Networking

Marine IT and Yacht Networking: The 2026 Buyer's Guide

How to design crew Wi-Fi, guest internet, VSAT failover, and onboard CCTV for superyachts 35m+

14 min readUpdated 22 August 2026

Modern superyachts run more infrastructure than a small enterprise: redundant VSAT and LEO satellite links, multi-VLAN Wi-Fi for crew and guests, AV-over-IP backbones for cinema rooms and bridge displays, NMEA 2000 gateways for navigation telemetry, IP CCTV for ISPS Code compliance, and PMS-style guest service systems. Getting any of it wrong on a 60m boat means an angry charter guest in the middle of the Tyrrhenian Sea with no internet. This guide walks through how to design, specify, and procure a yacht network in 2026 — what the standards say, what works in real-world refits, and how to keep total cost of ownership sane across a 10-year vessel life.

Connectivity: VSAT, Starlink, and the new dual-orbit reality

Until 2022, marine connectivity meant Ku-band or Ka-band VSAT (KVH TracPhone, Intellian, Cobham, Inmarsat Fleet Xpress) — high latency (600–900ms), modest throughput (4/2 to 20/3 Mbps), and four-figure monthly airtime. In 2023, Starlink Maritime arrived with 200 Mbps+ symmetric, sub-100ms latency, and roughly flat monthly cost — and it has reset the entire category. Most 35m+ vessels now run dual-orbit: a primary LEO link (Starlink, OneWeb Maritime) plus VSAT failover for Ku-band coverage outside Starlink's footprint and for compliance-critical traffic.

The design choice that matters most is the SD-WAN edge box that bonds the links. Peplink, Cradlepoint, Cisco IR1101 and Fortinet SecureRouter all do this, but the marine sweet-spot is Peplink BR-series / MAX-Transit / SpeedFusion bonded with hot-failover policies. SpeedFusion in particular lets you VPN-bond Starlink + VSAT + 4G/5G cellular into a single logical pipe with sub-second failover so a Zoom call survives the moment Starlink drops as the dish blocks behind a superstructure.

Cellular as a third path

In coastal Mediterranean cruising (Côte d'Azur, Balearics, Amalfi, Greek islands) cellular is often the cheapest and fastest path. A multi-SIM, multi-carrier router with eSIM (Peplink, Teltonika, Cradlepoint) automatically picks the strongest carrier and falls back to satellite outside coverage. Specify Cat-18 LTE-A or 5G NR Sub-6 modems and external high-gain marine antennas — bow-mounted or atop the radar arch.

Network topology: cores, distribution, and access

A 35m vessel typically needs a three-tier topology: two redundant Layer-3 core switches in the technical space (engine room or AV rack room), distribution switches in the upper-deck and bridge electronics cabinets, and PoE+ access switches near each Wi-Fi cluster. For 50m+ vessels with multiple guest decks, dual-star with MLAG/LACP between cores becomes mandatory for any RSTP convergence under one second.

Brand choice is mostly between Cisco Catalyst 9300/Meraki MS, HPE Aruba CX 6300, Ubiquiti UniFi Pro / Enterprise XG, Ruckus ICX, and Mikrotik CRS series. Meraki dominates the megayacht refits we see because the cloud dashboard lets the shoreside ETO troubleshoot from anywhere with a satellite session, and the licensing now ships under the unified Meraki+Catalyst Cloud Manager. UniFi is increasingly common on 35–45m owner-operated boats where capex matters more than a 24/7 support SLA.

  • Core: 2× L3 stackable 24-port multi-gig with 10/25/100G uplinks
  • Distribution: 12–24 port PoE+ switches per deck, multi-gig where the cabling tolerates Cat6A
  • Access: high-density Wi-Fi 6E or Wi-Fi 7 access points spaced for ≤−65 dBm at every guest position
  • Out-of-band: dedicated management VLAN reachable via a secondary cellular SIM

Wi-Fi: design for steel, not air

Wi-Fi inside a steel and aluminum hull behaves nothing like a hotel. Bulkheads, watertight doors, and SOLAS-rated joinery turn every cabin into its own RF cell. Plan ~1 AP per 2 cabins minimum and dedicate APs to crew areas; never share a guest AP across a watertight bulkhead. Wi-Fi 6E (6 GHz) and Wi-Fi 7 (320 MHz channels, MLO) are now the default for new builds — they let you escape the saturated 5 GHz spectrum that fills up in marina environments where 40+ vessels share the same band.

