Business Internet in Melbourne’s Outer East and the Dandenong Ranges

If your business is in the hills, the honest answer is that your address decides most of this before you get a say. A shop in Boronia and a workshop three kilometres up the road in Upwey can be on completely different nbn technologies, with completely different fault restoration entitlements, and neither of them will find that out from a sales page. This is how to check what you actually have, what business grade buys you, and how to build a connection that survives a storm.

The technology at your address is decided by nbn, not by your provider

nbn’s Multi Technology Mix is the set of access technologies nbn uses to connect premises: five fixed line types (Fibre to the Premises, Fibre to the Building, Hybrid Fibre Coaxial, Fibre to the Curb and Fibre to the Node) plus Fixed Wireless and Sky Muster satellite. Which one you get is set by nbn’s build, not by which retailer you sign with. Two retailers selling you “nbn 100” at the same address are selling you the same wholesale access product with different support wrapped around it.

Check the address at nbn’s Check address tool. Use the Check business toggle, not the residential one, because the business path also tells you about full fibre and Enterprise Ethernet eligibility. The result will give you the planned or connected technology, whether the premises is ready to connect, and whether nbn is planning a technology change.

If it comes back Fibre to the Node or Fibre to the Curb, check the full fibre upgrade eligibility separately. nbn’s published position is that selected FTTN and FTTC premises can upgrade to FTTP by ordering an eligible higher speed plan through a participating provider, and that depending on complexity and building type additional costs may apply to providers, who may pass them on. In the ranges, “depending on complexity” is doing real work in that sentence. Long private driveways, shared easements and pit-to-premises distances are exactly what turns a standard upgrade into a quoted one. Our post on which nbn technology your address is on goes through reading the checker result properly.

Business grade is a different wholesale product, not different marketing

This is where most of the money and most of the disappointment lives.

nbn publishes two business service tiers behind retail business plans: nbn Business Service Pro, with a 4 hour fault restoration target, and nbn Business Service Essentials, with a 12 hour target. Restoration options are supported 24 hours a day, 365 days a year. That is the thing you are actually paying extra for. Not speed, not a static IP, not a nicer portal. A shorter clock on a fault.

Read nbn’s own footnote before you get attached to those numbers. nbn states that those restoration times apply to premises in urban areas or other areas where no site visit is required, that fault rectification time may vary depending on the location of the premises, and that all times refer to what nbn offers providers, which may differ to the times they offer you. It also notes that not all providers offer plans based on the full range of enhanced service levels.

Two consequences for anyone east of Ferntree Gully:

  1. A site visit is more likely here, so the published target is less likely to be the one you experience. A fault on a node in Croydon and a fault on a lead-in up a bush block above Belgrave are not the same job.
  2. Ask your retailer what their retail restoration target is, in writing. The wholesale target is nbn’s promise to them. Your contract is with the retailer. If they cannot state a retail figure, they have not productised the enhanced service level and you are buying a residential product with a business logo on it.

The other thing to know is a hard exclusion. nbn states plainly that nbn Business Service is not available on the nbn Fixed Wireless or satellite network. If your address is Fixed Wireless, there is no business grade nbn tier to buy. That single fact reshapes the whole design for a lot of sites in the Yarra Ranges, and it is the reason redundancy stops being optional.

What the regulator does and does not give you

Do not assume a consumer safety net. ACMA is explicit that the Customer Service Guarantee does not cover mobile phone and internet services: it is a landline voice safeguard, and it also drops away if you have more than five landline phone lines. There is no legislated repair timeframe for your business internet.

The Telecommunications Consumer Protections Code (C628:2019) does apply, but its definition of “Consumer” has two limbs that must both be met: the customer had no genuine and reasonable opportunity to negotiate the contract terms, and annual spend with that supplier is no greater than $40,000. Negotiate your terms and you can fall outside the Code even on a modest spend. ACMA announced in March 2026 that it is replacing the Code with an enforceable industry standard under section 125 of the Telecommunications Act, and that C628:2019 stays in force until the new standard commences.

Practically, the protection you can rely on is the complaints machinery. Under the Telecommunications (Consumer Complaints Handling) Industry Standard, urgent complaints must be resolved within 2 working days, non-urgent complaints must have a proposed resolution within 10 working days, and you can take the matter to the Telecommunications Industry Ombudsman if it is unresolved after 30 calendar days. Log everything with a reference number from the first call, because that clock only runs on complaints that were actually raised.

Fixed wireless in the hills: the qualifying test happens at install

nbn Fixed Wireless uses dedicated hybrid 4G/5G technology to send data from a transmission tower to an outdoor antenna fitted to your premises by an approved nbn technician, then to an nbn connection box inside. The antenna goes on the roof of the main premises, under the eaves or on a wall, or on a nearby powered building. nbn says that in most cases it can connect a premises to Fixed Wireless within 14 days of an order being placed.

The service covers around 800,000 premises nationally and has been through a $750 million upgrade, of which $480 million came from the Australian Government. That programme is finished: nbn records Phase 1 complete in June 2024, Phase 2 in October 2024 and Phase 3 in December 2024, with more than 120,000 premises previously on satellite given access to Fixed Wireless for the first time. Tower reach was extended from 14 km to up to 29 km where possible.

Current tiers, as nbn publishes them: Fixed Wireless Plus was lifted from 75/10 to 100/20 Mbps and is available across 100 per cent of the Fixed Wireless coverage area. Fixed Wireless Home Fast and Fixed Wireless Superfast are available in select locations only, with higher peak download speeds and modest upload. Existing customers may need their antenna upgraded to get the boosted speeds, so if you were connected years ago and never had a truck out, you may be on old hardware.

Here is the part nobody tells you. nbn does not publish a line of sight rule and does not publish guidance about trees or terrain. Its published qualifying test is signal strength at the premises: if sufficient signal strength cannot be reached, the premises cannot be connected. That test is performed by the installer, at your building, on the day. So a Belgrave address can show as Fixed Wireless on the checker, and still fail at install.

We regularly see the same pattern on treed blocks around Belgrave, Upwey and the eastern edge of Lilydale and Mooroolbark: the checker says yes, the installer gets a marginal reading from the preferred wall position, and the connection only works from a mast, a different elevation or a different corner of the block. Sometimes it does not work at all. Budget for that possibility before you sign a lease, not after.

Business fibre exists out here, but you have to ask for a quote and a date

nbn Enterprise Ethernet is nbn’s flagship fibre product: a dedicated fibre connection between your premises and nbn’s Fibre Access Node, with symmetrical wholesale speed tiers up to nearly 10 Gbps and a Business Network Termination Device installed on site. nbn publishes a network availability target of 99.95 per cent offered to service providers, and three classes of service: High (contractual commitments on latency, jitter and frame delay), Medium (first 25 per cent of traffic prioritised) and Low (best efforts).

