The U Kapra guesthouse with 8 rooms in the Šumava region had for years a single shared WiFi password written on a piece of paper at the reception. Guests would photograph it and share it further: the password was effectively public. After switching to the voucher guest portal, each guest receives upon check-in a slip with a unique code valid for the duration of their stay. Access automatically expires after check-out. Reception generates a new voucher with one click in the controller, without technical knowledge. Guests appreciate the professional appearance of the portal featuring the guesthouse logo, and the operator has peace of mind regarding GDPR.
Guest WiFi portal, also known as a captive portal, is the page displayed to guests upon their first connection to the hotel's WiFi. Instead of direct internet access, guests must first pass through this portal by entering a password, confirming acceptance of the terms and conditions, or logging in via their room number. While it may seem like a minor detail, for both guests and hotel operators it is an important part of the overall experience.
In this guide we explain what a guest portal for hotel WiFi can do, how the setup works and what to watch out for.
Without a guest portal, guests either have unrestricted internet access (without any login) or must enter a WPA2 password, which is then shared in various ways, written down and remains valid long after the guest has departed. Both options have security and legal limitations.
The guest portal handles several tasks at once:
The UniFi guest portal (and managed WiFi portals in general) offers several ways for a guest to log in:
The simplest option: the guest enters a single shared password. Suitable for restaurants, cafés or smaller guesthouses where simplicity takes precedence over security. The password can be easily changed (daily, weekly) directly in the controller.
The reception generates single-use access codes with limited validity (e.g., for the duration of the stay). The guest receives a paper slip or a QR code. Upon departure, access expires automatically. This is the gold standard for hotels, every guest has their own unique code and records remain clear.
Advanced variant: the guest enters their room number and surname and logs in automatically, as the controller verifies the data in the property management system (PMS). Requires integration with systems such as Mews, Opera or Hestia. Suitable for larger hotels.
The guest logs in via a Facebook or Google account. Controversial from a GDPR perspective, if you collect data from social networks, you must have a clear legal basis. More suitable for restaurants and cafés where you want to build a fan base.
In the UniFi controller, create a new VLAN (e.g., VLAN 20) and a separate SSID for guests (e.g., "Hotel WiFi"). This network is isolated from the internal LAN, guests cannot see each other or access internal equipment.
In the WLAN profile settings, activate "Apply Guest Policy" and enable the portal in the Guest Control section. Select the login type (password, voucher, etc.) and set the session timeout (how long the login remains valid. We recommend 24 hours for hotels).
Upload the hotel logo, select colours (ideally matching the brandbook), add a welcome message and a link to the connection terms. The text field can be used for the restaurant's daily special or check-out information.
In the Voucher section, you can create templates: validity period (1 day, 1 week), number of devices per voucher (we recommend 3-5 for family rooms), and optionally a speed limit. Reception then prints or provides the code to the guest during check-in.
Connect to the Guest SSID using a mobile phone and complete the entire guest login process. Check that the portal works on iOS (Safari), Android (Chrome) and Windows, each browser behaves slightly differently during captive portal detection.
The portal will not display automatically after connection. The cause is usually incorrect DNS configuration on the guest VLAN: the controller must be set as the DNS server for this network. Alternatively, try visiting http://captive.apple.com (for iOS detection).
The portal works on mobile but not on a laptop. Windows and macOS use different captive portal detection mechanisms. Solution: ensure the portal URL is HTTP (not HTTPS) and the domain in the split DNS is correctly configured.
Guests complain that they have to log in again every day. Check the session timeout setting, by default it may be set to too short a duration. For hotels we recommend a timeout of 24 hours or the length of stay.
Configuring the guest portal in the UniFi controller is not complicated, but it requires access to the controller and network knowledge. If you operate managed WiFi via wifisprava.cz, we handle the entire guest portal setup for you, uploading your logo, configuring the voucher system, and testing from a guest's perspective. Any changes (new text, new logo, different colour) can be arranged by email.
The guest portal is your WiFi's calling card, but only if the WiFi works. The biggest risk for hotel and restaurant operators is a network outage, which they often discover last: from angry guests or poor reviews. In this article, we write about how to prevent outages and what to do in the first minutes of a crisis. WiFi outage in a hotel: prevention and emergency procedure.
If you are still considering whether to run the UniFi controller yourself or switch to managed hosting, read the detailed comparison in the article. UniFi controller hosting versus self-hosting.
As part of managed WiFi, we configure a custom guest portal. Voucher system, your colours and testing included.
Request a non-binding quote