Office relocations are one of the highest-risk IT events a business can go through. Connectivity downtime on day one isn’t just frustrating for a team of 10–15 people, even a few hours offline translates directly into lost productivity and revenue. When this client approached Pantheon ahead of their move, the brief was clear: the new office needed to be fully network-ready before anyone arrived.
Scope of the project
The engagement covered the full network stack: security, switching and wireless connectivity across a new office premises. The hardware platform of choice was Ubiquiti’s UniFi ecosystem, which allows all network components to be managed, monitored and configured from a single unified controller. This makes ongoing management significantly simpler and gives us full visibility of the network from anywhere.
The deployment comprised three core layers:
- Perimeter security – a Ubiquiti UniFi Gateway (UXG) deployed as the network firewall and router, handling WAN uplink, NAT, inter-VLAN routing and threat management.
- Core switching – a UniFi PoE switch providing Power over Ethernet to all access points and wired endpoints, eliminating the need for separate power supplies at each node.
- Wireless coverage – multiple UniFi access points positioned across the office to provide seamless, high-throughput Wi-Fi 6 coverage with no dead zones.
Network architecture and VLAN segmentation
A flat network, where all devices share a single subnet, is both a security and performance liability in a business environment. For this deployment we implemented VLAN segmentation to isolate traffic by function:
- Corporate VLAN– for domain-joined workstations and business-critical devices, with restricted inter-VLAN access rules enforced at the gateway.
- Guest VLAN– isolated internet access for visitors, with no route to internal resources.
- IoT / device VLAN– for printers, smart devices and any non-managed endpoints, isolated from the corporate segment.
Firewall rules were configured on the UXG to enforce these boundaries, ensuring that a compromised device on the guest or IoT network cannot reach corporate resources.
Pre-move deployment and testing
All infrastructure was installed, configured and tested in the new premises before the client’s move date. This included:
- Physical cabling and structured patch panel installation
- Full UniFi controller configuration with site-wide network policies applied
- SSID provisioning across all access points with WPA3 encryption and band steering enabled
- DNS and DHCP configured with static reservations for key devices
- Remote access VPN configured for secure off-site management
- Throughput and signal strength testing at all workstations and meeting areas
On move day, the team arrived to a network that was fully operational. Workstations were connected, tested and online within the first hour. No connectivity issues were reported during or after the transition.
Ongoing management
With all infrastructure running on the UniFi platform, Pantheon retains remote visibility of the entire network through the UniFi controller. Firmware updates, configuration changes, traffic analysis and alerts are all handled centrally. The client has a fully managed network without needing any in-house IT resource to maintain it.
Planning an office move or network refresh? Pantheon handles the full infrastructure so your team arrives to a working office. Get in touch to discuss your requirements.
