No VPN, no WAN, no problem: moving Boozt’s HQ with Zero Trust
Moving a company headquarters to a new country is a significant undertaking. For the infrastructure team, the job is to make all of it…
No VPN, no WAN, no problem: moving Boozt’s HQ with Zero Trust
Moving a company headquarters to a new country is a significant undertaking. For the infrastructure team, the job is to make all of it invisible. This is the story of how we built out a new HQ network from scratch, and why one architectural decision made years earlier meant that when hundreds of people arrived on the first day, everything simply worked.

By Jonny Johansson, Data Systems Director| Boozt
I’m Jonny, and I work on infrastructure at Boozt, the leading Nordic online department store. When the company moved its headquarters from Malmö, Sweden to a new building in Copenhagen called The Crystal, the network, security, wireless, and AV all had to be designed and delivered from the ground up. This is a technical account of how we did it: the decisions behind it, one honest story about WiFi in a glass-and-concrete building, and a core architectural principle that quietly made the whole thing far easier than it had any right to be.
A word on the building first, because it matters for the rest of the story. The Crystal is a modern Copenhagen office complex: extensive glass facades, exposed concrete, and two large open atriums running through it. It’s a great place to work. It is also, as you’ll see, a genuinely hostile environment for radio frequency.
Start with a clean slate
When the move was confirmed, the first decision we made concerned the network gear. Our network equipment in the old building was completely end-of-life, so migrating it was never an option. It went to recycling, and we designed the new network from scratch with entirely new hardware. Rather than shipping aging equipment across the Øresund and inheriting its limitations, we treated the move as a chance to build clean.
That reframed the work. This wasn’t a migration project, it was a greenfield build with a hard deadline and a simple brief: when the doors open, it has to work.

The Crystal, Boozt HQ. Copenhagen, Denmark.
Fiber: designed not to fail
The first question at any new site is connectivity. A modern office complex doesn’t automatically come with good fiber options, so we evaluated several providers and chose GlobalConnect: strong footprint across Denmark, a technically solid team, and commercial terms that worked.
We built in full redundancy from the start. A primary 5 Gbps dedicated link and a secondary 1 Gbps link. The detail that makes this resilient in practice rather than just on paper is the physical routing: the two cables enter the building from opposite ends. Single-trench cuts are the most common way redundant fiber setups fail, and this design removes that failure mode entirely. GlobalConnect also provides redundancy within their own network, so carrier-level faults are covered as well as physical ones. If any single element in that path fails, the office stays online and nobody notices.
Firewalls: trust what works
For the firewall layer, we went with what we know. We’ve run WatchGuard for years and the platform has earned that continuity. Standing up a new site in a new country on a tight timeline is exactly the wrong moment to be learning a new vendor’s quirks.
We deployed dual WatchGuard units in active/passive high availability. One handles all traffic under normal conditions; if it fails, the passive unit takes over automatically, with no manual intervention and no downtime. Combined with the dual fiber uplinks, that gives us layered redundancy at the network edge.

Boozt HQ, The Crystal. Copenhagen, Denmark.
WiFi: built for the next several years, and a lesson in humility
The internal wireless network runs on Ruckus R670 access points. Ruckus is an enterprise WiFi vendor known for handling high-density, RF-difficult venues, which made them a natural fit here. We deployed 27 APs across the building, serving roughly 600 clients. At that density, coverage is only part of the problem. Capacity, interference, and band steering matter just as much.
The R670s support Wi-Fi 7, so we’re provisioning for the next several years rather than just today’s devices. When Wi-Fi 7 clients become standard, the access points will already be ready.
Now the honest part.
The initial WiFi rollout wasn’t perfect. The building’s architecture, all that glass, concrete, and open atrium volume, is hard on radio frequency. Glass reflects and refracts signal. Concrete attenuates it. Large open atriums are difficult to fill with consistent coverage without access points interfering with one another.
After move-in, we saw the symptoms. Intermittent drops, slower-than-expected throughput in certain areas, the kind of inconsistent behaviour that’s hard to reproduce but easy to notice.
The answer wasn’t more hardware. It was better data. We brought in a vendor that specialises in exactly this kind of RF problem and ran a full professional site survey: every floor walked with measurement tools, signal strength and interference patterns mapped, channel contention identified, the behaviour of the atriums and glass surfaces properly understood. From that came specific recommendations on channel assignments, transmit power, band steering, and roaming thresholds. We applied them iteratively, testing after each change. Not one fix, a series of calibrations.
The WiFi is now fast, stable, and consistent across the building. Getting there meant treating the RF environment as a system to be measured and tuned, not just planned and deployed. In a building like this, a professional site survey isn’t a luxury. It’s the only way to actually solve the problem.
Meeting rooms: 28 rooms, one experience
The network was the one part of the estate that was fully end-of-life. Plenty of our other equipment still had life in it, and we reused it: a lot of it went into the new Hyllie office, and other gear, dashboards, TVs, older meeting room equipment, was sent on to our fulfilment centre in Ängelholm rather than scrapped.
The meeting rooms at the new HQ, though, were a fresh build. For the 28 standard rooms, we standardised on HP Poly video bars integrated with Google Workspace. One device per room, clean installation, camera and microphone in a single unit. Consistency at this scale pays off operationally. When every room behaves identically, there’s less to support and nobody has to relearn the setup depending on where they sit.

