Guest WiFi: Give Visitors Internet Without Opening Your Network

Guest WiFi is a separate wireless network for visitors, walled off from the one your staff and business systems run on. Visitors get an internet connection and nothing else, through their own network name, their own isolated lane, and usually a login page and a speed limit.

Guest WiFi for business: flat vector illustration of a separate visitor wireless network kept apart from the internal business network.

A courier is standing at reception in a Christchurch office asking for the WiFi password. The receptionist reads it off a card taped under the desk. It is the same password the accounts team uses, the same one in the office printer, and it has not changed since the router went in four years ago.

Nothing bad happens for months. Then a contractor’s laptop joins carrying something it picked up elsewhere, and it finds a file server, three unpatched printers and a camera recorder on the same flat network with no barrier between them.

Nobody did anything wrong. The business ran one network for everybody and kept the key to it on a card at the front desk.

Guest WiFi solves that, and on most sites it is a few hundred dollars and an afternoon of configuration. What follows is what a real guest network is, how it differs from your staff network, what a captive portal does, and what guest WiFi costs to put in.

What Is Guest WiFi?

Guest WiFi is a visitor network that provides internet access while blocking every route into the business network. This visitor WiFi appears as its own network name on a phone, runs in its own isolated lane, and the devices on it cannot see the file server, the printers, the till, the cameras or each other.

The rule underneath it is short. Business WiFi is for your team, guest WiFi is for everybody else, and the two never meet.

Our guide to business WiFi covers the internal network your staff work on, where the questions are coverage, capacity and dead spots. Guest WiFi asks something narrower: how do we give a visitor an internet connection without giving them anything else.

Business WiFi Guest WiFi
Staff, company devices and equipment Visitors, clients, contractors and the public
Reaches servers, files, printers and business systems Reaches the internet and nothing else
Individual accounts, managed devices Shared access, a login page, no account
Full speed, prioritised Capped per device and in total

Who counts as a guest?

Anyone not on your payroll who does not need your systems. Clients in reception, patients in a waiting room, couriers, tradespeople, auditors and job candidates all belong on guest WiFi.

Contractors are where it gets blurry. One who needs only email and their own cloud tools goes on guest WiFi. One who needs your line of business system needs a proper account.

Is guest WiFi just a second password?

No. A second password on the same network is still the same network, and that is the most common version of guest WiFi done badly. The device gets a different way in and the same access once it is inside. Separation comes from the firewall rule that stops guest traffic reaching your systems. The password on the front of it does no work at all.

Why Should Visitors Never Use Your Staff WiFi?

Visitors should never use the staff network because you have no control over the device they arrive with and no way to know what is already on it. Once it joins your business network it is treated as trusted, and trusted devices can reach things. Three exposures follow, and none of them require the visitor to have bad intentions.

You will also be asked about this in writing at some point. Client security questionnaires and cyber insurance applications routinely ask whether visitor traffic is separated from business systems, and for a lot of South Island businesses the honest answer today is no.

Lateral movement from an infected device

Malware on a visiting laptop scans whatever network it lands on for anything it can reach. On a flat network that means file shares, the accounting server, backup storage, and any machine running an operating system past its support date. This is the problem network security solves at the perimeter, applied inside the building. Splitting visitors off is the cheapest version of that job, and it is usually the first segment a business puts in.

The devices nobody thinks of as computers

Printers, multifunction devices, eftpos terminals, door controllers, security cameras and smart TVs all sit on the network, and most are years behind on firmware. A visitor’s device on the same flat network can reach every one. Printers are worth a closer look, because a multifunction device stores scanned documents on an internal drive and often has a web interface with the factory password still on it.

The password that never changes

A shared password handed to every visitor for four years is not a secret. It has been photographed, typed into personal phones, and passed on to people who never set foot in the building.

Changing it means changing it on every staff device and every printer, so nobody does. A separate guest password breaks that deadlock. You can rotate it on a Monday morning and no staff member will notice.

What Makes a Guest Network Genuinely Separate?