SSID design: at least three SSIDs — Guest (open captive portal, isolated VLAN, bandwidth-shaped), Crew (WPA3-Enterprise tied to crew RADIUS), and IoT (WPA3-Personal, isolated, blocked from internet). Avoid the common mistake of dumping bridge electronics on the IoT SSID — give nav gear its own VLAN with no WAN egress.

VLAN segmentation and security

Minimum VLAN scheme on a charter-grade yacht: Guests, Crew, AV/IPTV, Bridge/NMEA, BMS/HVAC, CCTV, VoIP, Management. Inter-VLAN routing flows through the L3 core with stateful ACLs (or a dedicated firewall — Sophos XGS, Fortinet 80/100F, Cisco Meraki MX, Kerio NG series). The bridge/NMEA VLAN must be one-way: it can be queried from the captain's tablet but never reachable from guest networks. ISPS Code-compliant CCTV similarly stays internal-only with NVR recording on-board, not in cloud.

WPA3-Enterprise with EAP-TLS certificates issued per crew member is now the expected baseline on yachts that hold passenger ship safety certificates. Cycle guest passwords per charter and isolate guest devices with client isolation enabled on the AP — sharing a network with the next charterer is a recipe for AirDrop chaos.

AV-over-IP and IPTV

Modern yachts run AV over the data network: Crestron NVX, AMX SVSI, ZeeVee ZyPer 4K, or Just Add Power 3G/4K send 4K HDR video, audio, and control over the same multicast-capable switching fabric. This collapses a previous decade's worth of HDBaseT matrix switchers into a network closet. Spec L3 switches that explicitly support IGMP snooping with querier, PIM-SM, and jumbo frames (9000 MTU). On Cisco/Meraki, enable IGMP snooping per VLAN; on Aruba CX, configure ip igmp snooping enable plus a querier. UniFi Enterprise switches now ship usable IGMP snooping; the older Pro line does not — verify before you spec.

Separate the AV-over-IP VLAN from data so a guest streaming a 4K Netflix doesn't share queue depth with the Crestron NVX feed of the cinema room.

CCTV, access control, and IP intercom

ISPS Code-certified vessels need recorded CCTV at all entry points with a minimum retention window (typically 30 days). Axis, Hikvision, Hanwha, and Bosch all offer marine-rated PoE+ cameras with stainless-steel housings rated to IP66/IP67. Pair them with a Synology, QNAP, Milestone XProtect, or Genetec NVR on a UPS-backed VLAN that does not depend on the WAN.

Access control (engine room, owner's stateroom, tender garage) is now usually IP-based — Paxton, Salto, Suprema — running over PoE+ with mag-locks or motorized hardware. Specify cards or mobile credentials with revocation built-in so a departing crew member can be locked out before they reach the gangway.

Procurement, warranties, and EU compliance

Yacht IT procurement is its own discipline: customs status (T2/T2L for EU-bagged vessels), VAT treatment (yacht in commercial vs private status), warranty operability outside the manufacturer's home country, and lead time during the May–September Med season. Working through an EU-based marketplace with multi-warehouse stock (MT, NL, DE, PL) avoids the classic disaster of waiting six weeks for a switch backordered in a US distributor while the boat sits in Antibes with a dead network.

One line item that is routinely forgotten until commissioning week is the onboard application server. Yacht management platforms — IDEA Yacht in particular — run on-vessel so ISM/ISPS documentation, crew rotas, and planned maintenance survive a satellite outage. FUSE is a Distributor for <a href="/brands/idea-yacht">IDEA Yacht</a> servers certified and optimised for IDEA software: SR100 and SR200 in 1U for a proper rack, NR100 and NR110 mini servers where space is tight on a refit.

