Quick Answer: The network is now the floor of the entire luxury home. Lighting, shades, HVAC, locks, cameras, audio, video, control system, and energy system all ride on it. Get the network wrong and every system on top eventually fails. The right design starts with enterprise-grade gear (UniFi or Ruckus or Meraki for wireless, Fortinet or Firewalla for the firewall, managed switches, Cat6A everywhere, fiber on the backbone), proper VLAN segmentation, real surveillance under local control, MFA on every account, and RMM so we see problems before the homeowner does. We own our jobsites. We will tell you the truth even when it is uncomfortable, and especially when a competing bid hides behind one router and an unmanaged switch.
Networks and security on a luxury home in 2026 are not the back-of-house afterthought they were 20 years ago. They are the foundation that every other system depends on, and the threat surface that every connected device opens. After 20+ years designing, deploying, and supporting networks and security on luxury residences, high-rises, hospitality, and light commercial properties in NJ, NY, and CT, the questions below are the ones homeowners, builders, architects, developers, and property managers ask before they sign. The answers are not hedged. If a competing installer told you something that contradicts what you read here, ask them to put it in writing. Then call us.. Michael Restrepo
<.-- FAQ SECTION -->Frequently Asked Questions
Why is the home network suddenly the most important system in the house, and why do you talk about it before lighting or audio?
Because the network is now the floor of the entire house, and if the floor is cracked, every system on top of it eventually fails. A modern luxury home runs the lighting controller, the shade controller, the HVAC thermostats, the door locks, the garage doors, the cameras, the doorbell, the irrigation, the pool controls, the leak detectors, the audio matrix, the Apple TV in every room, the streamer, the projector, the Crestron or Savant or Control4 processor, the homeowner's laptop, the kids' iPads, the staff phones, the EV charger, the smart panel, the battery, the solar inverter, the Wi-Fi-connected appliances in the kitchen, the gym equipment, and the video doorbell from a neighbor's pool house all on the same physical wires and the same wireless air. Twenty years ago a home network was an afterthought wired by the AV crew. Today it is the single point of failure for the entire home experience. We have walked into 25 million dollar homes where the lighting will not respond because the consumer router gave up at 60 connected devices. We have walked into 7,000 square foot estates with one access point in the basement and dead air on the third floor. The network is not the place to save money. We design and document it as a real piece of infrastructure, before we wire a single light fixture.
What is wrong with the router my internet provider gave me, and why do you replace it on every project?
It was built to a price point, designed for the average household of four people and 12 connected devices, with a single radio, a four-port switch, and firmware that gets a security patch maybe twice a year if at all. A real luxury home runs 100 to 400 connected devices on the network. The ISP gateway runs out of DHCP addresses, drops connections under load, has no concept of network segmentation, has no real firewall, has no VPN capability, has no logging, and the support contract for the gateway sends a contractor to your house with a USB stick and a script when something breaks. The right answer is to put the ISP gateway into bridge mode (which turns it into a dumb modem) and run a real router and a real firewall behind it. We deploy Ubiquiti UniFi Dream Machine Pro, Ruckus, Pakedge, Araknis, or for a security-forward home a dedicated firewall (Firewalla, Fortinet, Sophos, or Palo Alto), with a managed switch behind it and proper enterprise-grade access points. The ISP keeps providing the bandwidth pipe. We provide the plumbing.
How much should the network and security stack cost on a real luxury home, all in?
Honest ranges from real installs in our market. A small luxury home (3,000 to 5,000 square feet, single floor or two, 80 to 120 connected devices): 8,000 to 18,000 dollars for a managed switch, three to five wireless access points, a real firewall or router, a small UPS, structured cabling labels and patch panel cleanup, and a basic surveillance subsystem. A typical luxury home (5,000 to 10,000 square feet, 120 to 250 devices, multiple floors, exterior coverage, a few cameras): 25,000 to 60,000 dollars for a more capable managed switching backbone, six to twelve access points indoor and outdoor, fiber backbones between equipment closets, a security firewall, structured cabling, surveillance with NVR plus analytic licensing, RMM (remote monitoring and management) tooling, and labeling. A flagship estate (12,000 to 25,000 square feet, 250 to 500 devices, separate guest house, pool house, garage, and gate house): 80,000 to 250,000 dollars or more, with redundant fiber paths, multiple equipment closets, enterprise-grade firewalls in HA pair, professional-grade surveillance with site-wide license plate readers, integration with the access control system and the alarm panel, full RMM and MDM. We do not give blind numbers. Every quote follows a site visit and a real device count.
UniFi versus Ruckus versus Cisco Meraki versus Aruba: which wireless platform is right for a luxury home?
