Cloud Gateway Fiber
UniFi Cloud Gateway Fiber: SFP+ from the ISP, Cleanly
Fiber internet arrives at most homes as an awkward compromise: the ISP drops off a little plastic ONT, hangs a router off it that you did not ask for, and now you have two boxes doing the job of one, double NAT if you are unlucky, and a Wi-Fi radio you will never enable sitting in a device you cannot turn off. The UniFi Cloud Gateway Fiber (UCG-Fiber) exists to collapse that stack. It has an SFP+ WAN port, which means that in the right circumstances the fiber can terminate directly into the gateway and the ISP's router disappears from your rack entirely. That is the appeal, and it is a real one — but "in the right circumstances" is carrying weight in that sentence, and this post is about unpacking it.
The short version: the UCG-Fiber is a compact, fanless UniFi gateway that runs the Network controller on-box and takes an SFP+ uplink at up to 10 Gbps. Whether you can feed it straight from the ISP depends on how your fiber is delivered and what your provider allows. What you can control completely is how it goes into the rack, and an SFP+ device deserves more thought about cable bend radius than the average box. The Unifi Cloud Gateway Fiber (UGC Fiber) 10" Rack Mount - 1U is the mount for the small-rack case; there is a 19-inch option too, and we will get to both.
What the UCG-Fiber actually is
In the UniFi gateway ladder, the Cloud Gateway Fiber slots in as the multi-gig gateway built specifically around a fiber uplink. The headline is the SFP+ WAN cage: a 10G-capable optical/DAC port on the WAN side, paired with a set of 2.5GbE ports for LAN and a secondary copper WAN. Exact port counts and the IDS/IPS throughput ceiling get revised between firmware and hardware revisions, so treat Ubiquiti's current spec sheet as the authority on the numbers — what matters for this discussion is the category: a gateway that expects its internet feed to arrive as light, not as an RJ45 handoff from someone else's router.
It runs UniFi OS with the Network application on the device itself. There is no separate controller to buy or host, which is the same convenience the Dream Machine line brought, delivered in a smaller, fanless chassis. For a homelab that has been running fiber into an ISP router and then into a UniFi switch, the UCG-Fiber is the part that lets you delete the ISP router from the topology and route with your own gear from the fiber inward.
Taking SFP+ straight from the ISP
Here is the part that decides whether the clean version of this build is available to you. Fiber-to-the-home is usually a passive optical network — GPON, or increasingly XGS-PON for the multi-gig tiers — and the ISP terminates that PON with an ONT (optical network terminal). The ONT is what speaks the provider's PON protocol and hands you Ethernet. There are three common delivery shapes, and they are not equally friendly:
- External ONT with an Ethernet handoff. The provider gives you a standalone ONT that outputs RJ45 or its own SFP. You plug that into the UCG-Fiber's WAN and route from there. This is the easy case — the ISP router, if any, becomes optional and you bypass it by taking the ONT's Ethernet directly.
- SFP ONT "stick" you provide. On some networks you can drop a PON SFP ONT module — a transceiver that is a whole ONT in an SFP form factor — directly into an SFP+ cage, provisioned with your ISP's parameters. When it works, the fiber literally lands in the gateway and there is no separate ONT box at all. Whether it works is entirely a function of your provider's provisioning and their willingness to authorize a customer-supplied ONT, which varies from "documented and supported" to "flatly refused."
- Gateway/ONT combo you cannot bypass. Some ISPs deliver an all-in-one that is difficult or contractually off-limits to replace. Here you are stuck running the provider's box in at least bridge mode and feeding the UCG-Fiber from it, which still works but keeps a box you wanted gone.
The realistic guidance is to find out which shape your service is before you assume the SFP+ port solves everything. If your ISP gives you an ONT with an Ethernet or SFP handoff, the UCG-Fiber build is clean. If they insist on their own combined unit, the gateway still earns its place as your router and controller — you are just bridging through their hardware to reach it.
Fiber, DAC, and the bend-radius problem
An SFP+ cage accepts more than one kind of cable, and the choice has real consequences inside a small rack. The three you will actually consider:
- Optical transceiver plus fiber patch. An SFP+ module (single-mode for anything the ISP delivers, multimode only if you are doing short in-rack runs) with an LC duplex or LC/APC patch cable. This is what you use when the fiber is genuinely optical end to end.
- Direct-attach copper (DAC). A fixed-length twinax cable with SFP+ ends molded on. Passive DAC is cheap, draws almost no power, and is the right answer for a short rack-internal 10G hop — gateway to switch, for instance — but it is not what connects you to a PON.