The Atrium: broadcast-grade AV, presented as a normal meeting room
The ground floor Atrium is a different class of problem. It’s where we run company-wide all-hands and large townhalls, and a video bar isn’t the right tool for that scale.
We built a full AV installation around the acoustics and size of the space. The centrepiece is a 360x202cm LED wall: a COB panel running at 1920x1080, 600 nits, 30mm deep, mounted flush to the wall. Audio is handled by two Fohhn FS-200 active beam steering speakers. Beam steering suits an atrium well, because rather than flooding the room and fighting reflections off glass and concrete, it directs the sound electronically to where the audience actually is. Microphones are Sennheiser SpeechLine, with a multi-channel receiver supporting a handheld, two clip-ons, and a headset.
On the video side, two Vaddio EasyIP PTZ cameras feed a Vaddio mixer, with a BiAmp TesiraFORTE handling the DSP layer at 32x32 channels of Dante audio routing, controlled from a Crestron touchpanel. For all that complexity behind the scenes, the presenter-facing experience is an HP Poly G62 with a TC10 touch controller: the same Google Meet interface as every other room in the building. A 200-person all-hands and a 20-person hybrid call run on the same system, and from the front of the room they feel the same.

The decision that made everything else easy
This is the part that matters most, and the reason for the title.
The new building has no private WAN link back to the old office, or to anywhere else. No MPLS circuit, no site-to-site VPN, no private backbone between locations. All of our internal tools and systems are reachable over the public internet, and employees connect through Cloudflare’s Zero Trust Network Access platform.
This wasn’t a decision driven by the move. We adopted ZTNA well before the new HQ was on the radar. But the move is what revealed how much it was worth.
With ZTNA, access is tied to identity and device posture rather than physical location. So there was nothing to replicate in the new building. No internal services to mirror, no inter-office firewall rules to rebuild, no private WAN to provision, and no dependency on a cross-border circuit that could become a single point of failure. When engineers arrived on day one, they reached internal tools exactly as they always had. From a system access perspective, nothing changed at all.
That’s the quiet payoff of location-agnostic access. The move became a facilities event rather than an infrastructure event. When the business makes a big move, the network is already wherever the people are.

Boozt HQ, The Crystal. Copenhagen, Denmark.
The detail that made move-in day seamless
One operational decision is worth calling out, because it’s the kind of thing that separates a smooth launch from a chaotic one. Before move-in, we pushed the new WiFi SSID to every employee laptop through MDM.
When people arrived, their laptops already knew the network. No queue at the IT desk, no asking around for a password, no configuration friction on an already busy day. People walked in, opened their laptops, and got to work.
It sounds trivial. Making it trivial took coordination: aligning the SSID and credentials, deploying the config ahead of the physical move, and validating that the network was ready before the first person walked in. We did that work in advance so nobody else had to think about it. That invisibility is what good infrastructure looks like.
What we learned, or had confirmed
Design redundancy from first principles. Physically diverse fiber paths cost more and take more planning than a single link. They’re also the difference between an outage and a non-event when something fails.
Back proven vendors when timelines are tight. GlobalConnect and WatchGuard were chosen partly on existing confidence in the platforms. Delivering in a new country on a deadline makes that trust genuinely valuable.
Provision for the next several years, not just today. Wi-Fi 7 support costs more now. It also means we won’t be back replacing access points when the client devices catch up.
Adopt location-agnostic access before you need it. ZTNA didn’t help this move in theory, it helped dramatically in practice. If your internal tools still depend on which office network someone sits on, the next physical change will surface that technical debt at the worst possible moment.
Measure RF environments, don’t just plan them. No site plan survives contact with a real building. Complex architecture needs measurement and iterative tuning. That isn’t a planning failure, it’s just how RF behaves.
Prepare everything you can before the doors open. The people who connected to WiFi instantly on day one have no idea how much went into making that moment unremarkable. That’s the point. The best infrastructure work is the kind nobody ever notices.

메타데이터
- post_id
- b1f5d54f4a29
- slug
- no-vpn-no-wan-no-problem-moving-boozts-hq-with-zero-trust-b1f5d54f4a29
- url
- https://medium.com/boozt-tech/no-vpn-no-wan-no-problem-moving-boozts-hq-with-zero-trust-b1f5d54f4a29
- canonical_url
- https://medium.com/boozt-tech/no-vpn-no-wan-no-problem-moving-boozts-hq-with-zero-trust-b1f5d54f4a29
- author_url
- https://medium.com/@boozttech
- status
- ok
- fetched_at
- 2026-06-10 22:22:12