Honest by-brand from systems we have specified and supported. Ubiquiti UniFi (we are a Ubiquiti UISP and Pro Partner) is the right call for the majority of luxury homes. Excellent hardware, the cleanest controller UI in the industry, no ongoing license fees, real Wi-Fi 7 access points (U7 Pro, U7 Enterprise, U7 Outdoor) at 300 to 700 dollars per AP, and a real ecosystem (switches, gateways, cameras, doorbells, intercoms) that all live under one controller. The downside is reliability across multi-building campuses sometimes needs more design care, and Ubiquiti still ships beta firmware too aggressively for our taste; we hold updates back on critical sites. Ruckus (now CommScope) is the right call when the home is large, complex, or runs a real estate management operation. Beam-flex antenna technology delivers measurably better RF in dense Wi-Fi environments, and Ruckus access points (R760, R770) handle high-density better than anything in their price class. Pricier hardware (800 to 1,500 dollars per AP), and you may pay for cloud licensing on Ruckus Cloud. Cisco Meraki is the right call on commercial-feeling residences and on every light commercial site we touch. Excellent management, real reporting, real security integration. Required ongoing license fees (200 to 600 dollars per device per year) and the licensing is non-negotiable. If the license expires, the hardware bricks. Aruba (HPE) is the right call on enterprise-level sites with a real IT department. EnGenius and Pakedge are right calls on smaller projects with budget constraints. We have specified all five. The recommendation depends on the home, the integration platform, the willingness to pay license fees, and whether the customer wants a single pane of glass for everything.
How many wireless access points does a luxury home actually need?
More than the previous installer told you. The honest design rule for luxury homes is one Wi-Fi 6 or Wi-Fi 7 access point per 1,200 to 2,000 square feet of finished floor space, plus one per material change (a stone-walled wine cellar gets its own AP, a steel-framed gym gets its own AP, a pool house gets its own AP). A 6,000 square foot single-floor home is a four-AP design, minimum. A 10,000 square foot two-story home with a finished basement is an eight-AP design, minimum. A 15,000 square foot estate with exterior coverage out to the pool, the tennis court, and the gate house is a 12 to 16 AP design. The ones who say two access points cover a 12,000 square foot home are designing for a homeowner who will call back screaming about dead zones in 18 months. Materials matter: stucco-on-wire-mesh kills 5 GHz dead. Limestone walls kill 5 GHz dead. Curved structural steel in modern homes blocks signals in unpredictable patterns. Every ceiling-mounted AP needs a Cat6A drop and PoE+ from a managed switch. We do real heat-mapping with Ekahau or NetSpot during design and again during commissioning. We do not guess and add later.
Wi-Fi 6 vs Wi-Fi 6E vs Wi-Fi 7: which one should I deploy in 2026?
Wi-Fi 7. The honest answer is that Wi-Fi 7 (802.11be) is now the right call for any new deployment in 2026 because the access point pricing has come down to par with Wi-Fi 6 hardware, the client device penetration has crossed 50 percent (every recent iPhone, every recent Samsung, most premium laptops), and the technical advantages over Wi-Fi 6 are real on multi-band devices. Multi-Link Operation (MLO) lets a Wi-Fi 7 device talk to the AP simultaneously on 2.4, 5, and 6 GHz bands, dramatically improving real-world throughput and latency in mixed environments. The 6 GHz band gives you a clean spectrum that is not yet polluted by neighbors, microwaves, and Bluetooth. 320 MHz channel width on 6 GHz delivers real multi-gigabit wireless to a single client. Wi-Fi 6 is still fine on existing installs that work, and we do not rip out working Wi-Fi 6 hardware to chase numbers. Wi-Fi 6E was the awkward middle child and we no longer specify it on new builds. The honest caveat: wireless throughput depends entirely on the wired backhaul. A Wi-Fi 7 AP fed by a 1-gigabit switch port is a Wi-Fi 6 AP. Wi-Fi 7 deployments need 2.5G or 10G switch ports on the backbone, and we wire to 10G uplinks where the budget supports it.
What about mesh Wi-Fi systems like Eero, Orbi, Google Nest Wi-Fi, and TP-Link Deco?
Fine for a 1,500 square foot apartment. Wrong tool for a luxury home. Mesh systems trade a small amount of bandwidth for plug-and-play simplicity, and on a small space with a small device count they are an honest choice. On a luxury home they fail in three predictable ways. First, the wireless backhaul (mesh nodes talking to each other over the air) consumes 30 to 50 percent of the wireless capacity, leaving the actual clients on a fraction of the advertised speed; the right answer is wired backhaul, which mesh systems mostly do not advertise loudly because it defeats the marketing. Second, mesh systems have no real network segmentation, no real VLAN support, no real guest network isolation, no IDS/IPS, and no real logging. Third, mesh systems treat every connected device as equal, which means the kid's iPad streaming TikTok on the third floor competes for airtime with the Crestron processor running the lighting downstairs. We deploy proper enterprise-grade access points with wired Cat6A backhaul, properly configured QoS, and proper segmentation on every luxury home. We have ripped out a lot of mesh kits over the years.
Firewalla Gold vs Fortinet vs Sophos vs Palo Alto: which firewall is right for a luxury home?
