Local Tech Fix (626) 655-0020
All articles

Guest Wi-Fi for a Shop or an Office: What That "Guest" Switch Actually Separates

August 29, 2026

TP-Link's own router manual explains the whole thing in two checkboxes. Almost nobody reads them — and that is why the printer vanishes the morning after you switch guest mode on.

Free WiFi signage on wooden post
Photo by Bernard Hermant on Unsplash

The advice is everywhere and it is not wrong: if customers, contractors or visitors use your Wi-Fi, put them on a guest network instead of the one your business runs on. Every router sold in the last decade can do it, it takes about two minutes, and it is the single cheapest security improvement available to a small shop or office.

What none of those guides cover is the next morning. Somebody turns guest mode on at closing time, and by ten the following day the front-desk laptop cannot find the printer, the copier has stopped scanning to email, the tablet till will not pair with the card reader, and nobody can cast anything to the screen in the meeting room. So the switch gets turned off again, and the shop goes back to one flat network with the customer Wi-Fi password written on a chalkboard.

That whole cycle comes from one misunderstanding, and it is a genuinely reasonable one: the word "guest" is doing two completely different jobs, and on most routers you can set them independently. Once you can see which job is which, the failures above stop being mysterious and mostly stop happening. This is the setup half — the part about your own network. If your card reader is offline right now and you need to keep taking money today, that is a different and more urgent article, and we have written it separately.

The guest switch is doing two separate jobs

The clearest description of this we have found in any manufacturer documentation is TP-Link's, and it is buried in the router manual rather than on any marketing page. The guest network chapter of the Archer A20 user guide offers two tick boxes and describes them like this.

The first: "Tick this checkbox if you want to allow the wireless clients on your guest network to communicate with each other via methods such as network neighbors and Ping." The second: "Tick this checkbox if you want to allow the wireless clients on your guest network to communicate with the devices connected to your router's LAN ports or main network via methods such as network neighbors and Ping."

Read those twice, because they are the whole subject. Job one is the wall between your guests and each other. Job two is the wall between your guests and you — your computers, your file shares, your printer, your cameras, your till. They are separate walls with separate switches, and a router can have either, both or neither.

The second wall is the reason to have a guest network at all. The first wall is the one that decides whether guest Wi-Fi is a pleasant amenity or a small liability, because without it every stranger on your network can see every other stranger's laptop and phone — including whichever of them is bored and curious.

Different brands name these things differently, which is most of why this is hard to look up. Depending on what you own you will see client isolation, AP isolation, device isolation, guest isolation, "allow guests to see each other", "allow guests to access my local network", or a single unexplained toggle called Guest Network with no description at all. eero states its position for business networks plainly — "On the Guest and IoT networks, no two devices can talk to each other" — and gives you no switch, which is a defensible choice as long as you know that is what you bought.

Find those settings on your own gear before you change anything

Open the router or mesh app and go to the guest network section. Read the descriptions rather than the labels — the labels are marketing, the descriptions are the behaviour. You are looking for two things: whether guests can reach your main network, and whether guests can reach each other. Write down what you find before you touch it, because you will want to know what changed if something breaks.

If you are on an ISP-supplied gateway, expect less. Some carrier gateways offer a full guest network with both settings exposed, some offer an on/off toggle and no explanation whatsoever, and some do not offer a guest network at all — the hardware is capable but the ISP's firmware does not surface it. We are not going to tell you what your specific gateway does, because that varies by carrier, by model and by firmware revision, and the answer changes without warning. Test it instead.

The test takes three minutes and costs nothing. Join a phone to the guest network — mobile data off, so you know what you are testing. Then try to open your printer's web page by typing its address into the phone's browser (print the printer's own network configuration page from its front panel if you do not know the address). Then try to open the router's admin page at its address. If either loads, guests can reach your equipment, and the second wall is not up no matter what the label promised. Repeat with a second phone on the guest network trying to reach the first one's address if you want to check the first wall as well.

That test is worth doing again after any firmware update, any router replacement, and any visit from an ISP technician. All three have been known to quietly restore defaults.

What breaks the next morning, in the order we get called about it

Almost everything on this list is the same failure wearing different clothes: two devices that need to talk to each other locally ended up with a wall between them. Local discovery — the thing that makes a printer simply appear in the print dialog, or a speaker appear in the cast menu — is chatter on the local network, and a wall stops chatter by design.