Around 1.6 million business locations nationally have the option to upgrade, and nbn says that for 90 per cent of eligible premises there is no up-front build cost to service providers. That sits on top of the Business Fibre Initiative, an investment of up to $700 million which created 322 nbn Business Fibre Zones nationally, including a presence in 142 regional centres. In-zone premises get no up-front build costs and nbn’s most competitive wholesale service pricing. The exclusions are stated: it does not apply to unforeseeably complex premises, premises already served by other providers, data centres and temporary sites.

Almost none of the hills is in a Business Fibre Zone, and you should plan on that

This is worth stating plainly rather than fudging, because it changes the budget. We checked every zone name on nbn’s published Business Fibre Zone list, last updated 3 July 2025.

In the outer east, the zones are Croydon – Bayswater, Scoresby – Ferntree Gully, Ringwood and Dandenong. Nearby but further in, you also have Blackburn – Mitcham, Box Hill, Doncaster, Springvale – Noble Park, and to the north Eltham and Research.

That is the list. There is no Business Fibre Zone covering Lilydale, Mooroolbark, Chirnside Park, Kilsyth, Mount Evelyn, Coldstream, Seville, Healesville, Yarra Glen, Warburton, Boronia, Upwey, Tecoma, Belgrave, Monbulk, Emerald or Olinda. Not one Yarra Ranges suburb appears in either the Victoria metro or the Victoria regional zone list.

The consequence is specific and financial. A business in the Ferntree Gully or Croydon industrial pockets can ask its provider about Enterprise Ethernet on the in-zone terms: no up-front build cost to the provider and nbn’s best wholesale pricing. A business three kilometres up the hill in Upwey or Belgrave is out of zone, which means any Enterprise Ethernet build is quoted rather than free, and in terrain like that the quote is the whole decision. If you are choosing between two premises and one of them is inside the Croydon – Bayswater or Scoresby – Ferntree Gully boundary, that is a real and quantifiable difference between the two addresses.

Zone boundaries are drawn tightly and do not follow suburb lines. nbn publishes an indicative map for every zone, so check the actual map for your address rather than assuming the suburb name gets you in.

The availability catch matters here. nbn states that Enterprise Ethernet is only available in the Fixed Line network footprint and at limited premises served by the Fixed Wireless and Satellite networks, and that the no up-front build cost offer is not available for most premises in those footprints. A business park in Bayswater or Knox is a very different proposition to a site above Belgrave.

On lead times, be blunt with your retailer. nbn publishes no lead time for Enterprise Ethernet, no quote turnaround, no design timeframe, and no fault restoration hour target for the product. It says only that it will work with your provider to confirm a committed delivery date. So make the retailer put four things in writing before you commit:

  • The committed delivery date, and what happens contractually if it slips.
  • The build contribution amount, and the variation terms if the build turns out to be more complex than the desktop assessment assumed.
  • Your retail fault restoration target and the hours it applies over.
  • Whether the class of service you are buying is High, Medium or Low.

Telstra sells its equivalent as business-grade fibre under the product name Telstra Internet Direct (TID) Adapt, alongside National Ethernet and its own resale of nbn Enterprise Ethernet. Names differ by carrier. The four questions above do not.

4G and 5G: good as a second path, risky as your only one

Every carrier sells a fixed wireless product over its mobile network. Telstra sells 5G Business Internet, Optus sells 5G Business Internet and 4G Business Internet, and TPG and Vodafone sell 5G Home Broadband and 5G Home Internet respectively. Note that TPG’s promotional terms state the service is not for commercial or resale purposes, so it is not a business product no matter how good the price looks.

The thing that breaks businesses on these services is carrier grade NAT. TPG publishes the consequence in plain English on its own product page: the service uses CG-NAT, which assigns a private IP address instead of a public one, so port forwarding, hosting web, email or file servers internally, remote camera access and remote access will not work. Vodafone publishes the same list. Optus states that its 5G Home Internet does not support a static IP address, and by contrast lists a $0 static IP on its fixed line Business nbn plans. Telstra publishes nothing about CGNAT or IP addressing on its 5G Internet pages at all, which means you have to ask before you buy, not after your site-to-site VPN fails.

Two more published limitations worth knowing. Telstra’s 5G Internet plans are address-locked: move the modem outside your area and download speeds are capped at a maximum of 1.5 Mbps. And mobile fixed wireless sits below other traffic under congestion. Vodafone publishes it directly: the plan may be subject to data de-prioritisation, which could mean the speeds you experience are slower than the speeds experienced using its other 5G services. TPG publishes the same for periods of congestion.

Check coverage at the exact address, not the suburb. Telstra, Optus, TPG and Vodafone all publish checkers. Then test on site, with a device at the height and location the antenna would actually sit, at about 5pm on a weekday. In gullies around Belgrave and Tecoma the difference between the ground floor and a roof-mounted external antenna is the difference between a usable failover path and a decorative one.

As failover, it is genuinely good

Both major carriers bundle mobile backup into fixed line business plans, and this is the cheapest resilience you can buy.

Telstra states that on eligible business nbn plans the Telstra Smart Modem 4 switches automatically to the mobile network during an nbn fault, that the mobile backup is uncapped and unshaped on those plans, and that it switches back when the fault is resolved. Optus provides 4G Mobile Backup as a complimentary service on Business nbn plans using its Ultra WiFi Modem and Optus SIM, with no data limit, but with the backup path speed limited to a maximum of 25 Mbps down and 5 Mbps up, and limited to 30 consecutive days unless you contact Optus.

One design note. Carrier-bundled failover runs over that carrier’s mobile network. If you want genuine diversity, put the failover SIM on a different carrier to the one that fails most often at your address. If you run multiple sites, that decision interacts with how you link them, which we cover in connecting two or more offices.

Satellite is the fallback of last resort, and the business product is gone

nbn discontinued the business nbn Satellite Service as of 31 December 2025, with all remaining services disconnected on that date. What replaced it is not a business product. In October 2024 nbn amended the Sky Muster Plus interim agreement to remove the restrictions that had prevented medium to large businesses from connecting, so any business can now order nbn Sky Muster Plus Premium. There is no business grade service level on it.

Sky Muster Plus Premium is uncapped, with a fair use policy and shaping. nbn’s published shaping clause says it may at its discretion shape certain activities to maximum wholesale speeds of 256 kbps, including peer-to-peer, cloud storage, operating system and software and gaming updates, and unidentifiable traffic, and adds that other activity nbn considers may cause adverse network impacts may also be added to the list, including streaming video and VPN. Read that clause carefully if your business runs on a cloud file service or a VPN, because those are named categories.

The physics do not move. nbn describes the latency as inherent to the technology because of the 72,000 km round trip to the satellite and back. For a low earth orbit alternative and how it compares, see Starlink for Australian business.

