Skip to content
Client login

Free Audit

IT & infrastructure

The guest network: what your customers reach, and what they cost you

A guest network exists the moment a waiter gives out the password. What it should reach, what it takes off the line, and what not to collect.

Published on 19 June 2026 — Algeria Agency

The companion article compares professional and consumer equipment: throughput per device under load, roaming, why an access point is not a router mounted higher, and placement. It also says, in its section 8, that your customers care about this.

This page covers what happens next: the network your customers actually use, every day, and that nobody administers.

The fact that governs everything else is this: the guest network exists from the moment a waiter gives the password to somebody who asks. Nobody decided it, nobody named it, and it is already there.

So the only open question is not whether to have one. It is whether it is a separate network or yours — and everything that follows comes out of that answer.

It already exists, and it is probably yours

Run a thirty-second test: ask whoever serves at the counter which password they give customers. In most cases they know it by heart, and in most cases it is the business network’s.

It is nobody’s fault and it is entirely logical. A customer asks, the person wants to help, there is only one password in the place, and refusing would be stranger than giving it.

What that produces is easy to describe and rarely stated: your customers’ phones are on the same network as your till, your cameras, your server and your employees’ workstations.

The consequence is not dramatic and that has to be said too, because an article that exaggerates gets ignored: most of those phones do nothing in particular. The risk is not the malicious customer, it is more ordinary — an infected device looking around, and a till or a recorder still on its factory password.

The correction is not a policy, it is a second network, and on equipment from the last ten years it is a setting rather than a purchase. That is the next section.

A second network, and what it should reach

The principle fits in one sentence: a guest should be able to reach the internet and nothing that belongs to you.

Concretely that means three things. The guest network has its own name and its own password. It is separated from the business network, which is a setting on almost every recent access point and router. And guest devices cannot see each other, which is a checkbox usually called "client isolation".

The third is the forgotten one and it protects your customers rather than you. Without it, the phone at table three can see the phone at table seven, which is nobody’s problem until the day it is.

The mechanism of separation is covered elsewhere and we do not repeat it: the switch article explains why two devices handing out addresses break everything, and the firewall-rules article explains why a separation removes more rules than a day of tidying. What to keep here is the consequence: done properly, the guest network is what lets you have **fewer** rules, not more.

Check it once, from a phone connected as a guest: try to open the interface of your till, your camera recorder, or the operator’s box. If any of the three opens, the separation does not exist, whatever the network is called.

The line is the same, and it gets shared

The guest network is separated from your network and it is not separated from your line. Everything your customers consume comes off the same connection as your tills, your backups and your calls.

It is the only real cost on this page and it is rarely noticed, because it does not present as a failure: it presents as slowness, at your end, at the hour when you are busiest.

The setting that fixes it is not limiting each device, which is what everybody tries. A per-device cap is defeated by numbers: twenty individually limited phones still consume twenty times their cap.

What works is a **global** cap for the guest network, expressed as a share of your line — a half, a third, depending on what you do with the rest. The principle is the priority list from the line-outage article: you decide calmly what has to keep working when everything is loaded.

We will not give a percentage, and for once the reason is simple rather than methodological: it depends entirely on what your business does on that line. A hairdresser and a practice sending case files do not have the same answer, and you are the only one who knows which is yours.

The captive portal: what it actually does

The captive portal is the page that opens when you connect and asks you to accept something, sometimes to enter a number. It is the product every wifi solution vendor proposes first.

What it actually does is useful and modest: it displays a condition of use, it lets you show a page of your own, and it produces a connection log. Those are three real things.

What it also does, and which is never in the sales pitch, is add a step between the customer and the internet. On a phone that step fails regularly: the page does not open by itself, the device believes it has no connection, and the person gives up thinking your wifi does not work.

Our position is this and it holds for the size of business we serve: below around forty seats, a captive portal costs more irritated customers than it brings benefits. A password written on the board does the same job with no friction.

The case where it becomes justified is volume and turnover: a hotel, a large café, a space where dozens of people connect each day and where you have a precise reason to keep a log. The important word is "precise" — and the next section covers the moment that reason becomes a collection.

Asking for a phone number: what it commits you to

This is the feature vendors lead with: the customer enters their number to connect, and you build a list. It has to be handled honestly, because it is the one thing on this page that creates obligations for you.

