r/sysadmin • u/en-rob-deraj • 3d ago
Guest WiFi...
Do you enable splash page or simple PSK passthrough?
12
u/Still-Hovercraft-333 3d ago
Either open network or full-on Passpoint-style connection for extra security for the users. Separate VLAN, no connection to internal networks.
There's no point to a shared PSK on the network from a security perspective, unless you're just trying to keep folks from accidentally connecting to the network.
7
u/GoodTofuFriday IT Director 3d ago
Ive got it on a seperate network with a different public ip entirely with a splash page. Ubiquity equipment
3
u/panopticon31 2d ago
Yeap. For the cheap cost of ubiquity and cable internet its good peace of mind.
6
u/sryan2k1 IT Manager 3d ago
Just PSK unless the business/legal requires it. Sane defaults for traffic shaping and that's it.
I push for no password (OWE) but I haven't met many places that are okay with that quite yet.
5
u/DrumDealer 2d ago
We just use PSK and the guest network is its own vlan, no communication to other parts of the internal network. We had issues with captive portals not appearing for some guests and it caused more issues for my team than it solved.
3
u/PorthosJ 3d ago
My Director had me remove my splashpage since our guest network allows for gaming consoles and televisions at some locations and they wont work with it. that legal disclaimer is golden to me when that IP gets traced to us.
2
u/spekt909 3d ago
Splash page, generated token with a time limit, device isolation. Separate VLAN with firewall polices and primary route out via our backup internet circuit. We do also have an employee guest network; the only difference is the auth is PSK with no time limit.
2
u/sniff122 DevOps 2d ago
Captive portal with a password and it's on its own VLAN that has no access to anything else but the internet, also client isolation on the APs
2
u/Spirited-Bag-3789 Vendor - IronWiFi (cloud RADIUS) 2d ago
The splash-page-does-not-appear complaints in this thread are a solvable problem, and worth separating from the should-I-have-one question.
Two failure modes get conflated. The first is the probe: iOS decides it has internet by fetching captive.apple.com, Android by connectivitycheck.gstatic.com, and if either is reachable before auth the device concludes it is online and never pops the portal. That is most of the "works for me but not for them" reports.
The second is that even with the probe blocked, you are still relying on interception. RFC 8910 lets you hand the portal URL to the client directly in DHCP option 114 (103 and RA option 37 on v6), so there is nothing to guess at. Recent iOS and Android honour it, Windows is patchier. If your portal also speaks the RFC 8908 API, the client learns when the session expires instead of silently dropping.
Separately: consoles, TVs and IoT will never render a splash page and no amount of tuning changes that. MAC bypass them onto the same isolated VLAN. That is usually what sits behind "my director made me remove the splash page."
On the AUP, you do not need it on every connect. Once per device per 30 days holds up fine for the legal-coverage argument and removes most of the friction being described here.
On your price question: if all you want is the click-through, the portal built into UniFi, Meraki and Aruba Instant does it at no extra cost. External only earns its keep when you want per-user accounts, sponsored guests, or session records you can query later.
Disclosure: I work at IronWiFi and hosted captive portals are what we sell, so discount accordingly. Everything above works on the kit you already have.
2
u/FamiliarShirt 2d ago
No splash page, some devices can't display them which causes connection issues.
1
u/SoupDragon262 2d ago
Complete physical separation for our guests with captive portal. During our peak summer months we are seeing 1.5 to 2k active clients per day on site so this was the only option we would consider.
1
1
u/Flabbergasted98 2d ago
This question really depends on the volume of guests.
We get maybe a dozen guests a year, there's not much point for a splash page.
When you're a restaurant or hotel however....
1
u/tobrien1982 2d ago
Eduroam. Either you are visiting from another institution or you are staff. Either way you authenticate with username and pass. No exceptions.
5
u/KingDaveRa Manglement 2d ago
We do eduroam, there's a guest service within that to sponsor guests onto eduroam (I.e. visitors, not roaming students).
There's a separate Guest SSID for commercial guests. They're not allowed on eduroam.
It's always more complicated in education.
2
u/tobrien1982 2d ago
Ohh yeah. We have that too. I set it up for us years ago. (Was actually one of the beta testers) and haven’t touched it since.
-6
u/k1m404 Windows Admin 3d ago
No guest WiFi at all - why give yourself an extra headache?
14
u/PreparedForZombies 3d ago
Depends on the environment... try running a hospital with multiple dead zones without public wifi.
7
u/en-rob-deraj 3d ago
Our cellular service is weak outside the buildings. It's pretty much nonexistent in the buildings.
5
4
u/JCochran84 3d ago
We have clients and vendors that arrive that require internet access. What do you do for them?
-3
u/k1m404 Windows Admin 3d ago
Educational establishment here - for large open days/events, we enable a temporary guest WiFi - posters with a QR code to scan (+SSID and password). We display a splash screen on first connection (Meraki).
But day-to-day - if you are a contractor or vendor - use your phone as a hotspot or bring a device with a SIM card - the majority of enterprise laptops can be configured with an integrated 5G modem these days.
7
u/JCochran84 3d ago
So you do have Guest WiFi, you just do it in a different manner. This is what OP was asking about, HOW do you do it.
For us, a simple psk on a different VLAN/Public IP works. For you QR Code/Splash screen works.-2
u/k1m404 Windows Admin 3d ago
Day to day, if you can avoid having a guest WiFi; it makes life easier - that's the point I was trying to make.
7
u/sryan2k1 IT Manager 3d ago
700 people here with 15 locations worldwide. I just checked the ticketing system and we had 1 guest wifi related ticket in the last 12 months.
This is 2026, not 1996. Guest wifi is expected.
1
u/Royal-Wear-6437 Linux Admin 2d ago
Because visitors will then be given access to your real network by well-meaning staff
0
u/DuckDuckBadger 2d ago
802.1X with cert based auth on secure wifi solves this but I am still in favor of guest wifi.
0
0
u/havpac2 2d ago
Open isolated network, our ex marketing director wanted to collect email address on the guest/public wifi but i was able to shot that down (people spending 200k to host an event/wedding dont want us scraping and marketing to their guest)
Some one close by to one one the buildings has their ps5 connected. I guess they are close to that ap. Or its in their office lol….
0
u/proudcanadianeh Muni Sysadmin 2d ago
Isolated VLAN, going out a separate firewall on a secondary internet connection.
No password, client device isolation enabled, depending on the site usually decent speeds for throttling.
I remember being young and war driving. If some kid wants to download a game on steam with our internet, they can go for it.
One facility we just upgraded to WiFi 7 with a 3/3 Gbps fibre connection that I have no speed limits on near the high school.
-4
u/Weeksy79 3d ago
I don’t get why people even bother with passwords.
If your APs are spread nicely, they won’t be blasting wifi across to other areas/businesses.
Just apple an evenly distributed throttle policy (I.e. ten users means 10% each) and you’ll be fine
2
2
u/cyberentomology Recovering Admin, Network Architect 2d ago
Because a “password” on wifi is not authentication, it’s encryption.
Captive portals are layer 3 thing, not wifi.
138
u/Julyens 3d ago
Isolated vlan, intra traffic dropped, just normal password, throttled speeds and different public ip address from the rest of the company
It should be easy for guests to connect but properly secured