SNAPguard
Plug & Play
SNAPguard combines a pre-provisioned, on-site gateway with a virtual cloud network, giving Stampede direct control over how guest devices authenticate, connect and behave.
It removes reliance on access-point splash pages and third-party redirects, delivering fast, predictable and secure guest Wi-Fi across venues, devices and busy service periods.
SNAPguard is currently implemented using MikroTik ax2 devices, supplied pre-configured and ready to install. Alternative MikroTik models may be used depending on venue size and traffic requirements.
SNAPguard combines local intelligence with centralised cloud control:
Runs a full local authentication and captive portal server inside the venue
Supports DHCP Option 114 ensuring modern Apple and Android captive portal behaviour
Caches captive portal assets and Stampede modules locally to reduce latency
Runs local DNS and SSL services, resolving stampede.ai domains without external cloud lookups
Routes all guest traffic securely through an outbound VPN tunnel to the Stampede cloud
Avoids double NAT and inbound firewall dependencies, simplifying deployment
Result: near-instant login, with most guests authorised in under one second, even during peak service.
Enterprise-Grade Routing & Security
Built on MikroTik RouterOS, SNAPguard delivers professional-grade routing, firewalling, VPN, VLAN segmentation, traffic shaping and WPA3 support.
Reliable Captive Portal Behaviour
Full control over redirects and authentication resolves Apple and Android auto-login issues.
Virtual Cloud Network (Always On)
Each SNAPguard device connects into Stampede’s virtual cloud network, maintaining persistent control and policy enforcement across venues.
Rogue Device & Misuse Detection
Identifies suspicious behaviour, bandwidth abuse and illegal activity on guest networks.
Multi-SSID & Role-Based Separation
Clean isolation of guest, staff and operational networks without complex configuration.
Simplified Setup (No Double NAT)
Eliminates access-point splash pages, walled gardens, RADIUS servers and double NAT configurations, enabling true plug-and-play deployment.
Performance Gains via Local Caching
Captive portal assets and Stampede modules cached locally for near-instant login and consistent performance.
Mission Control Monitoring
Integration with Mission Control to monitor network health and connected operational devices such as EPOS, printers and CCTV.
MAC Randomisation Handling
Designed to cope with modern device MAC randomisation, improving repeat-visit recognition and re-authentication flows.
Automatic Updates
Security patches and enhancements delivered automatically over time.
Different rules for hotels, cafés and bars - from long-stay access to timed re-authentication.
Prevent individual devices from degrading performance for others.
Automatic updates keep SNAPguard protected and evolving over time.
Key benefits
iOS & Android Captive Portal Compliant
GDPR-Ready by Design (consent, audit logging, secure data handling)
Enterprise Security Standards (aligned to ISO 27001, SOC 2, Cyber Essentials)
Hospitality-Safe Network Separation
SNAPguard







