forumNew topic

Office guest network is open, no password — can customers see everything? How risky is the network traffic?

BBeyza K***Member
Job title
Field sales representative
Sector
Advertising and promotion
Organization type
two-branch business
Joined
Feb 2024
Message
6

Doki · Log management setup · 2026

#1

We have guest wifi in the office, we didn't set a password to keep it easy. When visitors or customers come, we say 'network is open, connect to the internet'. But today someone said they could see data transfer from another customer's computer — is this true? So, can't wifi networks see each other's computers?

Some of our clients carry company data, they're working on important projects. If someone sniffs the network, is there still a risk even if all protocols are TLS/SSL? Some programs use unencrypted http, those might be risky, right?

Should I split this wifi network into 'guest wifi' and 'employee wifi'? What do I need to do for the technical setup?

MMustafa E***MemberCommunity member
Joined
Feb 2024
Message
83
Most Helpful#2

On open wifi, devices on the same network can see each other (network discovery) and network traffic is sniffable. Even if HTTPS/TLS is encrypted, DNS queries, IP addresses, metadata etc. are still visible. Recommendations: 1) Put WPA2 with a pre-shared key on Guest Wi-Fi (at least 12 characters), 2) Do network segmentation: Guest VLAN should be completely separate from company VLAN. Make Guest VLAN unable to access company resources (Access Control List), 3) Put firewall rules on Guest WiFi (block ports 22, 3389, 445 etc.), 4) Put DNS filtering (malicious sites), 5) Encourage VPN tunneling (client VPN). 6) Keep WiFi AP logs. 7) Run a virus scan at specific times (clean network traffic). 8) Put bandwidth limiting (prevent guest network from slowing down the company). Setup: Managed switch, VLAN tagging, access point management interface.

NNurMember
Job title
Web Designer
Joined
Aug 2024
Message
96
#3

open wifi = risky obviously. everyone can see the network and do arp spoofing... at least put a password, WPA2 is a billion times better.. but and splitting the network setup is a bit complex but can be done, tp-link routers are variable speed...

AAyşe T***Member
Job title
Administrative manager
Sector
Plastic
Organization type
two-branch business
Joined
Jan 2023
Message
181
#4

If network segmentation is to be done: 1) VLAN configuration on Access Point (VLAN 1 = Guest, VLAN 2 = Corporate), 2) Inter-VLAN routing rules on Router/Switch, 3) Access Control List (ACL) rules: Guest → Corporate ports blocked. 4) Managed AP (meraki, ubiquiti etc.), unmanaged APs don't support VLAN. 5) RADIUS authentication with guest portal (Captive Portal). DNS, NTP traffic should even be separate or blocked. IDS (Suricata, Snort) can be used for sniffing detection but it's overkill for a small office.

İİsmail K***New member
Job title
Grocery
Organization type
medium-sized business
Joined
Dec 2024
Message
22

Doki · Log management setup · 2025

#5

don't do open wifi bro, put a password at least. the splitting thing is technical but it might be confusing for beginners — hire a netwwork admin it won't be done in 2 weeks. but if nothing has happened so far, putting a password quickly is very good. then when the admin starts, you do the network setup...

OOya B***MemberCommunity member
Joined
May 2023
Message
43
#6

Guest network segmentation best practices: 1) Separate SSID (ssid-guest), 2) Strong WPA2 Pre-shared Key, 3) VLAN isolation (no access from guest to corporate resources) 4) Web content filtering + DNS over HTTPS, 5) Rate limiting per client, 6) Portal page for terms and conditions, 7) Session timeout (8 hours) 8) Connection logs. Managed APs required (UniFi Meraki, Arista Instant On). Setup is tough at first but secure in the long run.

LLevent A***MemberCommunity member
Joined
Oct 2024
Message
40
#7

Are customers carrying company data on open wifi? Then that's their problem. But you can still protect yourself: encrypt the guest network, enable VPN at least make HTTP traffic HTTPS. Did you check if customers have antivirus installed on their computers? They're a risk too...

NNuri G***MemberCommunity member
Joined
Jun 2025
Message
158
#8

I've been in the IT sector for years, open wifi has zero security. An attacker on the same network (MITM, ARP spoofing, etc.) can see all unencrypted traffic. Industry standard: WPA2 enterprise + 802.1X authentication. But for SMEs, WPA2 personal + network segmentation is enough. Guest and corporate networks must be strictly separate.

MMerve K***Member
Job title
Supply chain manager
Sector
Retail
Organization type
a company within a holding
Joined
Apr 2025
Message
328

Doki · Infrastructure migration · 2026

#9

I agree and Id like to emphasize that... I mean if its your first time, start small; scaling comes later.

Hope this helps.

YYiğit E***Member
Job title
Customer service representative
Sector
Construction
Organization type
300-person organization
Joined
Mar 2023
Message
3

Doki · Brand identity · 2026

#10

You're right. When we decide without measuring, we always end up in the same place.

ZZerrin Y***Member
Job title
Production Manager
Sector
Retail
Organization type
family business
Joined
Oct 2022
Message
11
#11

Let me speak from the other side; I'm on the supplier side. Forgotten test environments are more often the entry point than live systems.

Security isn't absolute; it's about making attacks not worth the effort.

UUğur S***Member
Job title
Regional Manager
Sector
Chemistry
Organization type
sole proprietorship
Joined
Sep 2024
Message
22
#12

This is exactly what we experienced. When you try to change everything at once, nothing settles.

If I were you, I'd go this route.

NNuri Y***Expert
Job title
Store Manager
Sector
Leather
Organization type
300-person organization
Joined
Aug 2022
Message
95
#13

Just a heads-up... btw your time to detect an issue directly determines its cost.

Any unwritten clause becomes a point of disagreement later as both sides remember it differently. btw im also curious if anyone does it differently.

DDuyguMember
Job title
Market researcher
Joined
Jun 2024
Message
102
#14

I'm curious too.

YYavuz P***Veteran
Job title
Project manager
Sector
Freight
Organization type
sole proprietorship
Joined
Oct 2024
Message
35

Doki · Log management setup · 2023

#15

Great work. The harder it is to reverse a decision, the slower you should make it.

Good luck with that.

YYağmur T***MemberCommunity member
Joined
Jun 2024
Message
283
#16

I felt relieved reading this answer, so it's not just me. An untested backup is not a backup.

BBeyza K***Member
Job title
Store Manager
Sector
Electrical-electronics
Organization type
cooperative
Joined
Dec 2025
Message
165
#17

I'm writing this so you don't make the same mistake. like when you try to change everything at once nothing settles.

GGürkan Y***Member
Job title
Store associate
Sector
Plastic
Organization type
cooperative
Joined
Jan 2023
Message
213
#18

Exactly like that. Most incidents start with a leaked password not a vulnerability.

If I were you, I'd go this route.

HHasan K***MemberCommunity member
Joined
Apr 2023
Message
221
#19

Youre right.

KKader A***New member
Job title
Network Administrator
Sector
Consulting
Organization type
medium-sized business
Joined
Sep 2026
Message
10
#20

I've been dealing with this for a long time. If you scold false alarms, nobody will report again.

People defend habits, not processes. Resistance comes from there. Of course, it varies if your situation is different.

Reply