The short version
Migrations go wrong for predictable reasons, and almost none of them involve the new equipment. They go wrong because nobody knew what the old network was doing.
A static IP on a device somebody forgot. A port with a special configuration. A printer that only works because of an ancient DHCP reservation. A camera system quietly depending on a flat network. These surface at cutover, at the least convenient moment.
The fix is sequencing. Document first, fix the foundation, then change the visible parts, then add applications.
Stage one: find out what you have
Before ordering anything, establish the current state:
- Internet services — provider, service type, whether the router is supplied or your own, any static addressing
- What the gateway does — port forwards, VPNs, firewall rules, anything a remote user or supplier depends on
- Addressing — subnets in use, DHCP scope, and every static or reserved address
- Devices that must not break — payment systems, booking systems, alarm panels, lift phones, building services, medical equipment
- Existing wireless — network names, who uses them, and anything with credentials saved on devices nobody wants to reconfigure
- Cabling — where runs go, whether they test, and how many spare ports exist
- Cameras and door hardware — how they connect and what they record to
Most sites cannot answer all of this from documentation. That is itself the finding, and it is covered in comms room cleanup and network documentation.
Pay particular attention to devices with saved wireless credentials. Handheld scanners, label printers, older tablets and some equipment in clinical or industrial settings can be time-consuming to reconfigure, and that time belongs in the plan rather than in the cutover window.
Stage two: fix the foundation
Cabling and switching come before anything else, because everything else runs across them.
If cable runs are untested, undocumented or clearly damaged, resolve that first. Fixed cabling in Australia must be installed or altered by an ACMA registered cabler. If access points are fed through poor runs, replacing the access points will not fix the experience — it will just move the disappointment.
Managed switching is where the visible benefit starts. Ports become identifiable, PoE becomes measurable, VLANs become possible, and faults become findable without a site visit. This stage can usually happen with minimal disruption, one switch at a time, with each change verified before the next.
Plan PoE budget for the whole eventual load — access points, cameras, door readers — not the current device count. Adding capacity later means replacing a switch.
Stage three: the gateway
This is the one step that generally needs a planned window, because it changes the path to the internet for everything at once.
Preparation makes the window short. Every firewall rule, port forward and VPN from the old device should be recorded and recreated in advance, not discovered afterwards. VLANs should be designed before the change rather than added under pressure.
Do this outside business hours where possible, and have a rollback: keep the old gateway on site and configured until the new one has run through a full business day. The rollback almost never gets used, but its absence is what turns a problem into an outage.
Stage four: wireless
With cabling, switching and the gateway in place, the wireless design can be implemented properly rather than as a like-for-like swap.
This is the point to reconsider network names and structure. Separating staff, guest and device traffic is straightforward now and awkward later. Where the old network used one flat wireless network for everything, the migration is the natural moment to fix that.
A practical approach is to run the new wireless alongside the old briefly, move devices across in groups, then retire the old network once nothing is left on it. That avoids a single moment where every device needs reconfiguring.
Coverage should be designed rather than inherited. Mounting access points where the old ones happened to be reproduces the old coverage, including its gaps. Office Wi-Fi upgrade planning covers doing this properly.
Stage five: applications
Cameras and door access come last, once the foundation is stable.
There are good reasons for this order. Both depend on switching and PoE being right. Both add storage and power requirements to the comms room. And both are considerably easier to commission on a network that is already documented and behaving predictably.
UniFi Protect for business CCTV and UniFi Access for door entry cover what each involves.
What to keep and what to retire
Usually keep: structured cabling that tests well, patch panels, racks, and any recent PoE switching that still meets requirements.
Usually retire: consumer routers acting as the main gateway, unmanaged switches under desks, access points no longer receiving firmware updates, and equipment nobody can log into.
Depends: third-party switches and access points will keep working on the network, but they sit outside the UniFi console. That is a reasonable interim position during a staged migration and a poor permanent one, because losing single-pane management removes much of the reason for migrating.
A realistic sequence
- Document the existing network and identify anything that must not break
- Test cabling; repair or replace what fails
- Introduce managed switching progressively
- Design VLANs and addressing before touching the gateway
- Cut over the gateway in a planned window, with rollback available
- Deploy wireless to a coverage design, migrating devices in groups
- Retire the old wireless once nothing depends on it
- Add cameras and door access
- Document the result and hand over access properly
Steps one and two are where the value is. A migration that skips them usually produces the same network with newer badges on it.
Helpful starting points
If the network has grown organically and nobody can describe it, start with comms room cleanup and network documentation. If the driver is poor wireless, confirm the cause first with why is our office Wi-Fi slow. For a migration scoped and staged end to end, Ubiquiti network services covers the work.
