Security

Guest Wi-Fi that does not share the office VLAN

Business guest Wi-Fi is a separate SSID on a dedicated VLAN. Guests get internet only. They do not reach staff computers, file shares, printers, cameras, or the firewall admin page. Use a different password from the office network, turn on client isolation, and cap bandwidth so a visitor cannot soak the circuit. A second password on the same VLAN is not guest Wi-Fi.

Updated 2026-09-16

What most offices actually have

The lobby TV says Guest. The password is on a sticky note. That SSID often lands on the same network as laptops, the front-desk printer, and the NVR. A visitor, a contractor laptop, or a phone that picked up malware at the airport now has a path to those devices.

That is the finding auditors write down. It is also how a “can I get the Wi-Fi?” moment becomes an incident you did not plan for. The SSID name does not isolate anything. The VLAN and the firewall rules do.

What “done” looks like

One SSID for staff. One SSID for guests. Guests sit on their own VLAN. The firewall allows that VLAN to the internet and nowhere else on the LAN. No route to staff subnets, servers, cameras, badge controllers, or the UniFi console.

Client isolation is on, so two guest phones cannot talk to each other. The guest password is not the office password and is not printed on the same card as the admin login. A bandwidth cap keeps one tablet from flattening Teams for the rest of the floor.

A captive portal is optional. Retail and waiting rooms sometimes want terms on a splash page. A plain office usually does not. Do not add a portal just because the access point offers one.

A five-minute check you can run

Join the guest SSID on a phone that is not a company device. Confirm you can load a public site. Then try to reach something that should be internal: a mapped drive, a printer by IP, a camera, the firewall or UniFi login. If any of those answer, the guest network is not isolated.

If you do not know the internal IPs, that is the other finding. Isolation work starts with an inventory of what lives on the staff VLAN.

IoT is not a guest, but it is not staff either

Cameras, thermostats, TVs, and badge panels do not belong on the staff VLAN. They also do not belong on the visitor SSID. Put them on a third segment with only the access they need, usually to an NVR or a vendor cloud, not to file shares.

This page is about visitors. The camera split is a follow-on job. Do not dump IoT onto Guest to “get it off corporate” and call it finished.

How Tailored Tech treats this

When wireless is in scope we check whether the guest SSID shares a VLAN with production, whether management interfaces are reachable from it, and whether the password is the same as staff. Fixing that is a short, defined change on most UniFi and similar stacks we already manage.

We do not treat a second SSID as a security control by itself. The control is the VLAN, the firewall policy, and a test from a guest device that fails to reach the office.

Read the UniFi console article if the admin UI is still on a public address. Guest isolation and a public management plane are separate problems. Both show up in the same walkthrough.

Questions & answers

Questions on this topic

Short answers for buyers comparing options.

Is a second SSID enough?

No. Two names on one VLAN still share the network. The VLAN and the firewall rule are the control.

Will this break office Wi-Fi?

No. Staff stay on their SSID and VLAN. You are changing where guests land, not whether access points serve employees.

Do we need a splash page?

Only if you have a reason: terms for the public, a hotel-style flow, or a compliance note counsel asked for. Most offices need isolation more than a portal.

Where does this live on a plan?

Wireless design and hardening sit in the Service Catalog under network work. Scope is confirmed in the agreement. A one-site guest VLAN is usually a short project, not a standing mystery.

Want this applied to your environment?

Tell us how the business runs. We will map the model without a long pitch.

Start a conversation
Start a conversation