Some links on this page are affiliate links. If you buy through them, P2C Solutions may earn a commission at no extra cost to you. As an Amazon Associate we earn from qualifying purchases. We only recommend what we would use ourselves.
A shop, a salon, a clinic, an office with visitors: people ask for the Wi-Fi password, and it is easier to give it than to refuse. The trouble is that the password puts their phone on the same network as your computers, your printer, your card terminal and your files. A guest network gives them internet and nothing else, and every router made in the last ten years can do it.
What can go wrong without one
- Their device is infected. Malware on a visitor's laptop looks for other computers on the same network. Yours are on it.
- The password spreads. Once given out, it is written on a whiteboard, shared on a phone, and known by every former employee and every customer who ever asked. Changing it means changing it on every device you own.
- Your card terminal is exposed. Card processing rules expect the payment equipment to be kept apart from public traffic. A shared network fails that test.
- Someone finds the printer. A printer on an open network can be printed to, and often browsed, by anyone on it.
- Someone downloads something illegal. It comes back to the business's connection.
What a guest network is
Your router broadcasts a second Wi-Fi name, say "Yourshop Guest", with its own password. Devices on it can reach the internet and cannot see anything else on your network. To a visitor it is just Wi-Fi. To you it is a wall between the public and the business.
Setting it up
- Sign in to the router's settings. The address and the login are usually on a label on the router, or in the app that came with it. If you have never changed the admin password, do that first; our guide to router settings everyone should change covers it.
- Find the guest network option. It is usually under Wireless or Wi-Fi settings, and on mesh systems it is in the app.
- Turn it on, give it a name that says it is for guests, and set a password. The password can be simple, and it can be displayed at the counter, because it protects nothing of yours.
- Look for an option called client isolation, AP isolation or "allow guests to see each other", and make sure guests are isolated from each other as well as from you.
- If the router allows it, set a bandwidth limit for the guest network, so a visitor streaming video does not slow the card terminal.
- Move any device that is not the business's own, including staff personal phones, onto the guest network.
What goes on which network
- Business network: computers, the printer, the card terminal, the phone system, the security cameras, the network storage.
- Guest network: customers, visitors, staff personal phones, and anything you do not manage.
- A third network, if the router offers it, for smart devices such as TVs, speakers and thermostats, which are the least secure things in most buildings.
Wi-Fi provided by the internet company
The router supplied by the cable or fibre company usually has a guest option too, sometimes only in its app. If it does not, or if the guest option cannot be isolated properly, a modest business Wi-Fi router behind it is not expensive and gives you far more control.
A captive portal is optional
The page that asks visitors to accept terms or enter an email before they connect is called a captive portal. Cafés and hotels use them. For most small businesses it is unnecessary, and it annoys customers. A guest network with a simple password does the job.
Coverage
If the guest network is weak in the waiting room, the problem is the same as any other Wi-Fi coverage problem, and our guide to fixing Wi-Fi dead spots applies. A mesh system carries the guest network to every point along with the main one.
If you would like it done
Setting up a guest network, moving the right devices onto the right network and checking that nothing is exposed is an hour's work. We do it as part of a small business network check, along with the router settings and the printer.