PEPLINK UNIVERSITY  •  A WEST NETWORKS TRAINING RESOURCE (352) 316-7701  ·  SHOP PEPLINK →

Client Isolation on Guest Wi-Fi (Layer 2 Isolation)

Stop guest Wi-Fi clients from seeing each other or your network: Layer 2 Isolation, its own VLAN, Guest Protect and a firewall rule, in InControl or the Balance UI, with a test plan.

A guest network has one job: internet for people you do not trust, without letting them touch each other or anything of yours. Peplink does it with four settings that take about five minutes — Layer 2 Isolation on the SSID, the SSID on its own VLAN, Guest Protect, and one firewall rule as belt and braces.

Why four layers

Layer 2 Isolation (the “client isolation” checkbox) makes the access point refuse to forward frames between wireless clients on that SSID — no ping, no discovery, no AirDrop, no lateral movement. It is enforced per AP at layer 2, so on its own it does not stop a guest routing to your staff subnet, and it does not cover wired devices. The VLAN gives guests their own subnet and DHCP; Guest Protect blocks the route to every private network; the firewall rule catches whatever is left.

Steps — InControl (whole fleet at once)

  1. Create the guest VLAN. Group › Network Settings › VLAN (or Device › Network › LAN): add a network named Guest with its own VLAN ID, subnet and DHCP. Turn Inter-VLAN routing off for it. See Grouped Networks, VLANs & LAN.
  2. Open the guest SSID. Group › Wi-Fi AP › SSID Settings (or Organization › Wi-Fi AP for an org-wide guest SSID) › click the SSID, or Add new SSID. Security Policy WPA2/WPA3 – Personal with a posted passphrase, or Open plus a captive portal.
  3. Tick Layer 2 Isolation. Under Security Settings, enable Layer 2 Isolation. Leave Fast Transition off on a guest SSID — nothing roams that needs it and some client devices dislike 802.11r.
  4. Guest Protect. Enable Block All Private IP and Block SpeedFusion VPN. If guests must reach exactly one internal thing (a lobby printer, the portal server), add it under Block Exception — and nothing else.
  5. VLAN Tagging. Set it to the guest VLAN from step 1. If the SSID is served by AP One access points, the switch ports feeding them must trunk that VLAN — with a Peplink switch under the switch controller or InControl it is pushed for you.
  6. Belt and braces. Group › Firewall › Internal Network rule: source Guest VLAN → destination any other LAN, Deny. Optional hardening while you are on the form: Band Steering Prefer, a per-radio client cap, Management Frame Protection Optional, a schedule for after-hours, and a bandwidth cap on the guest group so guests can never starve the business.
  7. Save. Save Changes pushes it to every tagged device in the group; the SSID table now shows the guest SSID with its VLAN ID.

Steps — Balance / MAX local web admin

  1. Network › LAN › New Network: Guest VLAN, own subnet, DHCP on, Inter-VLAN routing off.
  2. AP › Wireless SSID › open (or add) the guest SSID. Security Settings › Layer 2 Isolation: Enable.
  3. Guest Protect › Block All Private IP + Block SpeedFusion VPN. VLAN › the Guest network.
  4. Network › Firewall › Internal Network: Guest → any LAN, Deny. Apply Changes.

Test it before you walk away

  • Two phones on the guest SSID: neither can ping the other, and casting / AirDrop / file-sharing discovery finds nothing. Internet works on both.
  • From a guest phone, browse to the router’s LAN IP and to a staff-VLAN address: both fail. From the staff SSID everything works as before.
  • InControl › Clients (or the router’s client list) shows both phones on the Guest VLAN with the guest SSID.
  • If the site has SpeedFusion tunnels, try a head-office address from the guest phone: it must fail.

Tip

Do this at the group level and the whole fleet gets it in one save; make the guest SSID organization-wide and every new site opens with guest isolation already in place. Every other field on the SSID form is explained in the SSID settings reference.

Payments next door?

If the same hardware carries point-of-sale devices, pair this recipe with Prioritize POS over Guest Wi-Fi and the PCI DSS hardening guide — guest isolation is the first thing an assessor checks.