A retail chain wants to let customers join a guest WLAN without sharing the corporate preshared key, while still keeping guest traffic isolated from point-of-sale systems. Which design best meets these requirements?
A distinct guest SSID bound to its own VLAN keeps guest traffic on a segmented broadcast domain, and client isolation prevents guests from reaching each other. With no routing or ACL permitting access to internal subnets, point-of-sale systems stay unreachable. This satisfies open or captive-portal guest access without distributing the corporate preshared key, which remains protected for internal users.
Why this answer
Guest access is best delivered on its own SSID mapped to a segmented VLAN with client isolation and no internal routing. This keeps the corporate preshared key private, prevents guest-to-guest and guest-to-internal access, and protects point-of-sale systems through network segmentation rather than relying on the guest credential.