- SFP ONT module. The all-in-one PON transceiver described above, when your provider cooperates.
The specification that bites homelabbers is bend radius. Single-mode LC patch fiber has a minimum bend radius you have to respect or you introduce macrobending loss — light literally leaking out of the core at a tight turn. Standard fiber wants a minimum bend radius of roughly ten times the cable diameter, which lands around 30 mm for a typical 2 mm jacket. Bend-insensitive fiber built to ITU-T G.657.A2 or B3 tolerates much tighter turns, down to the 7.5–15 mm range, and it is worth buying specifically for a cramped enclosure. The failure mode here is subtle and infuriating: a patch cable crushed into a 10 mm turn behind the gateway does not fail outright, it just quietly raises your optical loss until the link flaps or negotiates down, and you spend an evening blaming the SFP.
The practical rule is to give any fiber patch a gentle service loop rather than a hard corner, and never let a cable tie cinch down on fiber the way you would on copper. A DAC, by contrast, has a stiff minimum bend radius of its own but fails gracefully — it is copper — so for the short in-rack 10G runs a DAC is the low-drama choice and the fiber discipline is reserved for the one cable that actually carries light.
The controller-in-the-box angle
Because the UCG-Fiber runs UniFi Network on-device, adopting it means your gateway and your controller are the same object. For a fiber homelab this is the quiet win that comes along with the SFP+ port. You are not just replacing the ISP router; you are consolidating the router, the controller, and (if you had one) the reason you were running a separate Cloud Key for Network into a single fanless device. Whether a Cloud Key still has a job after that is a real question — it does, but for UniFi Protect and its storage rather than for Network, which is a separate discussion.
The thing to size before you commit is the IDS/IPS ceiling. Deep packet inspection is the expensive workload in any gateway, and a multi-gig fiber tier can outrun the inspection throughput of a small box if you turn everything on. If you are on a symmetrical multi-gig plan and you want full threat management enabled, check the current inspected-throughput figure against your line speed rather than assuming a 10G WAN port means 10G of inspected routing. That is the honest gotcha with every compact gateway, UniFi or otherwise.
Mounting it in a 10-inch (and 19-inch) rack
The UCG-Fiber is small and fanless, which makes it an easy tenant thermally but a slightly fussy one for cabling, precisely because of the fiber. In a 10-inch homelab rack the Unifi Cloud Gateway Fiber (UGC Fiber) 10" Rack Mount - 1U holds the gateway flush to the rails in a single U and, more importantly, positions it so the SFP+ port has somewhere for its cable to go without a hard turn. Leave yourself vertical room below the device for the fiber's service loop; the whole point of respecting bend radius disappears if the mount forces the patch into the exact corner you were trying to avoid.
In a full-size rack the UCG Fiber / Unifi Cloud Gateway Fiber 19" Rack Mount - 1U does the same job against 19-inch rails, with more lateral room to run the WAN fiber off to a side and keep it clear of the copper. Both mounts are printed in PETG, which holds up fine against the modest warmth a fanless gateway sheds — this is not a device that is going to cook a bracket. Orient the unit so its passive venting is not pressed against a blanking panel or the device above it; fanless gear relies on convection, and convection needs an unobstructed path for the warm air to leave.
One placement note specific to the fiber build: keep the ONT, if you have a separate one, close to the gateway so the run between them is short and the fragile optical segment is as contained as possible. A tidy fiber homelab minimizes the length of cable that has to be treated with fiber-grade care, and mounting the gateway and its ONT in adjacent U helps you do exactly that.
Wrap-up
The UCG-Fiber's promise is a rack with one fewer box in it: fiber in, your router and controller in a single fanless unit, and the ISP's hardware retired. Whether you get the fully clean version depends on how your provider delivers PON — an Ethernet or SFP ONT handoff makes it easy, a locked-down combo unit makes it a bridge-mode compromise — so confirm your delivery shape before you count on the SFP+ port doing magic. Everything downstream of that, you control.
Treat the fiber as the one cable in the rack that has real rules: respect its bend radius, buy bend-insensitive patch for tight turns, give it a service loop, and never cinch a tie down on it. Mount the gateway so those rules are easy to follow rather than fighting the enclosure, and the UCG-Fiber becomes what it is meant to be — the quiet, single-box edge of a homelab that finally routes its own fiber.
Not sure which mount you need?
Search by device and we'll show the mount that fits it.
Find my mount →