Design for the power going out, because it will

Every big storm in the ranges takes power out somewhere. This is the part of the design that gets skipped, and it is the part that costs you a trading day.

nbn’s own published position is that any equipment connected via the nbn network will not work during a power outage. The detail differs by technology, and the differences are the whole design:

  • FTTP. The connection box needs mains power. Battery backup is optional and ordered through your retailer, not from nbn. nbn states a battery may last approximately five hours, comprising roughly three hours plus another hour and a half once the Battery Emergency button is pressed. Each mains-powered item of equipment needs its own battery backup.
  • FTTN, FTTB, FTTC and HFC. Services will not work during a power outage within the network or within your premises, and nbn states that restoring power with an alternative power option is not possible if the network itself has lost power. A generator at your site does not help if the node down the road is dark.
  • Fixed Wireless. Will not work during an outage at the tower, in the fibre network or at your premises. Same limitation, one more failure point.
  • Sky Muster satellite. This is the exception. nbn states that restoring power with an alternative option will usually allow you to reconnect, unless a ground station is also affected. Satellite is the only nbn technology where a generator or a large UPS at your site genuinely restores service.

So the design in the hills is not “buy a UPS for the server”. It is:

  1. Put the whole path on protected power: modem or NTD, router, firewall, core switch, and the access points that matter. A server on a UPS behind a dead switch is a very expensive paperweight. Our guide to UPS and power protection covers sizing and runtime properly.
  2. Put mobile failover on a different carrier, with its own protected power, and test the cutover on purpose at least twice a year.
  3. If your phones matter, move them somewhere that survives the site. Hosted voice lets calls divert to mobiles automatically when the site drops, which is a better answer than a diverted landline you have to be on site to configure.
  4. Find out who your electricity distributor is and bookmark their live outage map. Knowing whether it is a five minute recloser trip or a three hour tree-on-wires job changes what you tell staff and customers.
  5. Write down which staff can work from home, and confirm their home connections are not on the same technology and the same failure mode as the office.

The five questions to put to any carrier before you sign

  1. What nbn technology is at this exact address, and is it eligible for a full fibre upgrade or Enterprise Ethernet?
  2. Are you selling me a plan built on nbn Business Service Pro or Essentials, and what is your retail fault restoration target and hours?
  3. If a truck roll is needed to this address, does the restoration target still apply?
  4. Is this service on CGNAT, and can I get a public or static IPv4 address, at what cost?
  5. What is the failover path, does it fail over automatically, and is it on a different carrier’s network?

If a salesperson cannot answer all five, they are quoting a price, not designing a connection. TechAssist is based in Tecoma and works across Ferntree Gully, Belgrave, Upwey, Boronia, Bayswater, Lilydale, Mooroolbark, Croydon, Knox and Dandenong, so we have driven most of these roads and stood on most of these roofs. Our note on on-site response times across the outer east explains how we scope that.

Send us the address and we will check the technology, the upgrade eligibility and the realistic failover options before you commit to a lease or a contract. Call 1300 028 324 or use the form at techassist.au/contact. It is a short conversation and it is a lot cheaper than finding out at install.

Starlink is a genuinely good answer for a small number of Australian business situations and a genuinely bad answer for a larger number. The deciding factors are almost never speed. They are the contract you are actually on, whether you can get a public IP, whether you have clear sky, and whether the site can tolerate a link that its own operator describes as not suited to mission-critical use.

Starlink is SpaceX’s low earth orbit satellite internet service: it connects a dish at your premises to satellites orbiting at about 550 km, rather than the 35,786 km of a geostationary satellite, which is why its latency is measured in tens of milliseconds instead of hundreds.

The first thing to check is which plan you are contractually allowed to use

Starlink’s Australian plan names changed. The old Business, Priority, Mobile Priority and Maritime names are retired. What Starlink publishes for Australia today is:

  • Residential Max, Residential 200 Mbps, Residential 100 Mbps and Residential Lite for fixed premises.
  • Roam (Unlimited, 100 GB and 300 GB) for land mobility and personal use.
  • Local Priority and Global Priority, the business tiers.
  • Standby Mode, a paused state.

“Starlink Business” now describes an account type, not a plan. If you have an account manager telling you that you are “on Starlink Business”, ask which service plan the line is actually on.

Then read this, because it is the single most commercially important line in Starlink’s Australian documentation. The Service Plan Descriptions state that Residential Max, Residential, Residential Lite and Roam Unlimited are not permitted for business or enterprise uses. Plenty of Australian businesses are quietly running on a Residential plan because it was cheaper and it worked. That is a breach of the service terms, and it is also the plan tier with the technical limitations that break business applications. Both problems are fixed by the same decision.

What the priority tiers actually change

Local Priority and Global Priority differ from Residential in ways that matter more than the headline speed:

  • Network precedence. Starlink states that priority data is given network precedence over Residential and Roam data, so users typically see faster and more consistent speeds.
  • A public IPv4 address is available, toggled in the account dashboard. It is not available on Residential or Roam.
  • No CGNAT session limit. Residential and Roam are capped at 1,200 concurrent sessions. Priority is not.
  • 24/7 prioritised support, ticket-based, with phone contact by callback requested through the ticket.
  • A telemetry dashboard and multi-site management, plus in-motion use up to 160 km/h.
  • Business account handling such as modified invoicing and tax exemption certificates, which Starlink says is not available on Residential or Roam.

There is also a real, published SLA, which is unusual for satellite and worth understanding precisely.

The Priority Plan SLA, read properly

Starlink’s Priority Plan Service Level Agreement commits to 99.9 per cent network availability per monthly billing period, on Local Priority and Global Priority only. The mechanics are where it gets interesting:

  • Connectivity to the point of presence is checked every second, but a failure must persist for at least 60 continuous seconds before any of it counts as outage time. A satellite link that drops for 20 seconds forty times a day accrues zero measured outage.
  • The remedy is a 20 per cent service credit on that line’s base monthly cost, expressly stated as your sole and exclusive remedy. Credits expire after 24 months.
  • You must raise a ticket within 14 days if an outage was not automatically recorded.
  • It does not apply to Mini Kits, Data Pools, Impact Plans or Bonded Gateways.
  • It is voided by obstruction. The exclusions include any obstruction of the sky view, non-compliant installation, unstable power, customer network configuration, rate limiting after data exhaustion, and dish misalignment beyond the stated tolerances.

That last point is the one that decides whether the SLA is worth anything at your site. A partially obstructed install is not a slightly worse service with the same contract. It is a service with no contractual remedy.

Set against that, Starlink’s Australian Terms of Service state that use of the services is at your sole risk and that the services are “not suited or intended as a mission-critical or safety-of-life service”, with aggregate liability capped at the total amount paid over the preceding six months and consequential loss excluded. Australian Consumer Law guarantees are preserved and cannot be contracted out of, but do not plan your business around them.

Latency: fine for voice, workable for remote desktop, not the same as fibre

Starlink’s published Australian specification puts latency at 25 to 60 ms on land, and 100 ms or more in certain remote locations such as oceans, islands and high latitudes. Starlink’s Australian technology page contrasts this with geostationary satellite at around 600 ms or more, and nbn describes the latency inherent in its Sky Muster service as a consequence of the 72,000 km round trip.

