Guest Wi-Fi, cameras and printers belong on their own network

By the NexusSec team · 5 min read · Published October 2026
Short version: Give guests their own SSID and VLAN with internet access only and client isolation on. Put cameras, recorders, attendance terminals and printers in an IoT zone that can reach only what each device needs, such as the recorder or the vendor's cloud. Change default passwords, remove port forwards, and route between these networks through the firewall rather than the core switch.

Walk around a typical office and count the devices nobody patches: the CCTV recorder, the biometric attendance terminal by the door, the networked printers, the meeting-room TV, the visitor's phone on Wi-Fi. They sit on the same network as the accounts PCs because that was the easiest place to plug them in. They are also the devices most likely to be running old firmware with a default password.

Why these devices are the soft spot

The Mirai botnet showed how this is exploited at scale: scan the internet for exposed devices, try the default passwords, recruit whatever answers. A device recruited that way, sitting on a flat office network, is also a foothold next to your servers.

Guest Wi-Fi: internet only

IoT: reach only what each device needs

DeviceNeeds to reachShould not reach
CCTV camerasThe recorder (NVR)Anything else, including the internet
CCTV recorderThe vendor's cloud service, if remote viewing is used; a time serverStaff devices and servers
Attendance terminalsThe attendance or HR server, or its cloud serviceEverything else
Printers and scannersThe print server; the mail relay or file share for scan-to-email or scan-to-folderThe internet, apart from firmware updates if you allow them
TVs and meeting-room displaysThe internet for casting and appsInternal networks

The pattern is the same each time: list what the device needs, allow exactly that from the IoT zone, and deny the rest. Staff who view cameras or manage the attendance system reach those devices from the staff zone through a specific rule. The devices themselves never open connections into the staff network.

Where cameras sit on their own PoE switch with the recorder, the cameras may not need to route anywhere at all. Only the recorder needs a rule.

Remote viewing without port forwarding

The usual way to view cameras from a phone is a port forward on the router to the recorder, which puts a rarely updated device directly on the internet. Two better options: the vendor's cloud service, which keeps the recorder making outbound connections only, or the company VPN with multi-factor authentication, so the recorder is reachable only by people who have signed in. Vendor cloud services have had vulnerabilities of their own, so keep firmware current either way. If a port forward to a recorder exists today, removing it is the first job.

Doing it without breaking anything

  1. Inventory first. The DHCP lease table on the firewall or server, plus a walk around the office, finds most devices. Note what each one talks to.
  2. Create the guest and IoT VLANs and zones, with rules that match the inventory.
  3. Move guest Wi-Fi first. It is a single SSID change and rarely breaks anything.
  4. Move IoT devices one type at a time, starting with printers, which are the easiest to test.
  5. Log before you block. Keep a logging catch-all rule on the IoT zone for a week, check what it caught, then make it a deny.
  6. Change default passwords as you go, and store the new ones in the password manager, not on a label on the device.

For the firewall side of this, see zones first; for why a flat network is the bigger risk, one laptop should not reach everything; and for how we carry it out, network segmentation and VLANs.

Frequently asked questions

Is a separate guest SSID enough?

Only if it is mapped to its own VLAN and the firewall blocks that VLAN from internal networks. An SSID with a different name on the same network separates nothing.

Our cameras need internet for the mobile app. Is that safe?

Allow the recorder, not each camera, to reach the vendor's cloud service, keep its firmware current, and remove any port forwarding. The cameras themselves usually only need to reach the recorder.

Can staff still print?

Yes. A rule from the staff zone to the printers on their printing ports keeps printing working, while the printers cannot open connections into the staff network.

Do we need new switches for this?

Usually not. Most managed switches and business access points support VLANs. Unmanaged switches cannot carry VLANs, so those are the parts that may need replacing.

Want the devices nobody patches off your business network?

We inventory what is connected, design the guest and IoT zones, and move devices in planned windows so nothing stops working.

Book a free consultation