If you have a wireless network and your friend brings over his
computer, how do you let them on your network as a guest without giving
out your wireless encryption key?
Time for my most popular … no, my most common, answer:
It depends.
It depends on how much you trust your friend.
And since you don’t want to share your wireless encryption key, I’m
going to assume that while you probably trust your friend to a point,
there’s clearly a limit.
]]>
<
Here you can see that the router on the left, your existing router I might add, continues to use a WPA key for wireless encryption. The router on the right is dedicated to your guests use, and can either be a completely open (no encryption, no key needed) hotspot that anyone can connect to, or you can set it up to use a different WPA key that you don’t mind sharing with your guests.
Using this setup, the two separate networks are isolated from each other. Neither can “sniff” the other’s traffic, and neither can access the other’s machines.
For the record, this is what I have in my own home: a private wireless network secured by WPA, and then a separate guest network that is open to anyone within range.
And as a fairly interesting side note, we are starting to see equipment that effectively bundles the equivalent of two routers and wireless access points into a single box, for exactly this scenario.
Now, there’s one final gotcha, that is once again a matter of trust.
Remember that your guest is using your internet connection. If they happen to do something, say, illegal … it can be traced by law enforcement, and that trace would lead to you as the owner of that connection. I’m guessing at that point you’d have some explaining to do.
Choose your friends, and your guests, wisely.


Well-explained, Leo. Instead of “additional” hardware, for simplicity I would suggest “replacement” hardware.
Apple truly solved this problem in a very simple way. Guest networking in any new Airport Extreme. Two SSIDs, two separate networks, one device. Brilliant. Done right.
Why not just use MAC address filtering on your wireless router. Just add the friend’s MAC address to the list of allowed addresses. No WEP/WPA needed.
17-Apr-2009
Craig – MAC address can easily be spoofed to connect. And without WPA, all traffic between the PCs and router can be openly read by a listener.
Rahul: Yes, but to spoof a MAC address someone first needs to find a valid MAC address to use.
And your traffic between PCs that are connected via ethernet cable isn’t encrypted either.
And data on your ethernet cable isn’t being broadcast to a 300 ft radius of your wireless connection. 🙂
17-Apr-2009
Leo: thanks for clarifying the pitfall of MAC address filtering.
And point taken about WiFI being broadcast, but the discussion was in the context of allowing friends onto your LAN.
19-Apr-2009
Thanks for that info, Leo. May I ask what to look for to obtain a hub/switch.
I have a DSL Router. The original one died and the computer store people (Best Buy) suggested I replace it with another one from Verizon. It still uses WEP and can’t, apparently, use WPA. As a DSL user are we stuck with old technology? What about FIOS fiber optic? If its router dies, can you buy a better one?
22-Apr-2009
I have a wireless gateway with four ports at the back, so if a friend brings over a notebook or whatever I just hook it up with a length of network cable. Much easier and quicker than configuring the wireless connection.
In scenario 2, would it be possible to use a G- series router for the guests’ usage without it affecting my encrypted N-series router? I remember reading previously that older router versions (ie G-series) can negatively affect the performance of newer ones. What effect can this have on wireless performance?