Home
›
Articles
›

Separate guest Wi-Fi from office network

Separate guest Wi-Fi from office network

By Ibi Hasanli

·

·

3 min read

Separate guest Wi-Fi from office network traffic when visitors, contractors, or BYOD phones sit on the same SSID as accounts, card terminals, or file shares. A flat office Wi‑Fi is fine until a guest laptop is one hop from finance. You need guest (and often IoT or CCTV) kept off the staff and payment path, with accounts you still own, not a full office rebuild.

Why a flat SSID is risky

One password for everyone usually means one broadcast domain for everyone. A compromised guest device can scan for shares, printers, and payment kit that should never see visitor traffic. I’ve walked London offices where the visitor SSID was only a different name on the same LAN as the bookkeeper’s machine. That is not hospitality. That is an open door with a polite label.

Finance systems, card terminals, and file shares are the must-isolate set. Staff laptops can share a trusted segment. Guests should reach the internet, and little else, unless you deliberately publish a printer or portal. Growing teams hit the same wall when the first contractor asks for the staff password “just this week” and nobody wants to admit the network was never split.

Options at decision level

Start with a dedicated guest SSID and client isolation so guests cannot talk to each other or to staff devices. That is the minimum for many small offices. When payment or finance kit shares the building, step up to VLANs: guest, staff, and payment (or IoT) on separate segments, with a firewall deciding what may cross. The firewall rule is the product, not a weekend of CLI theatre. If card terminals are in scope, treat segmentation as part of how you protect payment traffic, not as a Wi‑Fi cosmetic.

We already covered what a payment-oriented survey looks like in VLAN and payment systems. This piece is narrower: get visitors off the finance LAN without redesigning the whole firm. For the wider growing-office picture, see office network for a growing London team.

What a survey actually decides

A short office survey maps SSIDs, who connects, where accounts and card kit live, and which links are sacred. Then you get a fixed-price plan: guest SSID with isolation, or proper VLAN splits plus firewall rules, using kit you can still log into after we leave. Eight Mile’s networking work is built for that commercial install path: survey, segment, hand back the runbook.

Expect photos of the rack, a list of SSIDs and who knows the passwords, and a clear call on whether isolation on one access point is enough or whether the switch and firewall need VLAN work. That decision is what you buy. Not a binder of vendor screenshots.

Ownership after the install

You should keep the firewall and Wi‑Fi controller logins, the guest password process, and a one-page note of which VLAN is which. If only the installer can change the guest key or open a port, you rented a black box. After cutover, a second person in the business should be able to rotate the guest passphrase and confirm guests still cannot reach finance shares.

Get guests off the finance path

Stop treating one office SSID as good enough because nobody has complained yet. Separate guest Wi-Fi from office network paths that hold money and files, then keep the accounts.

If you want a short office Wi‑Fi and segmentation survey — what sits on which SSID today, what must be isolated, and a fixed-price plan to split it — contact Eight Mile and say how many staff, visitors, and payment devices share the floor.

Networking
VPN

Multi-site office network

Multi-site office network design for London SMEs: site-to-site links, consistent segmentation, accounts you keep.

·

3 min read

Backups
Disaster recovery

Backup restore test

A backup restore test proves copies work on a clock you can live with. Untested backups are hope with a green tick.

·

3 min read

Infrastructure
Cloud

Moving off the server under the desk

Moving off the server under the desk: stage a move to managed hosting or cloud you own — without a big-bang rewrite.

·

3 min read

Networking
London

Office network for a growing London team

Office network for a growing London team: when the ISP router fails, what a proper office network includes, and why survey first.

·

3 min read

Security
Audit

Security audit vs penetration test

Security audit vs penetration test: when to review config first, when a buyer needs a pentest, and usual order for SaaS.

·

3 min read

Security
Git

Secrets in git repository

Secrets in git repository history outlive a deleted file. Rotate first, then stop the next temporary commit.

·

3 min read

Wi-Fi

What is a Wi-Fi Survey?

What a Wi-Fi survey is, the passive, active and predictive types, the software and hardware used, and the steps to run one for better coverage and performance.

·

2 min read