Printing is first and it is first by a distance. Sometimes the printer is on the guest side, more often a laptop or an iPad has been joined to the guest network by somebody being helpful, and the two can no longer see each other. Casting and AirPlay are second, and fail the same way: the screen in the meeting room and the laptop are no longer on speaking terms. Scan-to-folder on a copier is third, and it is worse than the others because the copier usually reports success and simply never delivers the file — the scan is being sent to a share it cannot reach. Scan-to-email is a different animal entirely, since that one leaves through your internet connection and breaks for mail reasons rather than network ones.

Then the payments equipment, which is the one that costs money. A great many modern tills are a tablet talking to a card reader over the local network rather than over a cable, and that pairing is exactly the kind of local conversation an isolation wall exists to stop. Same for a receipt printer sitting on Wi-Fi, and same for the kitchen printer in a restaurant. Last on the list, and the one that surfaces weeks later, is cameras: the shop iPad that used to pull up the camera feed instantly now takes forever or fails, because it had been reaching the recorder directly on the local network and is now going out to the internet and back, or not getting there at all.

If you want the diagnosis rather than the prevention — how to tell in five minutes whether a printer problem is this problem — we have a whole piece on the tell that gives it away, which is a printer that prints happily from a phone and not at all from a computer.

The fix is almost never "turn isolation off"

The instinct, when the printer disappears, is to go back into the router and tick "allow guests to access my local network". That does fix the printer. It also removes the entire reason the guest network exists, and you have now spent two minutes building a wall and two minutes demolishing it.

The right move is to put each device on the side of the wall where it belongs, and to be deliberate about which side that is. Staff laptops, the printer, the copier, the till, the card reader, the camera recorder and the back-office computer belong on your network. Customers, contractors, the vendor rep who needs to show you a slide deck, and the delivery driver who asks belong on the guest network. Then check what got joined to the wrong one, because in practice that is where most of the damage lives — somebody's laptop was set up on the guest network at some point and nobody noticed until printing broke.

There is one consumer implementation that solves the printer problem properly rather than by demolition, and it is worth knowing about because it is the shape the rest of the industry should copy. Google's Nest Wi-Fi guest network lets you nominate individual devices to reach across the wall: "Guests can get online and use shared devices you choose, like a Google streaming device, smart TV, wireless speaker, or printer." The wall stays up; you cut a specific door in it for the printer and the cast target. If your gear has that feature, use it. If it does not, the answer is to move the device, not to lower the wall.

And the equipment that takes money should be on a cable wherever a cable is physically possible. That removes it from this entire class of problem in one move, and it is the single most useful thing on this page for a shop that runs a till.

A separate name is not a separate network

This is the distinction that separates a two-minute job from a proper one, and it is worth understanding even if you decide the two-minute job is enough.

A second network name — a second SSID — is a second door into the same building. What happens once someone is through the door depends entirely on the rules the router applies to them, which is what those two checkboxes are. A VLAN is a genuine second building: separate address range, separate rules, and traffic that cannot cross without passing through something that decides whether it may. The first is a rule that can be misconfigured, forgotten, or reset by a firmware update. The second is structural.

For a small office where the guest network is used by three visitors a month, the checkbox version is honestly fine, provided somebody has actually read the checkboxes and tested them. For a business where strangers are on the Wi-Fi all day — a café, a waiting room, a salon, a gym, a co-working suite — the structural version is worth what it costs, because a rule that only has to fail once is a bad thing to rely on daily.

The cost is not what people expect, and it is mostly a subscription rather than hardware. eero, which is what a lot of small shops already own, gates multiple networks behind eero Business: its own getting-started documentation states that "Your network can have up to 4 SSIDs: 1 Main, 1 Guest and 2 Business or 2 IoT, or 1 each of IoT and Business", and the subscription is listed at $299.99 per year, auto-renewing, at the time we checked this in August 2026 — promotional rates appear from time to time, so check the app before you assume the list price. Business-grade gear from the usual suspects will do VLANs without a subscription but expects somebody to configure it. Neither route is expensive by the standards of a business that takes cards; both are more than nothing, which is why it is worth deciding on purpose instead of drifting.

The cheapest structural option, if you have a spare LAN port and eighty dollars, is a second router of its own hanging off the first, which gives the guests a completely separate network with no configuration skill required. We have written about the trade-offs of that arrangement in the context of a detached office or an ADU, and they are the same here.