Honest by-brand from real deployments. Firewalla Gold SE and Gold Pro (700 to 1,500 dollars, no ongoing license, simple iOS app) is the right call for a small luxury home where the homeowner is not technical and wants visible blocking, traffic logs, parental controls, and basic IDS/IPS without paying ongoing fees. The interface is the cleanest in the consumer-prosumer market. Fortinet FortiGate (60F, 80F, 100F, 1,500 to 5,000 dollars for the appliance plus 500 to 2,000 dollars annual UTM license) is the right call for the typical luxury home that wants real firewall protection: deep packet inspection, application-aware policy, real IDS/IPS with automatic rule updates, geo-blocking, web filtering, and Forti Cloud reporting. The Forti ecosystem (FortiAP wireless, FortiSwitch, FortiSandbox) is integrated and well documented. Sophos XGS Series (1,500 to 5,000 dollars plus annual license) is the right call when the homeowner already runs Sophos on the work laptop and wants Sophos Synchronized Security across endpoint and network. Strong sandbox and AV integration, slightly less polished than Fortinet on day-to-day. Palo Alto PA-440 and PA-1410 (5,000 to 15,000 dollars plus annual license) is the right call on flagship estates and small commercial offices where the homeowner runs a public-facing brand, accepts payments at home, runs a media production setup, or has any reason to be a target. WatchGuard, SonicWall, and Cisco ASA are also options we have specified. We do not specify pfSense or OPNsense as primary firewalls on luxury sites because they require ongoing technical care that the average homeowner cannot self-administer.
Do I really need a firewall in addition to my router, or is the router enough?
You need a real firewall. The terminology is confused on purpose by ISPs and consumer router brands: every router has a basic stateful packet-filtering function that is sometimes called a firewall, but a real firewall does deep packet inspection, application identification, intrusion detection and prevention, and policy enforcement at the application layer. Consumer router firewalls block unsolicited inbound traffic, which is the bare minimum. They do not detect a malware-infected smart bulb beaconing to a command and control server in another country. They do not flag a TV that just started streaming to an IP address it has never talked to before. They do not block a phishing site from loading on your laptop. A real firewall does all of that. The threat model on a luxury home is real: connected appliances ship with stupid default passwords, security cameras phone home to manufacturers we do not trust, and a single compromised IoT device can be a beachhead into the rest of the network. The cost of a real firewall is small money relative to the home it is protecting. We deploy one on every project where the customer accepts the recommendation.
What is network segmentation and VLANs, and why do you keep talking about them?
Network segmentation is the practice of dividing a single physical network into isolated zones so a problem in one zone cannot spread to another. VLANs (Virtual Local Area Networks) are the technology that makes this work on a single set of cables and switches. The pattern we deploy on every luxury home: a Trusted VLAN for the homeowner's laptops, phones, and tablets; a Smart Home VLAN for Crestron, lighting controllers, shade controllers, locks, thermostats, and other tightly-controlled control plane traffic; an IoT VLAN for the smart appliances, smart TVs, and other devices that ship with weak security; a Camera VLAN for the surveillance system; a Guest VLAN for visitors and rentals, with internet but no access to anything else; a Staff VLAN for housekeepers, contractors, and others who need internet but not the rest of the house; and on commercial-feeling sites a separate Office VLAN for any work-from-home or business operations. Each VLAN has its own firewall rules, its own DHCP scope, its own DNS, and its own QoS policies. The IoT VLAN cannot reach the Trusted VLAN by default, even though they are on the same physical wires. If a smart bulb gets compromised, the attacker is sandboxed and visible. The honest fact is that 90 percent of consumer networks have zero segmentation. We deploy real segmentation on every project and document the rules.
How worried should I actually be about smart-home cybersecurity, and what are the real attack patterns?
Honestly worried, but not paranoid. The threats that matter on a luxury home in 2026: compromised smart cameras and doorbells that ship with backdoors and hardcoded credentials (avoid no-name brands, period); IoT devices beaconing to command and control servers and being recruited into botnets (segmentation contains this); ransomware on a homeowner's laptop spreading to network-attached storage and surveillance NVRs (proper backup and segmentation defeats it); credential phishing aimed at the homeowner's email and used to reset smart-home accounts (MFA on every account is non-negotiable); guest network abuse during rentals and parties (a real guest network with bandwidth limits and content filtering); supply chain attacks on cheap consumer routers (firmware injected at the factory in a small percentage of devices, which is why we specify enterprise-grade gear from vendors with real security teams). The pattern that gets a luxury homeowner in real trouble: a compromised low-end IoT device that pivots to the home's NAS or cloud-backup credentials and exfiltrates years of personal data. Proper segmentation, MFA, modern firmware, and a real firewall stop 95 percent of the threats that actually matter. We design and document every project with this threat model in mind.
Multi-factor authentication: which MFA approach do you actually recommend, and why not text messages?
MFA is required on every account that gates anything important. Texts are the worst form, hardware keys are the best, and a phone-based authenticator app is the right balance for a luxury homeowner. SMS-based MFA is broken because SIM-swap attacks are now a productized criminal service: an attacker calls the cell carrier, claims to be you, ports your number to a SIM in their pocket, and intercepts every code. We have seen real luxury homeowners lose access to their own accounts because of this. The right answer for a homeowner is: use a phone-based authenticator app (1Password, Microsoft Authenticator, Google Authenticator, Authy) for all routine accounts; use a hardware key (Yubikey 5C, Yubikey 5 NFC, Google Titan) for the highest-stakes accounts (primary email, password manager itself, primary bank, brokerage, and any administrative account on the home network or surveillance system). Carry the hardware key on your keychain or in your wallet. Keep a backup hardware key in a safe deposit box or a fireproof safe at home. Never let SMS be the only path to a critical account. We help homeowners audit their account security as part of the network handoff.