For practical purposes:

  • Voice. 25 to 60 ms one-way-ish latency is inside the range where a well-configured SIP call sounds normal. Jitter and packet loss during obstruction events, not latency, are what make calls sound bad on satellite. If voice matters at the site, read our note on VoIP over a satellite link alongside this.
  • Remote desktop and published applications. Usable, but noticeably less crisp than a fibre link. Starlink publishes nothing at all about remote desktop performance, so treat any vendor claim about RDP over Starlink as unsupported. Test it with your actual application before you commit staff to it.
  • Anything with a chatty, latency-sensitive protocol. Legacy line-of-business applications that do hundreds of small round trips per screen will feel every millisecond. Test, do not assume.

CGNAT is what actually breaks things

By default, Starlink assigns a CGNAT address in the 100.64.0.0/10 range. Starlink states plainly that the default IPv4 CGNAT policy does not allow inbound traffic.

The consequences, all published by Starlink:

  • Port forwarding does not work. Starlink’s own routers do not support port forwarding or firewall rules for IPv4 or IPv6. To do it you need a third-party router and a public IP assigned, which means a priority plan.
  • A public IPv4 is available on Local Priority and Global Priority only. There are no static IPs. Starlink operates a reservation system that retains the address across reboots, but states that relocating the unit or a software update may change it. If something depends on a fixed address, that is a risk you have to design around, not a feature you can rely on.
  • IPv6 is native everywhere, on all routers, kit versions and plans, with a /56 prefix delegated to the LAN. On a modern network this is often the cleaner path.
  • Some ports are blocked outright. Outbound TCP and UDP 25 (SMTP) and TCP 445 (SMB) are blocked, as are NetBIOS ports 135 to 139 in both directions.

VPNs: know which protocols survive

Starlink publishes a protocol compatibility matrix, and it is unusually specific. SSL-based VPNs traverse CGNAT best, and NAT traversal support is required.

  • Client-to-site that works: SSTP, OpenVPN, WireGuard.
  • Client-to-site that does not: PPTP, L2TP.
  • Site-to-site that works: MPLS, IKEv2 with IPsec, OpenVPN.
  • Site-to-site that does not: GRE, IPsec without NAT traversal, L2TP.

Starlink’s enterprise documentation is blunter still: protocols 47 (GRE), 50 (ESP), 51 (AH) and 115 (L2TP) are dropped by CGNAT. If your existing site-to-site design is a plain IPsec tunnel without NAT-T, or a GRE tunnel, it will not come up. Starlink also states it cannot troubleshoot VPN connection issues because they fall outside the scope of its network support, and that even with a public IP it cannot guarantee VPN compatibility. Plan your multi-site links accordingly, and prefer an SD-WAN or SSL-based overlay over legacy tunnels.

VoIP and video: Starlink names this problem itself

On Residential and Roam, the 1,200 concurrent session limit causes new sessions to drop the oldest ones. Starlink lists the symptoms in its own support article: VoIP calls dropping or failing to connect, one-way audio during phone or video calls, video meetings freezing, dropping or failing to join, and issues with gaming and VPNs. Its own recommendation is that customers who regularly use VoIP, video conferencing or other session-intensive applications should consider switching to a priority plan, because priority plans include a public IP and do not have the session limitations associated with CGNAT.

Read that as the vendor telling you the residential plan is not a business plan.

The same reasoning applies to remote camera access. If you want to view CCTV and access control from off site, either use a cloud-brokered platform that only makes outbound connections, or accept that you need a priority plan and a third-party router.

Obstructions are the whole ballgame in treed terrain

For business installations Starlink publishes a hard requirement: the dish must be 100 per cent unobstructed for best performance, with clear sky from roughly 20 degrees elevation across the full 360 degrees of azimuth. It states that even small obstructions have a negative impact, including intermittent outages, dropped packets or sessions, and a reduction in overall average bandwidth capacity. Do not install next to a wall or under cover.

Two practical notes for anyone on a treed block:

  1. Use the app’s “Check for Obstructions” tool before you order. It is camera-guided, and Starlink recommends checking before purchase in heavily obstructed areas. A full obstruction map can take up to 12 hours to build, so do it over a working day, not over a coffee.
  2. Field of view differs by hardware. The Performance kit has a 140 degree field of view against 110 degrees on the Standard kit, so it sees meaningfully more sky. If the site is marginal, the hardware choice is not cosmetic.

Where the sky is not clear, the answer is elevation: a pole, a mast, a tower, or a different corner of the property with a cable run back. Starlink’s own guidance is that if you cannot safely install the kit or clear obstructions, do not proceed and seek professional assistance.

Installation in Australia is a genuine gap

This one surprises people. Starlink runs a trained third-party installer programme, and the Australian partner is CIRCL. But Starlink states that third-party installers are available for Residential plans only, that customers outside the United States must contact their in-country installation partner directly, and that you are responsible for contracting with third-party installers yourself, with Starlink accepting no responsibility for pricing, contract terms, quality of work or damage to your property. Pole mount installations are excluded from the installer programme.

So the tier with the strictest obstruction requirement and an SLA that is voided by obstruction is also the tier with no vendor-provided installation path in Australia. If you are deploying priority Starlink at a business site, the mount, the cable route, the earthing, the surge protection and the alignment are your problem or your IT provider’s. Get it done by someone who does roof work properly, and then document it properly so the next person knows where the cable runs.

Data: read the fallback, not the headline

Starlink’s current structure is three classes of data: priority, residential and deprioritised.

  • Residential Max and Residential get unlimited high-speed residential data, subject to network management if usage consistently exceeds what is allocated to a typical residential user. Starlink publishes no numeric threshold for that.
  • Residential Lite gets unlimited data that is always deprioritised compared with other fixed plans.
  • Priority plans buy fixed monthly Data Blocks of priority data. Unused data does not roll over. When the block is exhausted and you have not opted into Top-Up Data, Starlink states the service is limited to substantially slower speeds, giving up to 1 Mbps download and 0.5 Mbps upload as its example, for the remainder of the month.

That fallback is the part to design around. It is not a gentle deprioritisation to a slower but usable service. It is a rate limit that will take a site off the air for business purposes until the billing cycle rolls over.

Top-Up Data is opt-out by default, and auto-billing once you opt in. Starlink states that once you opt in you will be automatically billed for top-up data used until you opt out, including in following billing cycles. Decide deliberately which way you want that set, and put a usage alert in place either way. A site that burns through its block in week two is a site with a monitoring problem, not a Starlink problem.

Prices, block sizes and speed ranges move. Starlink publishes them on its Australian pages and in its Critical Information Summaries, and at the time of writing the CIS documents and the live pricing page do not agree with each other. Check both, on the day, before you budget.

