Start with a separate network
A dedicated VLAN or network creates the boundary on which routing and firewall policy can operate. Assigning a guest SSID to that network keeps guest addressing and policy separate from employee, point-of-sale, camera and management traffic.
Block traffic between trust zones
Network isolation or explicit firewall rules should prevent the guest network from reaching internal networks. Confirm required exceptions deliberately; avoid broad rules that quietly reopen access.
Client isolation solves a different problem
Network isolation blocks traffic toward other VLANs. Client-device isolation helps prevent guest devices on the same wireless network from communicating with one another. Ubiquiti documents access-point and switch-level controls because enforcement can occur at different layers.
Plan DNS, printing and casting exceptions
Guest users generally need DHCP, DNS and internet access. Shared printers, displays and casting systems require deliberate discovery and access rules; opening the whole trusted network to make one convenience feature work defeats the separation goal.
Test from both sides
Connect a real guest device and verify internet, DNS and captive-portal behavior. Attempt access to gateways, management interfaces, cameras, printers and representative trusted devices. Then verify trusted administration still works and document the intended exceptions.
Common questions
Is a separate SSID enough?
No. The SSID must map to a separate network or policy boundary if it is expected to isolate traffic.
What is client isolation?
It restricts communication between client devices on the guest network; it complements rather than replaces inter-network firewall policy.
Can guests use a shared printer?
Yes, but the exception should be limited to the required device and protocols instead of granting access to the full trusted network.
Primary references
Product features and interfaces change. Confirm current compatibility and documentation before designing or purchasing equipment.