Cat5e vs Cat6 vs Cat6A vs fiber: what cabling should the home actually be wired with?
Cat6A everywhere, fiber on the backbone runs over 200 feet. Cat5e is dead for new construction. It tops out at 1 Gbps and runs out of headroom for Wi-Fi 7 access points and modern AV. Cat6 is fine for general-purpose drops to ordinary devices but should not be the default. Cat6A is the right answer for every drop on a luxury home: it supports 10 Gbps to 100 meters, supports the full PoE++ (90 watts) standard for high-power devices, has better shielding against the noise common in modern construction, and gives you 20-plus years of headroom for the next standards. The price difference between Cat6 and Cat6A on a real install is small (10 to 20 percent on cable and labor). The cost of running Cat6 today and ripping it out in 8 years is huge. Fiber is the right answer for backbone runs between equipment closets, between buildings on a campus, and on any run over 200 feet. Multimode OM4 fiber is the standard for short runs (under 400 meters), and singlemode for longer or future-proofed runs. We pull two redundant fiber paths between every closet on flagship estates so a backhoe in the lawn does not take down a building. We label every cable on both ends, document every drop in a network diagram, and hand over the documentation to the owner.
What is Power over Ethernet (PoE) and PoE++, and which devices need it?
PoE delivers electrical power and data over the same Cat6A cable, eliminating the need for a power outlet next to every device. The standards: PoE 802.3af delivers 12.95 watts (basic VoIP phones, simple sensors); PoE+ 802.3at delivers 25.5 watts (most wireless access points, basic IP cameras, intercoms); PoE++ 802.3bt Type 3 delivers 51 watts (Wi-Fi 7 APs, PTZ cameras, video doorbells with displays, pan/tilt cameras with IR illumination); PoE++ 802.3bt Type 4 delivers 71.3 watts to the device (high-end PTZs with heaters, displays up to 24 inches, building automation panels). The honest design rule is to budget the switch for the maximum PoE budget your device list could ever pull, plus 30 percent headroom. A 24-port switch with 240 watts of PoE budget supports 9 wireless APs at 25 watts each, but does not support 9 PoE++ Wi-Fi 7 APs at 50 watts each. We specify PoE++ switches with 720W or 1440W power budgets on luxury homes, both for the present devices and for future PoE-driven displays, intercoms, lighting fixtures, and smart shades that are coming.
What is a managed switch, and why do I need one instead of an unmanaged switch?
A managed switch is the difference between a network you can troubleshoot and a network you cannot. Unmanaged switches are simple traffic boxes: they pass packets between ports without any awareness of what those packets are, who is sending them, where they came from, or whether anything is wrong. They are fine for a small home with five ordinary devices and no critical control traffic. Managed switches add VLANs, port-level QoS, port mirroring for diagnostics, link aggregation, spanning tree, IGMP snooping for multicast (Crestron, Sonos, AirPlay, Dante audio all use multicast and break on switches that do not handle it correctly), real-time per-port statistics, and remote management. Every luxury home needs a managed switch because every luxury home has multicast traffic (whole-home audio, AirPlay, Sonos, AV-over-IP video routing on Crestron NVX or Q-Sys), and every luxury home needs VLANs. Brands we specify by tier: Ubiquiti UniFi for small to medium homes (US-XG, USW-Pro, USW-Enterprise series), Cisco Catalyst or Meraki MS for commercial-feeling residences and high-end installs, Aruba CX 6300 series for enterprise-class sites, Pakedge SX-24 series for AV-purposed networks where Pakedge is already a partner, Netgear M4250 AV Line for medium-budget sites where Netgear's AV-tuned defaults save commissioning time. Unmanaged switches do not belong on a real luxury home. Period.
Where should the equipment closet go in the house, and why does it matter so much?
Cool, central, accessible, and properly powered. The wrong closet kills a project before it starts. The honest design rules: place the main equipment closet centrally so cable distances stay under the 100 meter Cat6A limit to the farthest drop; put it on an inside wall (interior temperatures are stable, exterior walls swing 20 degrees in a New Jersey summer); plan dedicated cooling because a fully populated rack with a managed switch, gateway, two NVRs, a Crestron processor, and a UPS is a 1,200 to 2,500 watt heat source running 24/7; provide a dedicated 20 amp circuit (preferably two on different breakers) and a real UPS (1500VA minimum); leave 36 inches of clear floor in front of the rack for service; light the closet (we have walked into too many basement closets that needed a flashlight); and make the closet accessible without going through a finished space the homeowner does not want a tech walking through. A closet in the garage is acceptable in temperate climates with thermostatic ventilation. A closet in a finished basement is good. A closet in an attic is wrong (heat, humidity, vermin). On flagship estates we deploy multiple closets connected by fiber: one main closet, plus distribution closets in distant wings or outbuildings. We include the closet location and specifications in every set of network drawings we hand to the architect.
Surveillance: what brand of cameras should I deploy on my property, and why not Ring or Nest?
