(a) Guide
Guest Wi-Fi security and segmentation
Offering guest Wi-Fi is safe. Offering it on the same network as your registers is not.
One network, two worlds
The systems that run your business — payments, property management, cameras, back office, phones — should be unreachable from the network your guests join. Segmentation puts them on separate logical networks with no route between them, so a compromised guest laptop sees nothing but the way out to the internet.
The settings that matter
- Client isolation so guest devices cannot see each other
- No route from the guest segment to business systems
- Per-device bandwidth limits so one user cannot flatten the site
- Separate segments for cameras, payments and staff devices
- A firewall in front of everything, with only required services exposed
- Session limits and a captive portal with your acceptable-use terms
Payment systems have their own expectations
Card-industry practice expects payment traffic to be isolated from public access. Getting segmentation right at install is far cheaper than retrofitting it, and it is a question your insurer or card processor may eventually ask about.
Give it its own capacity
Segmentation protects the business network from risk; rate limiting protects it from load. Together they mean a full car park of guests streaming video cannot slow a card authorisation at the counter.
Commercial service only · United States