# USG Gateways and UniFi Network 10.6

> Ubiquiti has announced that UniFi Network 10.6 is the last release that can manage the USG, USG-Pro-4 and USG-XG-8. Your USG keeps working today. This page explains what changes when Network 11 arrives, how that differs between UniFi OS Server and the standalone Network Application, and how to replace a USG with one of Ubiquiti's UXG gateways.

---
## What Ubiquiti announced

- **UniFi Network 10.6 is the last release that can manage the USG, USG-Pro-4 and USG-XG-8.**
- 10.6 is also the last release of the standalone Network Application. Network 11 and later will only be released for UniFi OS Server.
- Ubiquiti hasn't given a release date for Network 11.

Your network isn't affected now. On 10.6 and earlier releases a USG is fully managed, as it is today.

## What Network 11 means for a USG

Once a console is running Network 11:

- The USG **keeps running with its current settings** and keeps passing traffic.
- You **can't change its settings** from the Network application.
- It **can't be adopted again**. If the USG is factory reset, fails or is swapped for another USG after that point, it can't be brought back under management.

So the USG doesn't stop working on the day Network 11 is installed, but from then on it is frozen. We recommend replacing it with a UXG gateway before that happens.

## If your console runs UniFi OS Server

UniFi OS Server installs new Network releases automatically when Auto Update is on. When Ubiquiti releases Network 11, your console will install it at the time set in its update settings.

You have two options:

1. **Replace the USG before Network 11 arrives.** This is what we recommend. See [Swapping your USG for a UXG](#swapping-your-usg-for-a-uxg) below.
2. **Hold your console on Network 10.6** by turning off Auto Update for the Network application. See [Holding a Network version](../unifi-os-server/updates.md#holding-a-network-version).

Holding 10.6 gives you time to plan, but treat it as temporary. Ubiquiti hasn't said how long 10.6 will receive fixes, and a held console doesn't get new Network features or fixes.

## If you run the standalone Network Application

The standalone Network Application stays on 10.6, so your USG keeps working as it does today. Nothing forces a change.

If you move to UniFi OS Server with us, the USG keeps working there too. Once Network 11 is installed on your console, it keeps running but can't be changed or adopted again. A USG never stops you moving: you can move now and replace the USG later, or replace it first. See [The standalone Network Application after 10.6](../standalone-unifi/network-10-6-last-release.md).

## Choosing a replacement

Your Cloud UniFi controller can adopt Ubiquiti's **UXG** gateways. Ubiquiti sells them as the Gateway Lite, Gateway Max, Gateway Fiber, Gateway Pro and Gateway Enterprise.

| Model | IDS/IPS throughput | Ports | Form |
|---|---|---|---|
| [UXG Lite](https://techspecs.ui.com/unifi/advanced-hosting/uxg-lite) | 1 Gbps | 2 x GbE RJ45 (1 WAN, 1 LAN) | Desktop |
| [UXG Max](https://techspecs.ui.com/unifi/advanced-hosting/uxg-max) | 2.3 Gbps | 5 x 2.5 GbE RJ45, up to 4 WAN | Desktop |
| [UXG Pro](https://techspecs.ui.com/unifi/advanced-hosting/uxg-pro) | 3.5 Gbps | 10G SFP+ and GbE RJ45 ports, up to 3 WAN | 1U rack |
| [UXG Fiber](https://techspecs.ui.com/unifi/advanced-hosting/uxg-fiber) | 5 Gbps | 1 x 10 GbE RJ45, 2 x 10G SFP+, 4 x 2.5 GbE RJ45 | Desktop |
| [UXG Enterprise](https://techspecs.ui.com/unifi/advanced-hosting/uxg-enterprise) | 12.5 Gbps | 2 x 25G SFP28, 2 x 10G SFP+, 2 x 2.5 GbE RJ45, up to 5 WAN | 1U rack |

Figures are from Ubiquiti's published tech specs. Check the linked pages before you buy, as Ubiquiti updates them.

**How to choose:**

- **Internet speed.** Pick a model whose IDS/IPS throughput is above the speed of your internet connection. That figure is the realistic one with threat protection turned on.
- **Number of internet connections.** If you use a second WAN for failover, check the WAN port count.
- **Where it goes.** The Lite, Max and Fiber sit on a desk or shelf. The Pro and Enterprise mount in a rack.

As a rough guide, a USG on a typical office connection is usually replaced by a UXG Lite or UXG Max. A USG-Pro-4 in a rack is usually replaced by a UXG Pro, and a USG-XG-8 by a UXG Pro, UXG Fiber or UXG Enterprise, depending on speed and ports.

## Swapping your USG for a UXG

Your internet connection is down from the moment the USG is unplugged until the UXG is adopted and has its settings. Plan the swap for a quiet time and have someone on site.

