Sea Current Tech
Connectivity, gadgets and digital life for people who work at sea

Separate Crew WiFi From Ship Network: How It Works

Updated 31 August 2026 · crew-welfare, connectivity, ship-networks, vlan

Separate Crew WiFi From Ship Network: How It Works

Some links on this page are affiliate links. If you buy through them we may earn a commission at no extra cost to you — it never changes which product we recommend.

If you want to separate crew wifi from ship network traffic, the split happens on the router using VLANs, and on most modern commercial vessels that is already the standard configuration according to a WeConnect vendor guide dated May 2026. Crew devices sit on their own logical network with their own address range and their own bandwidth allowance. The operational side, ECDIS, the loading computer, the engine room data logger, the company mail server, stays on a different VLAN that crew traffic cannot reach. Nobody plugs a second cable into a separate satellite dish. One pipe, several fenced lanes.

That is the short answer. The rest of this article is about why the fence matters, what the named products actually do, where they stop, and what to do when you are the engineer who gets asked to fix crew WiFi at 2200 on a Sunday.

Why the separation exists in the first place

The separation exists because crew devices are the least controlled hardware on the ship. A junior engineer's phone has been on hotel WiFi in Manila, a shopping mall network in Rotterdam, and a friend's laptop hotspot, all in the last three weeks. It runs whatever apps it wants. It gets no patch discipline from the company. Putting that phone on the same flat network as navigation and cargo systems is a bad idea for reasons that have nothing to do with anybody's intentions.

There is a second, less dramatic reason that matters more day to day. Bandwidth. Riviera Marine, in reporting on VSAT-equipped vessels, quotes the familiar complaint that WiFi speeds drop when too many people connect at the same time. If crew traffic and operational traffic share one undivided pipe, a single Netflix stream in a cabin competes with a weather routing download on the bridge. The VLAN is where you attach the policy that stops that happening.

Riviera Marine's own reporting has also linked communications problems onboard to fatigue and security risk, which is the honest framing: this is a welfare issue and a safety issue at the same time, and the network design sits in the middle.

What "separate" actually means technically

Separate means different broadcast domains with a routing decision between them. In practice, on a ship, that looks like this:

  • A crew VLAN carrying cabin and mess-room WiFi, with its own SSID and its own DHCP range.
  • An operational or corporate VLAN carrying company IT, mail, planned maintenance, reporting.
  • A voice and management VLAN carrying the ship's telephony and the equipment that manages the network itself.

Fleet Xpress, according to its product page last updated 29 August 2026, is documented as being able to create three separate routed networks along exactly those lines: Corporate LAN, Crew LAN, and Voice plus Management LAN. That is the clearest vendor-documented example of the pattern, and it tells you the three-way split is not something one clever superintendent invented. It is how the service is sold.

The vendor market, and what each product stops short of

Here is the honest version of who does what. I have kept the "where it stops" column, because that is the column that costs money when you ignore it.

Product What the source says it does Where the source stops
Fleet Xpress Creates three separate routed networks: Corporate LAN, Crew LAN, Voice plus Management LAN. Page last updated 29 August 2026. Does not specify required hardware, configuration burden, or security certifications.
Fleet Hotspot Add-on to Fleet Xpress. Onboard WiFi portal for crew self-service, issuing access by time or by data volume. Does not state that it does deep application filtering, and does not show that it isolates operational traffic by itself.
Dualog Network Control Sets up and manages separate networks, including crew, administrative and operational. Page last updated 5 September 2025. No pricing given, and no detail on captive portals, VLAN design, or bandwidth policies.
WELCOME Maritime WiFi Pay-as-you-go crew internet with Starlink-based connectivity plus onboard kit. Plans reported from US$1.65 per GB. Article dated 21 July 2025, last updated 24 October 2025. Routing architecture is not explained in enough detail to confirm isolation beyond the included gateway, switch and access points.

Two things to take from that table.

First, an access layer is not an isolation layer. Fleet Hotspot is a good example. It gives crew a portal, and the portal can hand out access by time or by data volume, which is genuinely useful because it moves the "who gets how much" argument off the chief engineer's desk and onto a self-service page. What the source does not claim is that the portal by itself keeps operational traffic separate. The portal is the turnstile. The VLAN is the wall. You need both, and buying the turnstile does not build the wall.

Second, "separate networks" in marketing copy means different things at different price points. Dualog Network Control is documented as setting up and managing separate crew, administrative and operational networks, which is the right shape. The published material does not go into whether that includes captive portal functions or the bandwidth policy layer. So when a vendor tells you the product does separation, the useful follow-up question is: separation with which of these four pieces included, VLAN design, captive portal, bandwidth policy, or just the management console?

