Stampede

SNAPguard

Plugs in.Dials out.Provisioned.

The appliance we put in the venue: an outbound WireGuard tunnel back to Stampede, so the whole network is provisioned remotely with nothing exposed.

Router
Access points
Till
Cameras
Staff devices
SNAPguard
Networks · tagged
Tunnel · outbound only
everything in the cupboard, behind one box

Powering 2,500+ UK venues

Art HospitalityNº 90OIR GroupPlonk'dSankey'sThe StablesCoast & CountrySiam NiyomHowiesLa-YamBuoy & OysterThe Northern Collective
Vittoria GroupNo.12 Hotel & BistroKneadFifteenThe Welsh HouseValiant Pub CompanyParadise PalmsArtisan InnkeepersFauna BrewingSmoke BBQRocca GroupOrnithology
The problem

Someone else’s network.

Every venue is a different router, a different ISP and a cupboard of switches installed by a different contractor. The usual way to manage any of it remotely was to ask the venue to open a port: a security problem, an IT problem and a support problem at once, dead the moment the ISP changes the address.

The comms cupboard, as found
ISP routerPort left open
Remote access
Managed switchNo login
CCTV recorderOwn network
a different cupboard in every venue, and the only way in used to be a hole in the firewall.
How it works

It dials out.

The opposite of asking a venue to open a port: a device that reaches out to us and never needs anything reaching in.

dial out · provision · segment
01Dial out

The box reaches out

SNAPguard holds an outbound WireGuard tunnel to a regional endpoint. Nothing is forwarded, nothing is exposed, and a changing public address never matters.

02Provision

Config comes down the pipe

Networks, bandwidth policy, portal certificates and firmware are pushed over the RouterOS API, as if we were stood in the cupboard.

03Segment

Four networks, tagged

Guest, staff, payments and cameras each get their own tagged network, so a card reader never shares a broadcast domain with a guest phone.

no ports opened, no inbound rules, ever. the tunnel is outbound only.
In practice

The venue, drawn.

What the box actually does to a comms cupboard, on one drawing.

Outbound only

No port-forwarding and no inbound rules. The box initiates the connection, so a NAT or a changing IP is never an obstacle.

Provisioned remotely

Networks, bandwidth policy, portal certificates and firmware are pushed over the tunnel. Nobody drives to the venue for a config change.

Segmented by design

Guest, staff, payments and cameras get their own tagged networks, so a card reader never shares a broadcast domain with a guest phone.

It takes stock

The box can scan the venue network and report what is on it: access points, speakers, printers, cameras, payment terminals.

SNAPguard venue network schematicAn ISP router feeds the SNAPguard appliance, which creates four tagged networks for guest, staff, payments and cameras, and holds an outbound WireGuard tunnel across the site boundary to a regional Stampede endpoint.THE VENUESTAMPEDESITE BOUNDARYISP ROUTERWANSNAPGUARDMIKROTIK · ROUTEROSTAGGED · 802.1QVLAN 10 · GUESTPORTALVLAN 20 · STAFFVLAN 30 · PAYMENTSISOLATEDVLAN 40 · CCTVSCAN · 4 APS · 6 CAMERAS · 3 TILLS · 2 PRINTERSWIREGUARD · OUTBOUND ONLYNO INBOUND RULESREGION · LDNREGION · FRARE-HOMED · NO VISIT
one box, four tagged networks, and a tunnel that only ever dials out
The toolkit

The spec.

What the box carries so the venue never has to think about any of it.

Outbound WireGuard

The box initiates a WireGuard tunnel to us and holds it open. Nothing forwarded, nothing exposed, and the venue’s public address can change as often as it likes.

Regional endpoints

Tunnels terminate on regional servers, each with its own address space, so a venue connects to infrastructure near it and can be re-homed without touching the hardware.

RouterOS provisioning

Once the tunnel is up the box is configured over the RouterOS API as if we were stood in the cupboard.

VLAN templates

Guest, staff, VLAN trunk, IoT and cameras built from templates, tagged and isolated from each other by default.

Controller mirroring

Where a venue runs UniFi or Omada, the networks are mirrored into the controller so the access points broadcast the right thing.

Portal certificates

Hotspot certificates are deployed down the tunnel, so the captive portal is served properly without anyone handling a cert by hand.

Bandwidth policy

Per-network bandwidth allocation, so a busy guest network never starves the till or the card machine.

Network inventory

The box scans the venue network and reports what is on it: access points, speakers, printers, cameras, payment terminals.

Setup

Hands-on, honestly.

The activation wizard in connect makes the visit short. It does not remove it, and we would rather tell you that now.

the activation flow
01Survey

Detect the existing setup, record the line speed, and find the switch nobody knew about before it finds you.

02Build

Create the networks from templates: guest, staff, payments, cameras, each tagged and isolated.

03Mirror

Push the same networks into UniFi or Omada where there is a controller, so every AP broadcasts the right thing.

04Prove

Join each network with a real phone, check the address it gets, and confirm the portal actually appears.

multi-AP sites and older cabinets need a real pair of hands, so setup runs with our team, alongside your IT or installer. and when the box or the line is down, capture stops: usually something upstream of us, still our problem to own.
Get the box

Odd cabinet? Ask.

Setup questions, odd cabinets and awkward switches welcome. The fastest way to find out if your venue is straightforward is to ask, and our team has seen most cupboards by now.