A guest network is genuinely separate when its traffic runs on its own VLAN, is blocked by firewall rule from reaching any internal address, and cannot see other guest devices. Miss any of those three and the separation is cosmetic. A properly built guest WiFi network has five characteristics:

  • Its own VLAN, so guest traffic never shares a lane with business traffic
  • A firewall rule blocking guest devices from every internal address range
  • Client isolation, so guest devices cannot see each other
  • Filtered DNS, so known malicious sites do not load
  • Bandwidth limits per device and across the guest network as a whole

Guest WiFi checklist: flat vector graphic listing the five features of a properly separated business guest wireless network.

What is a VLAN?

A VLAN splits one physical network into several logical networks that share the same cabling and equipment but cannot talk to each other. Think of it as separate lanes on the same road with a concrete barrier between them.

Guest devices get an address range of their own, and the firewall has a simple job: allow guest traffic out to the internet, and drop anything from the guest lane addressed to an internal system.
Guest WiFi network segmentation: flat vector diagram showing guest devices isolated on a separate VLAN from the business network behind the firewall.

What is client isolation?

Client isolation stops guest devices seeing each other. Without it, a laptop on guest WiFi can find another visitor’s laptop, which matters in a busy waiting room and anywhere strangers share a connection. It takes one tick box on business grade equipment and is switched off by default more often than not.

Filtered DNS belongs alongside it, blocking malware and phishing domains before they load. Keep it light. Guest WiFi that blocks half the internet generates complaints at reception and does nothing for security.

What Is a Captive Portal, and Does Your Business Need One?

A captive portal is the login page that appears when a device joins guest WiFi, before any browsing is allowed. It carries your branding, states the terms of use, and takes whatever the visitor has to do to get online, often nothing more than pressing a button.

Whether you need one depends on who walks in. A small office seeing a handful of visitors a week is fine with a rotating password. Anywhere the public sits down, a portal earns its place.
Captive portal example: flat vector of a guest WiFi splash page with an acceptable-use notice and a connect button on a phone.

What the portal actually gives you

Four things. It puts an acceptable use notice in front of the visitor before they connect, which matters when traffic leaves under your business name. It sets a session length. It records that a session happened. And it puts your logo in front of a customer at a moment they are looking.

What should the acceptable use notice say?

Keep it to a short paragraph in plain language: the connection is provided as a convenience, it is filtered and not private, illegal use is not permitted, the business accepts no liability, and access may be withdrawn. Have a lawyer read it once if you are in accommodation or hospitality.

Should you collect email addresses at the login?

Only if you will genuinely use them, and only with a clear explanation of what for. Under the Privacy Act 2020 you collect personal information for a purpose you can state, and principle 3 requires you to tell the person that purpose at the point you collect it. A cafe or motel running a real mailing list and saying so is on solid ground. A firm collecting addresses because the guest WiFi portal offered the option is taking on an obligation with no benefit attached.

How Do You Stop Guests Slowing the Business Down?

Bandwidth limits stop guests slowing the business down, set both per device and across the guest network in total. Without a cap, one visitor downloading a system update can noticeably degrade the connection the business is running its phones over.

It is the step most often left out, and staff are the ones who notice.

What limits should you set?

Set two numbers. A per device ceiling stops any single visitor taking a large share of the line, and a total guest allocation caps what all visitors combined can use. A few megabits per device, with the guest network held to a modest slice of the connection, suits most offices.

The right numbers depend on the line, and sizing it is covered in our guide to business internet. Set the guest allocation as a proportion so it scales when the connection is upgraded.

Priority for the traffic that cannot wait

Voice and video calls degrade first and most visibly when a connection is congested. Quality of service rules put business traffic ahead of guest WiFi traffic, so a queue at reception does not turn into a stuttering client call in the boardroom. Guest traffic sits at the bottom of that order and visitors on their phones never notice.

How long should a guest session last?

Session limits log a device off after a set period. Two hours is generous in a waiting room, a motel should run the length of the stay, and a cafe is making a commercial decision about table turnover. Guest WiFi scheduled to switch off outside trading hours also removes a target from the car park overnight.

What Does Guest WiFi Need From the Network Underneath It?

Guest WiFi needs equipment that can run more than one network at once, a firewall that enforces the separation, and cabling that reaches the access points covering your visitor areas. Consumer equipment can approximate this, and business grade equipment does it properly. When guest WiFi disappoints, the equipment is usually the reason.

