Back to blog
Network & Infrastructure·

Guest WiFi Solutions for Offices in India: A Buyer's Guide

IT technician configuring a ceiling-mounted WiFi access point in a modern office reception area for guest WiFi

The visitor who asked for the WiFi password and got the whole network

In March 2025 a 90-person logistics firm off Old Airport Road handed a visiting courier their WiFi password. Standard stuff. The password was Logistics@2019, unchanged since the APs were installed, and it was still the same credential the finance team used for the shared drive.

The courier's phone had been compromised weeks earlier. Nothing dramatic — a sideloaded APK from a "free recharge" app. It sat on the guest SSID for six days, scanned the /24 subnet, found an unpatched Synology DS218+ with SMB open, and encrypted 1.4 TB of scanned POD documents and GST filings. The ransom note asked for 0.9 BTC. They paid a recovery firm ₹2.1 lakh instead, and lost eleven days of dispatch records.

The fix cost ₹78,000. A FortiGate 60F with a dedicated guest zone, a proper captive portal, and a separate SSID mapped to VLAN 40. That is the entire story. The expensive part was not the hardware. It was that nobody had drawn a line between "people who work here" and "people who visit."

If you are evaluating a guest WiFi solution for offices in India, that line is the product. Everything else — the portal, the OTP, the bandwidth cap — is how you enforce it.

What a guest WiFi solution actually consists of

A guest WiFi solution is not an access point. You probably already have access points. It is a set of five components that work together.

1. A separate SSID bound to a separate VLAN

The guest SSID broadcasts on the same hardware as your corporate SSID but terminates on a different VLAN. On the firewall, that VLAN is a zone with a default-deny policy. Guests can reach the internet. They cannot reach 10.0.1.0/24, they cannot reach the file server, they cannot reach the printers, and they cannot reach each other.

Client isolation (sometimes called AP isolation or peer-to-peer blocking) is the second half of this. Without it, guest device A can talk to guest device B. That is how a compromised phone becomes a compromised laptop becomes a compromised NAS.

2. A captive portal with an onboarding method

The captive portal is the web page that intercepts the first HTTP request and asks for something before granting access. The "something" is the design decision. The four options in practical use:

Onboarding methodHow it worksBest fitFriction level
Shared passwordReception gives out one passwordCafes, 5-10 guests/dayLowest, weakest
OTP to mobileGuest enters number, receives SMS OTPOffices with 10+ guests/day, DoT complianceMedium
Self-registration formGuest fills name, company, phone; staff approvesBFSI, healthcare, defence-adjacentMedium-high
Voucher / printed codeReception issues a printed code per visitTraining centres, co-working day passesLow

For most Indian offices between 20 and 500 staff, the OTP path is the right default. It gives you a verified mobile number attached to every session — which you need for legal reasons I will get to — without making reception staff into network administrators.

3. Bandwidth controls

Guests should never be able to degrade the network your team works on. Two controls matter:

  • Per-client rate limit. Typically 2-5 Mbps down, 1-2 Mbps up. Enough for video calls and cloud docs. Not enough for one person to saturate a 100 Mbps leased line with a torrent.
  • Aggregate guest cap. The guest VLAN as a whole gets a ceiling — commonly 20-30% of total WAN bandwidth during business hours.

On a FortiGate or a Sophos XGS this is set in the traffic shaping profile. On a UniFi Dream Machine Pro it is the WiFi network's bandwidth profile. The mechanism differs; the intent does not.

4. Logging and retention

The Licence to Provide Internet Services conditions in India require that internet access logs be retained for a defined period and produced on lawful request. Most articles about guest WiFi skip this entirely. It is the part that turns a technical project into a compliance one.

5. A lifecycle process

Who issues credentials? Who revokes them? What happens when a contractor's engagement ends but their phone still has a valid session? Without a stated process, your elegant technical setup decays into a shared password within eight months. I have watched it happen at three different client sites.

The DoT logging obligation most Indian offices ignore

Let me be blunt about this because it is the reason a significant share of our guest WiFi engagements start.

