RelayPoint Technologies

Blog / How-to & troubleshooting

Guest Wi-Fi done right: visitors on, your network off

How to set up guest Wi-Fi properly: a separate SSID and VLAN, client isolation, bandwidth caps, and easy QR sharing for visitors.

Handing your Wi-Fi password to a visitor feels harmless. It is also handing them a connection to everything on your network: your NAS, your printer, your cameras, your kids' laptops. In a business, it is worse, because now a customer's possibly-infected phone sits on the same network as your point of sale. Guest Wi-Fi done properly fixes this, and on decent equipment it takes an evening, not a project.

A separate SSID is not enough by itself

Most routers can broadcast a second network name. People see "Guest" in the settings, flip it on, and assume the job is done. Sometimes it is. On a lot of consumer gear, though, the guest SSID is just a different password onto the same network, and a guest device can still see and reach everything else in the house.

The real separation happens at the network layer with a VLAN: a virtual network that shares your physical equipment but is walled off from your main one. Guest devices get internet access and nothing else. No file shares, no cameras, no printer, no management pages for your router.

If you have UniFi or similar prosumer gear, this is a checkbox and a firewall rule. If your all-in-one router does not support real isolation, that is a bigger sign it is time to move on than any speed test, a point we made back in our post on slow internet versus slow Wi-Fi.

Turn on client isolation too

VLAN separation protects your network from guests. Client isolation protects guests from each other. With it enabled, devices on the guest network cannot talk among themselves at all, only out to the internet.

For a home, this is a nice-to-have. For a café, a waiting room, or a shop, it is essential. You do not want one customer's laptop probing another customer's phone across your network, and you especially do not want to be the venue where that happened.

The one case where you relax it: if guests legitimately need to reach one shared device, like casting to a TV in a rental suite, you allow that single exception rather than turning isolation off entirely.

Cap the bandwidth

An uncapped guest network will eventually absorb everything your connection has. One visitor's phone deciding to back itself up, or one cloud game download, and suddenly your video call stutters.

Set a per-client speed limit on the guest SSID. Something in the range of 10 to 25 megabits per client is generous for browsing, streaming, and video calls, and it keeps any single guest device from flattening the connection. In a business, this is the difference between "free Wi-Fi" being a perk and being a support problem.

While you are in the settings, give the guest network a schedule if it only needs to exist during business hours. A network that is off cannot be abused at 3 a.m.

Share it with a QR code, not a sticky note

The last mile of guest Wi-Fi is how people get on it. Reciting a password four times while someone typos it is the old way. Every modern phone can join a network by scanning a QR code, and every decent controller (and plenty of free generators) will produce one from your SSID and password.

Print it, frame it, put it by the door or the till. For businesses, a small stand at the counter beats a chalkboard password that ends up on the internet. And because the guest network is isolated and capped, you can rotate its password on your schedule, or honestly, worry less about rotating it at all.

About the "just use the printer network" trick

We sometimes find workarounds in the wild: guests told to join the smart-plug network, or a spare SSID that was set up years ago for a printer, on the theory that it is somehow separate. It almost never is. Those networks usually sit on the same flat LAN as everything else, with none of the isolation people assume, plus a password nobody has changed since installation.

If a network exists, assume anything on it can reach anything else on it unless you have deliberately configured otherwise. The fix is not a cleverly repurposed SSID. It is five minutes of real VLAN configuration.

The checklist

A guest network done right looks like this: its own SSID, its own VLAN with firewall rules blocking access to your main network, client isolation on, a per-client bandwidth cap, and a QR code for joining. Businesses should add a schedule and, where required, a simple terms-of-use splash page.

None of this needs enterprise money. It needs equipment that supports VLANs and an hour of careful setup.

If your current router cannot do this, or you would rather have someone configure it properly and hand you the QR code, we set up segmented networks for homes and businesses all the time. Ask us about a network setup and we will get your visitors online without giving them the keys.

wifiguest-networkvlan

Written by RelayPoint Technologies

Cabling, networks, cameras, access control, smart homes, hosting and software for homes and small business across Southwestern Ontario. Twenty-plus years in the trade, and we still answer the phone.

Free site visit

Tell us what you're trying to do.
We'll tell you what it takes.