On the WELCOME kit, the reported figure is plans from US$1.65 per GB, and the WELCOME Pro kit is reported to include a Starlink terminal, an eight-port switch, two WiFi access points and a gateway at no cost to qualifying vessels. That was reported in an article dated 21 July 2025 and last updated 24 October 2025. What "qualifying" means, how many vessels qualify, and what the contract terms are, none of that is in the public reporting I could verify. Check the current terms directly before you build a budget line on it. Maritime pricing moves, and a figure from October 2025 is old enough to have moved twice.

The state of crew internet, with numbers attached

Crew internet is still far from universally free and unlimited, and the published numbers are blunt about it. Idwal, in material updated 25 February 2026, reported that among bulk carriers and container ships that offered crew internet access, fewer than 10% provided it on a free unlimited basis. For tankers the figure was about 15%. Those are the two figures worth memorising when someone claims the industry has solved this.

IMarEST has separately reported that seafarers still commonly face data caps, restricted access to email, social media and video calls, and high pay-for-use costs. That is the environment the crew VLAN lives in. The technical separation is usually the easy part. The policy sitting on top of it is where the friction is.

I want to be precise about something here, because it gets muddled constantly. Cruise ship internet prices you see quoted in the trade press are passenger prices, not crew network products. For reference on scale, Holland America's onboard packages page, last updated 24 August 2026, listed US$26 per day for one plan and US$38 per day for another, with prices noted as subject to change, and packages available up to 135 days ahead. A 2026 cruise-industry article also reported Carnival adding a Premium Multi-Device Plan starting at US$105 per day, up from US$90 in 2025. Interesting context. Completely irrelevant to what your company pays to give the engine cadet 5 GB a month. Do not let a vendor use passenger pricing to anchor a crew welfare conversation.

How the split works in practice on a ship

In practice the crew side terminates on access points in the accommodation and the operational side stays on cabled infrastructure and its own wireless where it exists. Here is the mental model I use when explaining it to a new joiner who wants to know why they cannot see the ship's file server from their cabin.

The satellite terminal, whether that is VSAT or a Starlink antenna or both with failover, lands on a router. That router is where the intelligence lives. It carries several VLANs. It decides what talks to what. It decides how much of the pipe each VLAN gets. It runs the NAT and the DNS. Everything downstream of it, the switches, the access points, the cabin sockets, is just plumbing that carries VLAN tags.

That is why "the WiFi is broken" is almost never a WiFi problem. When crew WiFi dies and operational traffic is fine, the fault is nearly always one of three things: the crew VLAN hit its allowance, the access point in that section of accommodation dropped off, or the captive portal is refusing new sessions. None of those are fixed by rebooting the antenna, which is what everyone tries first.

If your ship's crew WiFi is simply slow rather than broken, the fixes are mostly behavioural and device-side, and I have written up the ones that actually change the experience in 11 fixes for slow crew WiFi. Start there before you file a ticket.

The three questions to ask your IT superintendent

Ask these three and you will learn more in five minutes than from an hour of documentation. First, which VLAN is the crew SSID on, and can you show me it is a different one from the operational network? Second, what is the bandwidth policy between the VLANs, is crew capped at a percentage, a hard rate, or a monthly volume? Third, who can reset a crew account, is it the master, the ETO, an office ticket, or a self-service portal?

The third question is the one that decides whether the system works socially. A technically perfect separation where every password reset needs an office ticket during Manila office hours is a system that will annoy 22 people continuously.

Honest cons of the separated-network approach

Nothing here is free, and pretending otherwise is how superintendents lose credibility onboard. Here are the real trade-offs.

It depends entirely on correct router configuration. The separation is a configuration, not a physical property. One mistake in a VLAN tag or an access rule and the wall has a door in it. There is no light on the bridge that tells you the isolation is intact, which means you are trusting a config file you probably cannot read.

Crew get a smaller, policed slice, and it feels like it. Once traffic is separated, the crew allowance becomes explicit and visible. Under a flat network, crew sometimes benefit from operational headroom by accident. After separation, they get exactly what the policy says, no more. That is fairer, and it is also frequently slower at the moment it matters, which is Sunday evening when everyone calls home.

The access layer and the isolation layer get sold as one thing. As the table above shows, portal products document access control by time or volume without documenting operational isolation. Buying the portal and assuming you bought the wall is a real and common mistake.

Pricing transparency is poor. For Fleet Xpress, Fleet Hotspot and Dualog Network Control, I could not verify current prices or plan limits from public sources at all. You cannot compare what you cannot price, and that asymmetry does not favour the ship.

More devices means more failure points. A gateway, a switch, two or more access points, a captive portal service. Each one is a thing that can fail at sea, and the crew VLAN is always the lowest repair priority when it does. It should be, operationally. Knowing that does not make it feel better in week 14 of a contract.

Who should not go down this road

If you are an individual seafarer reading this hoping to build your own separation, this is not your project. The ship's network is company infrastructure. You do not get to reconfigure VLANs on it, and attempting to is a disciplinary matter, not an initiative. Your realistic lever is your own cabin setup and your own data.