The regulatory position, since people ask

Starlink Australia Pty Ltd holds carrier licence 542 on ACMA’s register of licensed carriers, granted in August 2020. The entity that contracts with you is different: Starlink Internet Services Pte. Ltd., a Singapore company with an Australian address in Sydney, operating as a carriage service provider.

Both entities are listed as active members of the Telecommunications Industry Ombudsman scheme, so you can escalate an unresolved complaint. Starlink publishes a statement of commitment to the Telecommunications Consumer Protections Code C628:2019, although that page has not been updated since April 2022.

ACMA has taken action against Starlink twice. In September 2023 it issued a direction to comply after Starlink breached the TCP Code by advertising a limited time offer with no end date. In May 2025 it issued a formal warning for four failures to lodge complaints records within 30 days, which incidentally confirms Starlink has passed the 30,000 services threshold in Australia. Treat that as a service maturity signal rather than a disqualifier, but do factor it into how you expect support escalations to go.

Where Starlink is genuinely the right answer

Sites with no viable fixed line or fixed wireless option. If nbn’s checker returns satellite, or returns Fixed Wireless and the install fails on signal strength, Starlink on a priority plan is usually a better service than nbn Sky Muster Plus Premium, particularly because nbn’s published shaping clause names VPN and streaming video as categories it may shape to 256 kbps. Check the nbn technology at the address first, because if fibre or a business grade fixed line service is available, that is the better primary.

Construction, temporary and project sites. A site office that exists for nine months, has no lead-in and needs to be productive next week is exactly the case Starlink was built for. There is no build cost, no lead time and no pit and pipe. Just check the sky.

Failover for a site that cannot use mobile. In the gullies of the Dandenong Ranges, mobile failover sometimes is not a real option because the mobile signal is worse than the fixed service it is meant to back up. Starlink on a priority plan, with its own protected power, on a separate router WAN port, is a legitimate second path. That combination is worth reading against what is actually available in the outer east and the Dandenong Ranges.

Remote depots, quarries, farms and field offices where the alternative is nothing.

Where it is not the right answer

  • As a like-for-like replacement for a business grade fixed line at a site that has one available. You are trading a contracted fault restoration target for a 20 per cent credit and a vendor statement that the service is not intended for mission-critical use.
  • Where you need reliable inbound access to on-premises systems and you are not willing to buy a priority plan, a third-party router and the design work to go with it.
  • Where your site-to-site VPN is GRE or plain IPsec without NAT traversal. Redesign first, or it simply will not work.
  • On a heavily treed block with no elevated mounting option. Partial obstruction does not give you a slightly degraded service. It gives you unpredictable session drops, and it voids the SLA.
  • As the only link at a site with unreliable mains power, unless the dish, the router and the switch are all on a UPS. Unstable power is a listed SLA exclusion.

The pattern we see most often is a business that put a Residential dish on the roof two years ago, has been quietly in breach of the terms ever since, and is now blaming “satellite” for problems that are actually the 1,200 session limit and a tree.

If you have a site where the fixed options have run out, send us the address and we will check the nbn position, model the obstruction risk and tell you honestly whether Starlink is the right primary, the right failover, or the wrong answer. Call 1300 028 324 or use the form at techassist.au/contact.

You have just opened a second office and someone has asked how to connect it to the first one. In most Australian SMEs in 2026 the correct answer is that you do not connect them at all. Both sites get their own internet service, both reach the same cloud services independently, and there is no tunnel between them.

A site-to-site link is not a default. It is a specific answer to a specific dependency, and if you cannot name the dependency in one sentence, you do not have one.

The ladder, in order of cost and complexity

There are four honest options and they are not equally likely to be right.

Option one: nothing. Two independent sites, each with its own internet connection, firewall and wireless. Identity, email, files, phones and line-of-business applications are all cloud services that both sites reach over the public internet. Nothing at site B depends on anything at site A.

Option two: a site-to-site VPN. An encrypted tunnel between the two firewalls so that devices at one site can reach devices at the other by IP address. Cheap, well understood, and the source of most of the problems in this article.

Option three: SD-WAN. Software-defined WAN, which in practice means a managed overlay that builds and monitors tunnels automatically across whatever underlying links you have, steers traffic by application, and fails over between links when one degrades. Both major SME platforms include it: Ubiquiti’s Site Magic in UniFi Site Manager automates tunnels between UniFi gateways, and Cisco Meraki’s Auto VPN does the same across the Meraki dashboard, with the application-aware path selection and cellular failover behaviour sitting under the Secure SD-WAN Plus licence edition.

Option four: a carrier-provided private link. A Layer 2 or Layer 3 service bought from a carrier that joins the two sites as if they were one network, with a contractual service level attached. In Australia this generally sits on dedicated fibre, of which nbn Enterprise Ethernet is the wholesale product, delivered over point-to-point fibre with symmetrical speeds. The carrier owns the path and the fault.

When each one is actually justified

Take option one, nothing, unless you can name the dependency. This is right for the large majority of professional services, retail, health and trades businesses opening a second location in 2026, because their entire working set is already in Microsoft 365 or Google Workspace. Two independent sites is not a compromise. It is a more resilient design than a hub and spoke, because a failure at head office does not take the branch offline.

Take option two, site-to-site VPN, when a small number of specific systems live at one site and are needed at the other. A practice management server, a CAD or drawing store, a line-of-business database, a legacy application that has to be on a LAN. The tunnel is justified by named systems and it is sized around those systems, not around everything.

Take option three, SD-WAN, when you have three or more sites, or when the link genuinely matters. The value is not the tunnel, it is not having to build and maintain each tunnel by hand, and having a console that tells you which link is degraded before staff do. If you already run UniFi or Meraki across both sites, you effectively have this available already, so the question is only whether to turn it on. Where SD-WAN earns its keep is failover: two internet services at each site with automatic path selection turns a carrier outage into a slow morning rather than a closed office.

Take option four, a carrier private link, only when you have a real-time dependency with a contractual consequence. Voice or video that must not degrade, a clinical or manufacturing system with a latency requirement, a data replication obligation with a recovery time objective you have committed to in writing. Note that the relevant part of the purchase is the service level rather than the bandwidth. nbn Co lets providers add enhanced service levels to business services, defined across an operational period (the hours during which faults can be worked), a response time, and a rectification time for faults within nbn’s control. That is what you are buying. Bandwidth you can buy anywhere.

Before you price any of this, check what nbn technology serves each address, because the two sites may be on completely different technologies with completely different upload capability, and that alone can settle the design. In the outer east and the Dandenong Ranges in particular, the address determines the option set more than the budget does, which we cover in business internet in the outer east.

The real problem is identity and file access, not the tunnel

Businesses ask how to connect two offices when the question they actually have is how someone at site B logs in and opens a file that someone at site A created. Those are different problems and only one of them is solved by a network.

