Unmanaged switches daisy-chained across the building
No VLANs, no port visibility, no way to tell which device is flooding the network — and a consumer switch under a desk that nobody documented.
Switches and gateways are the floor the rest of your technology stands on. When they're specified correctly you never think about them; when they're not, you get intermittent problems nobody can reproduce and a vendor blaming your network. AllTech designs, installs, and maintains that layer — primarily on Ubiquiti UniFi, and on other platforms when the requirements call for it.
Most of the switching we inherit was bought a box at a time, over a decade, by whoever needed a port that afternoon. It usually works. It also usually can't be troubleshot, monitored, or extended.
No VLANs, no port visibility, no way to tell which device is flooding the network — and a consumer switch under a desk that nobody documented.
Cameras, guest Wi-Fi, the POS, printers, the plant floor, and the domain controller all in the same broadcast domain, all able to reach each other.
Cameras and access points that reboot at random because the switch runs out of power under load, not because anything is broken.
Fine until backups, camera retention, and file traffic overlap on the same Tuesday morning.
No segmentation, no failover, no logging, and a device the ISP can replace remotely without telling anyone.
When the gateway dies, the recovery path is a two-day shipping estimate and someone rebuilding rules from memory.
On the device every other device depends on.
A designed network has a gateway that knows what it's routing, switches that can be seen and segmented, uplinks sized for what actually crosses them, and PoE budgeted with headroom. We build it as one managed system with one place to look, not a pile of independently configured boxes.
Routing, inter-VLAN policy, DHCP, DNS forwarding, VPN termination where appropriate, and multi-WAN failover. Sized to your actual throughput and to the features you'll have enabled — not to the marketing number with everything switched off.
Managed switches with per-port visibility, PoE and PoE+ where devices need it, and a documented port map so a problem can be traced to a port instead of guessed at.
10G copper or fiber between the core and each closet, so backups, camera retention, and user traffic aren't competing for one gigabit.
Separate networks for staff, guests, VoIP, cameras, door access, printers, servers, and OT/plant equipment — with explicit rules about what may talk to what. Guest and IoT isolated by default.
Power budget calculated against real device draw with headroom, not against the number on the datasheet. This is the single most common cause of "random" camera and AP reboots.
A second circuit (fiber, cable, or cellular) with tested failover, because failover that has never been tested is an assumption.
UniFi Network hosting decided deliberately — on-premise console, self-hosted, or Ubiquiti-hosted — with alerting and configuration backups either way.
Firmware baselines, a documented topology, config backups, and a defined spares position for the devices that would hurt most.
We're UniFi specialists, and for the large majority of the businesses we support that's the right answer. It's also a choice we make deliberately, per site, and we'll tell you when it isn't the right fit.
One controller for switching, Wi-Fi, cameras, and door access. No per-device licence to renew. Predictable hardware cost that leaves budget for the rest of the stack. And we run enough of it that our engineers know its behaviour — including its quirks — rather than learning your deployment on your time.
Requirements drive hardware, not the other way around. We move off the default when a site needs deep next-generation firewall inspection with vendor-backed threat intelligence and a support SLA; when dynamic routing or advanced Layer 3 is genuinely required; when an existing platform, cyber-insurance requirement, or compliance framework dictates a specific vendor; when throughput at the edge exceeds what the platform holds up under with inspection enabled; or when a client needs a hardware replacement guarantee that a consumer-channel RMA process does not provide.
The design is documented independently of the hardware — addressing plan, VLAN scheme, port map, routing and policy intent. A mixed environment is normal and supportable: we regularly run UniFi switching and Wi-Fi behind a different firewall, or UniFi at branch sites with something heavier at headquarters. Nothing here requires you to be single-vendor forever, and we will not pretend otherwise to keep a build simple for us.
What doesn't change. SASE and Zero Trust functions sit at the Cloudflare layer regardless of what hardware is in the rack — see Cloudflare Zero Trust. Choosing a different switch vendor doesn't rebuild your security stack.
Sizing rule we hold to: gateways get specified against throughput with the features you want turned on, and PoE budgets get specified with headroom for the devices you'll add next year. Both are cheap to get right on day one and expensive to fix afterward.
Physical walk of the closets and cabling, switch and gateway inventory with firmware and lifecycle status, VLAN and addressing review, PoE budget check, and uplink saturation review. You get a written topology, a prioritized findings list, and a replacement plan with rough costs. Stands alone as a deliverable — no obligation to buy hardware from us.
