Guest WiFi is either a courtesy or a hole in the side of the office. The supermarket mesh “guest” toggle is the second one dressed up as the first. Visitors get internet. They should not get the accounts share, the printer, or the NVR.
This is how we separate traffic on small Berkshire premises. It belongs with business WiFi and office WiFi not coping.
Why a second password is not enough
On many consumer kits, “guest” is a different name on the same party. Devices still fight for airtime. A curious laptop can still see things you did not mean to share. Isolation has to be real: different network, no lateral movement, a bandwidth cap if reception fills with phones.
Staff stay on a network that can reach servers, printers and internal tools. Guests get internet and nothing else. Warehouse handhelds often need a third SSID so they are not knocked off by someone’s iPad update.
UniFi and similar controllers make those SSIDs visible and boring to manage. Boring is the goal.
A second password on the same LAN is a courtesy name. The visitor’s laptop can still probe for printers, shares, and cameras if the kit never isolated them. We have walked offices where the “guest” SSID could print to the accounts tray. Nobody had meant that. The mesh button had implied it.
Real separation is a different network. On a proper switch that means a VLAN, client isolation, and a firewall rule that says guest may reach the internet and nothing inside. On UniFi that is a few screens once the APs and the switch exist. On a kitchen mesh it is a hope.
Airtime is still shared even when the networks are separate. Isolation stops a visitor reading your files. It does not stop a waiting room of phones drowning a small AP. That is why we design coverage first and names second.
Do not put cameras, tills, or door controllers on guest “because they only need internet”. If a device is valuable, it is trusted, preferably wired. One staff name, one guest name. Extra names are how phones stick to the wrong radio.
Portals, vouchers and the five-person office
A captive portal (click to accept, maybe a voucher) suits:
- Clinics and waiting rooms
- Busy receptions
- Spaces where you do not want the password written on a whiteboard forever
It does not suit a six-desk Maidenhead office where the same three clients visit. A guest password you change when someone leaves is enough. Portals add support. We install them when the site needs them, not as decoration.
Keep a written note of the guest password somewhere other than a Post-it on a monitor facing the street.
A portal is a landing page before the internet. Useful when you have a stream of strangers and you want a click-to-accept or a time limit. Useless when the same accountant visits every Tuesday.
Clinics like portals because the waiting room is full of phones you do not control, and because a written password on the desk becomes a street-facing advert. We set a simple page, a voucher if they want one, and a cap so lunchtime streaming does not kill the clinical WiFi. We do not add a marketing splash because someone saw one in a hotel.
A five-person office should rotate a guest password when a contractor leaves, and keep that password off the window. That is a five-minute UniFi change, not a portal project. Portals break. Someone has to reset them.
Vouchers suit a meeting-heavy Reading floor that wants a code which dies at 5pm. Overkill for a workshop with two regular hauliers. Write the guest password with the alarm code, not on a monitor. If it has not changed in two years, assume it is on a phone that no longer works there.
Airtime is still physics
Separation does not create coverage. If the meeting room is a dead zone, guests and staff both fail. Design APs first, names second. A WiFi survey is how you know whether you need two APs or six.
Do not put the only AP in reception “for guests” and starve the floor. Do not put guest on 2.4GHz only and then wonder why it feels like 2009.
Guest SSIDs run on the same access points as staff. There is no magic guest radio in the ceiling. If the meeting room has one bar, the visitor’s laptop has one bar. Cabling and AP placement are the product. The names are the policy on top.
We still see offices that hung a consumer node in reception because “that is where visitors sit”, then wondered why the floor could not take a Teams call. Put APs on a grid that covers desks, then let guest use those same APs on a separate SSID.
2.4GHz-only guest is a leftover from old kit. Phones and laptops want 5GHz. If you force visitors onto a crowded 2.4GHz band in a Slough unit, they will tell you the WiFi is broken even if staff laptops look fine.
If you already failed, measure. WiFi survey Reading and WiFi survey Slough are the town pages for that. Structured cabling is how the APs become honest once you know where they should hang.
