What a VLAN and a WiFi name actually do
Picture a venue with one set of corridors but colour-coded doors. Everyone walks the same building, yet a guest's key only opens guest doors. A VLAN, short for virtual local area network, works the same way: one set of cables, switches and access points carries several networks, and each one's traffic is tagged so it never mixes with the others.
The WiFi name, or SSID, is the part people see. Each network gets its own name and password, and the access points broadcast them side by side. A device that joins a name lands in that network's VLAN and sees only what lives there. The router at the top decides which VLANs reach the internet, which can reach each other, and how much of the connection each one gets.
None of this needs separate hardware for each group. A business router with VLAN support, plus the access points and switches beneath it, can run five networks as easily as one, provided they're planned before installation rather than added on the day.
The usual separate networks at an event
Not every event needs all five; most need at least three.
| Network | Who or what joins it | Shown to guests? | Why it's separate |
|---|---|---|---|
| Staff and production | Organisers, AV crew, registration laptops, streaming encoders | No | Keeps the run sheet, files and stream away from guest load |
| Guests | Attendees' phones and laptops | Yes, on signage | The busiest and least trusted network, fenced off from the rest |
| Payments and ticketing | EFTPOS terminals, POS tablets, ticket scanners | No | Transactions shouldn't share a network or airtime with the public |
| Devices | Screens, printers, digital signage | No | Fixed devices are rarely updated and shouldn't sit beside guests |
| Cameras | CCTV cameras and recording equipment | No | Constant video traffic and private footage, on reserved PoE ports |
These are categories. Actual WiFi names are chosen for each event.
Why separate WiFi networks matter at events
Separation is less about speed than about what happens when one part of the event gets busy or goes wrong.
Security
Guests on a widely shared password can't reach payment terminals, staff laptops or camera recordings when those sit on networks guests aren't on.
Performance
Each network can have its own share of the connection, so a guest network running flat out leaves the stream's and the payments' share untouched.
Payments that keep working
Terminals stay up at the worst moment for guest WiFi, which is usually your busiest moment at bars and gates. Our event EFTPOS network is built on this.
Simpler troubleshooting
When something slows down, you can see which network is busy instead of guessing, and a problem stays inside one lane.
Cleaner pack-down
Changing or removing one network's password after the event doesn't disturb the others, and nothing staff used is left exposed.
Staff and guest WiFi separation in practice
Staff and guest separation is the split nearly every event needs, even a small one. Guests get a WiFi name that's easy to find on signage and a password that can be printed. Staff get a different name, a password that isn't printed anywhere, and access to things guests shouldn't see: shared drives, the registration system, the encoder's controls.
Both networks run on the same access points, so staff don't need separate equipment. What they need is a reserved share of the connection, set at the router, so a session break that floods the guest network doesn't stall the registration desk. The guest side, from naming to signage, is covered in guest WiFi best practices.
Worked example: a 60-stall market with CCTV
A weekend market with 60 stalls, ticketed entry, a small stage and a few CCTV cameras over the cash-handling area. If each stall runs one or two terminals, that's 60–120 payment devices. At about 50 devices per access point, payment devices alone add up to 120 ÷ 50 = 2.4, so three access points' worth of capacity spread along the stall rows, before staff or guests are counted.
Five networks share those access points: payments and ticketing for terminals and gate scanners; staff for the organisers; devices for the stage screens; cameras on their own VLAN, cabled to reserved PoE ports; and a guest network if the organiser offers public WiFi. Guests can't see a single terminal or camera. Pairing the network with cameras in one visit, as in our network and CCTV package, puts camera traffic in its own lane from the first day.
How to plan the network split for your event
Work through these before anyone configures equipment.
List every group and device type
Write down who and what connects: staff, guests, terminals, scanners, screens, cameras, encoders. Each line is a candidate network.
Group by trust and importance
Combine groups that trust each other and matter equally. Keep payments, cameras and guests apart from everything else.
Decide which networks guests can see
Usually only the guest network appears on signage. The others get names guests won't mistake for theirs.
Set each network's share
Agree how much of the connection each network can use at peak, protecting the stream and payments first.
Test each network separately
Before doors, join each WiFi name with a real device and confirm it reaches what it should, and nothing it shouldn't.
Naming and password rules for event networks
Small habits that keep the separation intact through the event.
- Use one obvious guest name that matches your event, and put only that one on signage
- Give staff and payment networks names that don't look like the guest network
- Avoid names that reveal what a network carries, such as 'EFTPOS' or 'CCTV'
- Use a different password for every network
- Never print staff, payment or camera passwords on signage or run sheets
- Turn on guest isolation so guest devices can't see each other
- Change or remove event passwords after pack-down
Questions people ask
What is a VLAN in simple terms?
A VLAN, or virtual local area network, is a way of running several separate networks over the same cables, switches and access points. Traffic is tagged so each network stays apart, like colour-coded doors in one building. At events, VLANs let staff, guests, payments and cameras share equipment without being able to see each other.
Do I need separate WiFi for staff and guests at an event?
Yes, for almost any event that offers guest WiFi. Separate staff and guest networks keep guests away from registration systems and shared files, and let staff keep a reserved share of the connection when guests are busy. Both networks can run on the same access points, so separation doesn't mean doubling the equipment.
Should EFTPOS be on a separate network at events?
Yes. Payment terminals and ticket scanners belong on their own network, separate from guests, so transactions don't compete with the crowd for airtime and can't be reached from guest devices. Ask your payment provider what network setup it recommends for its terminals, and test each terminal on the payment network before doors open.
How many WiFi networks can one access point broadcast?
Business access points can broadcast several WiFi names at once, each tied to its own VLAN, so one set of access points can carry staff, guests, payments and devices together. Each extra name adds a little overhead on the air, so events usually keep the number to what's needed rather than creating one for every group.
Can guests see other devices on event WiFi?
On a flat network with no separation, guests can sometimes see printers, screens and even other guests' devices. Guest isolation stops guest devices seeing each other, and VLANs keep staff, payment and camera devices on networks guests can't reach. Both are configured at the router and access points before the event.
Should security cameras be on their own network?
Yes. CCTV cameras send video constantly and their footage should stay private, so they belong on their own VLAN, usually cabled to reserved PoE switch ports. That keeps camera traffic off the guest and staff networks and stops anyone on the WiFi from reaching the cameras or the recordings.