Addressing and VLAN design, hardware specification and procurement, staged install with a defined cutover window, labelling, and documentation handed over. Cabling and rack work in-house.
Monitoring and alerting, firmware lifecycle, config backups, port and VLAN changes, capacity review, and warranty/RMA handling. Billed monthly. When a switch fails, we already know which one it is and what was plugged into it.
Cabling and rack work is in-house — see Network & Infrastructure.
Addressing plan, VLAN scheme, and port map agreed on paper before anything is ordered. Hardware is configured and updated on the bench, not in your closet at 6 a.m.
Gateway and aggregation switch go in during a scheduled window, usually after hours. Old equipment stays in the rack, powered down and reachable, until the new path is proven.
Closet by closet, floor by floor. VLANs get applied in monitoring mode before enforcement where the platform allows it, because this is the phase that finds the label printer with a hard-coded IP and the machine nobody could identify.
Failover tested by actually pulling the primary circuit. PoE draw measured under load. Topology, port map, addressing, and credentials documented and handed to you — including if you later take it in-house or move to another provider.
That have outgrown it and are seeing problems nobody can pin down.
That's a PoE and segmentation project before it's a camera project.
Needing plant-floor equipment isolated from the office network without losing the visibility they need into it.
Where segmentation is a compliance requirement, not a preference.
Wanting one standard applied at every location, including the next one.
The cheapest time to do this correctly is before the walls close.
If that sentence landed, this is the conversation.
It does routing, segmentation, and basic threat signatures well. If your requirement is deep inspection with a vendor SLA and licensed threat intelligence, we'll specify a different edge device and say so during assessment — not after.
Headline throughput numbers assume features are off. We size against the configuration you'll actually run.
Ubiquiti's replacement process is serviceable, not same-day. For sites where an outage is measured in lost production, we recommend an on-shelf spare and quote it explicitly. Some clients would rather buy a vendor support contract instead — that's a legitimate reason to choose different hardware.
UniFi switching keeps forwarding traffic if the controller is unavailable, but you lose management, changes, and visibility until it's back. We make the hosting decision deliberately and back up the configuration.
Some device — a printer, a scanner, a licence server, a piece of shop equipment — depends on flat-network reachability nobody documented. Finding those is part of the work, and it's why the access layer is phased.
If the drops are unterminated, untested, or Cat5e where the application needs more, that's the actual problem. We test rather than assume, and we'll quote the cabling honestly.
A well-segmented network limits how far a compromise spreads. It doesn't stop one from starting.
Good switching is a prerequisite for good Wi-Fi, not a substitute for a site survey.
For the two gaps switching leaves open, see Cybersecurity and Wi-Fi design.
No. It's our default because it fits most of our clients well and we support it deeply, but requirements decide. Mixed environments — UniFi switching behind a different firewall, for instance — are normal and fully supportable.
Yes, and that's common. We start with an assessment: what's there, what firmware it's on, what's out of support, and what needs to change before we put our name on it.
Sometimes. If they're managed, in support, and have the PoE budget and port count for what you're adding, we'd rather reuse than replace. We'll tell you which units are worth keeping and which are the reason for your intermittent problems.
Core cutover is typically a scheduled after-hours window. The access layer is done in stages with brief per-closet interruptions. Nobody should lose a business day to this.
Between the core and the closets, usually yes — it's inexpensive now and it's what keeps backups and camera traffic from competing with users. To every desk, almost never.
Occasionally, and we plan for it. Some applications assume flat reachability. Those get identified during the phased rollout and handled with explicit rules rather than by giving up on segmentation.
You do. Configuration, credentials, addressing, and documentation are yours, and you get them whether or not you stay with us.
Under managed service we get the alert, identify the unit and what was on it, handle the warranty claim, and — if you've bought a spare — swap it and restore the config. Without a spare, you're on shipping time, which is exactly why we quote the spare.
Most of the work is remote-capable, and our engineers are based in Northern Utah — for the right project, we travel further than that. Tell us where you are and we'll scope it.
The parent service: cabling, racks, point-to-point, and the rest of the physical layer.
Reach these networks remotely without opening inbound ports.
The security layer that sits above the hardware, whatever the hardware is.
Endpoint and email defence — segmentation limits the spread, it does not stop the start.
Monitoring, patching, and the help desk that answers when a port goes quiet.
Send us a note about your sites and what's giving you trouble. We'll walk the closets, map what's there, and give you a written plan with priorities and rough costs — including the parts we'd leave alone.
Trusted by dozens of businesses