If you are on a vessel where crew internet is a paid, capped service, the separated-network story changes nothing about your monthly cost. The architecture decides who can reach what. It does not decide the price. Your money is better spent on a personal data strategy: Airalo installed ahead of arrival covers a port call for a few dollars regardless of what the crew VLAN allowance looks like that month, and the honest comparison of what actually works between port calls is in best eSIM for seafarers.

If your problem is coverage inside a steel accommodation block rather than network policy, a cabin router solves more of your actual pain than any VLAN discussion will. I have covered the ones worth carrying in portable WiFi routers for a ship cabin.

And if you are a small operator with one or two vessels hoping this is a weekend job, it is not. Somebody has to own the config, the policy, and the support path. Without an owner it degrades into a flat network with extra SSIDs, which is the worst of both worlds because it looks separated and is not.

What good looks like

Good looks boring. Crew connect to one SSID with credentials they can reset themselves. Their allowance is visible to them before they run out, not after. Operational traffic has priority that is defined in writing rather than negotiated per incident. Somebody ashore can see the VLAN configuration remotely and confirm it matches the standard. And when the crew network fails, the failure is contained to the crew network and nobody on the bridge notices.

That is achievable with the products documented above, and the architecture pattern that Fleet Xpress publishes, three routed networks for corporate, crew, and voice plus management, is a reasonable template even if you buy from someone else entirely.

FAQ

Does separating crew WiFi make the ship's network more secure?

It reduces one specific risk, which is unmanaged crew devices sitting in the same broadcast domain as operational systems. The separation is done on the router with VLANs, and the WeConnect guide from May 2026 describes this as standard configuration on modern commercial vessels. It does not make the ship secure on its own, because the separation is only as good as the router configuration behind it, and no public source I found benchmarks how often those configs are correct.

Can crew WiFi and operational traffic share one satellite connection?

Yes, and that is the normal arrangement. Fleet Xpress documents three separate routed networks, Corporate LAN, Crew LAN, and Voice plus Management LAN, running as distinct traffic domains over the service. The separation is logical, not a second dish. What you need alongside it is a bandwidth policy, otherwise the lanes are separate but the pipe still gets saturated by whoever is loudest.

How much does crew internet separation cost?

For the main products documented here, Fleet Xpress, Fleet Hotspot and Dualog Network Control, current prices and plan limits were not published in sources I could verify as of 31 August 2026. One comparable crew-internet service, WELCOME Maritime WiFi, was reported at plans from US$1.65 per GB in an article dated 21 July 2025 and last updated 24 October 2025, with a Pro kit including a Starlink terminal, an eight-port switch, two access points and a gateway at no cost to qualifying vessels. Treat every one of those figures as a starting point for a quote, not a price, and re-check before you rely on it.

Is free unlimited crew internet common now?

No. Idwal, in material updated 25 February 2026, reported that fewer than 10% of bulk carriers and container ships offering crew internet provided it free and unlimited, with about 15% for tankers. IMarEST has also reported continuing data caps, restricted access to email, social media and video calls, and high pay-for-use costs. Free unlimited is still the exception.

Why does crew WiFi slow down in the evening even after separation?

Because separation divides the connection logically without adding capacity. Riviera Marine has reported the standard complaint from VSAT-equipped vessels that speeds fall when too many people connect at once, and evening is exactly when everyone connects at once. A crew VLAN with a fixed share of a small pipe shared by 20 people will feel slow at 2000 regardless of how cleanly it is separated.

Can I tell from my cabin whether the networks are actually separated?

Not reliably, and you should not go looking. Probing a ship's network to test its segmentation is the kind of curiosity that ends up in a report about you. Ask the ETO or the IT superintendent which VLAN the crew SSID sits on. A straight answer to that question tells you what you need to know.

Verdict

If you have any say in how a vessel's connectivity is specified, insist on documented VLAN separation with a written bandwidth policy, and insist on knowing which product covers isolation and which product only covers crew access, because those are routinely sold as the same thing. Every price in this article carried a date for a reason. Re-check them before you commit, because the maritime figures I could verify range from October 2025 to August 2026 and the ones I could not verify at all are the ones vendors will quote you fastest. Getting somebody to separate crew wifi from ship network traffic properly is a one-time engineering decision that improves both safety and morale for the whole life of the ship.

About the author

I am a working marine engineer, and my hands-on side of this is the operational one: standing in an engine control room while somebody explains that the WiFi is down, working out whether that is a crew VLAN allowance, an access point, or a captive portal, and telling 20 people the honest answer. I write Sea Current Tech for people doing the same job. Every figure above is attributed to whoever published it, with the date it was published, and where I could not verify a price I have said so plainly rather than filling the gap.

Related reading