
“After a visitor connected to the Wi‑Fi, a printer icon popped up automatically on their phone. Out of curiosity, they tapped it, and 30 contracts with product quotations were printed out. That same afternoon, competitors obtained the quotation sheets.”
This is a real incident that happened at a technology company in Shenzhen. Where lay the root cause? The firm’s visitor Wi‑Fi shared the same network as the corporate office intranet with no isolation. Once visitors joined the Wi‑Fi, they gained an access pass to the internal network.
Handing over your visitor Wi‑Fi password is equivalent to giving the whole world a key to your intranet.
In Wi‑Fi environments without network isolation, visitors share the same network segment as employees after connecting. They can scan internal devices, access shared folders, and log into OA and other systems protected merely by internal IP addresses and simple passwords. More concerningly, you have no way of knowing whether the visitor’s mobile device carries malware, or if the previous password holder is still “piggybacking” on your network from a café downstairs.
Most enterprises deploy WPA2/WPA3 pre‑shared keys for visitor Wi‑Fi, using simple numeric combinations (e.g. 12345678) that remain unchanged for long periods and become broadly known. There is no automatic password invalidation mechanism after external visitors and on‑site partners leave, allowing outsiders to reconnect to the campus network at any time.
Visitor devices may already be infected with viruses that spread laterally to other equipment, host malicious applications designed for data theft, or enable file sharing and expose other networked devices.
Under the “password‑only internet access” model, businesses cannot record who accessed the network, when they connected, and what activities they performed. Without traceable records, companies face liability when inappropriate visitor speech is traced back to the corporate IP or legal notices arrive for illegal downloads. The Cybersecurity Law mandates network log retention of no less than six months. Without valid identity records and auditing mechanisms, enterprises are left vulnerable once security incidents occur.
Most businesses use a static universal Wi‑Fi password for all visitors. Passwords are simplistic and rarely updated. One password serves every user, making attribution impossible after security breaches.
While distinct SSIDs exist for staff and visitors, missing VLAN and ACL controls permit cross‑segment communication. This creates “superficial isolation with full underlying connectivity”. Visitors can still reach internal systems after joining the Wi‑Fi.
Traditional processes rely on handwritten paper registration at reception, which suffers from illegible entries, missing records and proxy filling, with no online identity validation. Complete logs covering visitor identity, access timeframes and browsing behaviour cannot be preserved, hindering human attribution following cyberattacks or data leaks.
The fatal flaws of legacy approaches fall into three categories: fully blended visitor and internal networks; isolated networks without user authentication; authenticated access without retained audit logs.
The core principle of AINOPOL’s integrated communication and encryption solution: enable visitors to go online, yet prevent them from reaching internal resources; maintain full records, while blocking all intranet access.
Through SSID‑VLAN binding, the all‑optical network delivers granular network segmentation and access control. The office SSID maps to VLAN100 for internal server and resource access; the visitor SSID is assigned to VLAN200, fully segregated from the corporate office network.
Visitor Wi‑Fi grants internet access exclusively, while internal devices remain completely invisible: visitors cannot scan IP addresses, open shared folders or reach OA platforms. Visitor and office networks are separated at the infrastructure layer to eliminate cross‑network risks.
After connecting to the visitor Wi‑Fi, users are redirected to a captive portal. Supported authentication methods include SMS verification (mobile numbers recorded for traceability), QR code authentication (linked to visitor registration data), and temporary account authentication (with configurable expiry such as same‑day invalidation).
Employee access to the office SSID uses robust authentication protocols including DingTalk/WeCom authentication and 802.1X. Dual authentication workflows clearly distinguish visitors from staff, supporting granular authorisation and auditing based on confirmed identities.
Legacy access control depended on limited switches, leaving blind spots for dumb terminals and visitor equipment. With an all‑optical architecture, access control is embedded alongside fibre links and ports rather than relying on standalone appliances. Security multi‑service gateways consolidate firewall, IPS, AV, behaviour auditing and real‑name authentication capabilities, closing management gaps caused by disjointed hardware deployments.
Visitor terminals are assigned to an independent VLAN with internet‑only connectivity. All requests targeting office and security networks are blocked per predefined policies. Every corporate workstation and mobile device must complete 802.1X identity authentication before gaining wired or wireless office network access. Invalid credentials block entry entirely.
Ministry of Public Security Order No.151 requires logs to be retained for a minimum of 180 days, with data protected against tampering, exportable and auditable. The all‑optical platform centrally collects and stores visitor internet logs, including real‑name information, login/logout timestamps, IP addresses, MAC addresses and visited URLs, with immutable data fields.
Prebuilt official compliance report templates support one‑click log export and standardised formatting, with integration available for real‑time reporting to network supervision platforms. Compliance reporting can be generated instantly during official inspections without last‑minute remediation.
Administrators configure custom lifecycles for temporary accounts (graded settings for 4‑hour validity, same‑day expiry or multi‑day on‑site contractors). After real‑name verification, the system generates time‑limited temporary network credentials. Once validity expires, network permissions are automatically revoked and accounts permanently deleted. When visitors leave, their access rights expire with them, eliminating lingering security loopholes from orphaned accounts.
Visitor networks represent an easily overlooked security weakness for enterprises. Outdated, coarse network designs carry substantial data leakage and compliance risks. AINOPOL’s integrated all‑optical communication and encryption solution creates a closed protection loop via VLAN isolation, mandatory real‑name verification, comprehensive auditing and time‑bound permissions. It fully seals intranet backdoors, delivering controllable, traceable, privilege‑restricted visitor internet access, streamlining compliance obligations and reinforcing the corporate intranet security perimeter.
Q: What specific requirements does the revised Cybersecurity Law impose on visitor internet access?
A: Businesses must verify users’ true identity information and prohibit anonymous access. Network logs must be retained for at least 180 days, with data protected against tampering, exportable and auditable. Violations may incur fines up to RMB 10 million for the organisation and RMB 1 million for directly responsible individuals.
Q: Do visitor accounts remain active after visitors leave?
A: The all‑optical network supports automatic account revocation. Administrators define custom validity periods; upon expiry, the system automatically withdraws network permissions and permanently deletes accounts with no manual removal required.