Identity has to be single, and it does not care where the person is sitting. One directory, one account per person, one set of multi-factor authentication and conditional access rules, applied consistently at both sites. If site B was set up in a hurry with its own local accounts, or its own tenancy, you have created two of everything: two joiner processes, two leaver processes, and one account you will forget to disable. In a Microsoft environment this means Microsoft Entra ID as the single authoritative directory with Conditional Access doing the policy work, and in a Google environment it means single sign-on configured at the Workspace level. Whichever you use, the answer is one directory, not one per building.

File access is where the tunnel gets built for the wrong reason. If both sites work out of SharePoint, OneDrive or Google Drive, there is nothing to connect: both sites reach the same service over the internet and the local cache on each laptop does the rest. If there is a file server at head office, a VPN will make it reachable from the second site and it will be miserable to use, because opening a large file over a WAN link is not the same experience as opening it over a LAN. The correct fix is almost always to move the files to cloud storage, not to buy a bigger tunnel. Do it before you open the second site if you can.

Whichever way the files go, they need to be backed up independently of either site, and you should know where your data actually lives before an audit or a client security questionnaire asks you.

Printing and phones: two small problems with different answers

Printing is not a WAN problem and should never be one. Nobody at site B should print to a printer at site A. Each site has its own printers, and the only thing that needs to be central is the print management and driver deployment, which modern cloud print services and endpoint management handle without any site-to-site connectivity. If your current design routes print jobs across a tunnel, that is a leftover from a print server that should have been retired.

Phones are genuinely easier across sites than within one site. A cloud or hosted phone platform treats both offices as extensions of the same system, with internal extension dialling, shared call queues, a shared receptionist and one set of numbers, and none of it depends on a link between the buildings, because both sites register to the platform independently. This is the single strongest argument for getting off any phone system with physical dependency on a building before you open the second site, and the options are compared in choosing a business phone system.

What phones do require at each site is a decent upload path and quality of service configured locally. Voice quality problems at a branch are nearly always a local internet or local network issue, not a distance issue.

“The second site feels slow” is almost never the second site

This complaint arrives within a month of opening and it is worth knowing what it usually turns out to be, because the reflex fix (buy more bandwidth) almost never works.

  • All internet traffic is being hairpinned through head office. Someone built the tunnel as a default route so the branch would inherit head office’s firewall and filtering. Now every Teams call, every web page and every cloud file request at site B travels to site A and back out, adding latency to everything and limiting the branch to head office’s upload speed. This is the single most common cause.
  • DNS is pointing at a server at the other site. Every lookup crosses the tunnel. If the tunnel wobbles, the branch appears to lose the internet entirely even though its own connection is fine.
  • A file server at head office is being used as if it were local. See above. Bandwidth does not fix latency and file protocols are latency sensitive.
  • Head office’s upload speed is the ceiling. If site A is on an asymmetric service, every branch user is sharing that upload. This is why the head office link, not the branch link, is usually the one that needs upgrading.
  • It is not the WAN at all, it is the wireless. Access points placed by eye in a new fit-out, or a single access point covering a floor plate it cannot cover. Test with a laptop on a cable before you blame the link.

Diagnose in that order. The number of times the answer has genuinely been “the branch needs a faster internet service” is much lower than the number of times it was assumed.

Do not build something that needs a network engineer to change

This is the constraint that should shape the whole design, and it is the one that gets ignored because the person building it is comfortable with complexity.

A two-site network in a 40-person business will be modified by whoever is available on the day: a new VLAN for a camera system, a firewall rule for a new application, a subnet change because someone bought a new appliance. If those changes require reading a routing table, the business is now dependent on one person or one provider, and every change becomes a ticket with a lead time.

Three rules keep it maintainable:

  1. Use non-overlapping, obvious IP addressing from the start. Site A on one clearly numbered range, site B on another, with room to add site C. Two sites that both use 192.168.1.0/24 cannot be joined without renumbering one of them, and renumbering a live site is a weekend nobody enjoys.
  2. Keep both sites on the same platform and the same management console. Whatever you pick, pick one, so that a change looks the same at both sites. This is a real argument in the platform you choose for each site, and it is why the automated overlay options are worth more than their feature lists suggest: they generate the tunnel configuration rather than asking a human to.
  3. Write it down. The addressing plan, the tunnel endpoints, the firewall rules and why each one exists, the circuit IDs and carrier account numbers for both sites. If it is not written down where the next person can find it, the design is only as durable as one person’s memory.

The direction this is all heading, and why it argues for doing less

The reason “connect nothing” is a defensible answer in 2026 and would not have been ten years ago is that the security model has moved. Access decisions are increasingly made on identity, device compliance and context rather than on which network a device is plugged into, which is the premise behind SASE and zero trust network access as a replacement for the VPN. In that model, a tunnel between two buildings buys you very little, because being on the network is no longer what grants access to anything.

Practically, that means the money is better spent on identity and endpoint security than on the link. A second site with strong conditional access, managed devices and cloud file storage is more secure and easier to run than two sites joined by a flat tunnel, where a compromise at the branch reaches head office because the firewall between them was configured to allow everything.

A short decision path

Ask these in order. Stop at the first yes.

  1. Is there a system at one site that people at the other site must reach directly by IP? If no, connect nothing. Give each site its own internet service and its own firewall, and finish.
  2. Is it one or two named systems? Build a site-to-site VPN scoped to those systems only, not a default route, and plan to retire it when the systems move to cloud.
  3. Do you have three or more sites, or does an outage at either site cost real money? Use the SD-WAN capability you already own in your network platform, with a second internet service at each site for failover.
  4. Do you have a real-time dependency with a written recovery obligation? Buy a carrier private link with enhanced service levels, and buy it for the service level.

Most businesses stop at one. Some stop at two. Very few genuinely need four, and the ones that do usually know why.

If you are opening a second site in the next few months, the connectivity order and the identity design are the two things worth getting right before anything is installed, and both have longer lead times than people expect. Call TechAssist on 1300 028 324 or get in touch at https://techassist.au/contact/ and we will map the honest option for your two addresses. If the second site is also a relocation, work through the office move runbook alongside it.

An office move fails on connectivity or it fails on phones. Everything else can be recovered on the Monday. The single decision that determines whether your move is calm or catastrophic is when you place the carrier order, and almost every business places it far too late because it is waiting on a lease that is still with the lawyers.

This is the sequence we run. The week markers below are our planning schedule rather than published vendor lead times, and where a carrier or regulator publishes an actual figure we say so explicitly.

Twelve weeks out: three decisions, one of which cannot wait for the lease

Three things get decided at twelve weeks. Two of them are cheap to change later. One is not.

Decision one, and the urgent one: what connects the new site to the internet. Order this before the lease is signed if you possibly can, on a conditional basis, because carrier delivery is the longest single item on the critical path and it does not care about your moving date.

