Stampede
SNAPguard

The box

Guest Wi-Fi is the one part of the platform that runs inside somebody else's building. Here is the appliance we put there, and why it dials out instead of letting us in.

The problem

Someone else’s network.

Guest Wi-Fi is the only part of the platform that lives inside infrastructure we do not own. Every venue is a different router, a different ISP, a different cupboard of switches installed by a different contractor, and often a phone system and a CCTV recorder quietly running their own managed switch that nobody has logged into for years.

The usual answer is to ask the venue to open a port. That is a security problem, an IT-department problem and a support problem all at once, and it fails the moment the ISP changes the public address. We wanted the opposite: a device that reaches out to us and never needs anything reaching in.

The design

It dials out.

SNAPguard is a MikroTik-based appliance that plugs into the venue’s existing router or controller and holds an outbound WireGuard tunnel back to us. Nothing is forwarded, nothing is exposed, and the venue’s public address can change as often as it likes. Once the tunnel is up we can configure the box over the RouterOS API as if we were stood in the cupboard.

The tunnel terminates on regional servers rather than one central endpoint, each with its own address space, so a venue connects to infrastructure near it and can be migrated between regions without re-provisioning the hardware. Peer keys, address allocation and certificate deployment are all handled by the same service that watches the tunnels.

Outbound only

No port-forwarding and no inbound rules. The box initiates the connection, so a NAT or a changing IP is not an obstacle.

Provisioned remotely

Networks, bandwidth policy, portal certificates and firmware are pushed over the tunnel. Nobody needs to drive to the venue for a config change.

Segmented by design

Guest, staff, payments and cameras get their own tagged networks, so a card reader never shares a broadcast domain with a guest phone.

It takes stock

The box can scan the venue network and report what is on it: access points, speakers, printers, cameras, payment terminals.

Setup

Hands-on, honestly.

The activation flow in connect walks the venue through it: detect the existing setup, record the line speed, create the networks from templates, mirror them into UniFi or Omada if there is a controller, then check what address a phone actually gets on each network and confirm the portal appears.

We are not going to call this a five-minute self-install. Multi-AP sites and older comms cabinets need a real pair of hands, and the most common failure is a managed switch nobody knew about stripping the guest VLAN. Setup runs with our team, usually alongside the venue’s IT or installer, and the wizard exists to make that call short rather than to remove it.

The same honesty applies to running it: when the box or the controller is offline, capture stops. It is the single biggest driver of support contact we have, it is usually something upstream of us, and we still own the problem.

Setup questions, odd cabinets and awkward switches welcome: the fastest way to find out if your venue is straightforward is to ask.