Honest by-brand from real installs. Ubiquiti UniFi Protect (we are a Ubiquiti UISP and Pro Partner) is our default for luxury residential. G5 series cameras (G5 Pro, G5 Bullet, G5 Turret, G5 Dome) deliver real 4K, real night vision, real onboard AI for person/vehicle/license plate detection, no monthly fees, all storage local on a UniFi NVR or Cloud Key. The system is a single-pane-of-glass with the rest of the UniFi network. Avigilon (Motorola) is the right call on flagship estates and commercial-feeling residential where the customer wants enterprise-grade analytics, license plate recognition, appearance search, and cross-camera tracking. Pricier hardware (1,500 to 4,000 dollars per camera) and license fees, but the analytics are best-in-class. Axis Communications is the right call when the project demands the highest video quality and longest service life (15-plus years), and where retrofit-friendly mounting matters. Hanwha (Samsung Wisenet) and Hikvision-tier alternatives are options we have specified on budget-conscious projects, with the caveat that Hikvision and Dahua are banned from US federal projects under NDAA Section 889 and we never specify them on residences with any government, military, or sensitive corporate connection. We do not deploy Ring, Nest, or Arlo as the primary surveillance system on a luxury home because they are cloud-locked, monthly-fee gated, recordings live on someone else's server, the AI runs on the manufacturer's servers and pulls your video out of your house, and the firmware is patched on the vendor's schedule.
How many cameras should a luxury home actually have, and where should they go?
Enough to deter and document, not so many that you live inside a panopticon. The honest design pattern for a luxury home: every exterior door (front, side, garage pedestrian, rear, pool) gets a camera covering the door and the approach to it; every vehicle approach (front gate, garage doors, motor court) gets a camera covering license plates at the angle that matters (license plate cameras are tuned at 12 to 18 degrees from the lane to capture plates clearly); every package-delivery zone gets a camera; the perimeter of the property at vulnerable approaches gets cameras; the pool deck gets a camera with audio for child safety; the driveway entrance gets a camera that reads license plates day and night; the front door gets a video doorbell with two-way audio. Interior cameras are a homeowner choice and we deploy them only where the homeowner asks: typically the great room and entry foyer (covered), and never bedrooms, bathrooms, or dressing rooms (privacy lines we never cross). Range is real: a 3,500 square foot home is typically a 6 to 10 camera design, a 7,500 square foot home is 12 to 18 cameras, and a 15,000 square foot estate with outbuildings is 20 to 40 cameras. We design with the homeowner, document field-of-view diagrams, and adjust until the coverage is intentional.
Do I need to keep camera recordings local, or is cloud storage fine?
Local-first, cloud as a backup, never cloud-only. The honest reasons: cloud-only systems lose all recordings the moment the internet is down, which is exactly when an intrusion is most likely; cloud-only systems give the manufacturer access to your video (read the privacy policy of any consumer brand and notice how broad the rights are); cloud subscriptions get expensive (300 to 1,500 dollars per year on a 12-camera system, every year, forever); cloud bandwidth chokes a residential internet connection (a 4K camera streaming to the cloud at high quality eats 15 to 30 Mbps continuously per camera, and 12 cameras consume 200 to 400 Mbps of upload bandwidth that most residential connections cannot provide). The right architecture: every camera records to a local NVR or to the access points and gateways themselves (UniFi Protect supports both), with 30 to 60 days of retention on local storage; selected event clips are pushed to encrypted cloud storage as backup; remote viewing happens through a properly secured tunnel back to the home network, not by streaming through the manufacturer. Storage math for the typical luxury home: 12 cameras at 4K with smart-codec compression and 30 days of continuous recording is roughly 30 to 60 terabytes of raw storage, hosted on RAID 5 or RAID 6 for redundancy. We size, deploy, and document this on every project.
Smart locks: what brands are actually professional-grade, and which ones do you avoid?
Honest by-brand. We specify Lockly, Yale (when paired with August Pro behind the door), Schlage Encode Plus (for matter and HomeKit homes), Aqara U200 (the cleanest in the matter category), Ring Door View Cam (for the door camera tied to a non-smart deadbolt). On flagship estates and high-rise units we specify Salto KS or Brivo or HID Mobile Access for full enterprise-grade access control with audit trails, scheduled access, and integration into the building's broader access control system. We avoid August's older standalone product (it was bought, abandoned, and limped); avoid any lock with a single vendor cloud as the only authentication path (a vendor outage locks you out of your own house, and Lockly had a major outage in 2025 that taught everybody this lesson); avoid no-name fingerprint and Bluetooth locks from Amazon (the security review is non-existent and we have walked into homes with smart locks that fall open if you swipe a credit card past the right side). The right design pattern for a luxury home is a smart lock at the front door with both a physical key override and a homeowner-controlled offline credential (PIN code that works without internet), integrated into the home's control system but not dependent on the internet for daily operation. We integrate every smart lock decision into the broader access control plan and the surveillance plan together.
How does the network integrate with Crestron, Savant, Lutron, and Control4 control systems?
