Network & Infrastructure · UniFi Specialist

The part of the network nobody thinks about
until everything stops.

Switches and gateways are the floor the rest of your technology stands on. When they're specified correctly you never think about them; when they're not, you get intermittent problems nobody can reproduce and a vendor blaming your network. AllTech designs, installs, and maintains that layer — primarily on Ubiquiti UniFi, and on other platforms when the requirements call for it.

UniFi specialist
On-site engineers
Segmentation by default
Local since 2009
01 · The problem

"It's probably the network."

Most of the switching we inherit was bought a box at a time, over a decade, by whoever needed a port that afternoon. It usually works. It also usually can't be troubleshot, monitored, or extended.

Unmanaged switches daisy-chained across the building

No VLANs, no port visibility, no way to tell which device is flooding the network — and a consumer switch under a desk that nobody documented.

One flat network

Cameras, guest Wi-Fi, the POS, printers, the plant floor, and the domain controller all in the same broadcast domain, all able to reach each other.

PoE budget quietly exceeded

Cameras and access points that reboot at random because the switch runs out of power under load, not because anything is broken.

A single 1G uplink carrying the whole building

Fine until backups, camera retention, and file traffic overlap on the same Tuesday morning.

The ISP router is the whole network

No segmentation, no failover, no logging, and a device the ISP can replace remotely without telling anyone.

No spare, no config backup, no lifecycle plan

When the gateway dies, the recovery path is a two-day shipping estimate and someone rebuilding rules from memory.

Firmware from three years ago

On the device every other device depends on.

02 · What we deploy

One managed fabric, documented.

A designed network has a gateway that knows what it's routing, switches that can be seen and segmented, uplinks sized for what actually crosses them, and PoE budgeted with headroom. We build it as one managed system with one place to look, not a pile of independently configured boxes.

Gateways

Routing, inter-VLAN policy, DHCP, DNS forwarding, VPN termination where appropriate, and multi-WAN failover. Sized to your actual throughput and to the features you'll have enabled — not to the marketing number with everything switched off.

Access-layer switching

Managed switches with per-port visibility, PoE and PoE+ where devices need it, and a documented port map so a problem can be traced to a port instead of guessed at.

Aggregation and uplinks

10G copper or fiber between the core and each closet, so backups, camera retention, and user traffic aren't competing for one gigabit.

VLAN segmentation

Separate networks for staff, guests, VoIP, cameras, door access, printers, servers, and OT/plant equipment — with explicit rules about what may talk to what. Guest and IoT isolated by default.

PoE design

Power budget calculated against real device draw with headroom, not against the number on the datasheet. This is the single most common cause of "random" camera and AP reboots.

Multi-WAN and failover

A second circuit (fiber, cable, or cellular) with tested failover, because failover that has never been tested is an assumption.

Controller and management

UniFi Network hosting decided deliberately — on-premise console, self-hosted, or Ubiquiti-hosted — with alerting and configuration backups either way.

Lifecycle and documentation

Firmware baselines, a documented topology, config backups, and a defined spares position for the devices that would hurt most.

03 · Vendor position

UniFi first, not UniFi only.

We're UniFi specialists, and for the large majority of the businesses we support that's the right answer. It's also a choice we make deliberately, per site, and we'll tell you when it isn't the right fit.

Why UniFi is our default

One controller for switching, Wi-Fi, cameras, and door access. No per-device licence to renew. Predictable hardware cost that leaves budget for the rest of the stack. And we run enough of it that our engineers know its behaviour — including its quirks — rather than learning your deployment on your time.

When we specify something else

Requirements drive hardware, not the other way around. We move off the default when a site needs deep next-generation firewall inspection with vendor-backed threat intelligence and a support SLA; when dynamic routing or advanced Layer 3 is genuinely required; when an existing platform, cyber-insurance requirement, or compliance framework dictates a specific vendor; when throughput at the edge exceeds what the platform holds up under with inspection enabled; or when a client needs a hardware replacement guarantee that a consumer-channel RMA process does not provide.