Cameras, tills and the things that must never be guest
- CCTV and recorders
- Card machines, if you can avoid public WiFi entirely
- Door controllers
- Staff file storage
If a device is valuable, it is wired or on staff WiFi, preferably wired. Guest is for humans with laptops who are leaving at 4pm.
Cameras on guest are how a visitor’s phone and your NVR share a network you cannot explain to an insurer. Do CCTV cameras need WiFi? The short version for premises: cameras should be on a trusted LAN, on PoE, in the cabinet. Not on the waiting-room SSID.
Card machines belong on a wired point or a dedicated staff path. Public guest WiFi is a bad place for payments. Door controllers, alarm panels, file storage and printers stay off guest, even though someone will ask, because the first visitor who can print is also the first who can see the queue.
A doorbell on guest will die every time you rotate the password. Put those gadgets on staff, or on a small IoT SSID you control. If a device cannot be wired and cannot live on staff, we will say so. We will not hide it on guest to make the install look tidy.
Where we fit this
Slough, Reading, Maidenhead and Bracknell offices, plus units that also need warehouse WiFi. Homes that want a visitor network can have one too, but this article is for premises that already feel the pain.
Slough trading estates often want guest for drivers in reception and a scanner SSID on the floor. Those are not the same network. Mixing them is how a lunchtime YouTube session drops a pick.
Reading floors want guest for clients in glass rooms, with a cap so phones do not drown the staff call. Maidenhead smaller offices usually want a rotating password and no portal. Bracknell mixed units want desks, floor, and sometimes a yard that should not be on guest at all.
We do this as part of the office WiFi job. If the APs and the switch are already right, a proper guest SSID is a controller change. If the APs are a kitchen mesh, guest isolation is theatre. Fix the radios, then name them. Office WiFi not coping is that conversation.
A simple policy you can actually keep
Write down, on one page:
- Staff SSID name and who may know the password
- Guest SSID name, how often the password rotates, and whether a portal is in play
- Which devices are allowed on staff (printers, till, NVR)
- A named person who can reset the guest key when a contractor leaves
If that page does not exist, the network will rot into one password on a whiteboard. Controllers like UniFi make the technical split easy. They cannot stop someone taping the staff key to the reception monitor.
For a house that wants visitors on a separate name, the same idea applies at a smaller scale. Do not put cameras on the visitor network. Do not put the kids’ consoles on guest if you then wonder why parental controls vanished.
The page should live with the alarm codes. When a contractor leaves, the named person changes the guest key that afternoon. When a new till arrives, it goes on staff, wired if we can. Guest exists so you can refuse the staff password without being rude.
We will set the technical split. You have to keep the social one. The most common failure six months later is not a VLAN. It is a staff password that leaked because it was easier. UniFi can show you which clients are where. It cannot take the Post-it down.
Pick a named person with a login and permission to rotate a key. Keep the names boring and stable. A dull guest SSID that rotates is better than a joke that never changes.
Bandwidth caps, hours of service, and being kind
A waiting room full of phones can drown a small broadband line at lunch. A cap on guest is not rude. It is how staff calls survive. Turning guest off at night is reasonable in a clinic that is closed. It is less reasonable in a co-working space. Match the policy to the building.
WiFi surveys are how you know whether the problem is policy or coverage. If the meeting room has one bar, no portal will save it.
A cap is a speed limit on the guest SSID. Staff keep the line. Visitors still get mail and a browser. They do not get to saturate a small circuit with four phones on a video. We set this as a matter of course on clinics and busy receptions. We leave it looser on a small office where three clients a week visit.
Hours of service are the same idea. A dental practice does not need guest at midnight. A warehouse with night picking might. A co-working floor should not kill guest at 6pm because someone copied a clinic template. We will ask when the building is actually used.
Test guest from a phone that is not already on staff, and walk to the meeting room. If it fails there, the policy is irrelevant. Guest policy cannot invent megabits. Coverage still comes from APs on cable. Names and caps come after.