forumNew topic

Do we need to set up a VLAN to keep guests from accessing company data via the guest WiFi?

GGizem E***Veteran
Job title
Social media manager
Sector
Food wholesale
Organization type
sole proprietorship
Joined
Sep 2024
Message
161
#1

We have guest WiFi at the office, it has a password but everything is on the same network. Someone could see other devices on the same network, access file sharing, or use the printer. If someone does ARP spoofing or something on the network, can they see all the data traffic?

We heard we need to split the network with VLANs. So guest network = its own network, company network = separate network, no traffic between them. But how do you set it up? Managed switch, Access Point config, firewall rules... Is it too complicated?

Are there other solutions instead of setting up VLANs in an SMB environment? Is it enough if guests only use the internet but can't access company resources?

BBurak Y***MemberCommunity member
Joined
Aug 2025
Message
74
Most Helpful#2

VLAN network segmentation is recommended for protecting guest and corporate data. Setup: 1) You need a managed switch (unmanaged switches don't support VLANs), 2) Access Point (AP) configuration: Guest SSID → VLAN 2, Corporate SSID → VLAN 1, 3) Switch side port configuration: tagging (trunk port) + untagging (access port), 4) Router/firewall: Block between VLAN 2 (guest) and VLAN 1 (corporate) (disable inter-VLAN routing), 5) Guest network is internet-only (outbound permitted, inbound corporate blocked), 6) Firewall rules: Guest → Corporate (block ports 445, 139, 3306, etc.). Alternative (simple environments): Network isolation without VLAN: guest WiFi on a different subnet (192.168.2.0/24), corporate (192.168.1.0/24), inter-subnet routing disabled on the router. SMB/File sharing (445/tcp): disable on the guest network. Printer access: default deny, whitelist. VLAN setup: Ubiquiti UniFi, Cisco Meraki (cloud-managed), TP-Link managed switches ($100-300). SMB cost: $500-1000 (managed switch + AP). Alternative: cloud-based WiFi (a corporate firewall product, Cradlepoint): auto-segmentation built-in.

TTaner Y***Expert
Job title
Regional Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Sep 2025
Message
3

Doki · Vulnerability scanning · 2025

#3

just set up a vlan and save the guy from his job then buy a managed switch, set up guest vlan on the ap add a rule in the firewall done. if even adding 1-2 thousand lira is too expensive for a simple smb, at least turn off the printer and file share...

SSelinMember
Job title
Frontend developer
Organization type
20-person company
Joined
Feb 2024
Message
164
#4

VLAN config example: Switch (Cisco/TP-Link/Ubiquiti): vlan 1 (corporate), vlan 2 (guest), interface eth1 switchport mode access switchport access vlan 1, interface eth2 switchport mode access switchport access vlan 2. Router/firewall: acl deny source-vlan-2 dest-vlan-1, allow vlan-2 destination 0.0.0.0/0. WiFi AP: SSID-corporate VLAN 1, SSID-guest VLAN 2. SMB disabled on VLAN 2 (firewall rule port 445 deny). Testing: ping a corporate device from a guest device (should fail).

BBeyza T***MemberCommunity member
Joined
Nov 2024
Message
336
#5

Set up a managed switch + access point, configure the guest vlan, write a firewall rule (no traffic between them), done. Otherwise guests can see each other, access the file share its risky. TP-Link managed switch is 300-400 lira, worth it...

JJülide S***MemberCommunity member
Joined
Nov 2025
Message
3
#6

Network segmentation best practice: 1) VLAN trunk (managed switch + AP) 2) Access control list (firewall) 3) DNS filtering (malicious sites), 4) Bandwidth limiting (QoS on guest network), 5) Captive portal (WiFi terms & conditions). Alternative: SD-WAN (cloud-based) zero-trust access (network access control). SMB: managed WiFi (Ubiquiti Meraki) vs. enterprise gear. Cost-benefit: VLAN setup 1-2k vs. breach cost (data theft compliance fines).

VVildan B***Member
Job title
Production planning
Sector
Livestock
Organization type
workshop
Joined
Feb 2023
Message
388

Doki · Mobile app · 2023

#7

You need to set up VLANs!!! Guest + company traffic together = disaster. Get a managed switch, set up VLAN tagging, add firewall rules, done. You can build a solid network for 1000 lira...

NNeslihan T***MemberCommunity member
Joined
Nov 2022
Message
226
#8

I felt relieved reading this answer, so it's not just me. If you scold false alarms, nobody will report again.

The answer varies greatly by industry; there is no one-size-fits-all rule. I'm also curious if anyone does it differently.

PPerihan A***New memberCommunity member
Joined
Sep 2026
Message
7
#9

If you're going this route sort this out first. If you get three different answers on a topic, the question was asked wrong.

If it's your first time, start small; scaling comes later. anyway just leaving this note, it might be useful.

DDamla Ç***MemberCommunity member
Joined
Nov 2023
Message
199
#10

i have an objection here. if you scold false alarms, nobody will report again.

if the notification path is long notfications don't arrive; missing notifications mean delayed incident detection. that's all, sorry if I went on too long.

BBaranMember
Job title
Game developer
Organization type
120-person company
Joined
Jun 2024
Message
98
#11

The answer above hits the nail on the head. tbh when making decisions, write down the worst-case scenario too, not just the best.

Hope this helps.

VVahide A***Member
Job title
QA Tester
Sector
Education
Organization type
a company within a holding
Joined
Dec 2023
Message
3
#12

Same here.

FFatma B***Member
Job title
Project manager
Sector
Media and publishing
Organization type
8-person team
Joined
May 2024
Message
164
#13

I'm in the same situation, that's why I'm asking. Forgotten test environments are more often the entry point than live systems.

If you post the result here, it will help others too.

GGökhan Ç***Member
Job title
Secretary
Sector
Catering
Organization type
medium-sized business
Joined
Jan 2023
Message
323
#14

ill try it.

BBurcu A***VeteranCommunity member
Joined
Apr 2024
Message
360
#15

I'm writing this so you don't make the same mistake. Taking notes for two weeks yields better results than a six-month estimate.

NNuri Y***ExpertCommunity member
Joined
Oct 2023
Message
246
#16

I partly agree, partly disagree. If it's your first time, start small; scaling comes later.

If I were you, I'd go this route.

PPolat M***MemberCommunity member
Joined
Nov 2025
Message
69
#17

My question might sound amateurish, sorry about that. If it's your first time, start small; scaling comes later.

YYavuz B***Member
Job title
Human Resources Specialist
Sector
Leather
Organization type
120-person company
Joined
Mar 2024
Message
5
#18

Saved.

EErcan C***MemberCommunity member
Joined
Sep 2024
Message
345
#19

Let me clarify the technical side. People defend habits, not processes. Resistance comes from there.

That's all, sorry if I went on too long.

TTuğçe C***Expert
Job title
Human Resources Specialist
Sector
Law
Organization type
40-person manufacturing company
Joined
Feb 2023
Message
185
#20

I felt relieved reading this answer, so it's not just me. Processes without records never improve, because you don't know what to fix.

Reply