Back to BlogNetworking

UniFi Network Failover Planning: What Stays Online When a Switch Fails?

September 12, 20264 min read
Blue Ethernet cables connected to a network switch

Network failover planning gets real the moment one switch goes dark. A second uplink may keep traffic moving, or it may only make the diagram look safer. The answer depends on where the two paths meet, how the attached devices are powered, and whether anyone has tested the design.

Picture a contractor with an office and warehouse in Pueblo. Estimating needs drawings from local storage, dispatch needs phones, and cameras send video across the same building link. If all three depend on one switch, one fiber strand, or one UPS, they share a failure point even if each system looks separate on a list.

Ubiquiti's September 2026 enterprise networking announcement adds stronger options for core, aggregation, and access switching. The resilience features are useful. But the hardware cannot decide which business functions must survive a failure. That part still starts with a map and a plain question: what exactly are we protecting?

Network failover planning starts with the failure you mean

"The network went down" can describe several different events. The internet circuit failed. A switch lost power. A fiber path was cut. A gateway rebooted. Or one PoE switch stopped powering the phones and cameras connected to it.

Write each event separately, then trace the impact. A useful review covers at least the gateway, core and access switches, inter-building links, power sources, internet circuits, and the endpoints that matter to operations. For a construction business, those endpoints might include estimating workstations, a local file share, VoIP phones, access control, and the camera recorder.

This is also where oversized specifications can distract. The Enterprise Campus Switch Core, model ECS-Core, has 32 QSFP28 ports and 3.2 Tbps of total non-blocking throughput in Ubiquiti's published specifications. Impressive, yes. But a faster core does not repair a weak cable route or create a second power source.

What UniFi MC-LAG protects, and what it misses

Multi-chassis link aggregation, usually shortened to MC-LAG, lets compatible equipment use links through a pair of aggregation switches. If a link or one member switch fails, traffic can use the surviving path when the upstream and downstream devices, port speeds, and configuration all support it.

Those conditions matter. Ubiquiti's MC-LAG configuration guide requires the links in a group to use the same speed and explains different behavior for different gateway designs. In one documented topology using other Cloud Gateways, spanning tree can block the standby ports and failover may take up to 10 seconds. "Redundant" does not always mean "nobody notices."

And MC-LAG only protects the path it spans. Two fibers in the same conduit can still be cut together. Two switches on the same unprotected circuit can still lose power together. A server with one network cable connected to one switch still has one connection.

A switch stack does not duplicate every attached device

UniFi's ECS-S stacking design combines supported switches into one logical switch. According to Ubiquiti's stacking guide, the switches connect in a ring, and cross-stack link aggregation can place an uplink or downstream connection across different members. The remaining switches continue forwarding traffic if one member goes offline.

That still does not keep every endpoint online. A camera connected only to the failed switch loses its network path. If that switch was also the camera's only PoE source, it loses power. The same applies to a phone, access point, or door controller. Keeping the stack alive and keeping every field device alive are different design goals.

A resilient network is one where you can name the failed part and predict what people will still be able to do.

PoE deserves its own calculation. Ubiquiti's PoE guidance distinguishes the power each device needs from the total power a switch can supply. Empty ports do not guarantee enough remaining wattage. And a large PoE budget is still unavailable during an outage unless the switch and its upstream equipment have appropriate backup power.

This is especially important when switching also supports cameras and access control. Decide whether the goal is continued recording, continued door operation, continued remote viewing, or all three. Each answer creates a different dependency chain.

Network failover planning needs an acceptance test

UniFi Network 10.6 added historical port information through Time Machine, automatic rollback for supported management VLAN changes through SafeOps, and a high availability readiness view. Ubiquiti's release announcement is careful about scope, including features that were still marked for Early Access. Historical evidence can shorten troubleshooting, but a dashboard cannot repair fiber or supply power.

Before calling a design resilient, test it during a maintenance window. Disconnect one uplink. Power down one switch. Confirm that the expected applications, phones, and security systems remain usable. Record how long traffic takes to recover and what alerts appear. Then restore the normal path and confirm that the network returns to a healthy state.

That test should have an owner, a rollback plan, and an agreed stopping point. If a business cannot tolerate even a short interruption, the test plan needs the same care as the network design.

Use the next upgrade to remove a specific weak point

A Pueblo business connecting another building or a Colorado Springs office moving into a new space has a good chance to document these dependencies before equipment lands in the rack. Start with the work, not the model number. Which functions need to continue? For how long? Which interruption is acceptable, and which one stops the day?

Then choose the architecture that fits. Some sites need a second internet circuit. Others need diverse fiber routes, redundant switching, better UPS coverage, or simply a spare configured switch and a clear replacement procedure. Managed IT support should keep that map current and make sure the recovery procedure still works after the next change.

GTZ Integrations can review the full path with you, from gateway and switching through power, cabling, and the devices your team uses. The useful outcome is a specific answer about what survives, what does not, and what improvement should come first.

Free Consultation

Questions About Your IT?

Book a free assessment with Efrain. No sales pitch, no obligation.

Get Your Free Assessment
Call (719) 203-7752