Service · Network and security

Hotspot and firewall management

Guest networks for hotels, hospitals, offices, cafés and dormitories: a solid firewall, correct configuration and lawful, protected logging. The management panel and log retention run in the cloud — no server goes into your premises. A setup that gives your guests internet without leaving your corporate network exposed.

Site survey and inventory are free · scope itemised in the quote · fee fixed for 12 months

5651
compliant logging
Cloud
management panel
VLAN
segmentation
Branded
captive portal
System

Three parts, two of them in the cloud

The heavy side of the system — management and log retention — runs in the cloud on separate services. The only component on your premises is the gateway. Hosting, backing up and patching a server is not your job.

01

Management panel

Runs in the cloud

Users, groups, speed limits, filtering rules and the captive portal are managed from a single panel. Who signed in to the panel and what they changed is itself logged.

02

Logging and retention service

Separate from the gateway

Access records are collected on a separate service, signed with a timestamp and kept for the period the regulation requires, with integrity preserved.

03

Hotspot gateway

Sits on site

This is the only component on your premises: it enforces verification, quotas and firewall rules. If your existing enterprise-grade device is suitable, no new hardware is needed.

Scope

What the deployment includes

Scope is narrowed or widened to suit the venue. Exactly which headings are included is written out, one by one, in the quote.

2 minutes · 4 questions

Is your guest internet set up properly?

Four questions about the internet you hand to visitors. If nothing looks wrong, we will tell you that too.

Do you give your visitors internet access?

Question 1 / 4

Do you give your visitors internet access?

Logging

Opening a guest network is easy; keeping it lawful is not

In Türkiye, venues offering public internet access fall under Law No. 5651, which requires access records to be kept, retained for a defined period and protected against tampering. A consumer router’s guest network does not meet that obligation.

  1. 01

    What is recorded

    Verified user identity, connect and disconnect times, device identifier and session details. Access records are kept — not the content of the pages visited.

  2. 02

    How it is stored

    Records are stored timestamped and signed. The point is that a record can be shown, when needed, not to have been altered afterwards.

  3. 03

    Who can access it

    The people allowed to reach the records are defined in writing at setup. Access requests are themselves logged — it is clear who viewed a record.

  4. 04

    How long it is kept

    For the period the regulation requires. The period and the retention responsibility are set out in the contract; if the regulation changes, the configuration is updated.

What you get at the end is not just working wifi but a written record of what is logged, how it is stored and who can access it. That document is exactly what an inspection asks for. For venues that want the whole network surface reviewed, a cyber security assessment is offered as a separate scope.

Verification

How your guests get on the network

One welcome screen with several verification paths behind it. Most deployments run a mix: one method for local guests, another for international ones, and a separate sign-in for staff.

What the sign-in screen asks for is kept minimal. Every field not needed for verification tires the guest and accumulates data you then have to protect — asking for less is a deliberate design choice here.

Comparison

What a router’s guest network does not cover

The conversation usually starts with “we already have a guest network”. The difference is not in the signal — it is in the record and the separation.

Item Consumer router guest mode Managed hotspot
User verification Shared password — nobody knows who connected Identity verified by SMS, e-government, ID or corporate account
Access records None, or a volatile record wiped on reboot A timestamped record per session, on a separate service
Record integrity Alterable, unverifiable Signed retention — later alteration can be detected
Exporting records Not possible on most devices Filtered by date range and exported as a readable file
Guest–corporate separation One flat network; printers, tills and servers are visible Separate VLAN segment with client isolation enabled
Bandwidth control A single download can saturate the line Per-user and per-group speed limits, priority for critical traffic
Multiple sites A separate device, password and problem per branch One panel; users connect at every site with the same credentials
Who responds to a fault You do Monitoring and alerting sit with us — problems surface before guests complain
Process

Five steps from survey to maintenance

Each step has a defined output. When the work is done, you hold the map of your own network.

  1. 01

    Site survey and capacity plan

    Floor plans, wall structure, existing cabling and concurrent user counts are mapped. How many access points are needed, and where they go, is settled here.

