Help Center Help Articles Professional Support Professional Integrators Community RMA & Warranty Downloads Tech Specs

Best Practices: Guest WiFi

UniFi allows you to create a secure and efficient guest network with advanced features like traffic management, client isolation, and hotspot portals. Easily prevent unauthorized access, optimize performance, and customize your guest experience—all while maintaining control over your network.

Creating a Secure Public WiFi

With a public WiFi hotspot, it's critical to ensure that guest devices cannot communicate with one another or access other VLANs within your organization. To achieve a secure configuration:

  1. Navigate to Settings > Networks.
  2. Select or create a network.
  3. Enable Network Isolation to isolate this network/VLAN from all other networks/VLANs.
    1. For more customized firewall configuration, see our Firewall guide.
  4. Navigate to Settings > WiFi and select or create a WiFi.
  5. Assign the network from step (2) to the WiFi.
  6. (Optional) Enable Hotspot Portal if you want WiFi clients to authenticate through a captive portal. For more information, read our Hotspot Portal article.
  7. Enable Client Device Isolation to prevent communication between clients connected to the same AP.
  8. Enable Device Isolation (ACL) to complete client isolation at the switch level. For advanced customization, refer to our Switch ACL guide.

Maintaining Optimal Performance on Your Guest WiFi

Here are some techniques to ensure your guests enjoy a seamless WiFi experience while preserving the peak performance of your network’s operations.

Enable Proxy ARP to Reduce Network Congestion

Enabling Proxy ARP enables the AP to proxy DHCP and other common multicast traffic, reducing congestion and airtime utilization on large networks.

  1. Navigate to Settings > WiFi.
  2. Select the guest WiFi network.
  3. Enable Proxy ARP.

Set Appropriate Speed Limits

Though optional, applying speed limits to guest WiFi can help ensure fair bandwidth distribution and prevent guests from overloading your network.

Set appropriate speed limits by following the instructions here.

Block Non-Critical or Bandwidth-Intensive Applications

Restrict specific apps or entire app categories, like file transfers to prevent torrents and other bandwidth-intensive tasks from bogging down your network. To learn more, see Traffic Management.

Was this article helpful?