What PCI actually says about keeping the register off it — and what it does not

If you take card payments you will eventually be told that separating your guest Wi-Fi from your payment equipment is a PCI requirement. It is worth knowing exactly what the standard says, because a lot of what is written about this online is written by people selling the fix.

The PCI Security Standards Council addresses it directly in its information supplement "Guidance for PCI DSS Scoping and Network Segmentation", dated December 2016, and the wording is unambiguous: "Network segmentation of, or isolating (segmenting), the cardholder data environment from the remainder of an entity's network is not a PCI DSS requirement. However, it is strongly recommended as a method that may reduce" the scope of the assessment, the cost of the assessment, the cost and difficulty of implementing and maintaining the controls, and the risk to the organisation.

So: not required, strongly recommended. The reason it is strongly recommended is in the same document, and this is the sentence that actually matters to a shop owner: "To be considered out of scope, a system component must not have access to any system in the CDE" — the cardholder data environment, meaning the equipment involved in taking payments. Read that as a plain-English test and it says something simple. If your customer Wi-Fi can reach your till, your customer Wi-Fi is part of the thing you are answerable for. If it cannot, it is not.

That is the honest case for doing this, and it is a better one than "it is the law", because it is true. Nobody is going to audit a six-person café. But the annual self-assessment your card processor asks you to sign is a set of questions about your own network, and how you answer them depends on which side of the wall the register sits. A shop with the payment equipment on a cable and the customers on an isolated guest network has a short and easy answer.

Which of those self-assessment forms applies to you, and what your acquirer expects of you, is between you, your processor and whoever advises you on it. We set up networks; we are not your compliance adviser and this is not legal advice. What we can tell you is which cable goes where and how to prove the wall is actually there.

The guest who ruins the afternoon

The other thing a shop wants from guest Wi-Fi and rarely gets is a speed limit. One customer syncing a phone backup or downloading a game update over your connection can make the card terminal slow and the back office unusable, and on a modest business connection this is not a hypothetical.

The honest position is that most consumer gear cannot do anything about it. Per-device or per-network rate limiting is a business-tier feature, and even where it exists it has holes: eero documents that "Bandwidth Limit isn't an available eero Business feature on networks that include an eero Max 7 or a Point-to-Point Protocol over Ethernet (PPPoE) network", so the shop that bought the most expensive hardware in the range may find it is the shop that cannot rate-limit. Check before you buy on the strength of a feature list.

If you cannot limit, protect the things that matter instead. Put the till, the card reader and the back-office computer on cables, because wired traffic does not compete with Wi-Fi traffic for airtime and is far more predictable under load. If a specific customer is genuinely hogging the line every afternoon, most routers will let you see it in the device list, and most of the time the fix is a conversation rather than a configuration change.

Captive portals: what you are actually buying

Search for guest Wi-Fi advice for a business and a large share of the results are selling captive portals — the branded sign-in page that asks for an email address before letting a customer online. It is worth being clear about what these are, because the pages describing them are almost all published by the companies that sell them.

A captive portal is a marketing product with a Wi-Fi feature attached. Its purpose is to convert people who are sitting in your shop into an email list. That is a legitimate thing to want, and for some businesses — a restaurant with a real mailing list, a salon that fills gaps with promotions — it earns its keep. But it is not a security control, and it does not do the job the two checkboxes do. A portal with no isolation behind it gives you a customer's email address and a completely open network. Those are unrelated features that happen to ship together.

It also puts you in the personal-data business, and this is where the search results become actively misleading for an American reader. A great deal of the "guest Wi-Fi compliance" material online is written to European rules — mandatory connection logging, data-retention periods, consent frameworks — and does not describe any obligation a California shop has. In California the relevant law is the CCPA, and the California Attorney General's office states which businesses it applies to: those that "Have a gross annual revenue of over $25 million", or "Buy, sell, or share the personal information of 100,000 or more California residents or households", or "Derive 50% or more of their annual revenue from selling California residents' personal information". Most independent shops meet none of those.

Being under the threshold is not the same as it not mattering. Once you collect email addresses you are holding a list of your customers, and a list of your customers is the kind of thing that gets breached, sold by a vendor you did not read the contract for, or emailed by a former employee. Our practical read for most small shops: skip the portal. A guest network with isolation and a password printed on a card at the counter delivers everything a portal delivers except the mailing list, in about two minutes, with no vendor holding your customers' data.