  2. 02

    Network design and VLAN separation

    Guest, staff and any special device networks are split into separate segments. Which segment may reach which resource is defined in writing.

  3. 03

    Firewall and hotspot setup

    Rule sets are applied, the hotspot and captive portal go live, and bandwidth quotas and content filtering are configured. The welcome page is built to your brand.

  4. 04

    Verification and log infrastructure

    The user verification method goes live; access logging, timestamping and signed retention are tested end to end. Access rights are defined in writing.

  5. 05

    Monitoring and maintenance

    Access point health, log flow and traffic patterns are monitored and alert rules are set. Configuration changes are managed with versioning.

Sector scenarios

Same infrastructure, different design

Guest experience leads in a hotel, device isolation in a hospital, protection of corporate resources in an office. The deployment is designed around that priority.

Hotel

Room-based access with sessions limited to the length of stay. With front-desk integration, access opens at check-in and closes at check-out. The welcome page runs in the hotel’s branding and the guest’s language.

Hospital

Patient, staff and visitor networks are kept apart, and the medical device network is isolated in its own segment. Clinical systems are unreachable from the guest side, and critical traffic is prioritised.

Office and private company

Staff device policy, visitor guest access and protection of corporate resources are designed together. File servers, accounting systems and printers are invisible from the guest network; staff access is defined by role.

Café and restaurant

Sign-in has to be short — a customer will not fill in a long form. The welcome page works with one tap on a phone. Card terminals and order tablets are kept on a segment separate from guest traffic, so payments do not stall during the evening rush.

Student dormitory

Usage is long-running and peaks late at night. Without per-user quotas and fair-use rules the network chokes within the first week. Capacity is calculated from concurrent device counts, not from floor area.

Shopping centre and estate management

Common-area guest access, tenant networks and the management network are kept apart. In multi-site properties every location is managed from one panel and records are collected centrally.

Businesses that want to hand over network and systems as a whole combine this deployment with the outsourced IT support package: monitoring, alert handling and hardware maintenance all run under one roof.

Commercial model

Fixed for 12 months · no surprise renewal

Legal logging compliance is not a one-off installation but an obligation that has to run without gaps, so the service is delivered on a 12-month agreement: deployment, log retention, monitoring and maintenance scope are written into the contract, and the agreed fee does not change during the year. At year end, device count, log volume and scope are reviewed together and the agreement is signed again — nothing extends automatically, and continuing is your decision.

The site survey and inventory are free. At the end of it you receive, in writing, how many access points are needed, which of your existing devices can stay and what the scope is — that document stays with you even if you do not accept the quote.

FAQ

Frequently asked

Are the sites guests visit recorded?

No. What is kept is an access record: verified user identity, connect and disconnect times, device identifier and session details. The content of the pages visited is not recorded. Where content filtering is applied, the blocked category may also be logged; that is agreed in writing at setup.

How long are logs retained?

For the period the regulation requires, with integrity preserved. The retention period, the retention responsibility and who may access the records are defined in writing at setup. If the regulation changes, the configuration is updated accordingly.

How are users verified?

SMS, national e-government identity or social login can be used. Which one fits depends on venue type and guest profile: SMS often suits a hotel with mostly international guests, while e-government identity is more practical for organisations working with the public sector.

Is a consumer router’s guest network not enough?

It is not. Guest mode on a consumer device usually just shares a password; it does not provide verified identity, timestamped access records or tamper-evident retention. For venues offering public internet access, that is exactly what is required.

Can my existing hardware be used?

Most enterprise-grade devices are compatible. After the site survey and inventory, we report what can stay and what needs replacing due to capacity or lack of firmware support. We do not recommend hardware changes you do not need.

Will the guest network slow the corporate network?

Bandwidth quotas and traffic prioritisation keep guest traffic from affecting corporate traffic. VLAN separation also means a problem on the guest side does not spill into the corporate network.

How many users does it scale to?

From a small office to hotel and hospital deployments with hundreds of concurrent users. Access point count and placement are calculated in the capacity plan from concurrent user density.

