The customer asks for the Wi-Fi password and someone behind the counter reads it off a sticky note taped to the register. It's the same password the card reader uses. And the kitchen printer, the camera system and the laptop in the back office with the accounts on it. Nobody planned it that way — the router came with one network, and everything joined it as it arrived.
Guest Wi-Fi is still worth offering. Customers expect it, a salon chair is a dull place to sit without it, and it costs you almost nothing. But the default setup — one network for everything — puts every stranger's phone a few feet, digitally speaking, from the machine that takes your money. Separating them properly is an afternoon's work.
Why one network for everything is the dangerous default
Devices on the same network can see each other. That is what a network is for. So when a guest's phone joins yours, it can discover the card terminal, the receipt printer, the camera recorder and the office PC — not the data, necessarily, but their open ports and their login pages.
The guest doesn't have to be malicious for that to matter. Phones and laptops carry malware their owners know nothing about, and malware scans whatever network it lands on for exactly those devices — a terminal with a default password, a printer with an old firmware bug, a camera recorder with remote access switched on. Every person who has ever asked for your Wi-Fi has, in effect, been invited behind the counter.
There's a second, duller risk: everything a guest does online comes from your public IP address, so if someone downloads something illegal, the complaint letter is addressed to you.
Guest isolation, in plain words
The fix is isolation, and it comes in two parts:
- Guest-to-business isolation — guest devices get a route to the internet and nothing else — not the POS, not the printer, nothing on your side of the wall.
- Guest-to-guest isolation (often called client isolation) — guests can't see each other either, which protects your customers from the infected laptop three tables over.
You want both. On most modern routers this is a built-in feature called guest mode: a second network name with the walls already up. On business-grade equipment it's done with VLANs — virtual networks that share the same cables and access points but behave as though they were in separate buildings. Same idea, more control: VLANs also let you wall the cameras and the POS off from each other. Our small office network guide covers that fuller picture.
Cap the bandwidth so guests can't starve the card reader
A card transaction uses almost no bandwidth, but it needs it at the exact moment the customer is standing there. A dozen phones streaming video can fill your line completely, and then the terminal waits, times out and retries while the queue grows. To your staff it looks like the card machine is broken; in fact it's losing a shoving match with someone's playlist.
Two settings prevent this. A bandwidth cap on the guest network — half your line's speed is a common ceiling — guarantees your own gear always has room. QoS (quality of service), where the router offers it, goes further and serves payment traffic first. If your card reader already has these bad days, the guide on POS and card readers going down covers the other causes too.
Captive portals: the honest trade
A captive portal is the page that appears when a guest joins — tap to accept the terms, or hand over an email address first. Whether you want one depends on what you'd use it for.
The genuine value is marketing: email capture, a count of returning visitors, and a terms page you can point to if a guest misuses the connection. Retail chains get real mileage out of that data. The genuine cost is friction: the login page fails to appear on some phones, the guest gives up, and your staff get asked why the Wi-Fi is broken. For a small restaurant or salon, a plain password with proper isolation usually serves better than a portal nobody asked for. If you wouldn't act on the emails, skip it.
Passwords: rotate them, or put them on a QR poster
Once the guest network is isolated, its password stops being a security matter and becomes housekeeping — it exists to keep the neighbours and the parking lot off your line, not to protect your books.
So change it on a schedule — monthly is plenty — and hand it out the painless way: a QR code on the table tent or the mirror. Guests scan, the phone joins by itself, and next month you reprint the poster with the new code. If you already use QR code menus, it's the same table tent. The sticky note by the register, meanwhile, has a way of ending up in photographs.
The PCI angle, kept short
If you take cards, your processor agreement holds you to PCI DSS, the card industry's security standard, and once a year you answer a self-assessment questionnaire against it. The standard cares a great deal about what can reach your payment devices. On one flat network, everything is part of that answer; with guests segmented away, the network you have to vouch for shrinks to the part that actually handles cards. And if a breach is ever traced back to you, guests on the POS network is a hard fact to explain. Segmentation is also half of what a small-business firewall is for — the two jobs are usually done together.
What your router has to support
- A guest network with client isolation — most routers from the last several years have it; the boxes ISPs hand out are hit and miss.
- Bandwidth limiting on the guest network, or QoS, or ideally both.
- VLAN support, if you run more than one access point or want the cameras and POS on their own segments — this is where business-grade gear earns its keep.
If your current router has none of these, replace it. Decent business-grade equipment costs less than one afternoon of the card reader being down.
The five-minute test any owner can run
Isolation is a setting somebody believes they turned on. Here's how to find out.
- Join the guest network with your own phone — forget the staff network first so it can't quietly fall back.
- Try to print something. If your phone offers the receipt or office printer, guests can see it too.
- Type your router's admin address (often 192.168.1.1 — it's on the router's label) into the browser. A login page means guests can knock on your router's front door.
- If you have an app for your cameras or POS, open it on guest Wi-Fi. If it reaches the devices locally, there is no wall.
- Run a speed test. If it shows your line's full speed, the cap isn't set.
If anything on that list succeeds, your guest network is a name, not a wall — fixable in a settings page if the router is capable, and with better hardware if it isn't.
When you'd rather just hand someone the router
VLANs, caps and isolation are quick for someone who does them every week and a lost weekend for someone who doesn't. Koadi designs and installs guest Wi-Fi with proper segmentation end to end — or, for a one-off fix, you post the problem free in plain words and vetted, identity-verified technicians pick it up. You set a fixed price or take bids, and payment sits in escrow until you approve the work. Much of this is done remotely, anywhere in the US; when the router needs hands on it, local technicians come on-site.