Skip to Content
Segment · Corporate networks and IoT

Isolated guests and safe browsing at every site

Hospitals, bank branches, hotel chains, franchises and industrial warehouses: the guest network separated from medical records, POS, cameras and smart TVs, and the same policy at every site.

No commitment. The technical team answers.

What weighs on a network with many sites

Risks of a network with guests and devices

Little preparation for incidents

In healthcare, only 30% of facilities had an incident response plan in 2025. In primary care units, 14%.

Source: Cetic.br, TIC Saúde 2025 survey

A connected device is a way in

Research by Forescout points to routers as more than half of the devices with the most critical vulnerabilities, and to retail as the sector with the most vulnerable devices.

Source: Forescout, 2025, vendor research

Guest Wi-Fi and the LGPD (Brazil's data protection law)

A legal article argues that passive consent on a Wi-Fi portal is not a valid legal basis and that the venue is liable together with the platform.

Source: Migalhas, 2024, legal article

How it applies

How it applies to a corporate network

Separation happens at the access layer, and the policy is the same at every site.

01

Microsegmentation

VLAN per profile, assigned through 802.1X or by individual password (MPSK), isolating guests from medical records, POS, cameras and smart TVs.

02

Bandwidth for work

Streaming and services defined by the company can be blocked by service, without buying a new link.

03

Web filtering on the AP itself

Phishing, scams and threat domains stopped on the access point, without a separate web filter appliance.

04

Multi-site

Location hierarchy, replicated profiles and the fleet of every site in the same dashboard.

Visitors own VLAN, isolated from internal systems ACCESS POINT Built-in gateway decides by DNS, TLS/SNI and HTTP dropped at the AP Company network Internet NETEXPERIENCE DASHBOARD same policy at every site

Diagram of the path of a request on the guest network. Internal systems stay on another VLAN.

Questions for this segment

Can I see what each employee accesses?

The activity report is optional per profile. When on, it shows the domains accessed per device. Monitoring the employee network requires an internal policy and the awareness of its users, and this should be defined with your legal team.

Does it replace the firewall?

No. The gateway works at the Wi-Fi access layer. Firewall, endpoint protection and perimeter security are still needed.

Does it solve LGPD compliance?

It helps with one part: the separation between the guest network and the systems that hold personal data. LGPD compliance involves other measures the gateway does not cover.

Start with one site.

Tell us how many sites and how many points the network has. We return the design, the network separation and what would be blocked.