The Department of Telecommunications, through the Unified Licence and the Licence to Provide Internet Services, places logging and retention obligations on entities that provide internet access to users. The operative requirements, in plain language:

  • Subscriber records. Name, address, and for mobile-linked access, the verified mobile number.
  • Usage records. Connection logs, session start and end times, and the IP address allocated to each user.
  • Retention. Commonly cited as 12 months for subscriber records and 6-12 months for usage logs, though the exact figure depends on the specific licence condition and any directions in force. Confirm with your legal counsel — do not take a blog as the last word on a statutory retention period.
  • Production on demand. Logs must be retrievable in a usable format when lawfully requested.

Now here is the uncomfortable part. A shared password with no portal gives you zero of this. You cannot say who was on your network at 9:40 PM on a Tuesday, because you never knew. If someone uses your guest WiFi for something illegal, the trail ends at your ISP circuit and starts pointing at your company.

An OTP captive portal changes that. Every session is tied to a verified mobile number, a device MAC, and a timestamp. You have an audit trail. It is not airtight — a determined attacker uses a burner SIM — but it is a defensible record, and it is what the obligation asks for.

The DPDP Act overlap

Since the Digital Personal Data Protection Act came into force, collecting a guest's mobile number is processing personal data. You need a lawful basis (consent works), a stated purpose, and you should not keep the data longer than necessary. In practice: put a one-line notice on the captive portal saying what you collect, why, and how long you keep it. Our standard portal text is three sentences. It costs nothing and it prevents an awkward conversation.

Do not collect Aadhaar numbers. Do not collect ID scans unless you have a specific regulated reason to. A mobile number and a name are proportionate. A photocopy of a driving licence is not.

What this actually costs in India in 2026

Here is where most vendor conversations get vague. Below are the figures we quote for Bangalore deployments in 2026. These are supply-and-install numbers, inclusive of configuration, excluding GST at 18%.

Deployment sizeFirewall / gatewayAPsController / licensingTypical project costAnnual running cost
20-50 users, 1-2 APsFortiGate 60F or Sophos XGS 88Ubiquiti U6-Pro ×2FortiCare 1yr bundled₹45,000 – ₹70,000₹8,000 – ₹12,000
50-150 users, 4-8 APsFortiGate 90GUbiquiti U6-Pro or Aruba AP-515FortiCare + AP licences₹1,10,000 – ₹1,80,000₹18,000 – ₹30,000
150-300 users, 10-20 APsFortiGate 121G or Sophos XGS 2100Aruba AP-535 or Cisco C9130AXFortiCare UTP + Aruba Central₹2,60,000 – ₹4,20,000₹45,000 – ₹75,000
300-500 users, multi-floorFortiGate 201G or Palo Alto PA-450Aruba AP-635 (WiFi 6E)FortiCare + Aruba Central₹5,50,000 – ₹9,00,000₹85,000 – ₹1,40,000

A few notes on those numbers, because line items matter more than totals.

  • SMS gateway cost is separate. OTP delivery runs ₹0.15-₹0.35 per SMS depending on volume and provider. A 200-guest-per-month office spends ₹400-₹1,000 a year. Trivial, but it is a line item.
  • Cabling is often the surprise. If your existing APs are on Cat5e runs that were installed in 2014, WiFi 6 APs will be bottlenecked at the uplink. Re-pulling 8 drops in a Bangalore office runs ₹1,200-₹2,000 per drop for structured cabling, more if it involves core drilling through a concrete slab.
  • Licence renewal is the recurring sting. FortiGate UTP bundles renew at roughly 20-25% of hardware cost annually. Budget for it or your guest portal quietly stops receiving firmware updates.

If you want this scoped against your actual floor plan and headcount, that sits inside what we do under network solutions.

Where cheap actually works

I am not going to pretend every office needs an Aruba and a Palo Alto. A 30-person software shop with two floors and 15 guests a week does fine on a TP-Link Omada setup — EAP653 APs, an ER605 gateway, an OC200 controller. Total hardware under ₹35,000. The Omada captive portal supports OTP via an SMS gateway, and VLAN separation is straightforward.

It is the right answer when your guest count is low, your building does not have a hostile RF environment, and you have someone on staff who will actually open the controller UI twice a year. It is the wrong answer when you are in a WeWork-style shared floor with 40 other SSIDs and your APs are fighting for airtime.

Isolating guests from the corporate VLAN: the part people get wrong

"We put guests on a separate SSID." Good. Now show me the firewall policy.

