A new office, a move, or a network that never quite grew with the company: sooner or later you have to decide what a clean UniFi setup for a small business should actually look like. The good news is that you don’t need enterprise-grade planning for it. What you do need is the right order of decisions — because buying hardware first and only then working out where the management software will run and how the networks will be separated creates rework that gets expensive later. This guide walks through the planning in the order that makes sense: requirements, management, switching and power, WiFi, segmentation, remote access.

Step 1: Map your requirements before you pick hardware

Ubiquiti frames network design around two principles: segmentation — the physical and logical separation of network areas in order to control traffic — and bandwidth, meaning present and future traffic requirements at each point of the network, avoiding bottlenecks. Only after that does Ubiquiti recommend reviewing product datasheets to make sure the proposed hardware meets the requirements of the intended network. Technical specifications for all UniFi devices live at techspecs.ui.com.

In practice, write down how many workstations and wireless clients you have (laptops, phones, printers, point-of-sale terminals and IoT devices all count), which areas need coverage, where cabling already runs and where it doesn’t, and which groups of devices have no business talking to each other — guests, production, administration, cameras. That list drives the number of access points, the size of your switches and your VLAN structure.

The layered model Ubiquiti describes in its introduction to hierarchical network topology is useful here too: Edge (routers or firewalls at the WAN boundary), Core/Aggregation, Distribution and Access (the switches your users and devices plug into). In a small business several of these layers collapse into one or two devices — but asking „what is my edge, what is my access layer?“ still helps you sort out the cabling.

Step 2: Decide where UniFi Network runs

The core of the system is the UniFi Network application. Ubiquiti spells this out: when someone refers to a „UniFi Controller“, they most likely mean the UniFi Network application by an informal name. It has to run somewhere — on what Ubiquiti calls a UniFi Host. You have several options:

OptionWhat it isWhat Ubiquiti positions it for
Cloud GatewayGateway/firewall with UniFi Network pre-installed in one unitThe recommended default; compact models such as the UCG-Ultra and UCG-Max for small and mid-sized businesses, UDM-Pro and UDM-SE in rack form
CloudKey+Dedicated console without gateway functionalityUsers who do not want to deploy a UniFi gateway — for example behind a third-party router; runs Network, Protect, Access and Talk
CloudKey EnterpriseRack-mounted console for larger networksUniFi Network for up to 1,000 access points and switches
Official UniFi HostingCloud-based management with no on-premise consoleFunctionally the same as a CloudKey without the appliance; per Ubiquiti, up to 1,000 UniFi devices, typically paired with a UXG gateway
Self-hosted Network ServerUniFi Network on your own hardware or in your own cloudUbiquiti recommends this only for users proficient with network administration, as it „requires constant and precise attention“

Two points matter most for a small business. First, a Cloud Gateway is the simplest route, because routing, firewall and management sit in a single device — Ubiquiti explicitly recommends starting there. Second, if cost is pushing you toward self-hosting, budget for the ongoing maintenance; we worked the numbers through in our guide on the real cost of self-hosted UniFi. A hosted controller takes that maintenance off your plate and keeps management independent of the hardware in your office — the trade-offs against a local console are covered in Cloud Key vs. hosted cloud controller.

One option to rule out deliberately: Standalone mode for access points. Ubiquiti says it should only be used with a small quantity of APs, because there is no seamless roaming, no wireless meshing and no remote management — you have to connect to each AP individually as you move out of range. For an office with several rooms, that is not a foundation.

Step 3: Do the PoE maths on your switches

Access points, cameras and many other UniFi devices draw power over the network cable, which makes the switch’s PoE availability a hard planning constraint. Ubiquiti puts the rule plainly: your PoE availability must be greater than the sum of all connected device power requirements, otherwise you risk instability or failure.

