A customer asks for the WiFi password at reception. You give them the network labelled Guest and carry on taking payments. Can their laptop reach the office printer or another business device? It can if the network permits it. The word Guest does not enforce a boundary.
We would separate three questions before changing anything: can visitors get online, can they reach business devices, and can they reach other visitors? A useful guest setup answers all three. The settings available depend on the installed equipment, so a named feature is a starting point for testing, not a security guarantee.
Give visitors internet access, not the office network
A wireless access point is the device that provides WiFi in a room. It can broadcast separate names for staff and visitors while both still lead to the same underlying network. That is why naming alone cannot establish separation.
A VLAN, or virtual local area network, is a way to keep groups of devices logically separate while sharing suitable cables and equipment. The gateway, which connects networks and the internet, needs rules that restrict guest traffic. The switches connecting wired devices also need the right configuration. Putting visitors in a separate group does not settle every permitted path.
List what guests should reach before asking for settings: normally the internet, plus any expressly approved shared service. List what they should not reach, including workstations, payment equipment, camera management and network administration. Keep the list specific enough that someone can demonstrate the result.
Check whether guests can see each other
Two visitors can share guest WiFi without needing to communicate with one another. Client isolation is the feature often used to restrict that communication. It is different from blocking access to the staff network.
Do not assume that one isolation checkbox covers every route. Manufacturer documentation describes implementations where access point client isolation applies within that access point. Visitors connected through different access points, or through a wired guest socket, can need additional controls. Ask the installer which paths are covered and which equipment enforces each restriction.
Only test devices and networks you own or are authorized to assess. A guest isolation check should not become an attempt to open customer files, scan neighbouring businesses or interrupt payment equipment.
Use an acceptance test the office can understand
Set up a test with your network specialist and designated test devices. First verify the business test service is reachable from an authorized staff device. Otherwise, a failed guest connection might only mean the target was offline.
Connect the guest device and confirm normal web browsing works. Then check that the same approved business test service is blocked. Record the network name, location, device and time. Repeat from another access point or wired guest connection where those exist. Ask the specialist to check the relevant network protocols and rules rather than judging separation from a missing printer icon.
If guests should be isolated from one another, test that separately with two authorized guest devices. Keep a short record of expected and observed results. A screenshot saying a policy is enabled is useful documentation, but it is not the same as checking the path a visitor uses.
- Guest device can use the internet as intended.
- Guest device cannot reach the designated business test service.
- Required guest to guest restrictions work across the installed layout.
- Staff can still use the services they need.
- Any exception has a named purpose, owner and review date.
Keep printer and casting exceptions narrow
A meeting room display or guest printer can complicate a clean separation. Discovery features, which help a phone find a nearby device, may cross network boundaries when specifically configured. That does not mean the device should receive unrestricted access to staff computers.
Ask whether the exception is worth maintaining. Reception may be able to print a document without opening a shared printer to every visitor. If direct access is justified, specify the device and required functions, then repeat the separation tests. Do not solve one failed presentation by temporarily allowing everything and leaving it that way.
The proof is what a guest device can reach, not what the guest network is called.Recheck after the network changes
Adding an access point, replacing the gateway or moving a cable to another port can change the path visitors use. Keep the separation checks with the network handover record so they can be repeated after an approved change.
A welcome page and a bandwidth limit may improve the guest experience, but neither replaces these checks. Decide who owns the guest settings, who can approve exceptions and where a staff member reports a problem. That gives reception a usable service without making reception responsible for interpreting security rules.
Plan the next step with NeuroDesk
NeuroDesk's business WiFi planning starts with the rooms, devices and access people actually need. Bring the guest network name and a list of business devices that must stay separate. We can scope the configuration and checks without asking you to expose private files during a test.
See our business WiFi planning for the relevant scope.
Sources and technical scope
The technical references below describe particular equipment and software. Features and limits must be checked against the installed model and configuration; they are not promises for every system.