I have audited dozens of SME networks in Bangalore and Karnataka. Roughly a third of them have a guest SSID that is on a separate subnet but has no inter-VLAN deny rule. The VLAN exists. The isolation does not. Guests can reach the corporate subnet because the Layer 3 switch routes between them by default.

The minimum rule set

On the firewall, your guest zone policy should look like this:

  1. Guest VLAN → Internet: ALLOW
  2. Guest VLAN → Corporate VLAN(s): DENY, logged
  3. Guest VLAN → Server VLAN: DENY, logged
  4. Guest VLAN → Management VLAN (switches, APs, iDRAC/iLO): DENY, logged
  5. Guest VLAN → Guest VLAN (intra-VLAN): DENY via client isolation on the AP/controller

Rule 4 is the one people forget. If a guest can reach your switch management interface on 10.0.0.2, they can change your port configs.

The DNS trap on guest networks

Guests need DNS. If you point them at your internal domain controller at 10.0.1.10, you have just handed them a map of your internal namespace. Advertise a public resolver on the guest VLAN — 1.1.1.1, 8.8.8.8, or your ISP's resolver. If you run a DNS filtering service like Cisco Umbrella or Cloudflare Gateway, give the guest VLAN its own policy profile with a looser category set, or you will spend your week unblocking conference-streaming sites for visitors.

The failure story that keeps coming up

A 140-person BFSI-adjacent firm in Bangalore's CBD had a guest network, a portal, and VLAN separation. What they did not have was a cap on the guest VLAN's DHCP scope. The scope was /24 — 254 addresses. During a two-day annual conference, 190 visitors connected. Combined with staff devices on the same floor's APs, the guest pool exhausted.

New guests got a 169.254 link-local address and no internet. The captive portal stopped loading. Reception started handing out the corporate WiFi password because guests were complaining, and that password had not changed in two years.

What fixed it: a /23 guest scope (510 addresses), a session timeout of 8 hours instead of 24, and a per-AP client limit of 40. Total cost, ₹0 in hardware. Three hours of a network engineer's time.

The lesson is not about DHCP. It is that a guest network under stress defaults back to the shared password unless the failure modes are designed out in advance.

Bandwidth caps: how to set them without getting complaints

The instinct when you first enable guest throttling is to be aggressive. Don't. A guest network that performs like 2011 3G generates more support calls than one that is slightly generous.

Our default starting points, refined across a few hundred deployments:

Guest profileDown / Up per clientSession timeoutIdle timeoutDaily data cap
Lobby / reception visitor5 / 2 Mbps4 hours15 min2 GB
Meeting room attendee10 / 5 Mbps8 hours30 min5 GB
Day-pass contractor10 / 10 Mbps10 hours30 min10 GB
Auditor / vendor on-site15 / 10 Mbps12 hours60 min20 GB

A few observations from running this in production:

  • 10 Mbps down is the practical floor for a video call. Below that, Teams and Zoom degrade to audio-only and someone complains. If your leased line is a 100 Mbps connection shared with 80 staff, you cannot afford to give guests more than 5 Mbps each without QoS on the corporate side.
  • Session timeouts are more effective than data caps. A 24-hour session on a laptop that sits in a meeting room all day is a session you are not logging properly. Force re-authentication.
  • Do not throttle DNS or NTP. It sounds obvious. We have seen traffic shaping profiles that inadvertently rate-limited UDP 53 and made every guest page load feel broken.

If your office has a 1 Gbps fibre circuit from ACT or Airtel, the arithmetic is easier. If you are on a 100 Mbps leased line from Tata or BSNL, guest traffic is real competition for your team's bandwidth and you should be explicit with the business about that trade-off.

Building the captive portal: OTP without the pain

The onboarding flow that works, in order:

  1. Guest connects to CompanyName-Guest.
  2. Captive portal loads. Three fields: name, mobile number, company (optional).
  3. Guest taps "Send OTP." An SMS arrives in 5-15 seconds.
  4. Guest enters the 6-digit OTP. Portal validates, allocates an IP, starts the session timer.
  5. Portal shows a "Connected" page with the acceptable-use line and your data retention notice.