StandardIEEEMax. power per portMax. power to deviceCabling
PoE802.3af (Type 1)15.4 W12.95 WCat3 or better
PoE+802.3at (Type 2)30 W25.5 WCat5 or better
PoE++802.3bt (Type 3)60 W51 WCat5 or better
PoE+++802.3bt (Type 4)100 W71 WCat5 or better

Add to that the consumption figures Ubiquiti publishes for common access points: U6+ 9 W, U6 Pro and U7 Lite 13 W each, U6 Long-Range 18.5 W, U7 Pro 21 W, U7 Pro Max 25 W, E7 43 W. Four U7 Pro units therefore draw roughly 84 W — more than a Lite-series switch, which Ubiquiti lists at 45–52 W of PoE availability, can deliver. The published ranges per switch class are 45–52 W (Lite), 42–195 W (Standard), 120–600 W (Professional), 180–720 W (Pro Max) and 120–720 W (Enterprise); the exact figure for your model is on its datasheet.

If the budget gets tight, PoE adapters are an alternative power source. Note Ubiquiti’s warning, though: all UniFi and UISP PoE adapters are passive, meaning they always output voltage without any negotiation. Their output ports must never be connected to computers, printers or similar equipment.

Step 4: Plan the WiFi instead of hoping

For coverage, Ubiquiti gives a measurable target: clients need a signal strength of at least -70 dBm for a stable connection, with -65 dBm or better recommended. If you can’t reach that even at high transmit power, the answer is another access point — not more power on the existing one.

In a high-density environment such as an office, Ubiquiti explicitly recommends medium rather than maximum transmit power so that APs don’t interfere with each other, along with 20 MHz channel width on 2.4 GHz, 40 MHz on 5 GHz and 160–320 MHz on 6 GHz. Keep Fast Roaming and Band Steering enabled. Channel selection can be optimised automatically by Channel AI.

Plan cabling to every AP location as well. Ubiquiti advises minimising wireless meshing wherever possible: each wireless hop reduces throughput by at least 50%, and if you have no alternative, the mesh link should sit at -60 dBm or better. To validate the finished installation, Ubiquiti recommends a WiFi site survey using the WiFiman mobile app, which requires a UniFi Gateway or Cloud Gateway.

If you want 6 GHz, additional requirements apply: a WiFi 6E or WiFi 7 capable AP (Ubiquiti names the U6 Enterprise, U6 Enterprise In-Wall, U7 Pro and U7 Pro Max), a region where 6 GHz is permitted, plus WPA3 and Protected Management Frames. Because 6 GHz has less range than 2.4 or 5 GHz, APs need to be placed closer together than in a 5 GHz-only design. For legacy and IoT hardware without WPA3 support, Ubiquiti recommends a separate SSID that does not broadcast 6 GHz — otherwise those clients either fail to connect or disconnect frequently.

A practical mounting note: UniFi uses two mounting systems. The Lite system covers smaller APs such as the U6-Lite and U6+, the Pro system covers larger ones including the U6-Pro, U7-Pro, U7-Pro-Max and E7. A Retrofit Mount bridges between them, and arm mounts let you wall-mount an AP with coverage similar to a ceiling mount. Worth checking early if you plan to reuse existing ceiling brackets.

Step 5: Separate your networks — VLANs, guests, isolation

You create VLANs in UniFi Network under Settings > Networks as a new virtual network, setting VLAN ID, subnet, DHCP, isolation and DNS there. One thing to be aware of: a newly created VLAN does not assign any devices by itself. There are several ways to do that — map an SSID to a single VLAN, assign VLANs to switch ports (ideal for printers, servers and fixed workstations), or use dynamic methods such as PPSK, RADIUS/802.1X and Virtual Network Override. For smaller sites UniFi also offers VLAN Magic: open the Topology view, click the „⊕“ symbol, name the VLAN and pick devices directly. It is not supported downstream of USW Flex, USW Flex Mini, USW Ultra, the USW Flex 2.5G series and ECS Aggregation switches.