How long does setup take?

It depends on the state of the existing infrastructure. A firm schedule follows the site survey; most office deployments finish in a single day. In multi-floor hotel and hospital installations, cabling and coverage work drive the timeline.

Do I need to run a server on my premises?

No. The management panel and the log retention service run in the cloud; you do not host a server, a backup unit or any separate machine. The only component on site is the hotspot gateway. On-premise hosting is possible for organisations that require it — we discuss that during the survey.

I have several branches. Can I manage them all from one place?

Yes. Every location is managed from a single panel and records are collected centrally. A user connects at any branch with the same username and password, so you do not distribute separate passwords per site. Opening a new branch means copying an existing policy to that location.

Does it work with our corporate accounts (Active Directory)?

It does. Staff connect with their existing corporate account and no second user list is maintained. When a leaver’s directory account is closed, network access closes with it. Besides Active Directory, LDAP and in-house user databases can also drive verification.

Can my staff see guests’ personal details?

No. Personal data is closed to unauthorised viewing; nobody — including your own system administrator — can read or alter records freely. Who may reach which record is defined in writing at setup, and every access is itself logged, so it is clear who viewed a record.

Can the welcome page carry our own branding?

Yes. The captive portal is built with your logo, colours and corporate language, and more than one language can be defined. Campaign announcements, internal notices or the privacy notice can be delivered on the same screen.

How is pricing determined?

Concurrent user count, number of locations, access point count and log volume are the drivers. The site survey and inventory are free, and the quote lists exactly which items are included. The fee stays fixed for the 12-month term.

Who handles it if something breaks after setup?

Access point health, log flow and traffic patterns are monitored by us, with alert rules in place. The point is to see the problem before a guest complains. Monitoring, alert handling and configuration maintenance are inside the 12-month agreement.

Project inquiry

Tell us about your project

Fill in the form and we will get back to you within 1 business day on the channel you choose. Your details are used only for this conversation.

Certifications

Our network and cyber security work is carried out by a team holding internationally recognised Cisco certification.

Cisco CyberOps Associate badge

Cisco CyberOps Associate

Issued by Cisco · Holder: Devrim Tunçer

A certification covering security operations centre (SOC) competency: security monitoring, incident response and analysis of network attacks. It is the foundation we rely on for intrusion detection, log correlation and post-incident response work.

Cisco CCNA Training

expired

Cisco training certificate · completed January 2023

Covers networking fundamentals: routing, switching, IP addressing and network security. The knowledge base we draw on for enterprise network setup and segmentation.

Hotspot and firewall management — compliant guest networks

Opening a guest network is easy; keeping it lawful is not

For hotels, hospitals, offices and other public-access venues, giving guests internet is not only technical but a legal obligation. In Türkiye, Law No. 5651 requires access logs to be kept, retained for a defined period and protected against tampering.

A consumer router's guest network does not meet that. Our hotspot service sets up user verification, log recording, timestamping and signed retention together.

Firewall, segmentation and control

The guest network is separated from the corporate network with VLANs — a guest device cannot reach the accounting machine. Firewall rule sets and config management sit with us; bandwidth quotas, content filtering and session policies are tuned to your venue.

Room-based access with stay-limited sessions in hotels, patient/staff/guest separation in hospitals, and device policy in offices. The captive portal is branded to you.

Frequently asked questions

How long are logs retained?
For the period the regulation requires, with integrity preserved. Retention period and access rights are defined in writing at setup.
How are users verified?
SMS, national e-government identity or social login. Which fits depends on venue type and guest profile.
Can my existing hardware be used?
Most enterprise-grade devices are compatible. After inventory we report what can stay and what needs replacing.
Will guest traffic slow the corporate network?
Bandwidth quotas and traffic prioritisation keep guest traffic from affecting corporate traffic.
How many users does it scale to?
From a small office to hotel and hospital deployments with hundreds of concurrent users. Access point count is planned to capacity.
How long does setup take?
It depends on existing infrastructure. A firm schedule follows the site survey; most office deployments finish in a single day.