What we will not tell you, and why

Several confident claims turn up repeatedly in the guest Wi-Fi results and we could not trace any of them to something checkable, so we are naming them rather than repeating them.

That you are legally required to log guest connections, or to be able to identify who was using your network. Every version of this we followed traces back to European or UK rules, or to nothing at all. We found no such requirement for a small business in California, and we are not going to invent one to sell you a logging appliance.

The percentages. Portal vendors publish figures for how much guest Wi-Fi increases dwell time, spend and repeat visits; security vendors publish figures for how many small businesses are breached through guest networks. We could not trace a single one of these to a study, a methodology or a sample size. Treat any page that leads with one as an advertisement, because that is what it is.

And one refusal about our own advice: we will not tell you what the guest toggle on your particular ISP gateway isolates. That behaviour differs by carrier, model and firmware version and changes without notice, and a confident wrong answer here is worse than no answer. That is exactly why the three-minute test earlier in this article exists — it tells you what your equipment actually does today, which is the only version of the answer worth having.

The password on the chalkboard, and the one that must never be on it

A guest Wi-Fi password is public information the moment you give it to the first customer, and you should treat it that way rather than pretending otherwise. Print it on a card, put it on the receipt, write it on the board. It does not need to be complicated and it does not need rotating on a schedule; what it needs is to be worthless if a stranger has it, which is what the isolation settings are for.

The password that must never appear on that board is the one for the network your business runs on. Different name, different password, known to staff and nobody else. If the two are the same today — and in small shops they very often are — changing the business one is the highest-value hour of work on this page. Budget for the tail: it is not the router that takes the time, it is the fifteen devices that need reconnecting afterwards and the two that put up a fight.

Then decide now, while nothing is wrong, what happens when somebody leaves. The Wi-Fi password is the one credential that essentially never gets changed on an employee's last day, because it is not attached to an account and nobody owns it. It is also the one that lets a former staff member sit in the car park and be on your network. Add it to the same list as the email account and the till login — we have written a full offboarding order elsewhere, and the Wi-Fi key belongs on it.

The order to do it in, on one page

One: before changing anything, open the guest network settings and write down what the two behaviours are currently set to — can guests reach your network, can guests reach each other.

Two: turn the guest network on with both walls up, and give it a name that is obviously the customer one.

Three: run the three-minute test from a phone with mobile data off — try to reach the printer's page and the router's page from the guest side. Do not trust the label; trust the test.

Four: go through every device you own and confirm which network it is actually joined to. This is where most of the surprises are.

Five: put the till, the card reader, the receipt printer, the copier and the back-office computer on cables wherever the building allows it.

Six: if your gear supports nominating shared devices across the wall, use that for the printer and the meeting-room screen rather than lowering the wall for everyone.

Seven: change the business Wi-Fi password so it is not the one the customers have, and put it somewhere your staff can find and your customers cannot.

Eight: if strangers are on your Wi-Fi all day rather than occasionally, price the structural version — a VLAN, or a second router of its own — and decide on purpose.

Nine: add the Wi-Fi password to your offboarding checklist, and re-run step three after any firmware update or ISP visit.

Where we come in

This is ordinary work and we do a lot of it across Southern California — cafés, salons, waiting rooms, clinics, workshops and small offices. Usually it is a single visit: read what the existing equipment can actually do, separate the customer side from the business side properly, get the till and the card reader onto cable, prove the wall is there rather than assuming it, and put every printer, copier, camera and screen back where it belongs afterwards.

We will also tell you honestly when the two-minute version is enough. Plenty of small offices do not need a VLAN and do not need a subscription; they need somebody to read two checkboxes, move four devices and change one password. If that is your situation we would rather say so than sell you a project.

And if the reason you are reading this is that something is broken right now — the reader will not pair, the copier stopped scanning, the printer went missing after somebody "fixed" the Wi-Fi — call us and say which. Most of these are a same-day fix once you know which wall is in the way.

Keep reading

Free calculators

Service areas we cover

Want a second opinion before you buy?

We don't sell hardware or warranties — call and we'll tell you what's worth buying and upgrading.

Call (626) 655-0020

Gear we recommend

All gear →