First point, and it is practical before it is legal: the list obtained this way is very poor. People enter false numbers, they do it quickly and without reading, and half the list leads nowhere. A list nobody agreed to give is not a customer file, it is a collection.

Second point: from the moment you collect a number you hold personal data. That means saying why you collect it, how long you keep it, and what it is for — at minimum on the portal page itself.

Third point, and it is the one nobody anticipates: that list is no use at all if you have not already decided what to do with it. We have seen several installations where the portal had been collecting numbers for eighteen months and nobody had ever exported them.

So our default recommendation is to collect nothing. If you want a customer list, ask for it at the counter, with a reason — a loyalty card, an offer — and you will get fewer numbers and far more real ones. It is the same reasoning as the email-list article, in another channel.

The password, and how often to change it

The guest password is a peculiar object: it is meant to be shared, which makes it different from every other password in this pillar.

It has to be easy to say and to type — it gets spoken aloud fifteen times a day — and it does not need to be complicated, because its function is not to protect a secret but to limit use to the people who are on your premises.

Changing it monthly is a ritual with no effect, and it costs: the person at the counter has to learn the new one, the board has to be rewritten, and regulars ask again. Once or twice a year is amply enough.

There are two moments when it should be changed and both are concrete. When a member of staff leaves — the same reasoning as for badges and accounts, and the only case where the guest password genuinely matters. And when you notice consumption that does not match your footfall, which usually means somebody is using it from the building next door.

Write it where the company’s other papers are, with the network name and the date it was last changed. Thirty seconds, and it avoids the classic situation: nobody knows the guest password any more, so everybody gives out the business one.

The network name, and the two mistakes

The network name is the only visible part of all this work, and it is nearly always chosen badly in one of two ways.

The first mistake is the factory name — a string of letters and digits that means nothing. A customer looking for your wifi sees six networks and does not know which is yours; they ask, somebody answers, and that consumes fifteen seconds of the counter’s time several times a day.

The second is subtler: naming the guest network **exactly** like the business one, with a suffix. The two appear side by side, employees pick the wrong one, customers do too, and you spend your time explaining the difference.

The right shape needs no explanation at all: the shop’s name for the guest network, and something nondescript for the business network. That is the reverse of most installations, where the visible network is the working one.

One last thing on this, because it always comes up: hiding the network name protects nothing. A hidden network is trivial to detect for anybody looking, and it complicates life for everybody who should be connecting to it. It is not a security measure, it is an inconvenience.

What your customers actually do on it

It is worth knowing what consumes, because it changes what to adjust and what not to.

A seated customer’s consumption over an hour is not in their searches or their messages, which weigh nothing. It is in video, and above all in something nobody anticipates: a phone that discovers a wireless network often decides this is a good moment to download its updates.

That explains the phenomenon all our clients describe: three seated people consume more than twenty standing ones. The three stayed long enough for their devices to update.

The practical consequence is that section 3’s global cap is the right tool and content filtering is not. Blocking sites does not reduce that consumption, because it does not come from sites — and the firewall article separately explains why we advise against that filtering in general.

One exception worth knowing: if your business runs on a modest line and you observe blockages at peak hours, a per-device rate limit **in addition** to the global cap helps in that specific case. It does not replace the global cap, it completes it.

The failure only your customers see

The guest network has a property nothing else in this pillar shares: it can be broken for weeks without anybody in the business noticing.

Your employees do not use it — they are on the business network — and your customers do not complain, they simply observe that the wifi does not work, which is information they keep to themselves.

The causes are ordinary and invisible: an access point restarted onto an earlier configuration, a cap set too low on a test day, a password changed by somebody and not passed on, a router update that disabled the second network.

The check takes two minutes once a month and needs no tools: take your personal phone, forget the network, reconnect as a customer would, and open a page. Then check section 2’s separation while you are there.

Note the date on the same sheet as the password. It is the cheapest act in this whole pillar and it concerns what your customers see of you — which, for a business whose wifi is advertised in the window, is not a technical detail.

What to display, and where

What you have to display is short, and it changes depending on whether you collect anything.

If you collect nothing — the case we recommend — the display is commercial rather than legal: the network name and the password, legible, where the customer sits. On the board, on the menu, in a small frame on the table. Half the customers who ask for the password ask because they did not find it written anywhere.

