contractor build a parallel network
CCTV installed on its own unmanaged switches, with its own cabling and a router doing port forwarding, is a second hotel network nobody monitors. Own the transport, let the contractor own the cameras.
Undersized backbone, generous edge
Gigabit to every bedroom aggregating into a single gigabit riser is a bottleneck with extra steps. Hotel network fibre risers and 10 Gb uplinks cost a fraction of the horizontal cabling around them.
Treating the guest segment as the only risk
The guest VLAN is well understood and usually well controlled. The building services segment, installed by five contractors over fifteen years, is the one with default credentials and no patch path.
Forgetting the analogue lines until 2027
Lift phones, alarm diallers, refuge phones and the spa’s standalone terminal are on copper that stops working on 31 January 2027, with rental costs already doubling ahead of it. This is a network design task with a hard deadline.
No hotel network as-built documentation
A network nobody can read is a network nobody can fix, secure or hand over. The drawings, matrix and labelling schedule are deliverables, not paperwork.
Designing for opening night, not year seven
Containment full at handover, no spare ports, no spare PoE budget, no spare addresses. The kiosks, chargers and cameras that arrive in year three then get installed badly, because there is nowhere good to put them.
Hotel Network Design FAQ
How many VLANs does a hotel actually need?
Six is the practical minimum — guest, payments, PMS and front of house, CCTV, staff, building services — plus a management segment and usually a separate in-room entertainment segment. Eight is typical for a mid-size property, and larger sites split conference, spa and franchised outlets further.
Can guest WiFi and staff WiFi share access points?
Yes. Multiple SSIDs on the same radios, mapped to different VLANs, is normal and correct. What must not be shared is the layer 2 broadcast domain or the rule set. Sharing radios is efficient; sharing segments is not.
Do I need a separate network for card payments?
You do not have to have one, but PCI DSS scope shrinks from 742 devices to 41 in the modelled property when you do, and to 18 with validated point-to-point encryption. The cost of a dedicated VLAN is one line in the address plan; the cost of not having one is measured in assessment scope every year.
Should CCTV sit on the same infrastructure as everything else?
On the same switches and cabling, yes — that is efficient and gives you monitoring and PoE management. On the same VLAN, no. Cameras are numerous, rarely patched, and generate a large sustained load, which is exactly the profile that belongs on its own segment.
What internet speed does a hotel need?
Work it from occupancy: occupied rooms × guests per room × devices per guest × concurrency × per-session bandwidth, then add events, operations and any off-site replication. For 164 bedrooms at 75% occupancy that arithmetic gives 1,047.5 Mbps, so a 2 Gbps primary with a 1 Gbps failover.
How long should CCTV footage be kept?
Long enough to be useful and no longer than you can justify, with the retention period documented and applied automatically. Thirty-one days is a common hospitality choice and costs 160.7 TB for the modelled camera set; fourteen days halves it. The legal basis and the storage bill both push in the same direction.
Is Wi-Fi 7 worth specifying now?
For a new build or a full refurbishment, yes — the access points cost more but the cabling and switching decisions around them last far longer than the radios. Cat6a and 802.3bt-capable switching are the parts that make a later upgrade a swap rather than a project.
Who should own the design document?
One named person in the operator’s organisation, not a supplier. Suppliers change; the building does not. The operator holds the diagram, the address plan and the rule matrix, and every contractor works to them.
What does a hotel network design cost to have done properly?
The design work itself — predictive survey, IP plan, rule matrix, drawing pack — is around £8,400 for a property of this size, which is 2.8% of the £301,695 build. It is the cheapest line in the project and the one that determines whether the other 97.2% is spent well.
Where should we start if the existing hotel network is a mess?
Inventory the hotel network first, then draw a diagram of what actually exists, then the rule matrix you wish you had. You cannot design a new hotel network on top of an unknown one, and the inventory usually pays for itself by finding devices nobody is supporting. If you want help with that, talk to us about IT support for hotels and hospitality.
References and Further Reading
NCSC — Network security fundamentals
NCSC — Device security guidance: infrastructure
NCSC — 10 Steps to Cyber Security
NCSC — Cyber Essentials overview
NIST SP 800-215 — Guide to a Secure Enterprise Network Landscape
NIST SP 800-41 Rev. 1 — Guidelines on Firewalls and Firewall Policy
NIST SP 800-82 Rev. 3 — Guide to Operational Technology Security
NIST SP 800-153 — Guidelines for Securing Wireless Local Area Networks
NIST SP 800-207 — Zero Trust Architecture
PCI Security Standards Council — PCI DSS
PCI PTS POI Modular Security Requirements v6.1
HCWS386 — Security Update on Surveillance Equipment
Protection of Freedoms Act 2012, section 33
Surveillance Camera Code of Practice
ICO — CCTV and video surveillance
ICO — A guide to data security
UK GDPR Article 32 — Security of processing
The Immigration (Hotel Records) Order 1972
Terrorism (Protection of Premises) Act 2025
Home Office — Martyn’s Law statutory guidance
ProtectUK — Martyn’s Law overview
Openreach — Time for a big switch-up as PSTN switch-off looms
IEEE 802.3bt — Power over Ethernet
IEEE 802.1X — Port-Based Network Access Control
IEEE 802.11be — Extremely High Throughput WLAN
Wi-Fi Alliance — Wi-Fi CERTIFIED 7
Wi-Fi Alliance — Passpoint and access
Ofcom — Improving spectrum access for Wi-Fi
Oracle — Hospitality Integration Platform (IFC8) overview
Oracle — Simphony Check and Posting Service (CAPS)
Oracle — Simphony workstation online and offline modes
RFC 1918 — Address Allocation for Private Internets
DESNZ — Quarterly Energy Prices