Separate guest Wi-Fi from office network
Separate guest Wi-Fi from office network traffic so visitors never sit one hop from finance, payments, or file shares.
·
3 min read
Multi-site office network design matters once a second London site needs shared files, phones, or apps. Consumer routers plus personal VPNs break printers and voice, and flatten the guest and payment splits you already wanted. You need a surveyed link between sites, clear local versus shared traffic, and accounts you keep.
A single floor can limp on one SSID, a cupboard switch, and whoever remembers the admin password. Add a second address and the same habits stop scaling. Someone installs a home-grade router, dials a personal VPN into HQ, and hopes printers and the phone system follow. They often don’t. Worse, once both sites share a flat tunnel, a guest on site B can reach the same finance shares you meant to keep local to accounts at HQ.
I’ve seen SMEs open a second desk in Zone 2 and discover that “we’re connected” only meant staff laptops could browse. Reception printers stayed stranded. Card terminals sat on whatever Wi‑Fi was nearest. Nobody owned a diagram of what should stay local and what must cross the WAN. That is the moment one-office networking stops being cheap and starts being risky.
At decision level you choose how the sites talk, not which CLI to paste. A site-to-site VPN between proper firewalls at each office is the usual commercial path: encrypted link, known endpoints, rules for which subnets may cross. A managed overlay (vendor SD-WAN or similar) can suit firms that want central policy and less DIY kit, still with clear ownership of the accounts. What you should avoid is a tangle of staff laptops dialling home, or bridging whole LANs so every broadcast and guest device becomes company-wide.
Decide early what stays local: printing, CCTV, guest internet, building IoT. Decide what is shared: file servers, phone registration, line-of-business apps. The multi-site office network is the set of intentional paths between those lists, not “everything tunnels to HQ.” Bandwidth and failover matter too: a single consumer uplink with no plan for outage is how the second office goes dark when the first site’s broadband hiccups.
Splitting guest from staff at one office and forgetting the other is how you reintroduce the flat SSID problem across a city. Staff, guest, and payment (or IoT) segments should mean the same thing in both buildings. Guests get internet, not finance shares, whether they sit in Shoreditch or Croydon. Payment kit stays off visitor Wi‑Fi. Staff identity and access follow the person, not the postcode.
We covered visitor isolation in separate guest Wi-Fi from office network, and payment-oriented splits in VLAN and payment systems. For the single-site growth picture, see office network for a growing London team. This piece is the join: connect sites without collapsing those boundaries.
A multi-site survey maps both floors: who connects, which apps must cross, what kit you already own, and where guests or contractors land today. Then you get a fixed-price design: site-to-site or managed overlay, VLAN or SSID plan that matches at each site, firewall rules at the right layer. Eight Mile’s networking work follows that path so you are not buying open-ended tunnel theatre.
After cutover you should hold firewall and Wi‑Fi logins for every site, a one-page map of local vs shared traffic, and a second person who can rotate guest keys and confirm payment segments stay isolated. If only the installer can open a port between offices, you rented a black box with two doors.
Stop treating a personal VPN and a second consumer router as a multi-site office network. Design the link, keep segmentation consistent, and keep the accounts.
If you want a multi-site network survey covering how the sites should connect, what stays local, and a fixed-price plan to join them cleanly, contact Eight Mile and say how many offices, staff, and systems need to share the path.
Separate guest Wi-Fi from office network traffic so visitors never sit one hop from finance, payments, or file shares.
·
3 min read
Office network for a growing London team: when the ISP router fails, what a proper office network includes, and why survey first.
·
3 min read
Security audit vs penetration test: when to review config first, when a buyer needs a pentest, and usual order for SaaS.
·
3 min read
Secrets in git repository history outlive a deleted file. Rotate first, then stop the next temporary commit.
·
3 min read
A backup restore test proves copies work on a clock you can live with. Untested backups are hope with a green tick.
·
3 min read
Moving off the server under the desk: stage a move to managed hosting or cloud you own — without a big-bang rewrite.
·
3 min read
VLAN and payment systems — what a survey actually covers: coverage, segmentation, kit, and a fixed price after the site visit.
·
3 min read