Skip to content
TECHNOWARE

Guest Wi-Fi that never touches the office network

A visitor password on the staff SSID is the most common way a small office gives strangers a route to the file server. Separation is a VLAN, a firewall rule and one setting on the controller.

9 September 20263 min readadmin

Guest Wi-Fi that never touches the office network
Share

Most offices offer guest Wi-Fi. Most of them offer it by writing the staff password on a whiteboard in reception. Everybody knows this is wrong and nobody changes it, because the alternative sounds like a project. It is not. It is three settings, and the order matters.

What "guest" has to mean

A guest device gets to the internet and to nothing else. Not the printer, not the NAS, not the recorder, not the other guests. If a visitor's laptop can see the accounts server on the network browser, the guest network is a second staff network with a weaker password.

That is a definition, not a preference. Everything below follows from it.

One: a VLAN of its own

The guest SSID is mapped to its own VLAN on the controller, and that VLAN is trunked to the access points and to the firewall — and to nothing else. It does not need to exist on the switch that serves the server room. If it does not exist there, nothing in there can be reached from it, whatever the firewall says.

Give it its own DHCP scope, handed out by the firewall rather than the office server. A guest network whose addresses come from the domain controller is a guest network that can reach the domain controller.

Two: the firewall rule, written the right way round

The rule is not "block guest from the LAN". It is "allow guest to the internet, deny everything else". The difference is what happens when a new internal subnet appears next year: a deny-list has to be updated and will not be; an allow-list needs nothing.

Allow DNS and HTTP/S outbound. Deny RFC 1918 destinations as an explicit rule above the default, so the log shows an attempt rather than a silent drop when somebody's laptop goes looking for a printer.

Three: client isolation

The setting on the SSID that stops guest devices from talking to each other. It is one tick box and it is usually off. With it off, a guest network at a busy reception is a room full of unpatched laptops introducing themselves to each other.

Bandwidth, and the reason it matters more than it looks

Rate-limit the guest SSID. Not to be unkind — because a visitor's phone syncing a photo library over your uplink at nine in the morning is indistinguishable, from the office's side, from the internet being down. A ceiling of 10 or 20 Mbps per client is generous for a guest and invisible to staff.

What to do about the whiteboard

Rotate the guest password monthly and print it on the visitor sign-in sheet. A guest password that has been the same since the network was installed is public. A captive portal is the tidier answer where the controller offers one, and a QR code on the reception desk does the same job for nothing.

How to check it

Join the guest network with a phone. Try the printer's address. Try the NAS. Try the recorder. Try a colleague's laptop on the same guest SSID. Every one of those should fail, and they should fail now — not after the next audit.

Related

Ran into this on your own network?

If something here matches a problem you are seeing, describe it and we will tell you what we would check first.