### Before you start

- Make a note of your **WAN settings**: connection type, PPPoE username and password, or static IP details. Your internet provider can give you these if you don't have them.
- Make sure you have a recent backup. The **Backups** tab on your service in the [customer portal](https://portal.cloudunifi.com) lists recent backups you can download.
- Have the UXG unboxed and powered up nearby.

### Steps

1. **Forget the USG** in the Network application: open the USG in your device list and choose **Forget** from its settings. A leftover USG record can block the new gateway from adopting, so do this first. Forgetting also resets the USG, so do it at the start of your planned outage.
2. **Unplug the USG** and connect the UXG in its place: your modem or internet line to the UXG's WAN port, and your switch to a LAN port.
3. **Adopt the UXG** to your controller. Follow [Adopting UniFi UXG Lite, Pro and Max](adopting-unifi-UXG-Pro.md).
4. **Check your settings** once the UXG shows as Online:
    - **WAN:** the connection type and details match what you noted, and the internet is working.
    - **Networks:** your networks, VLANs and DHCP ranges are in place.
    - **Firewall rules and port forwards:** each one you rely on is present and working.
    - **VPNs:** each VPN connects.
5. **Check your devices.** Access points and switches reconnect through the new gateway. Everything that was online before should be online again within a few minutes.

### What carries over to the new gateway

Most gateway settings belong to the site in the Network application, not to the USG itself, so they stay in the site when you forget the USG and apply to the UXG once it's adopted:

- **Networks and VLANs**, including their DHCP settings.
- **Port forwards.**
- **Firewall rules.**
- **Static routes.**

Some things need more attention:

- **WAN settings.** Port layouts differ between models, so check the UXG is using the right WAN port and connection type.
- **VPNs.** Check each VPN connects after the swap. If your public IP address changes, update the other end of any site-to-site VPN. For remote users, Ubiquiti recommends WireGuard or Teleport over L2TP, and WireGuard needs a UXG, so the swap is a good time to move remote users across.
- **Custom gateway configuration.** If you used a `config.gateway.json` file to add settings the Network application doesn't offer, UXG gateways don't support it. Set up what you need in the Network application instead.

**Zone-based firewall.** The USG can't use Ubiquiti's zone-based firewall, which UXG gateways support. Once the UXG is adopted and you've checked your rules, the Network application offers an **Upgrade** under **Security > Traffic & Firewall Rules**, which turns your rules into zone-based policies that behave the same way. The upgrade can create more policies than you had rules; once you've tested them, you can remove any that are redundant.

## FAQ

### Is my network affected right now?

No. On Network 10.6 and earlier your USG is fully supported and fully managed. Nothing changes until your console runs Network 11.

### Do I need to do anything today?

No immediate action is needed. On UniFi OS Server, plan the replacement before Network 11 is released, or hold 10.6 while you plan. On the standalone Network Application, your USG keeps working on 10.6.

### When will Network 11 be released?

Ubiquiti hasn't given a date. We'll update this page and your portal notices when they do.

### Will my USG stop working when Network 11 arrives?

No. It keeps running with its current settings and keeps passing traffic. You won't be able to change its settings or adopt it again, so any change to your network that needs the gateway, or a USG that fails or is reset, means replacing it at that point.

### Can I use a Dream Machine or Cloud Gateway instead?

Not with your Cloud UniFi controller. Dream Machines and Cloud Gateways are consoles in their own right: they run their own Network application and can't be managed from your hosted controller. The UXG range is what your controller can adopt.

### Will my firewall rules, port forwards, VPNs and DHCP carry over?

Networks, DHCP, port forwards, firewall rules and static routes belong to the site, so they apply to the new gateway once it's adopted into the same site. Check your WAN settings and each VPN after the swap. See [What carries over to the new gateway](#what-carries-over-to-the-new-gateway).

### How long will the swap take?

Expect a short outage while the gateway changes over: from unplugging the USG until the UXG is adopted and online. With the WAN details to hand this is usually minutes, not hours, but plan a quiet time in case something needs attention.

### The notice says I have a USG, but I've already replaced it

The old USG is probably still in your device list. Forget it in the Network application. Our checks refresh every 15 minutes for most services and daily for some, and the notice clears after the next check.

### My USG is offline and no longer used, but it still shows

Forget it in the Network application. An offline USG still counts while it's in your device list.

### Can I still move to UniFi OS Server with a USG?

Yes. A USG never blocks the move. It keeps working on UniFi OS Server until Network 11 is installed, then keeps running but can't be managed. You can move now and replace it later.

### Can Cloud UniFi do the swap for me?

The swap needs someone on site, so we can't do it for you. We're happy to answer questions before and after: email support@cloudunifi.com or use the chat in the customer portal.