Start by checking what serves the address. nbn Co’s address checker will tell you whether a premises is ready to connect, whether more work is required, or whether it is not currently available, and the technology serving it. That check is free and takes a minute. If the building is served by a non-nbn network such as Opticomm, the process runs through that operator instead. If you need symmetrical, higher-grade connectivity, nbn Enterprise Ethernet is the wholesale product, delivered over dedicated point-to-point fibre wherever nbn has declared the fixed line footprint ready for service, and where fibre is not already in the building it requires a build.

nbn publishes no build or delivery time for Enterprise Ethernet. Its customer-facing pages say only that it will work with your provider to confirm a committed delivery date. The single delivery figure in nbn’s published material is in the wholesale agreement, in the Service Levels Schedule for the Enterprise Ethernet product module, and it is an operational target that nbn states is non-binding, aspirational and not reported to the retail service provider: nbn aims to provide a Committed Delivery Date within 10 business days of the Order Accepted Notification. That is ten business days to be given a date, not ten business days to be connected.

Once the Committed Delivery Date exists it does carry weight, but the weight falls on the wrong side of the counter. If delivery is late against it, nbn pays rebates to your retail service provider, not to you: for an Ordered Product with a Committed Delivery Date on or after 15 November 2021, 100 per cent of the monthly recurring charge whether delivery runs 5 to 9 business days late or 10 business days or more late. That will not fund a fortnight of not trading.

So treat the timeline as entirely retail service provider dependent, which is exactly why it belongs at week twelve rather than week four. Get the Committed Delivery Date in writing from the retail service provider, with the slip terms, and get it before you commit to a moving weekend.

Two things to specify while you are ordering. First, whether you want enhanced service levels. nbn Co lets providers opt in to enhanced service levels on business plans, and defines them across three components: the operational period (the hours during which faults can be worked), the response time, and the rectification time for faults within nbn’s control. A standard consumer-grade service can be restored on a timeline that would be unacceptable for a business that cannot trade without it. Second, order a backup path at the same time. A 4G or 5G failover service, or a satellite link, ordered on day one costs a fraction of what it costs to arrange in a panic in week eleven. If the address is marginal, read business internet options in the outer east and work out which nbn technology serves the address before you assume anything.

Decision two: whether the phone numbers move with you. If you are still on any service with physical dependency on the old address, the numbers have to port, and porting is the second-longest item on the critical path. More on the mechanics below, but the decision is made now.

Decision three: what the new site’s network will be. Platform choice, switch count, access point count, whether the comms room needs a rack or a wall-mounted cabinet. This drives the cabling design, which drives the electrician and the builder, which is why it has to be settled before anyone touches the walls. The comparison is in which network platform the new site should run.

Ten weeks out: survey the new premises properly

The site survey is not a walk-through. It produces a drawing.

Walk the floor plate with the person who will do the cabling and mark: every desk position and how many outlets each needs, every wireless access point position, every printer, every camera, every door with access control, every screen, and the comms room. Note ceiling type and height, because it determines cable pathway and access point mounting. Note where the building’s lead-in and any existing carrier equipment sits, because your comms room wants to be near it.

In the comms room, confirm three things that get missed: dedicated power circuits with enough outlets, ventilation or cooling adequate for a sealed room in a Melbourne February, and physical security. A cabinet in an open corridor that anyone can walk up to is not a comms room. The detail is in designing the comms room and the cabling standards in structured cabling done properly. Work out the UPS you need now, not when the rack is already full.

Two survey items that consistently get skipped. First, meeting rooms: measure them, decide the AV approach, and specify the table power and cable runs before the joiner builds the table. Retrofitting power to a boardroom table is expensive and ugly. Read meeting room AV before you sign off on room design. Second, wireless: do a real predictive design rather than spacing access points evenly, because plasterboard, glass partitioning and metal racking behave very differently.

Finally, agree the labelling scheme now and put it in your documentation set. Every outlet, every patch panel port, every switch port. Do it once at the front and you never do it again.

Eight weeks out: submit the port, and understand what you have submitted

Number porting in Australia runs under the Local Number Portability Code, C540:2023, registered by the ACMA on 1 June 2023. The code introduced completion timeframes where previous versions had none. For a single number being ported, the ACMA states the code generally requires telcos to complete 80 per cent of ports within 8 business days, 90 per cent within 10 business days, and 98 per cent within 15 business days, with the timeframes varying by the number of services and the complexity of the port.

Read that carefully, because most businesses moving office are not porting a single number.

Simple versus complex is the distinction that matters. A simple port (Category A) is a single standalone number. A complex port (Category C) covers multiple lines, DID number ranges, and ISDN services. The percentile timeframes above apply to single-number ports. Complex ports are project managed manually between nominated contacts at the losing and gaining carriers, with a mutually agreed cutover date, and the code does not set a maximum completion timeframe for them. If your business has a main number with a block of direct dial numbers behind it, you have a complex port, and you should treat the timeline as open ended until the carriers agree a date in writing.

Practical points that prevent rejections:

  • The Customer Authority is valid for 90 days from signature. Sign it too early and it expires before the port runs. This is a documented rejection ground.
  • Account details must match exactly. The account number with the losing carrier, the account name, and the service address as the losing carrier holds them. A trading name where the carrier holds a company name will fail.
  • A losing carrier cannot reject a port because you are still in contract. The ACMA’s guidance to telcos is that they must tell a customer about the costs of changing providers, including contract terms, but that is not a basis to block the transfer. Exit fees may still be payable. The port still proceeds.
  • Other valid rejection grounds include the service being disconnected or pending disconnection, a port already pending on that number, the number no longer being with that carrier, and insufficient information supplied.

If you are moving to a cloud phone system anyway, the move is the right moment. Numbers ported to a hosted 3CX system stop being tied to a physical address at all, which removes this problem from every future move. Whoever sells you the voice service takes on obligations under the Telecommunications Consumer Protections Code, C628:2019 as varied in 2022, which is the currently registered version, and the Telecommunications Industry Ombudsman is the external dispute resolution path if it goes wrong. That is covered in what the TCP Code means when your IT provider sells you phones.

Six weeks out: settle the data and server position

Where your data lives determines how hard the weekend is.

If everything is in Microsoft 365 or Google Workspace, and there is no on-premises server, the weekend is easy. People carry laptops to a new building and sign in. Nothing moves. This is the strongest single argument for finishing a cloud migration before a move rather than after it.

If there is an on-premises server, decide now whether it moves or retires. Physically relocating a server is the highest-risk item in the entire move: it has been running for years, it may not survive a power cycle, and its disks do not enjoy being carried down stairs. If it is at end of life, the move is the natural retirement point and the cost of replacing it now is lower than the cost of moving it and replacing it in eighteen months anyway.

Whatever you decide, this is the week you verify that backups you have actually tested restore. Not that they ran. That they restore. Take a full verified backup immediately before anything is unplugged, and keep a copy off site and offline through the entire move.