The authentication backend can sit on the firewall itself (FortiGate supports this natively via FortiGuard SMS or a custom SMS gateway), on the controller (Aruba Central, Cisco Meraki), or on a dedicated portal appliance. For multi-site offices, a centralised portal with a shared guest database is worth the extra complexity — guests who visited your Whitefield office do not need to re-register at your Koramangala one.

Getting the SMS gateway right in India is where most deployments stumble. You need a DLT-registered sender ID and templates approved on the TRAI DLT portal. That approval takes 3-7 working days and cannot be rushed. If you are planning a guest WiFi rollout for a specific date, start the DLT registration a fortnight ahead of the install.

There is also a fallback decision to make: what happens when the SMS does not arrive? Options are a reception-issued voucher code, an approved-device allowlist, or a plain backup password with a 24-hour rotation. Pick one and train reception on it. "Sorry, the OTP system is down" is not a guest experience.

Choosing hardware: what to buy and what to skip

Some honest opinions, shaped by what we install and what we get called to fix.

Firewalls

  • FortiGate 60F / 70F / 90G. The default SME choice. Captive portal, traffic shaping, logging, and SD-WAN in one box. FortiGate 60F handles 10 Gbps firewall throughput, 700 Mbps threat-protected. For a 50-user office, it is more than enough. Street price in Bangalore around ₹42,000-₹52,000 for the 60F.
  • Sophos XGS 88 / 2100. Good alternative if you are already on Sophos Central for endpoint. The XGS 88 runs around ₹48,000-₹58,000.
  • Cisco Meraki MX68 / MX85. Excellent cloud management, genuinely simple guest portal. The licensing will cost you more than the hardware over five years. If you have not already standardised on Meraki, the total cost of ownership is hard to justify for an SME.
  • pfSense / OPNsense on a Dell R250. Perfectly capable for a technical team. No support contract, no vendor hand-holding, and if the person who configured it leaves, you have a problem. I like it for the right customer and would not deploy it for most.

Access points

  • Ubiquiti U6-Pro (₹16,000-₹19,000 each). The best value in the Indian market right now. WiFi 6, PoE, cloud-managed via a UniFi controller. Reliability has improved markedly over the UAP-AC-Pro generation.
  • Aruba AP-515 / AP-535. Better for high-density spaces. Instant On is the SME line; the full Aruba line with Central management suits larger campuses. AP-515 runs ₹32,000-₹38,000.
  • Cisco Catalyst 9130AX. Excellent hardware, expensive, and the licensing adds up. Justified only when you have campus-wide Cisco already.
  • TP-Link Omada EAP653. Around ₹7,500. Fine for a small office. Not fine for a 200-person open-plan floor with 60 devices per AP.

The controller question

For 1-3 APs in a small office, run them controllerless or use the vendor's cloud dashboard. For 5+ APs across multiple floors, a controller is not optional — you need centralised SSID config, roaming, and one place to manage the guest portal. Options range from a physical OC200 (₹6,500) to Aruba Central (subscription, roughly ₹4,000-₹6,000 per AP per year) to Meraki's bundled cloud.

The Bangalore operating reality

A few things that come up specifically here, because they affect guest WiFi projects in ways that do not apply in, say, Pune or Chennai.

ISP lead times vary wildly. An Airtel or ACT business circuit in Bangalore takes 7-15 working days for a standard address. A BSNL leased line can stretch to 4-6 weeks. If your guest WiFi rollout depends on a new internet circuit, order the circuit before you order the firewall, not after.

Power reliability is not what it was, but it is not what you want it to be. Most Bangalore offices in Grade-A buildings survive power events on UPS. The UPS needs to cover the firewall, the core switch, and the APs on the guest VLAN — not just the servers in the rack. A 60-minute runtime on a 1 kVA APC Smart-UPS is the minimum sensible spec.

Monsoon is a cabling issue. June through September, we get calls about APs dropping on outdoor-facing floors. Water ingress into the patch panel, or an outdoor Cat6 run that was never designed for it. If you are cabling any external-facing AP, specify outdoor-rated cable and inject the run from an indoor patch point.

GST treatment is straightforward. Hardware and services attract 18% GST. If you are GST-registered, it is input credit. If you are not, it is just a cost. Do not let a vendor quote you an "all-inclusive" figure without showing the GST line — it makes comparison impossible.