Is consumer router guest mode good enough?

The guest mode on a consumer router creates a second network name and blocks local access in a general way, with no per device limits, no portal, no logging, and no control over which internal ranges are blocked. For a two person office it is proportionate.

Where the public sits down, business grade access points and a firewall that understands VLANs deliver guest WiFi across the whole building with the separation, the limits and the portal in one system.

The wired backbone

Access points are only as good as the cable feeding them, and a guest network puts more devices on the same hardware. Our guide to network cabling covers the wired side the whole wireless network depends on. Placement matters too. The access point covering reception or the cafe floor is often the one furthest from the comms cupboard.

Who keeps guest WiFi working?

The network needs someone to rotate the password, keep firmware current, and confirm the isolation rules survived the last equipment change. None of it is difficult, and it is the first thing to slide once the install is signed off. Exodesk covers it inside managed IT services, so it is maintained alongside everything else instead of being remembered the day something goes wrong.

What Goes Wrong With Guest WiFi Most Often?

The most common failure is guest WiFi that looks separate and is not. It has its own name and its own password, and a device on it can still reach an internal address, because the isolation rule was never configured or was lost in a later change. Five other faults show up repeatedly:

  • The staff password handed out anyway. Guest WiFi exists and reception still gives out the staff password, because that is the one written down. Print the guest details on a card and take the staff one off the front desk.
  • No limits on the guest side. Everything works until a visitor’s laptop starts a large cloud sync and the phones break up. Two numbers in the configuration prevent this permanently.
  • Printers and IoT left in the middle. Guests get segmented off and the printers, cameras and eftpos terminals stay where they always were. They need a segment of their own.
  • An open network with no notice. No password and no acceptable use page means guest WiFi is available from the street with nothing on record about who used it.
  • A setup nobody rechecked. A firmware update or a replacement switch changes the VLAN behaviour, and nobody retests. It takes five minutes.

Which South Island Businesses Need Guest WiFi Most?

Guest WiFi matters most in any business where people who do not work for you sit down and wait. If your premises have a chair for visitors the case is made. Five settings account for most of the work we do across Canterbury, Otago and Southland:

  • Reception areas and waiting rooms. Professional services firms, medical and allied health practices, and any office where clients wait. The systems on the network are confidential, so the value of guest WiFi is in the separation more than the amenity.
  • Retail floors and hospitality venues. Cafes, restaurants, bars and shops, where customer WiFi is part of the offer and card terminals sit on the same premises. Card systems and customer devices on one flat network is a compliance problem as well as a security one.
  • Accommodation. Motels, hotels, holiday parks and lodges, where guest WiFi gets reviewed publicly by everyone who uses it. Coverage across units, a per stay login, and a per device limit that survives a full house.
  • Aged care and retirement villages. Residents, families and visitors all need a connection while care systems and resident records sit on the same site, so the separation has to hold across a spread out campus.
  • Workshops, yards and trade premises. Suppliers, drivers and subcontractors come through all day with their own tablets, and a shared staff password in that environment travels a long way.

What Does Guest WiFi Cost to Set Up?

For most businesses guest WiFi costs less than a single day of downtime, because the equipment is usually already capable and the work is configuration. A site running managed access points and a proper firewall is looking at a few hours of setup and testing.

Costs rise where hardware has to change. A site on consumer equipment, or one needing extra access points to cover a reception or a spread of units, becomes a small project.

If you are getting a quote, the setup fee is not the number that matters. Ask whether your existing access points and firewall can handle VLANs and per device limits. That answer decides whether guest WiFi is an afternoon or a project, and your IT provider should be able to check it while you wait.

How Do You Set Up Guest WiFi?

Setup runs to six steps, and on capable equipment all six happen in an afternoon:

  1. Create the guest VLAN and give it its own address range.
  2. Write the firewall rule that blocks guest traffic from every internal address.
  3. Broadcast the guest network across every access point, with client isolation switched on.
  4. Point guest traffic at a filtered DNS service.
  5. Set the per device and total bandwidth limits.
  6. Add the captive portal and your acceptable use notice, if you need one.

Then test it and keep the result on file. The ongoing part is password rotation, firmware, and retesting after network changes, which folds into an existing support arrangement.