Also at six weeks: line up the printers. Multifunction devices are usually on a lease with the supplier responsible for relocation, and their calendar is not your calendar. Book the de-install and re-install now, confirm the new IP addressing, and confirm scan-to-email and scan-to-folder settings will be reconfigured, because they always break.

Four weeks out: the sequence that has to hold

By four weeks you should be able to state the following as facts, not hopes:

  • The carrier has a confirmed installation date at the new site, and it is at least two weeks before the move, not the Friday of it.
  • Cabling is scheduled and the comms room will be ready to accept equipment before the movers arrive.
  • The port has a confirmed cutover date and time agreed by both carriers.
  • Every asset that is moving is on an accurate asset register, with a destination location.
  • Building access is arranged for the weekend, including loading dock booking, lift booking and after-hours security access for both buildings.

If the carrier date is not confirmed at four weeks, escalate now and plan a fallback: a temporary 4G or 5G service and a Starlink terminal will keep a business trading for a few weeks, badly but functionally, and arranging that at four weeks is a decision. At four days it is a crisis.

Two weeks out: bring the new site live before you need it

This is the step that separates a calm move from a bad one. Get the new site’s internet, network and wireless working, tested and signed off two weeks before anyone moves into it.

Install the gateway, switches and access points. Bring the carrier service up and test it under load, not with a single speed test. Configure VLANs, wireless, firewall rules and remote access. Put a laptop and a printer on it and use them. Find the problems in a quiet building with two weeks to fix them, rather than at nine o’clock on a Monday morning with 60 people watching.

For a period you will be running both sites simultaneously, which is a small version of the problem in running two sites at once. Keep it deliberately simple: both sites reach the same cloud services independently, and nothing at the new site depends on the old one.

The weekend, hour by hour

Assume a Friday close and a Monday open. The critical instruction: do not port numbers on the Friday of the move.

The reasoning is in the code text, and it is worth quoting because it sets the window you are working inside. C540:2023 defines Standard Hours of Operation as “8 a.m. to 5 p.m. (Standard Time) on Business Days”, where Standard Time means Australian Eastern Standard Time or Australian Eastern Daylight-Saving Time. That is the window. The Code does not oblige a carrier to port outside those hours, and where a carrier does agree to port outside them, that port normally runs through the complex Cat. C process.

Two more numbers from the same code that shape a move. For a complex port, the minimum lead time for a cutover date within Standard Hours of Operation, measured from the gaining provider receiving a valid Complex Port Confirmation Advice, is 5 business days, and losing carriers must support 85 per cent of gaining provider requests for a cutover date within those hours. Rejections on a complex port also have their own clock: the losing carrier must issue a reject advice for 90 per cent of failed validations within three business days and 99 per cent within five business days. Build that into your schedule, because a rejection you learn about on day five costs you a fortnight.

Now apply it. If a Friday port fails or partially completes at four in the afternoon, the window closes at five, the people at both carriers who can fix it have gone home, and you spend the weekend with numbers that ring nowhere and no way to escalate. Port on a Tuesday or a Wednesday, early in the window, with the old service still live and calls forwarding, and keep the whole week either side clear.

The sequence:

Friday, from midday. Last full verified backup. Users log off and shut down. Label and photograph every cable at the back of every device before anything is unplugged, including the server, the rack and the printers. Confirm the old site’s internet stays live over the weekend.

Friday afternoon. Decommission the old comms room. Rack equipment out, patch leads bagged and labelled, switches boxed. Anything not moving goes into a separate, clearly marked pile for disposal, not into the skip.

Friday evening to Saturday morning. Physical transport. The server, if it is moving, travels separately and carefully, not on a pallet with the desks.

Saturday. Rack and cable the new comms room. Patch and test every desk outlet, port by port, against the labelling scheme. This is slow and it is the reason you did the labelling properly. Bring up the server if there is one and verify services before anyone touches a desk.

Saturday afternoon to Sunday. Deploy desk equipment. Every workstation, monitor, dock and phone placed, connected and powered on. Test each desk with a real login, not a link light. Install and test printers, including scan destinations. Test the meeting rooms with a real call on each platform you use.

Sunday. Full walk-through with a checklist. Wireless coverage tested in every corner, including stairwells and the kitchen. Door access and cameras tested. Alarm tested. Sign off, or list what is outstanding and who is fixing it Monday morning.

The first Monday

Have people on site, physically, from before the first staff member arrives. Not on a phone queue. On the floor.

The Monday problems are predictable: a desk that was patched to the wrong port, a printer that will not scan, someone whose docking station did not come, a meeting room that will not connect, and a wireless dead spot behind a filing cabinet nobody surveyed. All small, all fast to fix, all catastrophic to a business’s confidence if the response is a ticket number.

Run a defect list for the whole first week rather than fixing things ad hoc. Everything gets logged, triaged and closed, and at the end of the week you have a record of what the fit-out got wrong, which is worth having when you talk to the builder.

The old site: decommissioning and make-good, which the landlord will invoice you for

This is the part businesses forget until the invoice arrives, and it is genuinely expensive.

Read your make-good clause before the move, not after it. Commercial leases commonly require the premises to be returned to their original condition, and in practice that means removing what you installed. For IT, that typically covers your data cabling, including cable in ceiling and floor spaces, your comms room fit-out including the rack and any cabinets, wall-mounted screens and their brackets, access control hardware on doors, camera mounts, and any penetrations made through walls, floors or ceilings, which have to be patched and made good. Some landlords require the cabling to be removed. Some require it to be left in place. Some require it to be left and certified. These are opposite obligations and only your lease tells you which one applies.

Budget for it and schedule it. Cable removal after the fit-out contractor has left, in an empty building, with a lift booking, is not a job you want to be arranging in the week the keys are due back.

Terminate the services, in the right order. Cancel the old site’s internet service only after the new site has been stable for a period and after any porting has fully completed. Cancel building access, alarm monitoring and any service tied to the old address. Then check the next invoice, because services keep billing long after they stop being used and nobody notices for months.

Deal with the equipment properly. Anything not moving falls into three categories: redeployed, sold or traded, or disposed of. Every device in the last two categories has data on it, including printers and multifunction devices, which hold scanned documents on internal drives, and cameras and access control controllers, which hold footage and personal information. Disposal without a certificate of data destruction is a Privacy Act problem waiting to become a notifiable data breach. The process is in secure device disposal.

Update the documentation. New addresses, new subnets, new device locations, new circuit IDs, new carrier account numbers. If the documentation still describes the old building in six months, the move is not finished.

If you are planning a move and want the carrier order placed before it is too late, that is the one call worth making early. Call TechAssist on 1300 028 324 or get in touch at https://techassist.au/contact/, and we will tell you what the realistic critical path looks like for your specific address and your specific numbers. If you are also fitting out the new space, start with the fit-out checklist for the new premises.

Ready to Make IT Your
Competitive Advantage?

Book a free consultation with our team. No pressure, no jargon — just a clear-eyed look at where you stand and what's possible.