Every modern control system is a networked computer at heart. Crestron processors (CP4, CP4N, MC4, AV4, MC4-R) are Linux-based servers that ride on the network and need a clean, properly segmented Smart Home VLAN with reserved IP addresses, jumbo frames support, and proper IGMP snooping for multicast (Crestron Home, NVX video over IP, and the Sonnex audio matrix all use multicast and break on switches that handle it wrong). Savant Pro Hosts, Smart Hosts, Audio Switches, and the new IP Audio system are similar: Linux-based, network-resident, sensitive to QoS, and dependent on proper VLAN configuration. Lutron HomeWorks QSX, RA3, and Athena processors live on the network too and integrate with smart-home, audio, and AV control via API. Control4 EA processors, OS3 controllers, and the new Halo and Halo Touch panels all need a stable network with proper QoS and segmentation. The wrong network kills the control system: high latency makes the touchpanel feel sluggish, packet loss drops audio multicast streams mid-song, no QoS lets a streaming TV starve the lighting controller of bandwidth, and a flat unsegmented network lets a misbehaving IoT device generate broadcast storms that crash the control processor. We design the network and the control system together, on every project, and we commission both as a single integrated system.
What is the right relationship between the network technician and the control programmer on a job?
They are the same person, or two people who talk every day. The honest reality is that a luxury home control system is a software project running on a network, and the only successful pattern we have seen is when the network engineer and the control programmer share the IP plan, share the device inventory, share the change log, and review each other's work. The wrong pattern is when the AV company subs out the network to a third party and the two teams meet for the first time at commissioning. We have walked into projects where the AV programmer assigned 192.168.1.50 to a Crestron processor and the network installer had already reserved that range for guest devices, and the lighting kept dropping for three weeks until somebody read the IP plan. We do both functions in-house: our network team and our control programmers work on the same drawings, the same IP plans, the same VLAN map, and the same change log. We eat our own dog food on this point.
What is QoS and why does it matter so much for AV-over-IP and audio multicast?
QoS (Quality of Service) is the way the network decides which traffic gets priority when there is contention for bandwidth or switch capacity. On a luxury home with whole-home audio (Sonos, Crestron Sonnex, Q-Sys, Dante), AV over IP (Crestron NVX, AVPro, Just Add Power), Wi-Fi calling, video conferencing, and streaming services all running simultaneously, QoS is the difference between music that plays in sync across 16 zones and music that drops out every 3 minutes when somebody starts a 4K stream upstairs. The mechanics: every packet on the network can be tagged with a DSCP value indicating its priority class. Real-time audio multicast packets get marked Expedited Forwarding (EF, DSCP 46), real-time video gets AF41, control plane traffic gets CS6, normal data gets default forwarding. The switch and the access point honor those markings and process high-priority packets ahead of low-priority packets when the network is congested. The honest reality is that QoS is widely mis-configured (or not configured at all) on consumer-grade gear, and on managed switches the defaults are often wrong for residential AV. We tune QoS specifically for the home's audio and video plan, on every project. We also deploy IGMP snooping and IGMP querier on every managed switch where multicast is in use, because without it multicast floods every port and crashes the network.
What is the right internet bandwidth to order from the ISP for a luxury home?
More than the ISP's recommendation by 2x, in 2026, on a luxury home with cameras, AV, and remote work. The honest rule is to size for symmetric bandwidth (equal upload and download) because cloud backup, remote camera viewing, and video conferencing all upload heavily, and most ISP cable plans throttle upload to 10 to 35 Mbps no matter what download number is on the bill. Symmetric fiber (Verizon Fios, Optimum Fiber 8 Gig, Frontier Fiber, Astound Business Fiber) is the right answer where it is available. Recommended tier: 1 Gbps symmetric minimum for a typical luxury home, 2 Gbps for a home with multiple 4K streamers and cameras pushing offsite backup, 5 to 10 Gbps for a flagship estate or any home that runs a real business or a media production. On any home that depends on internet for safety (security cameras, alarm communications, medical alerts, EV charging, primary phone service through Wi-Fi calling), we recommend a dual-WAN setup: primary fiber, secondary either cable or LTE/5G on a different carrier with automatic failover. Firewalla, UniFi UDM-SE, Fortinet, and most enterprise-grade gateways handle dual-WAN failover gracefully. We design the bandwidth tier and the redundancy tier into every project at the start, not at the end.
I live in a high-rise condo. The building has a network. Why do I still need my own?
Because the building's network is not yours, you do not control it, the building's IT contractor will not show up at 11 PM when your Wi-Fi is down, and most building networks are designed for the lobby and the gym, not for a residence with 200 connected devices. The honest pattern in luxury high-rises in NYC, Hoboken, JC, Stamford, Greenwich, and the Hamptons coastal market is that you keep the building's internet drop (delivered to your unit by the building's ISP) and you build your own network behind it. You put your own router and firewall behind the building's ONT or modem. You run your own access points throughout your unit. You keep your own VLAN structure, your own surveillance, and your own remote-access. The building network terminates at the door of your unit. We have done this on dozens of high-rise units and it is the right pattern every time. The other reason is privacy: the building has visibility into the building network, and most buildings are not capable of segregating that traffic in a way that protects a homeowner. Your own network keeps your traffic on your wires and your terms.
