商务支持

技术支持

About Guangxun

关于光迅

Can Visitors Breach the Intranet to Steal Data? How All‑Optical Networks Ensure “No Access Even After Connection”
2026-08-22 14:28:55 17

Can Visitors Breach the Intranet to Steal Data? How All‑Optical Networks Ensure “No Access Even After Connection”

“After a visitor connected to the Wi‑Fi, a printer icon popped up automatically on their phone. Out of curiosity, they tapped it, and 30 contracts with product quotations were printed out. That same afternoon, competitors obtained the quotation sheets.”

This is a real incident that happened at a technology company in Shenzhen. Where lay the root cause? The firm’s visitor Wi‑Fi shared the same network as the corporate office intranet with no isolation. Once visitors joined the Wi‑Fi, they gained an access pass to the internal network.

Handing over your visitor Wi‑Fi password is equivalent to giving the whole world a key to your intranet.

I. Visitor Networks Are Becoming Backdoors to the Intranet

Unauthorised intranet access by visitors

In Wi‑Fi environments without network isolation, visitors share the same network segment as employees after connecting. They can scan internal devices, access shared folders, and log into OA and other systems protected merely by internal IP addresses and simple passwords. More concerningly, you have no way of knowing whether the visitor’s mobile device carries malware, or if the previous password holder is still “piggybacking” on your network from a café downstairs.

Weak passwords widely shared

Most enterprises deploy WPA2/WPA3 pre‑shared keys for visitor Wi‑Fi, using simple numeric combinations (e.g. 12345678) that remain unchanged for long periods and become broadly known. There is no automatic password invalidation mechanism after external visitors and on‑site partners leave, allowing outsiders to reconnect to the campus network at any time.

Uncontrollable security posture of visitor endpoints

Visitor devices may already be infected with viruses that spread laterally to other equipment, host malicious applications designed for data theft, or enable file sharing and expose other networked devices.

Lack of identity logging and behaviour auditing

Under the “password‑only internet access” model, businesses cannot record who accessed the network, when they connected, and what activities they performed. Without traceable records, companies face liability when inappropriate visitor speech is traced back to the corporate IP or legal notices arrive for illegal downloads. The Cybersecurity Law mandates network log retention of no less than six months. Without valid identity records and auditing mechanisms, enterprises are left vulnerable once security incidents occur.

II. Why Traditional Solutions Fail to Govern Visitor Access

A single shared password posted at reception

Most businesses use a static universal Wi‑Fi password for all visitors. Passwords are simplistic and rarely updated. One password serves every user, making attribution impossible after security breaches.

Separate visitor SSIDs without underlying VLAN isolation

While distinct SSIDs exist for staff and visitors, missing VLAN and ACL controls permit cross‑segment communication. This creates “superficial isolation with full underlying connectivity”. Visitors can still reach internal systems after joining the Wi‑Fi.

No real‑name verification workflow

Traditional processes rely on handwritten paper registration at reception, which suffers from illegible entries, missing records and proxy filling, with no online identity validation. Complete logs covering visitor identity, access timeframes and browsing behaviour cannot be preserved, hindering human attribution following cyberattacks or data leaks.

The fatal flaws of legacy approaches fall into three categories: fully blended visitor and internal networks; isolated networks without user authentication; authenticated access without retained audit logs.

III. How All‑Optical Networks Achieve “No Access Even After Connection”

The core principle of AINOPOL’s integrated communication and encryption solution: enable visitors to go online, yet prevent them from reaching internal resources; maintain full records, while blocking all intranet access.

VLAN isolation: separate traffic lanes for visitors and employees

Through SSID‑VLAN binding, the all‑optical network delivers granular network segmentation and access control. The office SSID maps to VLAN100 for internal server and resource access; the visitor SSID is assigned to VLAN200, fully segregated from the corporate office network.

Visitor Wi‑Fi grants internet access exclusively, while internal devices remain completely invisible: visitors cannot scan IP addresses, open shared folders or reach OA platforms. Visitor and office networks are separated at the infrastructure layer to eliminate cross‑network risks.

Real‑name authentication for traceable user activity

After connecting to the visitor Wi‑Fi, users are redirected to a captive portal. Supported authentication methods include SMS verification (mobile numbers recorded for traceability), QR code authentication (linked to visitor registration data), and temporary account authentication (with configurable expiry such as same‑day invalidation).

Employee access to the office SSID uses robust authentication protocols including DingTalk/WeCom authentication and 802.1X. Dual authentication workflows clearly distinguish visitors from staff, supporting granular authorisation and auditing based on confirmed identities.

Instant detection of unknown connected devices

Legacy access control depended on limited switches, leaving blind spots for dumb terminals and visitor equipment. With an all‑optical architecture, access control is embedded alongside fibre links and ports rather than relying on standalone appliances. Security multi‑service gateways consolidate firewall, IPS, AV, behaviour auditing and real‑name authentication capabilities, closing management gaps caused by disjointed hardware deployments.

Visitor terminals are assigned to an independent VLAN with internet‑only connectivity. All requests targeting office and security networks are blocked per predefined policies. Every corporate workstation and mobile device must complete 802.1X identity authentication before gaining wired or wireless office network access. Invalid credentials block entry entirely.

Full log retention for 180 days

Ministry of Public Security Order No.151 requires logs to be retained for a minimum of 180 days, with data protected against tampering, exportable and auditable. The all‑optical platform centrally collects and stores visitor internet logs, including real‑name information, login/logout timestamps, IP addresses, MAC addresses and visited URLs, with immutable data fields.

Prebuilt official compliance report templates support one‑click log export and standardised formatting, with integration available for real‑time reporting to network supervision platforms. Compliance reporting can be generated instantly during official inspections without last‑minute remediation.

Automatic account revocation

Administrators configure custom lifecycles for temporary accounts (graded settings for 4‑hour validity, same‑day expiry or multi‑day on‑site contractors). After real‑name verification, the system generates time‑limited temporary network credentials. Once validity expires, network permissions are automatically revoked and accounts permanently deleted. When visitors leave, their access rights expire with them, eliminating lingering security loopholes from orphaned accounts.

Visitor networks represent an easily overlooked security weakness for enterprises. Outdated, coarse network designs carry substantial data leakage and compliance risks. AINOPOL’s integrated all‑optical communication and encryption solution creates a closed protection loop via VLAN isolation, mandatory real‑name verification, comprehensive auditing and time‑bound permissions. It fully seals intranet backdoors, delivering controllable, traceable, privilege‑restricted visitor internet access, streamlining compliance obligations and reinforcing the corporate intranet security perimeter.

FAQ

Q: What specific requirements does the revised Cybersecurity Law impose on visitor internet access?
A: Businesses must verify users’ true identity information and prohibit anonymous access. Network logs must be retained for at least 180 days, with data protected against tampering, exportable and auditable. Violations may incur fines up to RMB 10 million for the organisation and RMB 1 million for directly responsible individuals.

Q: Do visitor accounts remain active after visitors leave?
A: The all‑optical network supports automatic account revocation. Administrators define custom validity periods; upon expiry, the system automatically withdraws network permissions and permanently deletes accounts with no manual removal required.