CERT-In directions apply to logs. The 2022 CERT-In directions require organisations to maintain ICT system logs for 180 days and report specified incidents within 6 hours. Guest WiFi logs sit inside that perimeter. If you have a CERT-In-adjacent obligation — and any firm with a regulated client should assume it does — your guest logging retention needs to meet the 180-day floor at minimum, and your incident response plan needs to contemplate a guest-network event.

Where a managed approach makes sense (and where it does not)

A guest WiFi deployment is a project. A guest WiFi service is a promise that the portal stays up, the logs get retained, and the firmware gets updated. These are not the same purchase and are priced differently.

A managed guest WiFi service at SynergyScape typically runs ₹4,000-₹9,000 per month for a single-site office of 50-150 users, covering firewall management, portal uptime, log retention, and incident response. It is not the right answer for every office.

It is the wrong answer when:

  • You have an in-house network engineer who knows the FortiGate console better than we do. Keep them. Buy the hardware from us if you like and manage it yourself.
  • Your guest count is under 5 per day and you are happy with a voucher system. The management overhead does not justify the fee.
  • You are on a Meraki stack and already comfortable with the dashboard. Meraki's guest portal is genuinely good and there is little we add.

It is the right answer when:

  • You have 15+ guests a day and no one internally to own the portal.
  • You have a DoT or CERT-In obligation but no logging process to prove you are meeting it.
  • You are multi-site and need a consistent guest experience across locations.
  • You have had a guest-related incident and no one can tell you what actually happened.

We run this work under our network solutions practice, and the scoping conversation starts with your headcount, your guest volume, and your current firewall.

Frequently asked questions

How much does a guest WiFi solution cost for an office in India?

For a 50-user office in 2026, budget ₹1,10,000-₹1,80,000 for the full deployment — firewall, APs, licences, captive portal setup, and installation — excluding GST at 18%. Annual running costs sit at ₹18,000-₹30,000 for support and licence renewals. Small offices under 30 staff can deploy for ₹45,000-₹70,000 using Omada or UniFi hardware.

Is a captive portal with OTP mandatory for guest WiFi in India?

No specific rule mandates OTP. What the DoT licence conditions require is that internet access logs are retained and can be produced on request. An OTP portal is the most practical way to satisfy this because it attaches a verified mobile number to every session. A shared password gives you no attribution and is functionally non-compliant if you are providing internet access to the public or visitors.

Can a guest on our WiFi see the corporate network?

Only if your firewall policy lets them. A correctly configured guest VLAN has a default-deny rule against all corporate subnets, server VLANs, and the management VLAN. Client isolation should also be enabled so guests cannot reach each other. If you have a separate SSID but no firewall rule, assume guests can reach everything.

What is a reasonable bandwidth cap for guest WiFi?

5 Mbps down and 2 Mbps up per client for lobby visitors, up to 15/10 Mbps for on-site auditors and vendors. Cap the guest VLAN at 20-30% of your total WAN bandwidth during business hours. Anything below 3 Mbps starts breaking video calls and generating complaints.

How long do we have to keep guest WiFi logs in India?

DoT licence conditions generally cite retention periods in the range of 6-12 months for usage logs and 12 months for subscriber records, and CERT-In's 2022 directions require 180 days for ICT logs. Practical advice: retain guest session logs for 12 months and mobile numbers for 6 months after the last visit, and confirm the exact periods with your legal counsel.

Do we need consent to collect a guest's mobile number?

Yes, under the DPDP Act. The captive portal should display a one-line notice stating what you collect, why, and how long you retain it, and the guest should actively opt in to proceed. Keep the data set minimal — name and mobile number is proportionate. ID scans and Aadhaar numbers are not.

Do this before your next visitor arrives

If you take nothing else from this: check whether your guest SSID is actually isolated. Log into the firewall, look for the inter-VLAN policy, and confirm there is a deny rule between the guest zone and every corporate subnet. If you find three rules and none of them say DENY, you have a problem you can fix this afternoon.

If you would rather someone else did the audit, call us. We will look at your existing firewall config, your AP placement, your logging setup, and your DLT registration status, and tell you plainly what needs to change and what does not. Reach the team at synergyscape.co.in/contact.