How we keep that decision reversible

The design is documented independently of the hardware — addressing plan, VLAN scheme, port map, routing and policy intent. A mixed environment is normal and supportable: we regularly run UniFi switching and Wi-Fi behind a different firewall, or UniFi at branch sites with something heavier at headquarters. Nothing here requires you to be single-vendor forever, and we will not pretend otherwise to keep a build simple for us.

What doesn't change. SASE and Zero Trust functions sit at the Cloudflare layer regardless of what hardware is in the rack — see Cloudflare Zero Trust. Choosing a different switch vendor doesn't rebuild your security stack.

04 · How we size it

Specified against what you'll actually run.

Single office, under ~25 users

GATEWAY
Compact cloud gateway
SWITCHING
One or two PoE access switches
UPLINKS
1G, 10G if the budget allows

Office with cameras and door access

GATEWAY
Mid-tier gateway with headroom
SWITCHING
PoE+ access switches, budget calculated
UPLINKS
10G to the closet

Multi-closet building

GATEWAY
Gateway sized for inspection enabled
SWITCHING
Aggregation switch + per-closet access
UPLINKS
Fiber between closets

Manufacturer / plant floor

GATEWAY
Gateway with strict inter-VLAN policy
SWITCHING
Hardened or industrial access switches on OT VLANs
UPLINKS
Fiber, redundant where the run allows

Multi-site

GATEWAY
Per-site gateway, consistent template
SWITCHING
Same access model at every site
UPLINKS
Site-to-site or SASE overlay

High-throughput or compliance-driven edge

GATEWAY
Alternate vendor NGFW — see section 03
SWITCHING
UniFi switching still fine behind it
UPLINKS
10G+

Sizing rule we hold to: gateways get specified against throughput with the features you want turned on, and PoE budgets get specified with headroom for the devices you'll add next year. Both are cheap to get right on day one and expensive to fix afterward.

05 · How we engage

Three ways to start.

01 · ASSESS

Network review

Physical walk of the closets and cabling, switch and gateway inventory with firmware and lifecycle status, VLAN and addressing review, PoE budget check, and uplink saturation review. You get a written topology, a prioritized findings list, and a replacement plan with rough costs. Stands alone as a deliverable — no obligation to buy hardware from us.

02 · DEPLOY

Design and install

Addressing and VLAN design, hardware specification and procurement, staged install with a defined cutover window, labelling, and documentation handed over. Cabling and rack work in-house.

03 · OPERATE

Managed network

Monitoring and alerting, firmware lifecycle, config backups, port and VLAN changes, capacity review, and warranty/RMA handling. Billed monthly. When a switch fails, we already know which one it is and what was plugged into it.

Cabling and rack work is in-house — see Network & Infrastructure.

06 · How the rollout goes

Four phases, and nothing gets unplugged before the new path is proven.

Phase 1

Design and staging

Addressing plan, VLAN scheme, and port map agreed on paper before anything is ordered. Hardware is configured and updated on the bench, not in your closet at 6 a.m.

Phase 2

Core and gateway cutover

Gateway and aggregation switch go in during a scheduled window, usually after hours. Old equipment stays in the rack, powered down and reachable, until the new path is proven.

Phase 3

Access layer and segmentation

Closet by closet, floor by floor. VLANs get applied in monitoring mode before enforcement where the platform allows it, because this is the phase that finds the label printer with a hard-coded IP and the machine nobody could identify.

Phase 4

Verification and handover

Failover tested by actually pulling the primary circuit. PoE draw measured under load. Topology, port map, addressing, and credentials documented and handed to you — including if you later take it in-house or move to another provider.

07 · Who this is for

Where it makes the most difference.

Businesses on consumer or unmanaged gear

That have outgrown it and are seeing problems nobody can pin down.

Anyone adding cameras or door access

That's a PoE and segmentation project before it's a camera project.