If you use a captive portal, the portal page has to say what the customer is getting access to and what you do with whatever they enter. One sentence is enough and it has to be true, which assumes somebody decided the answer.

If you collect a number, add two things to that page: why, and how long you keep it. That is the same obligation applying to any personal data collected on this site, and the same one we apply to ourselves.

And one thing not to display: never write the business network’s password on the board. That sounds obvious and it is exactly what section 0’s situation produces, where there is only one password in the place.

What wifi will not bring in

A limit is needed before concluding, because this subject is sold with promises that do not stand up.

You will be told that good wifi brings customers back. We do not know and nobody knows, because measuring it would need the same business, in the same street, in the same month, without wifi. That business does not exist.

What we can say honestly is narrower and firmer: advertised wifi that does not work produces a disappointment attributed to you, which is a real cost. The promise in the window creates the expectation; that is what has to be kept, and it is what section 8 exists to check.

You will also be told that a portal lets you "get to know your customers". A list of numbers entered grudgingly to get a connection says nothing about anybody, and section 4 explains why a request at the counter with a reason teaches you more.

What we do know, and what is measurable, is what wifi costs you when it shares the line with your tills: that is section 3, it is real, and it is the only figure in this subject you can observe yourself.

What we do, and what we refuse to do

What we refuse first: installing a captive portal in a venue with fewer than about forty seats. It is the most profitable product in this subject, it sells with a subscription, and it adds a step that makes customers give up in exchange for a log nobody will read.

We also refuse to set up phone-number collection without somebody at your end having written down what they intend to do with it. That is not a legal position: it is that we have seen portals collect for eighteen months without anybody ever exporting the list.

And we refuse to hand over a guest network without running section 2’s test in front of you — opening the till’s and the recorder’s interfaces from a guest phone. A network with the word "guest" in its name that reaches your till is not a guest network, it is a name.

What we do fits in two hours: the second network created and separated, client isolation enabled, the global cap set with you against your priorities, the network names corrected per section 6, and the sheet with the password and the date.

And one thing to do today, in thirty seconds: ask whoever serves which password they give customers. If it is the business one, you know what there is to do, and it is a setting rather than a purchase.

Frequently asked questions

Do we really need a separate network for customers?

Yes, and one already exists in practice: ask the person at the counter which password they give out, and it is nearly always the business one. The risk is not the malicious customer but an infected device looking around, and a till or recorder still on its factory password. On equipment from the last ten years, the separation is a setting rather than a purchase.

How do we check the separation works?

From a phone connected as a guest, try to open the interface of your till, your camera recorder and the operator’s box. If any of the three opens, the separation does not exist whatever the network is called. Also enable client isolation, which stops guest devices seeing each other — that one protects your customers rather than you.

Should we limit guest bandwidth?

Yes, but globally rather than per device: a per-device cap is defeated by numbers, since twenty limited phones still consume twenty times their cap. Set a share of your line for the whole guest network. We give no percentage because it depends entirely on what you do with the rest of the line.

Is a captive portal useful?

Below around forty seats it costs more irritated customers than it brings: it adds a step that fails regularly on phones, the device believes it has no connection, and the person concludes your wifi does not work. A password on the board does the same job with no friction. It becomes justified with volume and a precise reason to keep a log.

Should we ask customers for their phone number?

Our default recommendation is to collect nothing. The list obtained is very poor — people enter false numbers — it creates obligations to say what you do with it, and we have seen portals collect for eighteen months without anybody ever exporting the list. Ask at the counter instead, with a reason.

How often should the guest password change?

Once or twice a year is enough: changing it monthly is a ritual with no effect that costs counter time. Two moments justify a change — a member of staff leaving, and consumption that does not match your footfall, which usually means somebody is using it from the building next door.

Where we come in

Whoever serves customers knows which password they hand out. If it is yours, your guests are on the same network as your accounts.

  • We create the second network and isolate it, in two hours, one morning.
  • We cap total bandwidth against your priorities rather than per device.
  • We open your server’s interface from the guest network, in front of you.

Under about forty covers, do not buy a captive portal: it costs more than it returns, and a plain second network is enough.

Read next

Let us talk about your project

A free audit, no commitment: we look at your online presence and tell you what is holding it back.

We measure how this site is used with Google Analytics, to learn which pages actually help. You can stop that measurement at any time from the footer. Cookie policy