Common-mode RFQ items: enterprise switches with five-year warranties (Cisco SMARTnet, Aruba Foundation Care, Meraki Enterprise license), spare PSUs, spare optics, redundant patch cabling, and a labeled spares box stowed on board. Don't forget UPS — Eaton 9SX or APC Smart-UPS SRT with the right NMC card so the BMS can monitor it.

Frequently asked questions

Should a new build use VSAT, Starlink, or both?

+

Both. Starlink Maritime is the primary high-throughput link in 2026 thanks to sub-100ms latency and 200+ Mbps throughput. VSAT remains the failover for coverage gaps, regulatory traffic, and high-latitude cruising outside the LEO footprint. A Peplink SpeedFusion or Cradlepoint NetCloud router bonds them with policy-based hot failover.

How many access points does a 50m yacht need?

+

Plan for 12–18 Wi-Fi 6E or Wi-Fi 7 APs on a 50m vessel — roughly one per pair of cabins plus dedicated APs for the saloon, sky lounge, bridge deck, crew mess, and engine control room. Steel bulkheads attenuate signal so heavily that you cannot share APs across watertight zones.

What's the right firewall for a superyacht?

+

For 35–60m vessels, a Fortinet FortiGate 60F/80F, Sophos XGS 116/126, Cisco Meraki MX85/MX95, or Kerio NG200 series is appropriate. They handle multi-WAN failover between Starlink, VSAT, and cellular, run IPS/IDS for the guest segment, and integrate with cloud dashboards your shoreside IT can manage remotely.

Can I use UniFi on a megayacht?

+

Yes, increasingly common on owner-operated 35–45m boats. UniFi delivers 70–80% of the capability of Cisco/Aruba/Meraki at roughly a third of the capex. The trade-offs are no 24/7 vendor support SLA and a less mature ecosystem for advanced multicast (IGMP querier behaviour) and 802.1X certificate workflows.

How do I segment guest, crew, and bridge networks?

+

Implement at least eight VLANs (Guest, Crew, AV/IPTV, Bridge/NMEA, BMS/HVAC, CCTV, VoIP, Management) with inter-VLAN ACLs on a Layer 3 core. The bridge VLAN must be unreachable from the guest network in any direction. WPA3-Enterprise with per-user EAP-TLS certs is the expected baseline for crew Wi-Fi.

Do I need IGMP snooping for AV-over-IP?

+

Yes. AV-over-IP systems like Crestron NVX, AMX SVSI, ZeeVee ZyPer, and Just Add Power use multicast for video distribution. Without IGMP snooping with an active querier and jumbo frames enabled, multicast traffic floods every port and saturates the switching fabric. Verify the switch you're specifying supports both before purchase.

What server should run IDEA Yacht management software on board?

+

IDEA's yacht management suite expects a dedicated onboard server so crew, ISM/ISPS records, and maintenance logs stay available when the satellite link drops. FUSE is a Distributor for <a href="/brands/idea-yacht">IDEA Yacht</a> and supplies servers certified and optimised for IDEA software: the 1U rack SR100 and SR200 for engine-room or AV-rack installation, and the compact NR100/NR110 mini servers for smaller vessels and refits where rack space is scarce.

Where do I buy yacht-grade networking equipment in Europe?

+

FUSE stocks the full range of yacht-grade networking, security, and AV-over-IP equipment from EU warehouses in Malta, Poland, Netherlands, and Germany — including Cisco/Meraki, Aruba, Fortinet, Sophos, Peplink, Ubiquiti, Axis, Hikvision, Crestron, and AMX. Multi-warehouse stock minimizes lead times during the Med season.

Browse Peplink Routers on FUSE

Multi-warehouse EU stock from Malta, Poland, Netherlands, and Germany — with EU-resident technical support and ETSI-compliant regulatory-domain hardware.

Primary sources

Technical and regulatory claims in this guide are checked against these first-party references. Product availability and regional variants should still be confirmed before ordering.

Related guides