Multifamily building: how do you design the network for a 50-unit luxury condo or apartment building?
Property-wide is one network with serious segmentation, not 50 little networks. The honest reality on luxury multifamily (and on the amenity-floor projects we cover separately) is that each unit gets its own VLAN, its own DHCP scope, its own SSID prefix, and complete isolation from every other unit. The building network has a small number of trunks running from the building's main equipment room to each floor's IDF closet, with managed switches at each IDF and the access points serving the units distributed on each floor. Each unit's owner sees a private wireless network as if it were their own router, but the network is centrally administered, centrally monitored, centrally backed up, and centrally serviced. The amenity floor (gym, pool deck, lounge) has its own VLAN. The lobby has its own VLAN. Building operations (alarm, fire, BMS, leak detection, access control, surveillance) has its own VLAN. The cost reality is that this approach is more expensive than the bid you will get from a generic AV vendor who proposes one VLAN for everything, and it is the only architecture that works for 5-plus years without weekly headaches. We have rebuilt enough mis-designed multifamily networks to know.
Secondary home or vacation property: what changes about the network design?
More resilience, more remote management, more aggressive monitoring, less in-person presence. The honest design rules for a secondary home (the Hamptons, Litchfield County, Cape Cod, ski-country in NY/VT/CO): assume the homeowner is gone for weeks at a time and that no one is watching the network. Deploy redundant internet (primary fiber, secondary LTE/5G on a different carrier) with automatic failover so the alarm and the cameras stay online when one carrier has an outage. Deploy environmental sensors on the network (Phyn or Watts for water, Ubiquiti or Aqara for temperature, Honeywell for thermostat alerts) so the homeowner is alerted to a problem hours before it becomes a disaster. Deploy a real UPS on the equipment closet sized for at least 30 minutes of runtime so brief power blips do not require a homeowner to drive 4 hours to power-cycle a router. Deploy RMM (remote monitoring and management) tooling (Domotz, Ihiji, OvrC, UniFi Protect, Pakedge BakPak) so we are alerted when something fails and can often fix it remotely before the homeowner notices. Deploy a documented procedure for the housekeeper or property manager to power-cycle gear if remote intervention fails. The cost of all this on a secondary home is 4,000 to 12,000 dollars on top of the base network. The cost of an unattended water leak in a secondary home is six figures. The math is clear.
What is RMM and why is it included in your handover, not sold as an add-on?
RMM (Remote Monitoring and Management) is the layer that tells us a problem is happening before the homeowner notices. The honest reality is that a luxury home network has 100 to 400 devices, any one of which can fail silently, and a homeowner only knows something is wrong when they pick up an iPad to dim a light and nothing happens. RMM tools (Domotz, Ihiji Invision, SnapAV OvrC, UniFi Protect, Pakedge BakPak, Auvik for commercial) sit on the network and check the health of every connected device every few minutes: ping the camera, ping the access point, check the disk space on the NVR, check the firmware version on the firewall, alert if a device drops, alert if a Wi-Fi channel suddenly degrades, alert if a previously-known IP address changes, alert if internet bandwidth drops below a threshold, alert if a port goes down on a managed switch. We get the alert before the homeowner does. We diagnose remotely. We dispatch only when we cannot fix it remotely. RMM is not a luxury, it is the difference between a network we can support and one we cannot. We include first-year RMM in every install we do, and recommend a multi-year service contract to continue it. We do not let a system we built run blind.
VPN and remote access: how should the homeowner reach the home network from the road?
Through a real VPN, never through port-forwarded ad-hoc tunnels, and never by giving the homeowner direct internet exposure to a single device. The honest options for 2026: WireGuard VPN (built into UniFi, Firewalla, Fortinet, pfSense; the cleanest, fastest, and most secure modern VPN protocol) is our default. We deploy a WireGuard server on the home gateway and install the WireGuard client on the homeowner's laptop and phone. The homeowner connects, gets a route to the home network, and reaches the cameras, the NAS, the smart-home portal, all through the encrypted tunnel. Tailscale is a peer-to-peer mesh built on WireGuard that we deploy on commercial-feeling sites and on homeowners who run distributed teams. Twingate and Zscaler are zero-trust options for sites with serious threat models. OpenVPN is older but still acceptable. IPsec is fine for site-to-site between offices and homes. We do not deploy port forwarding to expose individual devices (cameras, NVR web interfaces, control system web pages) to the public internet because they are immediately scanned and probed, and any unpatched vulnerability becomes a back door. Tailscale and WireGuard fix this completely. Every luxury home should have a real VPN as the default remote-access path.
How does the network plan interact with the energy and battery system?
