Restaurant connectivity with payments first
Give tills, kitchen displays, delivery tablets and guests the access they need, with a branch pattern that supports a busy service period.

Reserve backup capacity for trading
Separate kitchen and payment systems
Repeat an accepted branch configuration
How the solution connects
Independent uplinks meet a controlled network boundary. Local access is separated by purpose.
Read the connection map
- Restaurant broadband → MX75 firewall · Primary path
- RUT241 LTE · backup → MX75 firewall · Alternate WAN
- MX75 firewall → Compact PoE switch · Policy boundary
- Compact PoE switch → POS + payment · Separate zone
- Compact PoE switch → Kitchen + delivery tablets · Separate zone
- Compact PoE switch → Guest Wi-Fi · Separate zone
The challenge on the ground
Delivery aggregators, cloud POS and kitchen displays can each have different internet dependencies. A guest streaming session should not compete with payment authorisation when the restaurant is relying on LTE.
The first design question is which transactions must continue during a busy service, not the headline speed of the router.
Inside the design
Use an MX75 to enforce payment, business, guest and management policy. A compact Catalyst C1300 PoE switch connects tills, APs and supported kitchen devices; CW9172I provides indoor wireless coverage.
Connect a RUT241 LTE router to the secondary WAN for the essential workload. Keep guest clients isolated, allow only documented payment-provider destinations and give the POS supplier controlled remote-support access.
Operating it day to day
Create a backup policy that pauses guest access and bulk updates before restricting trading systems. Check how each ordering tablet handles interrupted sessions and duplicate orders.
Maintain an approved branch template and record exceptions for local ISPs or terminals. Hardware selection can support segmentation, but PCI DSS scope and validation remain an assessment of the complete payment environment.
What to test before handover
- Place test dine-in and delivery orders while the primary WAN is disconnected.
- Confirm payment-network isolation from guests and kitchen devices.
- Check order reconciliation after WAN restoration.
- Run the backup link during a representative busy period without guest traffic.
Technical references
The bill of materials
One restaurant with a till area, kitchen, office and guest seating. Quantities below describe the example; your proposal confirms the final equipment and services.
Teltonika RUT241 Cellular network router
RUT241010000Essential-traffic LTE backup
Capacity is sized for trading systems, not unrestricted guest internet.
View productComplete the installation
The equipment above is one part of the project. Include these items in the final scope.
- Meraki and AP licences
- LTE service and antenna assessment
- UPS, patching and installation
- Payment-provider validation
Questions before you specify
Is the network automatically PCI DSS compliant?
No. Segmentation must be implemented and tested within the organisation’s assessed payment environment; product selection alone does not establish compliance.
Let’s design it for your site.
Send us the details below. We can turn the reference architecture into a scoped design, equipment schedule and quotation.
Start your projectBring these to the first conversation
- 01POS and payment processor
- 02Kitchen and delivery-platform dependencies
- 03Peak transactions and guest policy
- 04Remote support and compliance scope







