A guest WiFi installation is not complete when the SSID appears and one phone connects. The venue operator also needs a clear record of what was built, how it is protected, and what to check when guests report a problem.
Use this checklist when handing over a UniFi guest WiFi deployment.
1. Document the deployment
Record:
- UniFi Console or Network application owner
- Site name and location
- Guest SSID name
- Guest network or VLAN ID
- Gateway and DHCP ownership
- AP names and physical locations
- Switches and uplinks carrying the guest VLAN
- Portal, voucher, RADIUS, or external-authentication method
- Internet connection and support-provider details
- Date of handover and software versions
Ubiquiti notes that the required VLAN must be carried across the network path between the gateway and APs; incorrect tagging can prevent clients from connecting. (help.ui.com)
2. Explain the security boundaries
The handover should state explicitly what guests can and cannot reach.
Document whether the deployment uses:
- Network Isolation or zone-based firewall policies
- Switch-level Device Isolation or ACLs
- AP-level Client Device Isolation
- Guest bandwidth or application controls
- Any approved exceptions for printing, casting, or other services
These controls operate at different layers. Gateway isolation controls traffic between networks, switch ACLs can restrict traffic within or between VLANs, and Client Device Isolation restricts communication between clients associated with an AP. (help.ui.com)
Include the result of an isolation test with two guest devices and one representative internal resource.
3. Provide an operator runbook
Keep the first-line procedure short:
- Confirm the guest SSID is enabled.
- Check whether the affected AP is online.
- Check whether the client receives an IP address.
- Check the client’s signal strength and AP association.
- Test another device to identify device-specific issues.
- Record the time, location, device, and symptom before escalating.
Give the operator a named escalation path and specify which changes they should not make without support.
4. Include normal operating baselines
Record representative observations from the handover:
- Typical client signal strength by area
- Expected AP coverage zones
- Normal internet test results, if measured
- Typical number of guest clients
- Known weak-coverage locations
- Expected roaming behavior
- Any bandwidth limits or scheduled policies
Ubiquiti’s current troubleshooting guidance recommends reviewing client signal, airtime, interference, retries, and channel congestion. Its tools include WiFi Agent, AirView, Client Inspector, and Environment views. (help.ui.com)
These observations are baselines, not guarantees. Venue occupancy, nearby networks, building changes, and client devices can change performance.
5. Record supported changes
Tell the operator which settings are safe to request or change through the support process. Examples include:
- Guest SSID name or branding
- AP broadcast scope
- Guest speed limits
- Portal content or authentication settings
- Temporary guest-network shutdown
- Adding or removing an AP from the guest SSID
Also record settings that require testing after modification, such as roaming thresholds, channel plans, firewall rules, VLAN assignments, and client-isolation exceptions.
Ubiquiti warns that poorly tuned Minimum RSSI settings can repeatedly disconnect clients, so such changes should be validated rather than copied blindly across APs. (help.ui.com)
6. Hand over credentials securely
Do not put administrator passwords or API keys in an ordinary handover document.
Instead:
- Transfer ownership through the appropriate account process.
- Use individual administrator accounts where possible.
- Record who has administrative access.
- Store API credentials in a secure secrets manager.
- Remove temporary installer access when the engagement ends.
- Confirm backups and recovery ownership.
The document should identify where credentials are managed, not expose the credentials themselves.
7. Include the test evidence
Attach or link to:
- Guest connection test
- VLAN and IP-assignment result
- Guest-to-internal isolation result
- Guest-to-guest isolation result, if enabled
- Portal or authentication result, if configured
- Coverage or walk-test notes
- AP and switch inventory
- Known limitations and open issues
A short evidence log is more useful than a statement that the system was “tested.”
8. Give the operator a change-control rule
Every future change should record:
- What changed
- Who approved it
- Which site, SSID, VLAN, AP, or policy was affected
- Why it changed
- What was tested afterward
- How to reverse it
This is especially important when a venue adds APs, changes switches, introduces a new VLAN, or modifies guest authentication.
Handover acceptance checklist
- Network diagram or topology reference supplied
- Guest SSID and VLAN documented
- AP locations and broadcast scope documented
- Isolation boundaries explained
- Portal or authentication ownership documented
- Support and escalation path provided
- Administrator ownership transferred securely
- Baseline performance observations recorded
- Connection and isolation evidence attached
- Known limitations listed
- Change-control process agreed
- Operator walkthrough completed
Next step
Once the handover is complete, the venue can evaluate whether a hosted marketing portal fits its guest WiFi workflow.
Contact LiquidEdge for a UniFi deployment discussion and an availability check.
Self-service account creation and proposed plan terms should be confirmed before presenting signup or pricing details.