Two-way, on every project. The energy system depends on the network: solar inverters (Tesla, Enphase, SolarEdge, SMA), battery management systems (Tesla, FranklinWH, Sonnen, Enphase IQ Battery 5P), smart panels (Span, Eaton Brightlayer, Schneider Pulse, Lumin), and EV chargers (Tesla Universal Wall Connector, Wallbox, ChargePoint, Span Drive) all live on the network and report telemetry through the network. They sit on a Smart Home VLAN with proper QoS. The network also depends on the energy system: during a grid outage, the network needs to keep running, so the equipment closet UPS and the home's critical-loads plan must include the firewall, the gateway, the main switch, the wireless backbone (typically the AP closest to the homeowner's bedroom and the AP at the surveillance camera over the front door), the surveillance NVR, and the home control processor. We coordinate the critical-loads plan with the energy system designer at SD, not at commissioning. See the [Energy and Power Management FAQ](energy-and-power.html) for the detailed look on how solar, battery, smart panels, and EV charging fit together.
What is the relationship between the network and the building leak-detection and water management system?
The leak detection system rides on the network, talks to the network, and depends on the network to alert anyone of a problem. Phyn Plus, Flo by Moen, Watts SentryHydro, WaterCop with Centura, StreamLabs Control, and Aqara water leak detectors all are network-connected. They sit on an IoT VLAN with strict outbound rules and clear inbound paths from the homeowner's phone for status. The smart shutoff valves talk to the home control system through the network so a leak event triggers a Crestron, Savant, or Control4 alarm scene (lights flash, sirens sound, an alert hits every phone in the family group, the home logs the event). On a secondary home or a high-rise unit where the homeowner is gone for long stretches, the network plus the leak system plus the cellular backup is the difference between a dropped pipe noticed in 30 seconds and one that floods three units. A future Water Management FAQ will go deep on Phyn vs Watts vs WaterCop, BMS integration, and the insurance math. For now, the network design assumes leak detection sits on it.
Where does the surveillance NVR fit on the network, and how do I keep cameras off my private VLAN?
On its own VLAN, with strict firewall rules. The pattern: cameras live on a Camera VLAN that has zero outbound internet access except to manufacturer firmware update servers (whitelisted by IP and updated quarterly), zero access to the Trusted VLAN, and zero access to the Smart Home VLAN. The NVR (UniFi Protect Network Video Recorder, Avigilon ACC server, Axis Camera Station server, Synology Surveillance Station) sits on the Camera VLAN with the cameras, has a one-way path to the Trusted VLAN so the homeowner's phone and laptop can reach the viewing app, and is reached from the road through the home's WireGuard or Tailscale VPN, never through a port-forwarded public-facing web interface. Storage on the NVR is RAID 5 or RAID 6 for redundancy, sized for 30 to 60 days of full retention plus event-clip retention beyond that. Backup: nightly snapshot of the configuration to encrypted offsite storage. The honest brand point: avoid surveillance brands whose primary cloud-streaming model demands the NVR phone home through the manufacturer's servers (Ring, Nest, Arlo, most consumer-tier products). We deploy systems where the homeowner owns the storage and the homeowner controls the access path.
What is your role on a network and security project? Are you the IT department, the AV integrator, or both?
Both, by design, because the line between AV and IT no longer exists on a real luxury home. Restrepo Innovations is an Elite Pro Crestron Dealer, HTA Luxury Certified, OSHA Certified, and a Ubiquiti UISP and Pro Partner. We are not a corporate IT consultancy and we do not pretend to be: if a homeowner runs a public-facing brand with 50 employees working from the home office and has SOX compliance obligations, we partner with their MSP for the corporate piece and we own the residential and entertainment networks. What we are is the only team that can take responsibility for the home as a single integrated system from the network up through every connected service: the firewall, the switches, the wireless, the VLANs, the surveillance, the access control, the control system, the audio, the video, the lighting, the shades, the HVAC integration, the energy system, and the documentation. We own the wires, the configurations, the firmware schedules, the change log, and the on-call rotation. We will tell the homeowner the truth even when it is uncomfortable, and especially when a competing bid promises managed network for half the price and means an unmanaged switch with a label on it.
What is the worst network or security mistake you have walked into on a real project?
Three competitors for the worst, all real, all in our service area. First: a 250-unit luxury condo building where the developer's vendor put the entire building (every unit, every amenity space, every camera, every BMS controller, every staff laptop) on one giant flat VLAN. The first time a kid in unit 1503 ran a Bittorrent client that beaconed to a malware command and control server, the firewall flagged outbound traffic from that IP address as malicious. Because there were 247 other units on the same VLAN, the firewall could not tell which device or which unit was actually compromised. The whole building came down for 11 hours while a vendor walked unit-to-unit. The unit count and shared-VLAN architecture made it a recipe for disaster. We rebuilt that building's network from a flat one-VLAN topology to a properly segmented per-unit-VLAN architecture. Second: a 12,000 square foot estate where the previous installer had specified a single consumer-grade router for 327 connected devices and the network would crash every Saturday night when the family had guests and AirPlay multicast traffic exceeded the router's capacity. We replaced the router with a UDM-Pro and a managed switch and the crashes stopped that week. Third: a high-rise penthouse where the previous installer had port-forwarded the surveillance NVR's web interface to the public internet so the owner could view cameras from the road. Within 90 days the NVR was scanned, exploited, and used as a botnet beachhead. We replaced the NVR, deployed a real WireGuard VPN, and rebuilt the camera VLAN. The honest lesson on every one of these is that the cheapest installer is rarely the cheapest installer over five years. We will tell the truth about it, on day one, in writing.