Manufacturers

Needing plant-floor equipment isolated from the office network without losing the visibility they need into it.

Clinics and professional services

Where segmentation is a compliance requirement, not a preference.

Multi-site organizations

Wanting one standard applied at every location, including the next one.

Offices moving or building out

The cheapest time to do this correctly is before the walls close.

Anyone whose network is one undocumented device away from a bad week

If that sentence landed, this is the conversation.

08 · Honest limitations

What we'll tell you before you buy anything.

UniFi is not a next-generation firewall. It does routing, segmentation, and basic threat signatures well. If your requirement is deep inspection with a vendor SLA and licensed threat intelligence, we'll specify a different edge device and say so during assessment — not after.

Gateway throughput drops when inspection is enabled. Headline throughput numbers assume features are off. We size against the configuration you'll actually run.

Hardware support is a channel, not an SLA. Ubiquiti's replacement process is serviceable, not same-day. For sites where an outage is measured in lost production, we recommend an on-shelf spare and quote it explicitly. Some clients would rather buy a vendor support contract instead — that's a legitimate reason to choose different hardware.

The controller is a dependency. UniFi switching keeps forwarding traffic if the controller is unavailable, but you lose management, changes, and visibility until it's back. We make the hosting decision deliberately and back up the configuration.

Segmentation will break something on day one. Some device — a printer, a scanner, a licence server, a piece of shop equipment — depends on flat-network reachability nobody documented. Finding those is part of the work, and it's why the access layer is phased.

New switching does not fix bad cabling. If the drops are unterminated, untested, or Cat5e where the application needs more, that's the actual problem. We test rather than assume, and we'll quote the cabling honestly.

It doesn't replace endpoint or email security. A well-segmented network limits how far a compromise spreads. It doesn't stop one from starting.

Wi-Fi is a separate design problem. Good switching is a prerequisite for good Wi-Fi, not a substitute for a site survey.

For the two gaps switching leaves open, see Cybersecurity and Wi-Fi design.

09 · FAQ

Common questions

Do we have to use UniFi?

No. It's our default because it fits most of our clients well and we support it deeply, but requirements decide. Mixed environments — UniFi switching behind a different firewall, for instance — are normal and fully supportable.

We already have UniFi that another vendor installed. Will you take it over?

Yes, and that's common. We start with an assessment: what's there, what firmware it's on, what's out of support, and what needs to change before we put our name on it.

Can you reuse our existing switches?

Sometimes. If they're managed, in support, and have the PoE budget and port count for what you're adding, we'd rather reuse than replace. We'll tell you which units are worth keeping and which are the reason for your intermittent problems.

How much downtime does a switch and gateway replacement take?

Core cutover is typically a scheduled after-hours window. The access layer is done in stages with brief per-closet interruptions. Nobody should lose a business day to this.

Do we need 10G?

Between the core and the closets, usually yes — it's inexpensive now and it's what keeps backups and camera traffic from competing with users. To every desk, almost never.

Will segmenting the network break our line-of-business software?

Occasionally, and we plan for it. Some applications assume flat reachability. Those get identified during the phased rollout and handled with explicit rules rather than by giving up on segmentation.

Who owns the equipment and the configuration?

You do. Configuration, credentials, addressing, and documentation are yours, and you get them whether or not you stay with us.

What happens when a switch fails?

Under managed service we get the alert, identify the unit and what was on it, handle the warranty claim, and — if you've bought a spare — swap it and restore the config. Without a spare, you're on shipping time, which is exactly why we quote the spare.

Can you support this if we're not local?

Most of the work is remote-capable, and our engineers are based in Northern Utah — for the right project, we travel further than that. Tell us where you are and we'll scope it.

Start with a look at what you actually have.

Send us a note about your sites and what's giving you trouble. We'll walk the closets, map what's there, and give you a written plan with priorities and rough costs — including the parts we'd leave alone.

Trusted by dozens of businesses