With a third-party router the order reverses: create the VLAN on the gateway first, then in UniFi select Third-party Gateway under Router using the same VLAN ID. Most third-party gateways block inter-VLAN communication by default, so routing and firewall rules have to be configured there, not in UniFi.

For guest WiFi, Ubiquiti sets out a specific sequence: create the network or VLAN and enable Network Isolation so it is separated from all other VLANs; assign that network to a WiFi SSID; optionally enable a Hotspot Portal; enable Client Device Isolation so guests on the same AP cannot talk to each other; and enable Device Isolation (ACL) to complete the isolation at switch level. For performance, Ubiquiti additionally suggests Proxy ARP, per-guest speed limits and blocking bandwidth-intensive application categories.

Step 6: Remote access, ports and backups

For initial setup, the UniFi mobile app is Ubiquiti’s recommended route — over WiFi or Bluetooth, staying within 3 metres (10 feet) if you use Bluetooth. A UI account is optional but strongly recommended: it enables management through the UniFi Site Manager, automatic system backups and pre-configured email notifications. Our guide on setting up UniFi remote access covers how to do that securely.

Ports come with an important distinction: in a full UniFi deployment with native gateways, the required ports are opened automatically. The port list matters mainly for self-hosted Network Servers, third-party gateways and restrictive firewalls. In those cases you need TCP 8080 for device-to-application communication, TCP 8443 for the application GUI on a console, UDP 10001 for device discovery during adoption, plus UDP 3478 (STUN), TCP 443, TCP 8883, UDP 123 and TCP/UDP 53 for remote management.

Finally, plan backups from day one rather than after the first incident. How they work in UniFi and what matters during a restore is covered in our guide to UniFi controller backup and restore, and the controller itself should be protected against unauthorised access.

Conclusion

You plan a small-business UniFi network from the top down: work out which devices and groups exist, decide where UniFi Network runs, do the switching and PoE maths, design the WiFi around measured signal strength rather than guesswork, and separate the networks properly. The two things most often fixed after the fact are an undersized PoE budget and missing cabling to AP positions — both solvable on paper beforehand. If you would rather not tie network management to hardware sitting in your office, our team runs managed UniFi cloud controllers in a German data centre, maintained and backed up. Get in touch and tell us about your site — we’ll tell you what makes sense.

Frequently asked questions

Do I need a UniFi gateway to run UniFi?

No. Ubiquiti recommends a Cloud Gateway as the best option, because routing, firewall and UniFi Network live in one device. But you can also run UniFi Network on a CloudKey, via Official UniFi Hosting or on a self-hosted server and keep a third-party router. In that case you have to configure VLANs and firewall rules on that router — most third-party gateways block traffic between VLANs by default.

How many access points does my office need?

Ubiquiti does not publish a blanket number, but it does give a criterion: every client should have at least -70 dBm of signal strength, with -65 dBm or better recommended. If you can’t reach that even at high transmit power, add another AP. You can verify it after installation with a site survey using the WiFiman app.

How do I calculate the PoE budget?

Add up the power requirements of everything connected to the switch — Ubiquiti lists access points at, for example, 9 W (U6+), 13 W (U6 Pro, U7 Lite), 21 W (U7 Pro) or 25 W (U7 Pro Max). The switch’s PoE availability must be greater than that total, or you risk instability and failures. The exact figure for your model is on its datasheet at techspecs.ui.com.

Is a mesh network enough if there is no cabling?

It works, but it costs you real performance. According to Ubiquiti, each wireless hop reduces throughput by at least 50%, and meshing increases interference. If you have no alternative, the mesh link should be at -60 dBm or better. For an office network, a wired uplink to every access point is a far better foundation.

What is the difference between a UniFi Controller and UniFi Network?

They are the same thing. Ubiquiti notes that „UniFi Controller“ is an informal name for the UniFi Network application. It runs on a UniFi Host — a Cloud Gateway, a CloudKey, Official UniFi Hosting, a hosting provider, or a server you operate yourself.