Two things worth doing this week

Join your own guest WiFi on your phone and try to open the printer’s web page. If it loads, the network is not separated. Then check whether the password on the card at reception is the one your staff use. If it is, you do not have a guest network in any useful sense.
Give Visitors a Connection, Not the Keys
Exodesk has supported South Island businesses since 1989 and works with organisations across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. We design and configure guest WiFi that is genuinely separated, set the limits so visitors never slow your business down, brand the login page, and test the isolation before handover.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Frequently Asked Questions

What is guest WiFi?
Guest WiFi provides visitors with an internet connection on a wireless network that is kept apart from the systems a business runs on. It has its own network name, its own segment, and firewall rules that stop anything on it reaching servers, files, printers or payment terminals. Visitors browse normally and see none of the business.
How much does guest WiFi cost to set up?
Guest WiFi is priced on what the existing equipment can already do. A business running managed access points and a firewall that handles VLANs is looking at a few hours of configuration and testing, with no hardware to buy. Sites on consumer gear, or needing extra access points to cover a reception or a spread of units, are quoted as a small project. Exodesk checks the existing kit before quoting.
Is guest WiFi safe for a business to provide?
Guest WiFi is safe when it is properly segmented, and risky when it is only a second password on the same network. Segmentation, client isolation and filtered DNS mean a visitor’s infected device has nowhere to go. The danger comes from a network that looks separate in the settings and is not separate in the firewall.
What is the difference between guest WiFi and business WiFi?
Business WiFi is the internal network staff and company devices use to reach servers, files, printers and line of business systems. Guest WiFi is a visitor network that reaches the internet only. The point of running both is that a device on one can never reach anything on the other.
Does a business need a captive portal for guest WiFi?
A captive portal is worth having anywhere the public sits down, and unnecessary in a small office that sees a few visitors a week. The portal shows an acceptable use notice before the visitor connects, sets a session length, and puts the business logo in front of a customer. Offices with light visitor traffic manage well on a guest password that gets rotated regularly.
How do you stop guest WiFi slowing down the business connection?
Bandwidth limits are the answer, set in two places. A per device cap stops one visitor taking a large share of the line, and a total guest allocation caps what all visitors combined can use. Quality of service rules then put business voice and video traffic ahead of guest traffic when the connection gets busy.
Can devices on a guest network see each other?
Client isolation prevents it, and it is switched off by default on a lot of equipment. Without isolation, a laptop on the guest network can discover and connect to another visitor’s device, which matters most in waiting rooms, shared receptions and accommodation. Turning it on takes one setting and costs nothing.
Does guest WiFi need a separate internet connection?
A second connection is not required. Guest traffic shares the same line as the business and is kept separate by VLAN and firewall rules rather than by separate wiring. Bandwidth limits handle the sharing, so a busy guest network cannot take capacity the business needs.
How often should the guest WiFi password be changed?
Quarterly rotation suits most offices, and monthly suits venues with high public traffic. The advantage of a separate guest network is that the password can be changed without touching a single staff device or printer. A captive portal removes the question entirely by issuing access per session.
Can a business collect email addresses on a guest WiFi login page in New Zealand?
Collection is permitted when the business has a genuine purpose for the information and tells the visitor what that purpose is at the point of collection, in line with the Privacy Act 2020. A cafe or motel building a real mailing list is on solid ground. Collecting addresses with no plan for them creates an obligation with no benefit.
How can you tell if guest WiFi is actually separated?
A five minute test settles it. Join the guest network on a phone, then try to open a printer’s web page or reach a shared folder by its internal address. Anything that loads proves the isolation rule is missing or was lost in a later network change.
Does Exodesk set up guest WiFi in Christchurch and Dunedin?
Exodesk designs, configures and supports guest WiFi for businesses across Canterbury, Otago and Southland from offices in Christchurch and Dunedin, and has worked with South Island businesses since 1989. That covers the VLAN and firewall rules, client isolation, content filtering, bandwidth limits, a branded login page, and testing that proves visitors cannot reach the business network.

Start typing and press Enter to search

Meeting room technology: flat vector of a room with a wall screen showing remote participants, a camera bar covering the table, a table microphone, and a join panel. Call Us Now