Back to all articles

Secure Wi-Fi and guest access — keep visitors off the inside

Giving visitors the same Wi-Fi as printers and servers risks their laptop scanning your LAN. Use a guest SSID/VLAN with internet-only egress and keep corporate devices on managed access.

Enable client / AP isolation on guest SSIDs so visitors cannot see each other — useful at events where devices are untrusted.

WPA2-PSK vs. 802.1X

WPA2-PSK for all staff beats nothing, but larger teams benefit from 802.1X so you can revoke access centrally when someone leaves without rotating a shared passphrase on every AP.

WPA3 improves resilience against offline handshake attacks where hardware supports it; guest networks often combine a simple passphrase with captive portal vouchers.

Practical rules

  • Guest Wi-Fi without a path to internal apps; captive portal with short-lived codes when possible.
  • Manage APs from a management VLAN, not from the guest network; strong passwords, not defaults.
  • Patch AP firmware — outdated access points are common entry points via public CVEs.

Home office: even on one router, an isolated guest subnet reduces risk when visitors bring unknown devices.