Networking

Hospitality Wi-Fi Design: A Hotel and Resort Buyer's Guide for 2026

How to spec guest Wi-Fi that survives 1,000 devices, satisfies GDPR, and integrates with PMS

12 min readUpdated 22 August 2026

Hotel guest Wi-Fi is now the single highest-leverage IT investment a property can make: it dominates online reviews, it drives ancillary revenue through captive-portal marketing, and it underpins every PMS, POS, IPTV, and IoT system in the building. Designing a hospitality network in 2026 means planning for 4–6 devices per guest, AV-over-IP cinema rooms, IP CCTV, smart-lock integration, and GDPR-compliant guest logging — all on a 24/7 SLA. This guide covers what to spec, what to avoid, and how to procure across the EU.

Capacity planning: it's about density, not coverage

The single biggest mistake hospitality IT projects make is treating Wi-Fi as a coverage problem ("will I have signal in the room?") rather than a density problem ("how many devices can I serve in the lobby at 7pm?"). A typical 4-star European city hotel needs to support 4–6 active devices per occupied room plus 2–3 devices per public-area guest. A 200-room property in full occupancy with a busy bar means ~1,200 concurrent clients in 20,000 sqm of space.

Plan one AP per 2 guest rooms minimum, one per 30–50 sqm in public areas, and 1 per 20 sqm in conference space. Wi-Fi 6E or Wi-Fi 7 is now the default — 6 GHz spectrum is essential in dense city centres where the 5 GHz band is already saturated by neighbouring properties. For new builds, run Cat6A to every room so you can future-proof to multi-gig PoE.

Choosing the right AP platform

The hospitality AP market has three serious players in 2026: Cisco Meraki, Aruba Instant On / CX with Aruba Central, and Ruckus (CommScope) for high-density properties. Ubiquiti UniFi is now common in 3-star and budget brands but lacks the PMS integrations expected in upper-upscale.

Meraki MR-series with the unified Meraki+Catalyst Cloud Manager is the default for chains because the cloud dashboard lets a regional IT manager troubleshoot 50 properties from one pane of glass. Aruba Instant On + Central wins on price-per-AP and on the multi-tenant management console for hotel groups. Ruckus dominates large-resort and convention-centre tenders thanks to BeamFlex and unusually good performance in steel-framed buildings.

  • Meraki MR46/MR56 — chain-friendly cloud dashboard, expensive per AP
  • Aruba AP-535/AP-635 — best price-per-AP for 4-star independent properties
  • Ruckus R650/R760 — best high-density for 800+ device convention spaces
  • UniFi U7-Pro / U7 Enterprise — budget 3-star, owner-operated boutique

Captive portals and PMS integration

A modern hospitality captive portal does three jobs: it authenticates the guest against the PMS (Opera, Mews, Cloudbeds, Apaleo, Protel), it collects opt-in marketing consent under GDPR, and it brands the experience. Cloud4Wi, Purple, Tanaza, MyWiFi, and Cisco Spaces dominate the European market. Native PMS integrations matter — when a guest checks in at the front desk, their Wi-Fi credentials should be ready in their welcome email without staff intervention.

The portal must log username, MAC address, IP, and session start/end for the retention period required by the relevant member state (typically 6–12 months in EU jurisdictions that retain post-Tele2 data-retention requirements). Build this into the spec so a future audit doesn't catch you with no logs.

VLAN segmentation for hotels

Minimum segmentation: Guest, Staff/Back-of-house, IoT (smart locks, thermostats, lighting), POS, PMS/Back-office, CCTV, AV/IPTV, BMS/HVAC, VoIP, Management. PCI DSS compliance for card-present POS requires the POS VLAN to be isolated with stateful inspection at the firewall — not just an ACL on the switch. Smart locks (Assa Abloy VingCard, Salto, dormakaba) should run on a strictly internal VLAN with no internet egress except to the lock vendor's cloud endpoint via an explicit allowlist.

Client isolation must be enabled on the guest SSID — without it, every guest's laptop sees every other guest's AirDrop, Chromecast, and SMB shares. Brand-damaging incidents (guests printing to other guests' shared printers) are surprisingly common in hotels that skip this.

Firewall, IDS, and content filtering

A hospitality firewall is doing more than gateway: it terminates site-to-site VPNs to the chain's central data centre, enforces content filtering on the guest VLAN (most properties block pornography by default — Sophos XGS, FortiGate, Cisco Meraki MX and Kerio NG all provide this with subscription content categorization), runs IPS on north-south traffic, and is the policy enforcement point for the captive portal redirect.

FortiGate 80F/100F, Sophos XGS 116/136/166, Meraki MX85/MX95, and the Kerio NG500 series are the typical platforms. For a 100–300 room property, the MX95 or FortiGate 100F is the sweet-spot in 2026.

