A hotel has a controller, a rack and somebody who looks after them. A café has one access point, whatever the internet provider supplied, and nobody. That is a different job rather than a smaller one — and it is worth ten minutes before you buy anything.
Almost every small-site mistake is one of these two, and both fail in ways that look like success for the first few minutes.
Every phone has its own identity on a network, and that is what a sign-in is attached to, what your usage records name, and what a checkout takes offline. Put a router in between and every guest arrives wearing that router's identity instead — one identity for the whole café. One person signs in, everybody is on, no session can be told from another, and a single checkout takes the room off.
An internet provider's router lets nothing in, and nobody is going to log into it to change that — the password was on a sticker that got thrown away, or the provider owns the box. So for a checkout to take somebody offline, the site's own equipment has to dial out and hold a line open to us. Whether it can is what decides the third feature on every page in this section.
And the one that does not is the one most people try first, because it looks the cheapest and reads as though it ought to be fine.
| Arrangement | Sees guests individually | Checkout cut-off | Verdict |
|---|---|---|---|
| A. One combined router and access point, replacing what the provider's box does for your network | Yes | Yes | Best. What we recommend |
| B. The same box, sitting behind the provider's router with its own network | Yes | Yes | Fine |
| C. A standalone access point on the existing network | Yes | Usually not | Workable |
| D. The sign-in page upstream of a router | No | — | Does not work |
A combined router and access point takes over the routing, the addresses and the Wi-Fi, and the provider's box is demoted to just being the internet connection. Everything the product needs is in one device: it sees every guest individually because it is what they connect through, it holds the sign-in page open, and it dials out to us so a checkout arrives.
This is the arrangement we recommend. A MikroTik hAP costs less than a call-out fee and does the whole job — here is the page for it.
The same device, but the provider's router keeps doing its job and the new box sits behind it with its own network. Nothing here minds that, because everything that matters is dialled outwards from the site.
Use it where the provider's box cannot be demoted — typically a fibre box that also carries the phone line. The one real consequence is that your own devices and your guests end up on opposite sides of a boundary, so a till on the provider's network is not reachable from the guest Wi-Fi. That is usually exactly what you want.
The access point runs the sign-in page itself and puts guests onto the network that is already there. It sees each guest individually, because it is what they connect to. It works. Two things to know before choosing it:
Checkout cut-off usually will not work. The access point has no way of being reached from outside, and most standalone access points cannot dial out and hold a line open. Access then ends at the guest's time limit — which for a café is often perfectly acceptable, because a coffee is an hour and not a three-night stay. The exception is the Netgear WAC on current firmware, which can.
Your guests land on your own network — next to the till, the card terminal and your laptop. This has to be fixed before you go live. Most standalone access points have a setting that separates guests from everything else; turn it on. Where the access point cannot do that, arrangement B is the answer, and the reason to insist is the card terminal rather than the Wi-Fi.
A sign-in page upstream of a router — classically a firewall running the portal with a consumer Wi-Fi router plugged into it. Every guest presents the router's identity rather than their own. One sign-in admits the room, sessions cannot be told apart, usage records mean nothing, and a single checkout takes everybody off.
It is worth naming because it fails in a way that looks like working. The first customer signs in, everybody has internet, and nobody notices until one checkout empties the café.
We do not sell hardware and we take nothing from anybody who does, so this is the advice we would give a friend.
A MikroTik hAP or cAP does routing, addresses, Wi-Fi and the sign-in page in one unit, and it is the only inexpensive way to get every feature — including a checkout that really takes somebody offline.
If it is on the supported list and it can keep guests away from your own devices, it will do. Find it on the list and read what it does — the page will tell you whether checkout cut-off is available on it.
One more thing. Turn off any guest Wi-Fi your internet provider's box offers. Two sign-in pages on one premises leaves a phone on the wrong network looking at a page nobody recognises.
Photo of the equipment, rough size of the room, and whether there is a card terminal on the same network. That is enough for a straight answer.