Planning the Network in a New Build or Hotel: Checklist from Cabling to Wi-Fi
Checklist for network planning in new builds, hotels and offices: cabling, switches, segmentation, firewall, Wi-Fi, guest Wi-Fi and documentation.
A network in a new build can only be planned properly once. Once the ceilings are closed, every additional cable costs many times more, and missing segmentation is retrofitted with compromises. That applies especially to hotels, where guests, staff, tills, the locking system and building services share one building.
Clarify requirements and plan the cabling
The IT-Grundschutz of the German Federal Office for Information Security (BSI) does not begin with devices. Module NET.1.1 requires a security policy, documentation, a requirements specification and a network plan. These points are settled in writing first:
- User groups: staff, guests, delegates, service providers, patients. Each group later becomes its own zone.
- Systems: booking, tills, locking system, telephony, building automation, cameras.
- Availability: what may fail and for how long.
- Growth: the number of devices per room or workstation rises steadily.
- Regulations: IT-Grundschutz, payment provider requirements for hotels, the GDPR for everyone.
The passive infrastructure lasts longest and is hardest to change. Proven practice: two data outlets per workstation or room, a ceiling outlet for an access point in every room and cabling that supports Power over Ethernet. Equipment rooms need access control, air conditioning and an uninterruptible power supply, and distributors are connected by fibre.
Zones, switches and firewall
Segmentation is decided in planning, not in configuration. Under NET.1.1.A4 the network must be separated at least into internal network, demilitarised zone (DMZ) and external connection. Under A5 clients and servers sit in different segments, under A6 only devices with a similar security level share a segment.
Typical hotel zones: guest Wi-Fi, room technology, reception, payment, locking system, building services, cameras, servers, backup and management. Each zone becomes its own VLAN and reaches only what it needs. Building services get no internet access, and the backup is reached only from the servers, never the reverse.
Switches need enough ports, Power over Ethernet and reserves. NET.3.1 applies: secure basic configuration, protected administration interfaces, logging and configuration backup. What switches, VLANs and zones do is explained in the article Network security for businesses.
The firewall controls all transitions between zones, not just the internet gateway. NET.3.2 requires unambiguous rules on the allowlist principle, stateful filtering and logging, and NET.1.1.A10 an external DMZ for every service reachable from the internet. The firewall is sized for all traffic between the zones, the rule set is complete before the first guest arrives, and service providers’ remote access runs through a VPN with multi-factor authentication, limited to its zone. Typical rule set mistakes are described in the article Firewall rules and port forwarding.
Plan and survey the Wi-Fi
Module NET.2.1 requires suitable cryptographic methods, suitable placement of access points and the separation of security zones.
- Radio planning before installation: planning from the drawings and measurement on site, because reinforced concrete and lift shafts change the range considerably.
- Encryption: under NET.2.1.A3 at least WPA2, with a pre-shared key of at least 20 characters. In the staff Wi-Fi, certificates or user accounts are preferable to a shared password.
- Guest Wi-Fi: own SSID, own VLAN, an “internet only” rule and isolation of guests from each other.
- Basic configuration: under NET.2.1.A5 default SSIDs, passwords and keys are changed and insecure administration access is disabled.
Building services, documentation and operation
Building services are often underestimated. Heating, ventilation, lifts and access control come from different trades, each with a networked device and a wish for remote access. NET.1.1.A6 applies without exception: separate zones, no internet, remote access only through the firewall with logging.
Documentation (NET.1.1.A2) suffers most under time pressure. The handover includes a network plan with zones and transitions, a cable plan with labelling scheme, a device list with location and firmware version, the firewall rule set with a purpose per rule, the Wi-Fi plan, a list of all remote access with owners, and a password manager the operator can access, not just the installer.
After that, a network is only as secure as its maintenance. The BSI’s 2025 situation report names timely updates as a decisive lever for 2026. Planning therefore includes maintenance windows for updates, monitoring with alerting, configuration backups, spare devices and the annual target-actual comparison (NET.1.1.A15). The role of anomaly detection is discussed in the article AI in network security.
Key points
- Requirements, zones and the rule set are defined in writing before the electrical planning, because cabling and segmentation are the most expensive to retrofit.
- Every user group and every trade gets its own VLAN with firewall rules in between.
- The handover includes complete documentation, access to the password manager and a plan for updates, monitoring and backups.
How DEVACON plans and delivers networks for hotels, offices and public administrations is described on the page Network and IT infrastructure.
Sources
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.1.1 Netzarchitektur und -design, bsi.bund.de
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.2.1 WLAN-Betrieb, bsi.bund.de
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.1 Router und Switches, bsi.bund.de
- BSI IT-Grundschutz-Kompendium, Edition 2023, module NET.3.2 Firewall, bsi.bund.de
- Federal Office for Information Security (BSI): Die Lage der IT-Sicherheit in Deutschland 2025, bsi.bund.de/lagebericht
This article comes from the DEVACON blog and was editorially revised for the new website.