Switching, PoE, and cabling

Spec PoE++ (802.3bt, 60–90W per port) at the access layer if you intend to power Wi-Fi 6E/7 APs that pull 30W+ peak, plus IP phones, IP cameras, and smart-room hardware. Multi-gig (2.5/5/10 GbE) access ports are now standard for the rooms and lobby because Wi-Fi 7 APs can saturate a 1 GbE uplink on the 6 GHz band alone.

Core: 10/25/100 GbE stackable L3 with redundant PSUs. For a 200-room property: 2× Meraki MS425 or Aruba CX 6300, with 10 GbE uplinks to a campus-class firewall.

  • Access: 802.3bt PoE++ multi-gig switches, 24/48 ports
  • Core: 2× L3 stackable with 10/25/100 GbE uplinks
  • Cabling: Cat6A minimum, Cat6A shielded in EMI-noisy MEP risers
  • UPS: APC Smart-UPS SRT or Eaton 9SX, 30-min runtime on each IT closet

AV-over-IP, IPTV, and in-room entertainment

In-room IPTV is increasingly delivered as IP video over the data network rather than as separate coax — solutions from Samsung, LG, Otrum, Quadriga, EXFO/Beamr, and Allbridge encode 4K HDR streams onto the same VLAN-segmented Layer 3 core. Spec switches with IGMP snooping + querier and jumbo frames (9000 MTU) on the AV VLAN.

Conference and ballroom AV-over-IP (Crestron NVX, AMX SVSI, Just Add Power) follows the same network requirements — multicast-aware switching, separate VLAN, and over-provisioned uplinks. A wedding reception that drops video mid-toast is a five-figure refund waiting to happen.

Procurement, lead time, and EU compliance

Hospitality refits run on hard deadlines — the property reopens on a specific date and the GM does not care about the supply chain. Specify components with EU stock from multiple warehouses, get power cables in the correct regional plug type from day one (don't accept US C13-to-NEMA adapters as a stopgap), and confirm CE marking for radio equipment (some grey-market US APs ship without ETSI radio firmware and are unusable in the EU).

FUSE stocks the major hospitality Wi-Fi, switching, and security platforms from EU warehouses with multi-warehouse fulfilment in MT, NL, DE, and PL — reducing single-source risk during a tight refit window.

Frequently asked questions

How many access points does a 150-room hotel need?

+

Plan for 80–110 Wi-Fi 6E or Wi-Fi 7 access points in a typical 150-room 4-star property — roughly one per 2 guest rooms, plus dedicated APs for the lobby, restaurant, bar, conference rooms, pool deck, and back-of-house. Public areas need higher density than rooms.

Should I use Meraki, Aruba, Ruckus, or UniFi?

+

For chain hotels, Meraki with the unified Meraki+Catalyst Cloud Manager wins on multi-property management. Aruba Instant On + Central wins on price-per-AP for 4-star independents. Ruckus R650/R760 wins for 800+ device convention and resort spaces. UniFi U7 series is appropriate for 3-star and boutique properties where capex matters more than vendor SLA.

What captive portal works with Opera, Mews, or Cloudbeds?

+

Cloud4Wi, Purple, Tanaza, MyWiFi, and Cisco Spaces all offer native integrations with the major PMS platforms. Verify your specific PMS version is supported before committing — Opera Cloud, Mews v3, and Cloudbeds API v1.2+ are the safer choices in 2026.

How long do I have to retain Wi-Fi guest logs in the EU?

+

Retention requirements vary by member state. Some EU countries retain post-Tele2 mandatory retention regimes (typically 6–12 months for authentication metadata); others are at the controller's discretion under GDPR. Consult local counsel and configure your captive portal to retain MAC address, username, IP, and session start/end for the applicable window with a documented deletion routine.

Do I need a separate VLAN for smart locks?

+

Yes. Assa Abloy VingCard, Salto, and dormakaba IP locks should run on a strictly isolated VLAN with no internet egress except to the lock vendor's cloud endpoint via an explicit firewall allowlist. Never share the smart-lock VLAN with guest, staff, or POS traffic.

What firewall is right for a 200-room hotel?

+

Cisco Meraki MX95, FortiGate 100F, Sophos XGS 166, or Kerio NG520 are appropriate for a 200-room property. They handle the inter-VLAN policy, content filtering on the guest segment, IPS, and site-to-site VPN to the chain's central infrastructure.

Where do I buy hotel-grade Wi-Fi equipment in the EU?

+

FUSE stocks the full hospitality networking stack — Cisco/Meraki, Aruba, Ruckus, Ubiquiti, FortiGate, Sophos, Kerio — from EU warehouses in Malta, Poland, Netherlands, and Germany. Multi-warehouse fulfilment minimizes the supply-chain risk of a tight refit window.

Browse Ubiquiti Wireless Access Points on FUSE

Multi-warehouse EU stock from Malta, Poland, Netherlands, and Germany — with EU-resident technical support and ETSI-compliant regulatory-domain hardware.

Primary sources

Technical and regulatory claims in this guide are checked against these first-party references. Product availability and regional variants should still be confirmed before ordering.

Related guides